HomeSecurityChrome "Device Bound Session Credentials": Hackers will not be able to use...

Chrome “Device Bound Session Credentials”: ​​Hackers won’t be able to use stolen cookies

Google has added a feature to Chrome called " Device Bound Session Credentials ," which ties cookies to a specific device , preventing hackers from stealing and using them to compromise accounts.

Device Bound Session Credentials

Cookies are files that websites use to remember users' information and browsing preferences and automatically log them into a service or website. These cookies are created after you log in to a service and verify with multi-factor authentication (MFA). So, on future logins, cookies can bypass (MFA) and that's why hackers "hunt" them.

Often, they use malware to steal cookiesand compromise connected accounts.

See also: PayPal: Strengthening account security by detecting stolen super-cookies

To solve this problem, Google is bringing the “Device Bound Session Credentials” (DBSC) feature to Chrome, which makes it impossible for attackers to steal your cookies. After enabling DBSC, the authentication process is tied to a specific new public/private key pair generated using your device’s Trusted Platform Module (TPM) chip, which cannot be exported and is stored securely on your device. This way, even if hackers steal cookies, they won’t be able to access your accounts.

“ We believe this will significantly reduce the success rate of cookie-stealing malware . Attackers will be forced to act locally on the device, which makes detection and cleanup on the device more effective ,” a Google engineer said

See also: How to enable or disable cookies in Google Chrome

The feature is still in the prototype phase, but you can try out DBSC by going to chrome://flags/ and enabling the “enable-bound-session-credentials” flag in Windows, Linux, and macOS Chromium-based web browsers.

“Device Bound Session Credentials” allows a server to start a new session with your browser and associate it with a public key stored on your device, using a dedicated API. Each session is backed by a unique key to protect privacy , with the server only receiving the public key used to verify ownership later. DBSC prevents websites from tracking you across different sessions on the same device, and you can delete the keys it generates at any time.

Chrome cookie hacker

"When fully deployed, consumers and enterprise users will automatically receive upgraded security for their Google accounts," the company said.

“We are also working to bring this technology to our Google Workspace and Google Cloud customers so they have another layer of account security“.

See also: Google: Fixed two zero-day vulnerabilities in Chrome

Google Chrome's new 'Device Bound Session Credentials' security feature significantly enhances user security. It will effectively block the misuse of stolen cookies, as hackers will not have access to the cryptographic keys required to use them. This means that even if a hacker manages to steal a user's cookies, they will not be able to use them to compromise account unless they have access to the device itself.

Additionally, the new security feature may encourage users to browse in incognito mode more often, as cookies are not stored after the session is closed. This may also help protect user.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Finally, it is important to note that although the new security feature offers additional protection, users should continue to be vigilant with the security of their devices, regularly update software, and implement security best practices.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS