Chrome Introduces New Standard to Prevent Account Takeovers

Photo: Ars Technica
Quick answer
Google Chrome is rolling out Device-Bound Session Credentials (DBSC), a security feature that binds active sessions to devices, making account takeovers via stolen cookies nearly impossible.
Google has announced the integration of Device-Bound Session Credentials (DBSC) into the Chrome browser, a new security technology designed to prevent widespread account takeovers through stolen session cookies—a common tactic among cybercriminals.
DBSC works by binding active user sessions to specific devices. Even if attackers gain access to cookies, they cannot use them on other devices, drastically reducing the effectiveness of such attacks. Developed in collaboration with industry partners, DBSC may become a new security standard for web services.
Currently, DBSC is undergoing testing in experimental Chrome builds. If trials succeed, the mechanism will be integrated into stable browser versions, enhancing security for millions of users globally. Google is also urging web service developers to adopt the initiative to foster a unified security ecosystem.
Common questions
- What is Device-Bound Session Credentials (DBSC)?
- DBSC is a technology that binds active user sessions to a specific device, preventing hackers from using stolen cookies on other devices. This significantly enhances account security against unauthorized access.
- How does DBSC protect against account takeovers?
- DBSC blocks session transfers to other devices, even if hackers obtain session cookies. This makes stolen session data far less effective for unauthorized account access.
- When will DBSC be available in Chrome?
- The technology is already being tested in experimental Chrome builds. While no official release date has been announced, it is expected to become a standard security feature in future browser versions.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml