JALURI 17,453 SUMMARIES / 50 SOURCES
SEARCH LAST PASS 07:00 ATOM

Google Just Killed A Major Hacker Strategy

Google Chrome and other Chromium-based browsers have introduced "device-bound session credentials" to enhance security by encrypting cookies with a cryptographic key stored in the computer's TPM module, preventing session hijacking even if cookies are stolen.

MAIN POINTS FROM TRANSCRIPT
  1. Device-bound session credentials encrypt cookies using a TPM module key.
  2. This feature prevents session hijacking by making stolen cookies useless.
  3. Previously, app-bound session credentials offered limited protection.
  4. The feature is available in Chrome version 146 and other Chromium browsers.
TAKEAWAYS
  1. Device-bound credentials enhance security against "pass the cookie" attacks.
  2. Websites must implement this feature for it to work.
  3. A TPM module is required on the computer for functionality.
  4. Users can verify the feature in Chrome dev tools under the Network tab.
WATCH ON YOUTUBE