加载中... --°C -- · --% · --
|
加载中... --°C -- · --% · --

Chrome adopts what may be the best protection yet against account takeovers

Chrome adopts what may be the best protection yet against account takeovers
摘要

Chrome浏览器新增“设备绑定会话凭证”(DBSCs)功能,旨在防范因会话cookie被盗而导致的账户接管攻击。该机制在设备内置的安全芯片(如Windows的TPM、macOS和iOS的安全隔区)中存储唯一加密密钥,使会话凭证与特定设备绑定。此举针对用户已采用双因素认证等防护后仍日益猖獗的cookie窃取手段,为账户安全提供额外保障。

Google’s Chrome browser has added a new feature that could go a long way in preventing a form of account takeover that’s grown increasingly common as users adopt two-factor authentication, passkeys, and similar protections.

The new Chrome protection is known as device-bound session credentials (DBSCs). The measure stores a unique encryption key in a silicon-resident fortress that’s built into the device running the browser. On Windows machines, this fortress is called a TPM, short for Trusted Platform Module. On macOS and iOS, it’s known as a secure enclave. Other platforms have differing names. Recently released versions of Chrome for Windows and macOS generate a key that’s stored in this fortress.

An antidote to session cookie theft

DBSCs protect against the theft of session cookies, the unique strings of characters that websites store on browsers. Session cookies greatly speed up browsing on sensitive sites that require user authentication. Instead of requiring the exchange of credentials each time a user opens a new site page, the server sets a session cookie that effectively proves the user has already successfully logged in.

Read full article

Comments

转载信息
原文: Chrome adopts what may be the best protection yet against account takeovers (2026-08-11T20:59:52)
作者: Dan Goodin 分类: 科技
评论 (0)
登录 后发表评论

暂无评论,来留下第一条评论吧