Chrome adopts what may be the best protection yet against account takeovers
Summary
Chrome introduces device-bound session credentials (DBSCs) to curb session cookie theft and account takeovers by binding authentication to hardware roots like TPMs and secure enclaves. The feature, in limited release for Windows and macOS, signs authentication challenges with a private key stored in hardware, moving beyond passwords and shared secrets.