-
Notifications
You must be signed in to change notification settings - Fork 19
Closed
Labels
Description
Introduction
Device Bound Secure Credentials (DBSC) aims to reduce account hijacking caused by cookie theft. It does so by introducing a protocol and browser infrastructure to maintain and prove possession of a cryptographic key.
This proposal offers two important features that we believe makes it easier to deploy than previous proposals. DBSC provides application-level binding and browser initiated refreshes that can make sure devices are still bound to the original device.
Feedback
I welcome feedback in this thread, but encourage you to file bugs against Device Bound Secure Credentials.
arnar, sameerag, jawnsy and backkem