Elektrine lite

← Feed

@neilmadden@infosec.exchange

Post #4492989

2026-08-11 08:21 UTC

This is a really interesting and thorough experience report of deploying Device-Bound Session Credentials. My feeling is that DBSC needs another spec iteration or two before being ready for wide deployment. My guess is that if it does catch on, we’ll see attacks move from exfiltrating session cookies to proxying requests through the user’s browser/device - as we’ve seen in the past eg with HttpOnly cookies. Without an equivalent of WebAuthn’s UserPresence bit, I’m not sure this is a long-term solution. See https://neilmadden.blog/2021/03/20/towards-a-standard-for-bearer-token-urls/ for my thoughts on an alternative approach. https://scotthelme.co.uk/everything-i-learned-shipping-device-bound-session-credentials/

Replies (0)

No replies.