Skip to content

Device Bound Session Credentials #912

Description

@MrBrain295

Request for Mozilla Position on an Emerging Web Specification

Other information

In their words "Device Bound Session Credentials (DBSC) aims to reduce account hijacking caused by cookie theft. It does so by introducing a protocol and browser infrastructure to maintain and prove possession of a cryptographic key. The main challenge with cookies as an authentication mechanism is that they only lend themselves to bearer-token schemes. On desktop operating systems, application isolation is lacking and local malware can generally access anything that the browser itself can, and the browser must be able to access cookies. On the other hand, authentication with a private key allows for the use of system-level protection against key exfiltration."

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

Status
Position is proposed

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions