Chrome's new security feature could make stolen session cookies virtually useless
The change targets a common method of account takeover. Attackers who obtain a browser session cookie can sometimes load it into another browser and gain access to an account without entering the victim's password or completing two-factor authentication. Device-bound session credentials are designed to stop that by requiring proof that...Read Entire Article
This is a summary aggregated from TechSpot. Read the complete article on the original site:
Read full article at TechSpot