Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DBSC (Device Bound Session Credentials) #106

Closed
kmonsen opened this issue Jul 6, 2023 · 4 comments
Closed

DBSC (Device Bound Session Credentials) #106

kmonsen opened this issue Jul 6, 2023 · 4 comments

Comments

@kmonsen
Copy link

kmonsen commented Jul 6, 2023

Introduction

Device Bound Secure Credentials (DBSC) aims to reduce account hijacking caused by cookie theft. It does so by introducing a protocol and browser infrastructure to maintain and prove possession of a cryptographic key.

This proposal offers two important features that we believe makes it easier to deploy than previous proposals. DBSC provides application-level binding and browser initiated refreshes that can make sure devices are still bound to the original device.

Feedback

I welcome feedback in this thread, but encourage you to file bugs against Device Bound Secure Credentials.

@sameerag
Copy link

sameerag commented Jul 6, 2023

Thanks @kmonsen.

Microsoft has been working on something similar to secure the web artifacts in browser context. We propose a new protocol BPoP (similar to DPoP which binds the access tokens) to bind a browser artifact (such as a cookie) issued by a website. Our explainer can be accessed here: Binding Context.

We are happy to collaborate in this space to arrive at a common proposal. Looking forward.

@mikewest
Copy link
Member

Given the interest in this space from Microsoft and Google, this seems like something that could reasonably migrate to the WICG for incubation (which might also make it easier for others to comment). WDYT, @cwilso, @yoavweiss, @marcoscaceres?

@yoavweiss
Copy link
Collaborator

Yup. Transfer the repo over the me, and I can handle the rest.

@yoavweiss
Copy link
Collaborator

The repo now lives in https://github.com/WICG/dbsc
Happy incubating!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants