Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Planning 2023-10-18. #634

Closed
mikewest opened this issue Sep 18, 2023 · 4 comments
Closed

Planning 2023-10-18. #634

mikewest opened this issue Sep 18, 2023 · 4 comments
Labels

Comments

@mikewest
Copy link
Member

Let's plan the agenda for our upcoming call on October 18th.

@kmonsen
Copy link

kmonsen commented Sep 27, 2023

We would like to present and get feedback on DBSC. Device Bound Secure Credentials (DBSC) aims to reduce account hijacking caused by cookie theft. It does so by introducing a protocol and browser infrastructure to maintain and prove possession of a cryptographic key.

This proposal offers two important features that we believe makes it easier to deploy than previous proposals. DBSC provides application-level binding and browser initiated refreshes that can make sure devices are still bound to the original device.

There is an explainer from Microsoft in the same space, and we have invited them to share this presentation.

@sameerag
Copy link

sameerag commented Sep 27, 2023

Thank you @kmonsen for adding us. I will be representing Microsoft and we are looking forward to the presentation. We are finalizing the explainer from our end and will update the final draft next week.

Appreciate the collaboration and the invite.

@mikewest
Copy link
Member Author

Thanks, @kmonsen and @sameerag. As things look at the moment, I think we can dedicate a good chunk of the meeting to this topic. Looking forward to the discussion.

@mikewest
Copy link
Member Author

Posted the agenda to public-webappsec@ and https://github.com/w3c/webappsec/blob/main/meetings/2023/2023-10-18-agenda.md.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants