How Google plans to make stolen session cookies worthless for attackers

Google is working on a new security feature for Chrome called Device Bound Session Credentials (DBSC), meant to prevent attackers from using stolen session cookies to gain access user accounts. Session (i.e., authentication) cookies are stored by brows… Continue reading How Google plans to make stolen session cookies worthless for attackers

Smashing Security podcast #364: Bing pop-up wars, and the British Library ransomware scandal

There’s a Bing ding dong, after Microsoft (over?) enthusiastically encourages Chrome users to stop using Google, and silence hits the British Library as it shares its story of a ransomware attack.

All this and more is discussed in the latest editio… Continue reading Smashing Security podcast #364: Bing pop-up wars, and the British Library ransomware scandal