spec, enterprise spec, Chrome explainer, another Chrome explainer, Chromium explainer, Chrome platform status
Seems like a useful hardening against session theft.
spec, enterprise spec, Chrome explainer, another Chrome explainer, Chromium explainer, Chrome platform status
Seems like a useful hardening against session theft.
This is now entering public availability: https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html . We'll look into working on this in the next few months.
One big question: do we just implement this to work with native Chrome support? Since no other browsers seem to support this right now, or possibly any time soon? Or do we also want to explore a far more complex DPoP-like fallback as well?
Comments from another task:
I don't think device compromise is such a low threat these days, still this is a good clarification about the extent to which device-bound cookies will increase security.