Global Conflict
SIT Reports
Public Telegram broadcast channel promoted after bounded no-media handle validation on 2026-05-31.
Original English English
🔍 Google enables DBSC by default in Chrome for Windows
Google has moved Device-Bound Session Credentials to general availability in Chrome for Windows. The control is now enabled by default for Google Workspace users and also covers Workspace Individual and personal Google accounts. DBSC binds session cookies to device-held keys in TPM-class hardware, preventing stolen cookies from being reused on another system.
Operationally, this targets a key post-authentication gap: session hijacking after malware or infostealers extract valid cookies. For defenders, it adds hardware-backed proof of possession to web sessions, raises the cost of cookie theft, and provides audit visibility through Workspace security tools.
🛰️ Open sources - closed narratives
@sitreports