Nemeski@lemm.ee to Technology@lemmy.worldEnglish · 1 year agoFighting cookie theft using device bound sessionsblog.chromium.orgexternal-linkmessage-square9linkfedilinkarrow-up158arrow-down12cross-posted to: security
arrow-up156arrow-down1external-linkFighting cookie theft using device bound sessionsblog.chromium.orgNemeski@lemm.ee to Technology@lemmy.worldEnglish · 1 year agomessage-square9linkfedilinkcross-posted to: security
minus-squaredracslinkfedilinkEnglisharrow-up5·1 year agoI don’t think WebAuthn protects against cookie theft. WebAuthn better protects the login process. But if the result of the login process is still a session/auth cookie, that can be stolen like any other cookie.
I don’t think WebAuthn protects against cookie theft. WebAuthn better protects the login process. But if the result of the login process is still a session/auth cookie, that can be stolen like any other cookie.