Reading view

Chrome adopts what may be the best protection yet against account takeovers

Google’s Chrome browser has added a new feature that could go a long way in preventing a form of account takeover that’s grown increasingly common as users adopt two-factor authentication, passkeys, and similar protections.

The new Chrome protection is known as device-bound session credentials (DBSCs). The measure stores a unique encryption key in a silicon-resident fortress that’s built into the device running the browser. On Windows machines, this fortress is called a TPM, short for Trusted Platform Module. On macOS and iOS, it’s known as a secure enclave. Other platforms have differing names. Recently released versions of Chrome for Windows and macOS generate a key that’s stored in this fortress.

An antidote to session cookie theft

DBSCs protect against the theft of session cookies, the unique strings of characters that websites store on browsers. Session cookies greatly speed up browsing on sensitive sites that require user authentication. Instead of requiring the exchange of credentials each time a user opens a new site page, the server sets a session cookie that effectively proves the user has already successfully logged in.

Read full article

Comments

© Getty Images

  •  

New surveillance tech links your phone to your license plate

Imagine that you share a ride to work with the same colleague most mornings. As it passes by a license plate reader, the camera records the car, which can be linked through vehicle records to its registered owner. Beside it, another sensor detects signals broadcast by devices traveling nearby, such as your phone and your colleague’s smartwatch.

After enough trips, software may treat some of those devices as a recurring electronic signature associated with the vehicle. Weeks later, one of the same device signals appears alongside a different car connected to an investigation. The signal itself may not contain its owner’s name, but its previous association with a known vehicle gives investigators another clue they can use to work out who was carrying the device.

SignalTrace, a system marketed by the security company Leonardo, is designed to work alongside automatic license plate readers. The company says it can recognize groups of consumer devices that regularly move together, then associate them with license plate records and time-stamped locations. The pattern can then be searched even when a police investigator does not know the plate number.

Read full article

Comments

© Getty Images | Smith Collection/Gado

  •  

New Pass-ta-key attack reveals all the things we didn't know about passkeys

Last week, a researcher outlined what he said was a “novel attack surface” in passkeys, the new authentication paradigm that offers a more secure alternative to password-based methods. In fact, the attacks demonstrated in the post are neither novel nor unique to passkeys. This distinction is important because the research has generated confusion among end users and security professionals as they assess whether this new mechanism is truly safe to use.

The attack is called Pass-ta-key—a blending of the word passkey with the phrase “pass the key” and a nod to a plate of pasta. Arie Olshtein, a researcher at security firm Palo Alto Networks, described in a post last week how Pass-ta-key could obtain all passkeys stored in the Google Password Manager app (GPM) for Windows when it’s running on a machine infected with malware.

This came as a surprise to many people because they believed passkeys are stored exclusively in the trusted platform manager (TPM), the locked-down enclave in a hardened silicon chip that’s reserved for storing cryptographic keys and other highly sensitive information on Windows machines. If passkeys are stored in the TPM, then how was Pass-ta-key able to extract the entire set of passkeys stored by the app, they wanted to know.

Read full article

Comments

© Aurich Lawson | Getty Images

  •  
❌