Light

Episode #1021 Quiz

Device Bound Session Credentials
Date: 2025-04-15 | Length: 2.75 hrs | Episode page at twit.tv

About this episode

Security Now! Episode 1021 covers the new Device Bound Session Credentials (DBSC), a W3C protocol enhancing web session security by binding session cookies to a device’s cryptographic key stored in hardware, like a TPM.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What is the primary security advantage of Device Bound Session Credentials (DBSC) over traditional session cookies as highlighted in the episode?
Question 2: According to the episode, why are traditional session cookies insufficient for protecting logged-on sessions in modern web security contexts?
Question 3: What mechanism does DBSC use to refresh session cookies without overwhelming web infrastructure, as explained in the episode?
Question 4: What requirements or capabilities are necessary on user devices to support the DBSC feature as outlined in the episode?
Question 5: Based on the episode's discussion, which of the following best describes the expected deployment and adoption path for Device Bound Session Credentials?
Cancel