Chrome adopts what may be the best protection yet against account takeovers
Chrome is testing device-bound session credentials, which tie session authentication to a hardware-protected private key so stolen cookies cannot be reused for account takeover. HN discusses how DBSC differs from passkeys and the privacy implications of hardware-bound identity.