Google has a new way to try and stop cookie theft leading to possible cyberattacks

HTTPS in a browser address bar
(Image credit: Shutterstock)

Google wants to put an end to browser cookie theft by making today’s cookies practically worthless.

In an announcement on its Chromium blog, Google revealed it is working on a new model that binds user sessions to the actual devices, rather than the browser. That should give antivirus solutions and other endpoint protection tools a better fighting chance against hackers.

Lately, cookies have become a popular target for threat actors, as they grant access to various accounts, even with multi-factor authentication (MFA) enabled. They can be extracted with infostealing malware and, even if a subsequent antivirus scan removes it, will remain active and useful to the attackers.

Substantial reduction

To tackle the problem, Google’s engineering team is working on something they call Device Bound Session Credentials (DBSC), a new web capability “that will help keep users more secure against cookie theft”. 

The project is being developed in the open at github.com/WICG/dbsc, Google said, adding that the goal is for the project to become an open web standard. 

BDSC will bind authentication sessions to the actual device, rendering cookies practically worthless. “We think this will substantially reduce the success rate of cookie theft malware,” Google said. Furthermore, for account theft to work in the new environment, the attackers would need to act locally, on the device, which will be somewhat more difficult due to antivirus and other protection tools. 

Finally, Google added that many server providers, identity providers, and browsers, said they were interested in the project, as well. “We are engaging with all interested parties to make sure we can present a standard that works for different kinds of websites in a privacy preserving way.”

Eliminating cookie theft would definitely improve the security standing of many organizations, but we’re fairly certain threat actors would again find a way to compromise user accounts.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
Fingerprint
Profit over privacy? Google gives advertisers more personal info in major ‘fingerprinting’ U-turn
Dozens of chocolate cookie biscuits floating on a light pink background
How to prevent data collection (and kick unwanted cookies to the curb)
Robotic hand clicking on captcha 'I am not a robot'.
"A tracking cookie farm for profit" - report claims reCAPTCHA has caused 819 million hours of wasted human time, and billions in Google profits
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
Chrome 90 Browser for iOS
Google Chrome might soon use AI to make you a better password
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over