#DBSC
Blogged: Experimental support for Device Bound Session Credentials (DBSC) in ASP.NET Core - Exploring the .NET 11 preview - Part 8

andrewlock.net/exploring-th...

In this post I look at the new experimental support for DBSC coming in .NET 11

#dotnet #security #aspnetcore
Experimental support for Device Bound Session Credentials (DBSC) in ASP.NET Core: Exploring the .NET 11 preview - Part 8
In this post I look at the new experimental support for DBSC provided by the Microsoft.AspNetCore.Authentication.DeviceBoundSessions package
andrewlock.net
September 22, 2026 at 3:13 PM
Understanding Device Bound Session Credentials (DBSC)

andrewlock.net/understandin...

In this post I provide an introduction to Device Bound Session Credentials, I look at how DBSC protects against session hijacking, and how the protocol works.

#security #dotnet
Understanding Device Bound Session Credentials (DBSC)
In this post I provide an introduction to Device Bound Session Credentials, I look at how DBSC protects against session hijacking, and how the protocol works
andrewlock.net
September 15, 2026 at 4:37 PM
Do you like Mega Man and wholesomeness? Please go check this guy out. It would be nice to have less drama, cynicism, and bait and more of what YouTube used to be. www.youtube.com/@Solaris8.0/...
☀️DBSC Animating☀️
Hello, i'm Solaris 8.0, a spriter and sprite animator, welcome to DBSC Animating (Deadly Big Sun Collisioner Animating), on this channel you will find sprite animations based on the classic saga from ...
www.youtube.com
June 5, 2026 at 3:49 PM
My most feminine trait is that Goku and Kuririn’s friendship makes me cry bsky.app/profile/dbsc...
March 26, 2026 at 12:15 AM
DBSC (Device Bound Session Credentials) binds browser session credentials to the device and mitigate cookie thefts. Chrome has just started its second origin trial with some updates.

Learn more: developer.chrome.com/blog/dbsc-or...
October 23, 2025 at 11:08 AM
Experimental support for Device Bound Session Credentials (DBSC) in ASP .NET Core: Exploring the .NET 11 preview - Part 8 by @andrewlock.bsky.social andrewlock.net/exploring-th... #aspnetcore
September 25, 2026 at 8:44 AM
Google has rolled out Device Bound Session Credentials (DBSC) protection in Chrome 146 for Windows, designed to block info-stealing malware from harvesting session cookies.
Google Chrome adds infostealer protection against session cookie theft
Google has rolled out Device Bound Session Credentials (DBSC) protection in Chrome 146 for Windows, designed to block info-stealing malware from harvesting session cookies.
www.bleepingcomputer.com
April 9, 2026 at 6:33 PM
DBSC is a proposed standard that helps mitigate cookie theft by cryptographically binding a session to the user's device at the time of issuance. It's finally shipped in Chrome for Windows.

- Announcement: developer.chrome.com/blog/dbsc-wi...
- How to implement: developer.chrome.com/docs/web-pla...
Device Bound Session Credentials now available on Windows  |  Blog  |  Chrome for Developers
Device Bound Session Credentials (DBSC) are now available in Chrome 145 on Windows to help protect users from cookie theft.
developer.chrome.com
March 4, 2026 at 9:26 AM
Experimental support for Device Bound Session Credentials (DBSC) in ASP.NET Core andrewlock.net/exploring-th...
Experimental support for Device Bound Session Credentials (DBSC) in ASP.NET Core: Exploring the .NET 11 preview - Part 8
In this post I look at the new experimental support for DBSC provided by the Microsoft.AspNetCore.Authentication.DeviceBoundSessions package
andrewlock.net
September 22, 2026 at 4:15 PM
DBSC arbeitet stattdessen auf HTTP-/Anwendungsebene. Dadurch bleibt die Gerätebindung auch in modernen Web-Architekturen erhalten. Das Ziel bleibt dasselbe: Gestohlene Cookies sollen auf anderen Geräten nicht nutzbar sein.
May 30, 2026 at 7:21 PM
DBSC (Device Bound Session Credentials) soll gestohlene Sitzungscookies wertlos machen. Der Browser weist dazu den Besitz eines hardwaregebundenen privaten Schlüssels (z. B. TPM) nach, um kurzlebige Sitzungscookies auszustellen oder zu erneuern.
May 30, 2026 at 7:20 PM
Blink: Intent to Prototype: Device Bound Session Credentials (DBSC) JavaScript API
Blink: Intent to Prototype: Device Bound Session Credentials (DBSC) JavaScript API
Blink: Intent to Prototype: Device Bound Session Credentials (DBSC) JavaScript API
groups.google.com
July 10, 2026 at 11:17 AM
We've released a new version of report-uri/dbsc-php thanks to community contributions!

Full details: github.com/report-uri/d...

Background: scotthelme.co.uk/open-sourcin...
Releases · report-uri/dbsc-php
Contribute to report-uri/dbsc-php development by creating an account on GitHub.
github.com
July 20, 2026 at 12:55 PM
Device Bound Session Credentials (DBSC) is a new web capability designed to protect user sessions from cookie theft and session hijacking. This feature is now available for testing as an Origin Trial in Chrome 135.

Test DBSC on your website. Learn more:
Origin trial: Device Bound Session Credentials in Chrome  |  Blog  |  Chrome for Developers
Learn about the Device Bound Session Credentials Origin Trial in Chrome and how it can help protect user sessions from cookie theft.
developer.chrome.com
April 28, 2025 at 10:10 AM
Our #GoogleIO session video "Reshaping user authentication and identity verification" is now published. Checkout the exciting new capabilities such as the unified credential manager, automated password change, Digital Credentials and DBSC.
www.youtube.com/watch?v=jaaS...
Reshaping user authentication and identity verification
YouTube video by Chrome for Developers
www.youtube.com
May 22, 2025 at 11:53 PM
The thing about the DBSC is I always wanted it to be about making art together as a fandom and keeping it alive. It lost a lot of steam when things got shifted around in HS, but I'm still fond of it. Obviously it doesn't make money so it's hard to justify pouring so much time into it.
July 24, 2026 at 7:51 AM
DBSC is exciting! I hope it will lead to both meaningful better security and less hassle getting logged out all the time from websites. The convention of mobile apps staying logged in but websites logging out by default makes the web more frustrating!
Device Bound Session Credentials (DBSC) is a new web capability designed to protect user sessions from cookie theft and session hijacking. This feature is now available for testing as an Origin Trial in Chrome 135.

Test DBSC on your website. Learn more:
Origin trial: Device Bound Session Credentials in Chrome  |  Blog  |  Chrome for Developers
Learn about the Device Bound Session Credentials Origin Trial in Chrome and how it can help protect user sessions from cookie theft.
developer.chrome.com
May 4, 2025 at 8:39 PM
Google впровадила функцію DBSC для захисту облікових записів у Chrome. Вона прив’язує сесійні cookie до конкретного пристрою. Ключі зберігаються в апаратних модулях безпеки. Функція ускладнює обхід MFA через викрадені cookie.

https://channeltech.space/soft/chrome-dbsc-cookie-protection/
Google додає захист від викрадення cookie у Chrome
Google впровадила DBSC у Chrome для захисту від викрадення cookie, прив’язуючи сесії до пристрою та ускладнюючи обхід MFA і захоплення акаунтів.
channeltech.space
May 30, 2026 at 7:10 AM
Cookieが盗まれても、もう悪用されなくなります。
Chrome 146のDBSCが全ユーザーに展開され、セッションCookieがハードウェアに縛られます。

Vivaldi 8.0は全面刷新でAI非搭載を明言。
Amazonでは社内AI利用の水増しが横行しリーダーボード廃止。
Thunderbolt Shareはライセンス制約、Linuxは同等機能をライセンス不要で実装へ。

youtu.be/mr-OCZpJ3qU

#ChromeDBSC #Vivaldi8 #トークンマクシング #トークンマキシング
Cookie theft is dead.
Chrome DBSC全展開。秘密鍵を守る / Vivaldi 8.0・Amazon AI・セキュリティチップ
YouTube video by 情報の灯台
youtu.be
May 30, 2026 at 9:40 AM
We’ve rolled out Device Bound Session Credentials to 100% of Report URI logins. 🔐

67.7% of our active sessions are already device-bound, making this what we believe to be one of the first production DBSC deployments outside Google.

Here’s how we did it: blog.report-uri.com/we-rolled-ou...
We rolled out Device Bound Session Credentials to every Report URI login
Since 1st September 2026, every single login to Report URI has been offered a Device Bound Session Credential. That's 100% of our users, on the live site, all day, every day. As far as we can tell, t...
blog.report-uri.com
September 22, 2026 at 2:12 PM