Problem
Currently the sessions expiring on mobile
Overall possibility of losing a token to theft
Proposal
Using an existing DBSC or creating a solution to bind session tokens to hardware TPMs.
Notes
Technically, when the device changes, the token would be incompatible. Devices with TPMs disabled or lacking would be out of scope for this.
A workaround for non-TPM devices is to calculate a hash locally and confirm it with a locally saved one.
Comments
No comments yet.