DBSC bound session tokens

(#1294) Feature Under consideration security

Problem

Currently the sessions expiring on mobile Overall possibility of losing a token to theft

Proposal

Using an existing DBSC or creating a solution to bind session tokens to hardware TPMs.

Notes

Technically, when the device changes, the token would be incompatible. Devices with TPMs disabled or lacking would be out of scope for this. A workaround for non-TPM devices is to calculate a hash locally and confirm it with a locally saved one.

Comments

Sign in with Fluxer to comment and vote.

No comments yet.