Edit history

Earlier versions of DBSC bound session tokens, newest first.

Current version | Edited by Rex
Changes
A workaround for non-TPM devices is to calculate a hash locally and confirm it with a locally saved one.Removed: ### ChecksRemoved: Removed: - ☑ I searched existing discussions.Removed:
Show

DBSC bound session tokens

Problem

Currently the sessions expiring on mobile Overall possibility of losing a token to theft

Proposal

Using an existing DBSC or creating a solution to bind session tokens to hardware TPMs.

Notes

Technically, when the device changes, the token would be incompatible. Devices with TPMs disabled or lacking would be out of scope for this. A workaround for non-TPM devices is to calculate a hash locally and confirm it with a locally saved one.
Original by Rex
Show

DBSC bound session tokens

Problem

Currently the sessions expiring on mobile Overall possibility of losing a token to theft

Proposal

Using an existing DBSC or creating a solution to bind session tokens to hardware TPMs.

Notes

Technically, when the device changes, the token would be incompatible. Devices with TPMs disabled or lacking would be out of scope for this. A workaround for non-TPM devices is to calculate a hash locally and confirm it with a locally saved one.

Checks

  • ☑ I searched existing discussions.