Device Bound Session Credentials (DBSC) — worth tr acking for Debian?

Michael Lazin <[email protected]>
Newsgroups gmane.linux.debian.devel.general
Message-ID <CALdcr8f6Hb4_HhUB9z+LcJABRjsdcReU2iywr4O+A20OsYohzg@mail.gmail.com>
Hi all,

I wanted to raise Device Bound Session Credentials (DBSC) as something
worth keeping on our radar, and to ask whether anyone is already looking
into it.

For those unfamiliar: DBSC is a W3C WebAppSec / WICG proposal (spec at
w3c/webappsec-dbsc on GitHub) that binds web session cookies to a
hardware-backed private key on the client device, rather than relying on a
bearer token alone. The goal is to blunt session/cookie-theft attacks —
even malware with full access to the browser's cookie jar can't replay a
stolen session from another machine, since the browser has to periodically
prove possession of a device-bound key (TPM on Windows, Secure Enclave on
macOS, etc.) to keep the session alive.

Chrome has already moved this from origin trial to GA on Windows, and
there's a growing ecosystem around it (e.g. early server-side integrations
like the Spomky-Labs DBSC bundle for Symfony). Given the trajectory, I
think it's plausible that DBSC support becomes relevant to us on a few
fronts:

- Browser packaging (Chromium/Firefox) and how key storage integrates with
Linux TPM/keyring infrastructure
- Server-side libraries and frameworks in the archive that may want to add
DBSC support (auth stacks, reverse proxies, etc.)
- Documentation/guidance for maintainers of security-sensitive packages

The spec is still evolving — there are newer extensions like DBSC(E) for
enterprise and a cross-origin SSO variant — so nothing here is urgent, but
it seemed worth flagging early rather than reacting after the fact.

Is anyone already tracking this, either on debian-security or elsewhere?
Happy to help monitor the spec or work on packaging/integration pieces if
there's interest.

Thanks,
Michael
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.