Rendered at 13:17:08 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
maratc 6 hours ago [-]
If Chrome can write into TPM/Secure Enclave it's like the best fingerprinting ever?
coffe2mug 5 hours ago [-]
> If Chrome can write into TPM/Secure Enclave it's like the best fingerprinting ever?
Please. Hatred for tech is stupid.
Read the specs before commenting. Even any free AI would have told you better.
Chrome is not writing into TPM or secure enclave.
maratc 5 hours ago [-]
From the article:
> The new Chrome protection is known as device-bound session credentials (DBSCs). The measure stores a unique encryption key in a silicon-resident fortress that’s built into the device running the browser. On Windows machines, this fortress is called a TPM, short for Trusted Platform Module. On macOS and iOS, it’s known as a secure enclave. Other platforms have differing names. Recently released versions of Chrome for Windows and macOS generate a key that’s stored in this fortress.
coffe2mug 5 hours ago [-]
article poorly written (may be by AI).
> generate a key that’s stored in this fortress.
It refers to the private key that is resident inside SecureEnclave. (During manufacturing)
See further. Dont just read one or two lines.
“The attacker can’t steal the private key from the device because the TPM / Secure Enclave will not release it. That is the core protection here,” Scott Helme, a researcher and founder of Report URI who blogged about the new protections on Tuesday, told Ars. “The attacker can steal the cookie, but they can’t answer a DBSC challenge by signing it with the private key, which is still safe on your device.”
I don't think it matters whether Chrome can add keys to TPM/Secure Enclave (as the article argues) or if it can only read the keys already in TPM/Secure Enclave (as you argue). In my understanding: both ways the key (either new or existing) could be attributed to the hardware owner, and not even an OS reinstall will help. Hence, my question.
coffe2mug 1 hours ago [-]
Don't try to give oblique reasons.
You are not forced to use DSBC. You are not even forced to use Chrome.
Lots of people - lose accounts by installing malware. They don't care about giving info to Google. at the end, many already store passport data in Google Photos or drive.
You can still buy coreboot/libreboot based laptops.
maratc 1 hours ago [-]
You seem to not have any answer to my question.
shim__ 4 hours ago [-]
How is that any different from an TPM backed passkey?
kotaKat 4 hours ago [-]
Does this stop Google's constant crusade of "making sure it's you" every two days with another fifteen password challenges?
I bought the security keys, I have all the whizbang security features on, and Google still makes me go dig out my password for no real good reason nonstop. I bought all this crap to stop making Google beg!
theandrewbailey 3 hours ago [-]
If a trillion dollar corporation is begging you for something, you should consider stop using them.
Please. Hatred for tech is stupid.
Read the specs before commenting. Even any free AI would have told you better.
Chrome is not writing into TPM or secure enclave.
> The new Chrome protection is known as device-bound session credentials (DBSCs). The measure stores a unique encryption key in a silicon-resident fortress that’s built into the device running the browser. On Windows machines, this fortress is called a TPM, short for Trusted Platform Module. On macOS and iOS, it’s known as a secure enclave. Other platforms have differing names. Recently released versions of Chrome for Windows and macOS generate a key that’s stored in this fortress.
> generate a key that’s stored in this fortress.
It refers to the private key that is resident inside SecureEnclave. (During manufacturing)
See further. Dont just read one or two lines.
“The attacker can’t steal the private key from the device because the TPM / Secure Enclave will not release it. That is the core protection here,” Scott Helme, a researcher and founder of Report URI who blogged about the new protections on Tuesday, told Ars. “The attacker can steal the cookie, but they can’t answer a DBSC challenge by signing it with the private key, which is still safe on your device.”
Read https://support.apple.com/en-gb/guide/security/sec59b0b31ff/...
You are not forced to use DSBC. You are not even forced to use Chrome.
Lots of people - lose accounts by installing malware. They don't care about giving info to Google. at the end, many already store passport data in Google Photos or drive.
You can still buy coreboot/libreboot based laptops.
I bought the security keys, I have all the whizbang security features on, and Google still makes me go dig out my password for no real good reason nonstop. I bought all this crap to stop making Google beg!