This "BPoP" (Browser Proof of Possession) proposal out of Microsoft is really interesting! If you've bemoaned the loss of Token Binding then you owe it to yourself to read this explainer they just published:

https://github.com/MicrosoftEdge/MSEdgeExplainers/blob/main/BindingContext/explainer.md

I think the tl;dr is "bind session tokens to browsers using browser-managed public-key cryptography."

And I'm excited by the idea as a potential solution to the question of, "how do we defend against session token theft after passkeys lock down credential theft as a vector of attack?" 🤔

#bpop #passkeys #webauthn

MSEdgeExplainers/BindingContext/explainer.md at main · MicrosoftEdge/MSEdgeExplainers

Home for explainer documents originated by the Microsoft Edge team - MicrosoftEdge/MSEdgeExplainers

GitHub
De Buurmannen voor de Nacht van de Vluchteling 2023!

Wij gaan de uitdaging aan en lopen in het weekend van 17-18 juni mee met de Nacht van de Vluchteling! Deze uitdaging valt totaal weg tegen de uitdagingen waar vluchtelingen voor staan. Op deze manier willen we graag awareness creëren én geld ophalen...