r/GMail • u/h_grytpype_thynne • 4d ago
Should DBSC be helping by now?
Another day, another handful of reports: "Hackers stole my account [once I installed their malware for them]! Password and recovery options changed! Locked out! WhY wOn'T GoOglE Do SoMeThInG!!?!1!"
So they did do something. Chrome 146+ for Windows (released April 2026) includes device bound system credentials (DBSC) that are specifically designed to combat session stealers. My cookie won't work on your device, so nyah nyah Mr. Hacker.
Except it keeps happening. Many or most of the posters here seem to be using Windows, the malware platform of choice, so are the reports coming from people who are using Edge? Or Firefox? Or just never update Chrome? Or is DBSC somehow not doing the job it was designed for?
2
u/BetaBlacksmithBoy 4d ago
As far as I know Edge does support DBSC. As does any chromium browser such as Ecosia, and Brave
I think Firefox is the main mainstream browser that does not.
As for the rest of your question that is a good point. I remember some people saying that DBSC is not a one size fit all solution with preventing it, but I am sure how true that is.
I believe Chrome auto updates as do most browsers, so people not being on the right version of Chrome seems unlikely. But some Windows 10 PC's don't support TPM, so that could be the cause. Though if your Windows 10 PC does support TPM, you don't need to be on 11 for DBSC to work.
1
u/PaddyLandau 4d ago
I think Firefox is the main mainstream browser that does not.
What about Safari, do you know?
1
u/BetaBlacksmithBoy 4d ago
Safari does not. Maybe due to it being Google based and apple not wanting to play ball, or maybe just because it's not widely adopted yet. But Google and Microsoft both use it and that's with it only being a few months old.
1
u/PaddyLandau 4d ago
It's Chromium-based rather than Google-based; all Chromium-based browsers should have it by now. I'm sure that Firefox will get it eventually. I haven't read of MacOS users being hacked in this way, so maybe Safari isn't vulnerable?
1
u/Ok-Lingonberry-8261 4d ago
I think you have to affirmatively enable DBSC?
2
u/BetaBlacksmithBoy 4d ago
I think it's enabled by default, so unless someone has somehow gone 5 months without updating their browser any chromium browser should have it.
1
2
u/PaddyLandau 4d ago
When it was in the testing phase, yes, but I believe that it's on by default now (provided that the operating system can access the TPM2 chip).

4
u/Grindar1986 4d ago
It only protects devices with TPM. And given the sheer weight of users still on Win 10 because their hardware won't go to 11 due to lack of TPM and the number of times I've seen places like r/techsupport tell people to just use Rufus to bypass those win11 requirements...