v145 · Web APIs · Security · demo

Threat Model

DBSC doesn't change what secrets a server trusts — it changes where session proof must come from. Step through four attack scenarios side by side: what an attacker achieves with classic session cookies versus what DBSC allows them to do.

attack matrix

Attack vector Classic session cookie DBSC-protected session

see also