Making a stolen session useless
How production systems try to make a copied session or access credential worthless to the thief, and why bearer tokens keep defeating every control short of binding.
A field guide to session and token theft, reconstructed from seven public incidents (Okta, Cloudflare x2, BeyondTrust, 1Password, GitHub, Meta, Storm-0558) and the standards now answering them (KEP-1205, DBSC, CAEP, RFC 9700, DPoP). It shows why the reflex controls after a theft, MFA, short lifetimes, rotation, leave the root fact untouched, gives a decision tree for which binding fits which holder, a five-class failure catalogue with transferable rules, and the residual-window number to measure per resource.
The controls teams reach for after a session theft, MFA, shorter lifetimes, rotation, do not change the one fact that made it work: the server cannot tell the thief's copy from the owner's, because possession is the whole proof. Only binding the credential to something uncopyable changes that answer, and even binding has a documented ceiling.
What you get out of it
- A bearer credential's blast radius is the population, not the known-stolen set: Facebook reset ~90M tokens and GitHub invalidated all sessions because neither could tell which copies existed.
- Network or console binding alone is bypassable: BeyondTrust's console policy held, so the attacker drove the same stolen cookie through the admin API, which policy could not gate.
- Revocation is a distributed-systems problem in disguise: a locally validated token has no recall channel, which is why Entra leaves a residual window of up to 90 minutes and only for CAE-capable apps.
- The residual window is the number to measure, per credential and per resource; a resource with no revocation channel has the full token lifetime as its window.
Scope
Why this, now. DBSC shipped to Chrome 146 in April 2026 and CAEP reached 1.0 in August 2025, so the binding-and-revocation answer to a problem the 2023 Okta breaches made unavoidable is now concrete enough to design against rather than await.
What it does not cover. The login itself (MFA factor choice, phishing-resistant enrolment), authorization logic once identity is established, and secret management for issuing credentials, each covered by a sibling guide. Several cited hosts were unreachable from this session's egress proxy and their quotes were retrieved via web-search rather than direct fetch.
Other field guides
Letting humans into production
A field guide to the human-access plane: the three legitimate doors into production (automation, pre-validated tooling, audited break-glass), why non…
27 sources · 23 organisations · 5 postmortemsWhen the secret leaks: the hour after exposure
A field guide to the race that starts when a token goes public: who is allowed to kill a credential automatically, how fast the machinery actually wo…
26 sources · 18 organisations · 7 postmortemsThe leak goes around the tenant filter, not through it
A field guide to tenant isolation built from seven published cross-tenant incidents (Steam 2015, Cloudbleed 2017, GitHub 2021, ChaosDB 2021, AutoWarp…
27 sources · 25 organisations · 5 postmortems