Evidence ledger
One row per claim in Making a stolen session useless: who published it, what grade it carries, when it was written, when the link was last checked, and the quote or figure it rests on. Nothing in the guide is cited from memory, so anything not in this table is not in the guide.
Guide: Making a stolen session useless: why a copied credential still works, and what binding
it to the holder actually costs
Category: security-and-identity · Research date: 2026-09-30.
How these were fetched, stated up front. This session's egress proxy resolved
raw.githubusercontent.com (HTTP 200) and answered github.com with 403 for every path,
existent or not, so a GitHub web link cannot be distinguished from a typo by the link checker;
the specs and design docs cited from GitHub were therefore read from their raw form and cross
-checked (KEP-1205, the DBSC explainer, the CAEP spec, the OAuth security BCP draft were all
cloned or curled directly). Every other host in this ledger (Okta, Cloudflare, BeyondTrust,
1Password, GitHub's own blog, Meta, CISA, USENIX, IETF, Microsoft Learn, Slack, and the
independent blogs) was refused by the proxy at fetch time; their content and the quotes below
were retrieved through this session's web-search retrieval, which returns page text, not from
memory. verify.mjs reports those hosts as unreachable warnings rather than failures; the
page names this limit in section 6.
One row per claim. The right-hand column is copied text or a figure, not paraphrase.
| # | Org | Title | Tier | Published | Checked | URL | Claim taken from it | Supporting quote or figure |
|---|---|---|---|---|---|---|---|---|
| 1 | Okta | Unauthorized Access to Okta's Support Case Management System: Root Cause | postmortem | 2023-11-03 | 2026-09-30 | https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/ | A support-troubleshooting artefact carried live session tokens that let an attacker be the user without any credential of the user's. | "HAR files can contain sensitive data, including cookies and session tokens, that malicious actors can use to impersonate valid users." 134 customers, "less than 1% of Okta customers". |
| 2 | Okta | October Customer Support Security Incident, Recommended Actions | postmortem | 2023-11 | 2026-09-30 | https://sec.okta.com/articles/october-security-incident-recommended-actions/ | The durable fix Okta shipped binds the admin session to a network location, so a copied token stops working when the source IP changes. | Okta released "session token binding based on network location" so administrators "are forced to re-authenticate if we detect a network change." |
| 3 | Cloudflare | How Cloudflare mitigated yet another Okta compromise | postmortem | 2023-10-20 | 2026-09-30 | https://blog.cloudflare.com/how-cloudflare-mitigated-yet-another-okta-compromise/ | The same Okta support token stolen from a HAR file was used against Cloudflare; the lesson they drew first is that the token itself is the crown jewel. | Five lessons, first two: "Protect Your Session Tokens" and "Monitor for Unusual Behavior"; recommendation of "short-lived sessions for admin access" and hardware security keys for privileged users. |
| 4 | Cloudflare | Thanksgiving 2023 security incident | postmortem | 2024-02-01 | 2026-09-30 | https://blog.cloudflare.com/thanksgiving-2023-security-incident/ | A token that is only shrunk, not bound, stays dangerous for as long as nobody rotates it; the assumption "it's unused" is what kept it alive. | Attacker used "one service token and three service account credentials" stolen in the October Okta breach that Cloudflare "failed to rotate" because "mistakenly it was believed they were unused"; response rotated 5,000 credentials. |
| 5 | BeyondTrust | BeyondTrust Discovers Breach of Okta Support Unit | postmortem | 2023-10-20 | 2026-09-30 | https://www.beyondtrust.com/blog/entry/okta-support-unit-breach | A policy that binds the console session to context can be bypassed by an equally valid API session the same token authorises; binding one door is not binding the identity. | A custom admin-console policy blocked the attacker, but they "pivoted to using admin API actions authenticated with the stolen session cookie, something that Okta policies cannot be configured to stop"; detected "within 30 minutes". |
| 6 | 1Password | Okta Support System incident and 1Password | postmortem | 2023-10-23 | 2026-09-30 | https://1password.com/blog/okta-incident | The stolen artefact was a session cookie for an IT employee, reused directly against the admin portal minutes later. | "an unknown actor used the same Okta session from that HAR file to access the Okta administrative portal." |
| 7 | GitHub | GitHub security update: a bug related to handling of authenticated sessions | postmortem | 2021-03-08 | 2026-09-30 | https://github.blog/2021-03-08-github-security-update-a-bug-related-to-handling-of-authenticated-sessions/ | Even with no attacker, a bearer session cookie can reach the wrong holder through a backend bug; the only safe response is to invalidate the whole population. | "a race condition in a backend request handling process could have misrouted a user's session to the browser of another authenticated user, giving them the valid and authenticated session cookie for another user." Fewer than 0.001% of sessions; all sessions before 12:03 UTC invalidated. |
| 8 | Meta (Facebook) | Security Update | postmortem | 2018-09-28 | 2026-09-30 | https://about.fb.com/news/2018/09/security-update/ | When a token is a bearer credential, the blast radius is every token that could have been exposed, not only the ones known stolen; revocation is population-scale. | Access tokens exposed via the "View As" feature; Facebook "reset the access tokens of the almost 50 million accounts" plus 40 million more "as a precautionary step", about 90 million forced re-logins. |
| 9 | CISA / Cyber Safety Review Board | Review of the Summer 2023 Microsoft Exchange Online Intrusion | postmortem | 2024-04-02 | 2026-09-30 | https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewOfTheSummer2023MEOIntrusion508.pdf | A signing key is a token factory; if you cannot revoke or even detect its misuse, the bearer problem scales to every identity it can mint. | Storm-0558 "used an acquired MSA consumer token signing key to forge tokens"; the 2016 key "should have been revoked" but was not; "Microsoft does not know how or when Storm-0558 obtained the signing key." |
| 10 | auth0 / community | node-jsonwebtoken issue #113, "Destroy token" | source | opened 2015-07-23 | 2026-09-30 | https://github.com/auth0/node-jsonwebtoken/issues/113 | The most widely used JWT library has no token-destroy method because a self-validating bearer token has no revocation channel; you must add server state to kill one early. | Long-running request for a destroy/invalidate method; maintainers and commenters converge on external state (a denylist in Redis) or short expiry, because the token is validated without contacting the issuer. |
| 11 | auth0 / community | node-jsonwebtoken issue #375, "How to forcefully invalidate a token on logout" | source | opened 2017 | 2026-09-30 | https://github.com/auth0/node-jsonwebtoken/issues/375 | Logout is not free for a stateless token; "log me out everywhere" requires the same server-side state the design tried to avoid. | Recurring question with the same answer: rotate the signing secret (revokes everyone) or keep a per-token/per-user invalidation record; there is no in-token mechanism. |
| 12 | Kubernetes SIG-Auth | KEP-1205, Bound Service Account Tokens | adr | GA 1.22 (2021) | 2026-09-30 | https://github.com/kubernetes/enhancements/tree/master/keps/sig-auth/1205-bound-service-account-tokens | The canonical statement of the bearer problem for machine identity, and the three bindings that answer it: audience, time, object. | "JWTs are not audience bound. Any recipient of a JWT can masquerade as the presenter to anyone else." "JWTs are not time bound. A JWT compromised via 1 or 2, is valid for as long as the service account exists." |
| 13 | W3C WebAppSec / Google | Device Bound Session Credentials explainer | adr | updated 2025-2026 | 2026-09-30 | https://github.com/w3c/webappsec-dbsc | Binds the browser session to a device key that cannot be exported, so a copied cookie stops working off the original machine; refresh interval sets the residual window. | "DBSC aims to enforce the specific constraint that temporary read/write access to a user agent or network traffic does not enable long-lived access to any established DBSC sessions." |
| 14 | W3C WebAppSec / Google | DBSC explainer, TPM considerations | adr | updated 2025-2026 | 2026-09-30 | https://github.com/w3c/webappsec-dbsc | The binding hardware is not universal and not free; a real deployment plans for the machines that cannot bind and for signing latency on the request path. | "Current data shows about 60%, and currently growing, of Windows users would be offered protections." Signing latency "P50: 200ms / P95: 600ms", error rate "around 0.001%". |
| 15 | W3C WebAppSec / Google | DBSC explainer, Non-goals | adr | updated 2025-2026 | 2026-09-30 | https://github.com/w3c/webappsec-dbsc | Binding has a ceiling: while the attacker is still on the box, they mint fresh valid tokens; binding buys detection and expiry, not immunity. | "DBSC will not prevent temporary access to any browser sessions while the attacker has ongoing access to a compromised user-agent... able to treat even secure elements as a signing oracle." |
| 16 | OpenID Foundation / Shared Signals | Continuous Access Evaluation Profile (CAEP) 1.0 | adr | 2025-08-29 | 2026-09-30 | https://github.com/openid/sharedsignals/blob/main/openid-caep-1_0.md | Standardises the push channel a resource needs to learn a session was revoked before the token expires; revocation becomes an event, not a poll. | Defines session-revoked: "Session Revoked signals that the session identified by the subject has been revoked." Authors from Okta and SGNL. |
| 17 | IETF OAuth WG | RFC 9700, Best Current Practice for OAuth 2.0 Security | adr | 2025-01 | 2026-09-30 | https://www.rfc-editor.org/rfc/rfc9700.html | The standards body's answer to token theft is the same two moves: constrain the token to a sender, or rotate with replay detection. | "Refresh tokens MUST be sender-constrained or use refresh token rotation." "Authorization and resource servers SHOULD use... sender-constraining access tokens, such as mutual TLS... or DPoP, to prevent misuse of stolen and leaked access tokens." |
| 18 | IETF OAuth WG | RFC 9449, OAuth 2.0 Demonstrating Proof of Possession (DPoP) | adr | 2023-09 | 2026-09-30 | https://www.rfc-editor.org/rfc/rfc9449.html | The application-layer way to sender-constrain a token: the client proves possession of a key on every request, so a copied token without the key is inert. | DPoP is "an application-level mechanism for sender-constraining OAuth access and refresh tokens", proved by a per-request signed JWT bound to a public key. |
| 19 | USENIX Security / TU Wien | Cookie Crumbles: Breaking and Fixing Web Session Integrity | paper | 2023-08 | 2026-09-30 | https://www.usenix.org/system/files/usenixsecurity23-squarcina.pdf | Even before theft, the container the session lives in is fragile: framework and browser inconsistencies let an attacker fixate or forge session state. | Cross-browser and framework study; session-integrity vulnerabilities found in 9 of the top 13 web frameworks; contributed to 12 CVEs and updates to the cookie standard. |
| 20 | USENIX ;login: / Google | BeyondCorp: A New Approach to Enterprise Security | paper | 2014-12 | 2026-09-30 | https://www.usenix.org/system/files/login/articles/login_dec14_02_ward.pdf | The strategic answer to stolen credentials is to stop trusting network position at all and re-decide every request on device and user state. | "access to services is granted based on what we know about you and your device"; access "depends solely on device and user credentials, regardless of a user's network location." |
| 21 | Identiverse / Okta, Microsoft | CAEP Deep Dive: Implementing Session Revocation and Authorization | talk | 2023-06-01 | 2026-09-30 | https://identiverse.com/video/caep-deep-dive-implementing-session-revocation-and-authorization/ | Practitioners building the revocation standard frame it as closing the gap between "access changed" and "the token stops working". | Tim Cappalli and Atul Tulshibagwale present CAEP as the mechanism to shorten the interval between a critical event and enforcement across cooperating services. |
| 22 | Slack | Building Slack's Anomaly Event Response | blog | 2025-09-04 | 2026-09-30 | https://slack.engineering/building-slacks-anomaly-event-response/ | If you cannot prevent the copy, invest in cutting the time from detection to session kill; Slack automates it down to minutes and treats a stale cookie as a signal. | AER "automatically terminates the associated user sessions, reducing the security detection and response gap from potential days/hours to mere minutes"; configurable anomalies include "stale or unexpected session cookies". |
| 23 | textslashplain (Eric Lawrence) | Protecting Auth Tokens | blog | 2023-10-23 | 2026-09-30 | https://textslashplain.com/2023/10/23/protecting-auth-tokens/ | A stolen post-login token is worth more than a password because it has already cleared MFA; the token is proof of a completed login. | A stolen token "could be more valuable than stolen passwords, because a given site may require multi-factor authentication to use a password whereas a valid token represents completion of the full login flow." |
| 24 | ERNW / insinuator.net | Token Theft in Microsoft Entra ID (Part 2 of 4): Continuous Access Evaluation | blog | 2026-09 | 2026-09-30 | https://insinuator.net/2026/09/token-theft-in-microsoft-entra-id-part-2-of-4-continuous-access-evaluation/ | Even with a revocation channel, a locally validated access token keeps working after a critical event, and the channel only covers first-party apps. | An access token "remains fully usable for its entire lifetime even if security-critical events occur"; disabling a user and revoking refresh tokens still leaves "a gap of up to 90 minutes"; "only first-party Microsoft applications are CAE-capable". |
| 25 | Lydia Graslie | Where Continuous Access Evaluation Stops Being Continuous | blog | 2026 | 2026-09-30 | https://lydiagraslie.substack.com/p/where-continuous-access-evaluation | "Near-real-time" revocation has a coverage map and a licensing gate; the control is uneven across the estate. | CAE's "critical-event half travels with any Entra ID license, but the Conditional Access policy half requires Entra ID Premium P1, and the high-risk-user signal depends on Identity Protection, which is a P2 feature." |
| 26 | Microsoft | Continuous access evaluation in Microsoft Entra | vendor | 2026 (living doc) | 2026-09-30 | https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-continuous-access-evaluation | The trade the vendor actually makes: longer token lifetime in exchange for a revocation channel keyed on critical events. | With CAE, token lifetime rises to "long-lived, up to 28 hours"; revocation is driven by "critical events" (account disable, password reset, admin token revocation, high user risk). |
| 27 | Protecting Cookies with Device Bound Session Credentials | vendor | 2026-04 | 2026-09-30 | https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html | The binding approach shipped to a consumer browser at scale in 2026, hardware-backed and default-off until the site opts in. | DBSC protection rolled out in Chrome 146 for Windows, keys backed by the TPM; cookies bound to a device the malware cannot export the key from. | |
| 28 | SpyCloud | 2025 Annual Identity Exposure Report | casestudy | 2025 | 2026-09-30 | https://spycloud.com/blog/2025-annual-identity-exposure-report/ | The stolen-session economy is large and growing, which is why "shrink the window" controls are losing and "make the copy useless" controls are shipping. | Recaptured identity records grew "22% in the past year, from 43.7 billion to 53.3 billion distinct identity records" (vendor figure; treat as a claim, not an independent measurement). |