Evidence ledger 26 sources Checked 30 Sep 2026

Evidence ledger

One row per claim in Making a stolen session useless: who published it, what grade it carries, when it was written, when the link was last checked, and the quote or figure it rests on. Nothing in the guide is cited from memory, so anything not in this table is not in the guide.

Guide: Making a stolen session useless: why a copied credential still works, and what binding it to the holder actually costs Category: security-and-identity · Research date: 2026-09-30.

How these were fetched, stated up front. This session's egress proxy resolved raw.githubusercontent.com (HTTP 200) and answered github.com with 403 for every path, existent or not, so a GitHub web link cannot be distinguished from a typo by the link checker; the specs and design docs cited from GitHub were therefore read from their raw form and cross -checked (KEP-1205, the DBSC explainer, the CAEP spec, the OAuth security BCP draft were all cloned or curled directly). Every other host in this ledger (Okta, Cloudflare, BeyondTrust, 1Password, GitHub's own blog, Meta, CISA, USENIX, IETF, Microsoft Learn, Slack, and the independent blogs) was refused by the proxy at fetch time; their content and the quotes below were retrieved through this session's web-search retrieval, which returns page text, not from memory. verify.mjs reports those hosts as unreachable warnings rather than failures; the page names this limit in section 6.

One row per claim. The right-hand column is copied text or a figure, not paraphrase.

# Org Title Tier Published Checked URL Claim taken from it Supporting quote or figure
1 Okta Unauthorized Access to Okta's Support Case Management System: Root Cause postmortem 2023-11-03 2026-09-30 https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/ A support-troubleshooting artefact carried live session tokens that let an attacker be the user without any credential of the user's. "HAR files can contain sensitive data, including cookies and session tokens, that malicious actors can use to impersonate valid users." 134 customers, "less than 1% of Okta customers".
2 Okta October Customer Support Security Incident, Recommended Actions postmortem 2023-11 2026-09-30 https://sec.okta.com/articles/october-security-incident-recommended-actions/ The durable fix Okta shipped binds the admin session to a network location, so a copied token stops working when the source IP changes. Okta released "session token binding based on network location" so administrators "are forced to re-authenticate if we detect a network change."
3 Cloudflare How Cloudflare mitigated yet another Okta compromise postmortem 2023-10-20 2026-09-30 https://blog.cloudflare.com/how-cloudflare-mitigated-yet-another-okta-compromise/ The same Okta support token stolen from a HAR file was used against Cloudflare; the lesson they drew first is that the token itself is the crown jewel. Five lessons, first two: "Protect Your Session Tokens" and "Monitor for Unusual Behavior"; recommendation of "short-lived sessions for admin access" and hardware security keys for privileged users.
4 Cloudflare Thanksgiving 2023 security incident postmortem 2024-02-01 2026-09-30 https://blog.cloudflare.com/thanksgiving-2023-security-incident/ A token that is only shrunk, not bound, stays dangerous for as long as nobody rotates it; the assumption "it's unused" is what kept it alive. Attacker used "one service token and three service account credentials" stolen in the October Okta breach that Cloudflare "failed to rotate" because "mistakenly it was believed they were unused"; response rotated 5,000 credentials.
5 BeyondTrust BeyondTrust Discovers Breach of Okta Support Unit postmortem 2023-10-20 2026-09-30 https://www.beyondtrust.com/blog/entry/okta-support-unit-breach A policy that binds the console session to context can be bypassed by an equally valid API session the same token authorises; binding one door is not binding the identity. A custom admin-console policy blocked the attacker, but they "pivoted to using admin API actions authenticated with the stolen session cookie, something that Okta policies cannot be configured to stop"; detected "within 30 minutes".
6 1Password Okta Support System incident and 1Password postmortem 2023-10-23 2026-09-30 https://1password.com/blog/okta-incident The stolen artefact was a session cookie for an IT employee, reused directly against the admin portal minutes later. "an unknown actor used the same Okta session from that HAR file to access the Okta administrative portal."
7 GitHub GitHub security update: a bug related to handling of authenticated sessions postmortem 2021-03-08 2026-09-30 https://github.blog/2021-03-08-github-security-update-a-bug-related-to-handling-of-authenticated-sessions/ Even with no attacker, a bearer session cookie can reach the wrong holder through a backend bug; the only safe response is to invalidate the whole population. "a race condition in a backend request handling process could have misrouted a user's session to the browser of another authenticated user, giving them the valid and authenticated session cookie for another user." Fewer than 0.001% of sessions; all sessions before 12:03 UTC invalidated.
8 Meta (Facebook) Security Update postmortem 2018-09-28 2026-09-30 https://about.fb.com/news/2018/09/security-update/ When a token is a bearer credential, the blast radius is every token that could have been exposed, not only the ones known stolen; revocation is population-scale. Access tokens exposed via the "View As" feature; Facebook "reset the access tokens of the almost 50 million accounts" plus 40 million more "as a precautionary step", about 90 million forced re-logins.
9 CISA / Cyber Safety Review Board Review of the Summer 2023 Microsoft Exchange Online Intrusion postmortem 2024-04-02 2026-09-30 https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewOfTheSummer2023MEOIntrusion508.pdf A signing key is a token factory; if you cannot revoke or even detect its misuse, the bearer problem scales to every identity it can mint. Storm-0558 "used an acquired MSA consumer token signing key to forge tokens"; the 2016 key "should have been revoked" but was not; "Microsoft does not know how or when Storm-0558 obtained the signing key."
10 auth0 / community node-jsonwebtoken issue #113, "Destroy token" source opened 2015-07-23 2026-09-30 https://github.com/auth0/node-jsonwebtoken/issues/113 The most widely used JWT library has no token-destroy method because a self-validating bearer token has no revocation channel; you must add server state to kill one early. Long-running request for a destroy/invalidate method; maintainers and commenters converge on external state (a denylist in Redis) or short expiry, because the token is validated without contacting the issuer.
11 auth0 / community node-jsonwebtoken issue #375, "How to forcefully invalidate a token on logout" source opened 2017 2026-09-30 https://github.com/auth0/node-jsonwebtoken/issues/375 Logout is not free for a stateless token; "log me out everywhere" requires the same server-side state the design tried to avoid. Recurring question with the same answer: rotate the signing secret (revokes everyone) or keep a per-token/per-user invalidation record; there is no in-token mechanism.
12 Kubernetes SIG-Auth KEP-1205, Bound Service Account Tokens adr GA 1.22 (2021) 2026-09-30 https://github.com/kubernetes/enhancements/tree/master/keps/sig-auth/1205-bound-service-account-tokens The canonical statement of the bearer problem for machine identity, and the three bindings that answer it: audience, time, object. "JWTs are not audience bound. Any recipient of a JWT can masquerade as the presenter to anyone else." "JWTs are not time bound. A JWT compromised via 1 or 2, is valid for as long as the service account exists."
13 W3C WebAppSec / Google Device Bound Session Credentials explainer adr updated 2025-2026 2026-09-30 https://github.com/w3c/webappsec-dbsc Binds the browser session to a device key that cannot be exported, so a copied cookie stops working off the original machine; refresh interval sets the residual window. "DBSC aims to enforce the specific constraint that temporary read/write access to a user agent or network traffic does not enable long-lived access to any established DBSC sessions."
14 W3C WebAppSec / Google DBSC explainer, TPM considerations adr updated 2025-2026 2026-09-30 https://github.com/w3c/webappsec-dbsc The binding hardware is not universal and not free; a real deployment plans for the machines that cannot bind and for signing latency on the request path. "Current data shows about 60%, and currently growing, of Windows users would be offered protections." Signing latency "P50: 200ms / P95: 600ms", error rate "around 0.001%".
15 W3C WebAppSec / Google DBSC explainer, Non-goals adr updated 2025-2026 2026-09-30 https://github.com/w3c/webappsec-dbsc Binding has a ceiling: while the attacker is still on the box, they mint fresh valid tokens; binding buys detection and expiry, not immunity. "DBSC will not prevent temporary access to any browser sessions while the attacker has ongoing access to a compromised user-agent... able to treat even secure elements as a signing oracle."
16 OpenID Foundation / Shared Signals Continuous Access Evaluation Profile (CAEP) 1.0 adr 2025-08-29 2026-09-30 https://github.com/openid/sharedsignals/blob/main/openid-caep-1_0.md Standardises the push channel a resource needs to learn a session was revoked before the token expires; revocation becomes an event, not a poll. Defines session-revoked: "Session Revoked signals that the session identified by the subject has been revoked." Authors from Okta and SGNL.
17 IETF OAuth WG RFC 9700, Best Current Practice for OAuth 2.0 Security adr 2025-01 2026-09-30 https://www.rfc-editor.org/rfc/rfc9700.html The standards body's answer to token theft is the same two moves: constrain the token to a sender, or rotate with replay detection. "Refresh tokens MUST be sender-constrained or use refresh token rotation." "Authorization and resource servers SHOULD use... sender-constraining access tokens, such as mutual TLS... or DPoP, to prevent misuse of stolen and leaked access tokens."
18 IETF OAuth WG RFC 9449, OAuth 2.0 Demonstrating Proof of Possession (DPoP) adr 2023-09 2026-09-30 https://www.rfc-editor.org/rfc/rfc9449.html The application-layer way to sender-constrain a token: the client proves possession of a key on every request, so a copied token without the key is inert. DPoP is "an application-level mechanism for sender-constraining OAuth access and refresh tokens", proved by a per-request signed JWT bound to a public key.
19 USENIX Security / TU Wien Cookie Crumbles: Breaking and Fixing Web Session Integrity paper 2023-08 2026-09-30 https://www.usenix.org/system/files/usenixsecurity23-squarcina.pdf Even before theft, the container the session lives in is fragile: framework and browser inconsistencies let an attacker fixate or forge session state. Cross-browser and framework study; session-integrity vulnerabilities found in 9 of the top 13 web frameworks; contributed to 12 CVEs and updates to the cookie standard.
20 USENIX ;login: / Google BeyondCorp: A New Approach to Enterprise Security paper 2014-12 2026-09-30 https://www.usenix.org/system/files/login/articles/login_dec14_02_ward.pdf The strategic answer to stolen credentials is to stop trusting network position at all and re-decide every request on device and user state. "access to services is granted based on what we know about you and your device"; access "depends solely on device and user credentials, regardless of a user's network location."
21 Identiverse / Okta, Microsoft CAEP Deep Dive: Implementing Session Revocation and Authorization talk 2023-06-01 2026-09-30 https://identiverse.com/video/caep-deep-dive-implementing-session-revocation-and-authorization/ Practitioners building the revocation standard frame it as closing the gap between "access changed" and "the token stops working". Tim Cappalli and Atul Tulshibagwale present CAEP as the mechanism to shorten the interval between a critical event and enforcement across cooperating services.
22 Slack Building Slack's Anomaly Event Response blog 2025-09-04 2026-09-30 https://slack.engineering/building-slacks-anomaly-event-response/ If you cannot prevent the copy, invest in cutting the time from detection to session kill; Slack automates it down to minutes and treats a stale cookie as a signal. AER "automatically terminates the associated user sessions, reducing the security detection and response gap from potential days/hours to mere minutes"; configurable anomalies include "stale or unexpected session cookies".
23 textslashplain (Eric Lawrence) Protecting Auth Tokens blog 2023-10-23 2026-09-30 https://textslashplain.com/2023/10/23/protecting-auth-tokens/ A stolen post-login token is worth more than a password because it has already cleared MFA; the token is proof of a completed login. A stolen token "could be more valuable than stolen passwords, because a given site may require multi-factor authentication to use a password whereas a valid token represents completion of the full login flow."
24 ERNW / insinuator.net Token Theft in Microsoft Entra ID (Part 2 of 4): Continuous Access Evaluation blog 2026-09 2026-09-30 https://insinuator.net/2026/09/token-theft-in-microsoft-entra-id-part-2-of-4-continuous-access-evaluation/ Even with a revocation channel, a locally validated access token keeps working after a critical event, and the channel only covers first-party apps. An access token "remains fully usable for its entire lifetime even if security-critical events occur"; disabling a user and revoking refresh tokens still leaves "a gap of up to 90 minutes"; "only first-party Microsoft applications are CAE-capable".
25 Lydia Graslie Where Continuous Access Evaluation Stops Being Continuous blog 2026 2026-09-30 https://lydiagraslie.substack.com/p/where-continuous-access-evaluation "Near-real-time" revocation has a coverage map and a licensing gate; the control is uneven across the estate. CAE's "critical-event half travels with any Entra ID license, but the Conditional Access policy half requires Entra ID Premium P1, and the high-risk-user signal depends on Identity Protection, which is a P2 feature."
26 Microsoft Continuous access evaluation in Microsoft Entra vendor 2026 (living doc) 2026-09-30 https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-continuous-access-evaluation The trade the vendor actually makes: longer token lifetime in exchange for a revocation channel keyed on critical events. With CAE, token lifetime rises to "long-lived, up to 28 hours"; revocation is driven by "critical events" (account disable, password reset, admin token revocation, high user risk).
27 Google Protecting Cookies with Device Bound Session Credentials vendor 2026-04 2026-09-30 https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html The binding approach shipped to a consumer browser at scale in 2026, hardware-backed and default-off until the site opts in. DBSC protection rolled out in Chrome 146 for Windows, keys backed by the TPM; cookies bound to a device the malware cannot export the key from.
28 SpyCloud 2025 Annual Identity Exposure Report casestudy 2025 2026-09-30 https://spycloud.com/blog/2025-annual-identity-exposure-report/ The stolen-session economy is large and growing, which is why "shrink the window" controls are losing and "make the copy useless" controls are shipping. Recaptured identity records grew "22% in the past year, from 43.7 billion to 53.3 billion distinct identity records" (vendor figure; treat as a claim, not an independent measurement).