Device-bound session credentials thwart an increasingly common form of account takeover.
To respect copyright, we link to the source rather than republishing the full text. Read the complete article on Ars Technica.