4 ms·
I was recently trying to set a cookie to "never" expire. Apparently there's no good way to do this other than pick a date that's far enough out in the future.
by throwaway_bad 7y ago
I was recently trying to set a cookie to "never" expire.
Apparently there's no good way to do this other than pick a date that's far enough out in the future.
A stackover answer gave an example setting it for 10 years. I thought I would be defensive and set it to 20 years.
But then it will immediately break because 32 bit dates wrap around in 2038!
- NohatCoder 7y agoJust set it to 1000 years, browsers have been able to handle such cookies for as long as I can remember.
- pferde 7y agoPerhaps it is because whoever came up with the specification for "browser cookies" never intended them to not expire, and thus you are trying to subvert the feature to do something it wasn't meant to. The Jurassic Park quote comes to mind: "Your scientists were so preoccupied with whether or not they could, they didn't stop to think if they should."
- ThePadawan 7y agoThe format for "Expires" is e.g. "Expires=Tue, 15 Jan 2013 21:47:38 GMT". Why would that wrap around in 2038? Are you assuming that browsers handle this incorrectly?
- throwaway_bad 7y agoIt was mostly a theoretical problem and not something I went through with. I only thought about it because I was also saving the expiration in a session table in mysql and my expires column is a `timestamp` which is 4bytes. I was using a language that uses more than 32 bits for dates, so you're right, it probably would've sent out the right cookie.
- nsuser3 7y ago> But then it will immediately break because 32 bit dates wrap around in 2038! Do modern browsers still use 32 bit timestamps internally? Regardless, it's probably not a good idea to rely on the browser saving cookies forever.
- onion2k 7y agoIt's bad enough supporting browsers from 10 years ago now. If we get to 2038 and I still need to support browsers from 2019 I'm going to be very sad indeed.
- wopian 7y agoYou'll still need to support browsers from 2009 ;)
- bluGill 7y agoWhat is your target? I work in embedded systems: I fully expect software I write today to run for the next 100 years. This is based on experience, we have customers still using 75 year old machines to do real work (that is not collectors) and I like to think engineering has learning something about making better machines since then. I think that computers will forever be able to drop back to 10baseT ethernet, ipv4 and html 1.0. Of course I don't expect everybody will be able to support those configurations. There are currently unknown security holes someplace in out old equipment so nobody sane will connect our old stuff to the public internet. Thus most developers are safe depending on users having something fairly new. However a few will target behind the firewall customers and they will be stuck supporting whatever that old machines supports.
- devtul 7y agoAfter watching a few Def Con talks, I' am sure there is a good chance of a very dedicated asshole out there trying to target those old systems.
- bluGill 7y agoThis has kept me awake at nights for years... It is now keeping boards of directors up at nights unlike a few years ago when I was told not to worry. No solution is in sight, but things are getting better.
- numlock86 7y agoI am impressed of the idea of using the same browser (and cookie store, related OS, whatever) for 20 years ...