3 ms·
Why are cross site cookies allowed at all? Wouldn’t it make more sense to just disable them entirely?
by RaiseProfits 7y ago
Why are cross site cookies allowed at all? Wouldn’t it make more sense to just disable them entirely?
- jimbo1qaz 7y agoI've heard that https://tools.ietf.org/html/rfc2109 https://tools.ietf.org/html/rfc2109 (the cookie RFC) was originally meant to not allow third-party cookies by default. In my opinion, cookies on cross-site requests (third-party cookies) should be sent to web servers under a different request header, since they're semantically different (do not necessarily imply user authorization and intent) from cookies attached to a request initiated by the user from a first-party page.
- Thorrez 7y ago>cross-site requests (third-party cookies) I thought "third-party cookies" generally referred to cookies that were set in a third-party context. Whereas you're talking about cookies being read in a third-party context.
- RaiseProfits 7y agoWhat is a scenario that would illustrate the difference? On paper third party cookie just means “any cookie from another domain”. How would you read another domain’s cookie without some feature that explicitly allows it, like the Chrome feature in question?
- Thorrez 7y agoOh, you're right there isn't a distinction, for some reason I thought there was.