4 ms·
I dont mean to be dismissive, but it has been long announced, discussed, and noisily in the console. My honest question would be how you've missed it (because
by ergothus 7y ago
I dont mean to be dismissive, but it has been long announced, discussed, and noisily in the console.
My honest question would be how you've missed it (because I'm assuming your missing means others would also reasonably miss this) but I have no idea how you could know the answer to that.
- bartread 7y ago> and noisily in the console. This is true but not necessarily helpful because what the console is often noisily complaining about is cookies from Google properties and the like. For many cases where I'm not making use of those cookies myself that's simply irrelevant... noise: what I need to understand are changes required for my own cookies, on which the console has remained silent. Also, not something I'm going to be paying attention to if I'm debugging something unrelated. (I'm not saying the console is a bad place to show these warnings - far from it - but there are plenty of reasons people might not spot them.) I found out about the changes a while ago through HN but even that was months after the announcement was made. I don't closely follow announcements from Google simply because the vast majority of them aren't relevant to me. That being the case it's quite easy to miss things, or find out about them further down the line via another source.
- ergothus 7y agoI understand the complaint about noise, but the message is fairly explicit as to what is changing and what you need to do and where to go for more info: "A cookie associated with a resource at http://google.com/ http://google.com/ was set with `SameSite=None` but without `Secure`. A future release of Chrome will only deliver cookies marked `SameSite=None` if they are also marked `Secure`. You can review cookies in developer tools under Application>Storage>Cookies and see more details at https://www.chromestatus.com/feature/5633521622188032." https://www.chromestatus.com/feature/5633521622188032." A quick google (ha!) check shows articles from plenty of development and security blogs (i.e. not from google direct) going back to May (though a LOT seem to be from the last few months, not sure if that's because chatter picked up or because Google is giving me more recent results, and I'm too lazy to experiment - I definitely heard about it from multiple sources before the original impact date in Oct) Focusing on the point - Obviously this is a change Google should give "enough" notice for (both time-wise and breadth-wise). What would you recommend them doing differently than they have? At the end of the day, I'm not really sure what they can do that they didn't do - indeed, since they delayed the original release, there's a real risk of people ceasing to pay attention if you delay too much. I'm asking out of curiosity, not accusation.
- bartread 7y agoNo stress, and I do get it, but it's bound to happen that people don't find out. My issue with the console warning is that, as explicit as it is, unless you know at least some of the background it's not immediately obvious why it's relevant to me as a developer of mysite.com.
- nitwit005 7y agoI'd assume plenty of people will completely miss any news of it. A lot of sites have no developer actively working on them. Even if the developer exists, a lot of them will happily ignore warnings. I've certainly been guilty of that.