5 ms·
How can a browser differentiate between a first-party cookie needed for login and a first-party cookie for tracking? It's legal to use cookies for behaviour su
by wjdp 6y ago
How can a browser differentiate between a first-party cookie needed for login and a first-party cookie for tracking?
It's legal to use cookies for behaviour such as login which is necessary but you need consent for tracking.
If a browser blocked all cookies until the user turned them on you'd have the choice of "no login" or "login works, but so does all the tracking".
Not saying the current state of affairs is good, it's awful.
- _puk 6y agoIf we're going down the route of regulation, and browser control, would it be a step too far to require standardised metadata in a cookie? That way, each cookie could describe itself as login, tracking, optional functionality etc. You can then penalise on cookies that purposefully violate this, and allow the user to centrally opt in or out of each type.
- wjdp 6y agoAha, place trust in the site to label their cookies correctly? I see you've covered that with penalising sites who mislabel. Who maintains this list? If it's the browser vendor remember which company owns the largest share in this market.
- saagarjha 6y agoThe evil bit is currently little used, I suggest repurposing that: https://en.wikipedia.org/wiki/Evil_bit https://en.wikipedia.org/wiki/Evil_bit
- qwerty456127 6y ago"Evil" is subjective and too broad (most of it has already been outlawed anyway and that works: e.g. a competing business is going to think twice before DDoSing you as they know they are doomed if that gets discovered and proven). Surveillance, however, is a much more specific thing. Stalking people already is illegal for people, it should also be made illegal for companies.
- tgsovlerkhgsel 6y agoOne simple factor could be "does the user have a password (or WebAuthN credential) stored for this web site". Otherwise have a way for the web site to trigger a browser-controled consent UI. This would be a one-shot thing and clicking "no" would trigger a spam signal. Too many of these and the web site loses its "ask for cookies" permission. Cookies for anything not trusted have a lifetime of "until the tab is closed".
- qwerty456127 6y ago> This would be a one-shot thing and clicking "no" would trigger a spam signal. Too many of these and the web site loses its "ask for cookies" permission. Don't be too rough on them. You should look for a viable and sustainable solution, not a radical GtFO doomed to end here. > Cookies for anything not trusted have a lifetime of "until the tab is closed". "until the tab is closed" policy isn't convenient even for the user. I tried it and reverted to "until the browser is closed" quickly.