3 ms·
While on the topic of third-party cookies - is there any legitimate use for those at all (outside of semi-covert user tracking)? I understand how first-party c
by nousermane 6y ago
While on the topic of third-party cookies - is there any legitimate use for those at all (outside of semi-covert user tracking)?
I understand how first-party cookies are useful - you take a stateless protocol (HTTP) and make it aware of "sessions". And those in turn are a nifty block to build upon - login/authentication, "shopping cart", whatever...
But having one website to be able to save state that is only accessible to a chosen different site - what's the use for that?
- acdha 6y agoThings like single-sign on or social networking where you toss some JavaScript from api.example.com on your page and it does things like automatically log you in or display messages you might have. I see this is as a tragedy of the commons problem: it's kind of nice to have, say, a counter of unread Disqus messages but the relative value of that compared to the use by tracking companies is hard to ignore.
- tootie 6y agoOauth and SAML use callbacks, not cookies.
- iooi 6y agoThat's if you're implementing SSO on your own, which most folks don't do. Most SaaS using SSO in their apps will use Auth0 or Okta. Dropping third-party cookies has implications for these integrations: https://support.okta.com/help/s/article/FAQ-How-Blocking-Third-Party-Cookies-Can-Potentially-Impact-Your-Okta-Environment?language=en_US https://support.okta.com/help/s/article/FAQ-How-Blocking-Thi...
- acdha 6y agoI didn't specify those protocols for a reason. While that's technically true at the API level, I was referring to things like the “Sign-On with <service>” widgets – you can make a completely static version of that which doesn't use cookies but there is a nice UI improvement if the button can load and say things like “Login as @tootie” or “@tootie, you have 5 DMs” anywhere you see it. Instead, I think we're going to recognize that this is too broad to be secured and either come up with ways to scope it down (e.g. requiring the third-party to have some sort of opt-in prompt) or that entire market category replaced with browser-controlled alternatives, which isn't great for companies other than Apple, Google, and maybe Microsoft but does have the appeal of not trusting an entity which the user isn't already trusting.