7 ms·
Third-party cookies have got to go
- foxbee 2y agoI find it hard to believe Google will let go of their golden goose. It's too risky for them.
- crngefest 2y agoThey just recently announced that they won’t phase out third party cookies next year - delayed until further notice or next golden goose.
- 4RealFreedom 2y agoThere's a link in the article where Google says they are not phasing out third party cookies at all - https://privacysandbox.com/news/privacy-sandbox-update/ https://privacysandbox.com/news/privacy-sandbox-update/.
- vbezhenar 2y agoThey are already gone on Firefox. I had to reengineer one system to make it work. So if you’re care about compatibility, third party cookies are already effectively gone.
- zokier 2y agoThey aren't letting go of their golden goose. They are just killing off the competition.
- spacebanana7 2y agoIsn't it the opposite? Most of Google's competitors in the ad space are very dependent on third party cookies but Google itself can get browsing information from Chrome directly. AFAIK this is why the UK's competition authorities were hostile to Google removing third party cookies.
- soared 2y agoIt’s unclear - competitors rely on 3p cookies, but abuse them. Google getting rid of them in theory levels some of the playing field - smaller companies can compete with larger ones because larger ones can no longer track users across every site where they have a pixel installed (IE fb’s massive advantage of having a pixel on virtually every website means only they know every single site you visit). But in practice, the engineering lift and complexity of the solutions is absolutely massive, so many companies simply will not be able to play ball. Additionally, because the internet will be more private the sketchy companies doing things like fingerprinting will cease to exist. Google has never said they will kill off competing solutions that are not privacy safe (UID2), but have explicitly said they will stop any fingerprinting, cross site tracking, etc.
- shiandow 2y agoWhen browsers finally step up and start managing cookies properly for once, can we finally get rid of the silly cookie banners? I still find it odd how I'm constantly being asked if I'm fine with a website storing information in a place I have full control over. In theory it's the perfect method, privacy wise, it's just the user-agents who have dropped the ball massively.
- Semaphor 2y agoThose banners are mostly not about cookies.
- fmajid 2y agoGlobal Privacy Control, effectively legally enforced Do-Not-Track (already the law in California) is the way forward on cookie banners. https://www.cookieyes.com/blog/global-privacy-control/ https://www.cookieyes.com/blog/global-privacy-control/
- manbitesdog 2y agoGPC is definitely the way forward. Why asking constantly for a preference when the browser can state your preferences in a header? I made a minimal Chrome extension for it and I've noticed a few sites are actually compliant: https://chromewebstore.google.com/detail/gpc-enabler/ilknagnpcicckgohjailfooamibaolnj https://chromewebstore.google.com/detail/gpc-enabler/ilknagn...
- fmajid 2y agoCalifornia is suing Sephora for noncompliance, more will follow when the word gets out. I don’t know why the EU is dragging its feet incorporating GPC into GDPR.
- Flimm 2y agoEven if all cookies were completely disabled in all browsers, current privacy laws like GDPR would still require consent for all the tracking and sharing of private information that companies do through other means, and so websites would probably still display banners to remain in compliance.
- cookiengineer 2y agoAs if this would change anything. The idea of third party cookies being bad is a reflection of the current state, not a methodology. What happens if third party cookies are blocked? Websites will just add a CNAME entry that points to whatever service they were using before. Then it's a second party (subdomain) cookie. We need a different methodology how to keep cookies but limit their lifetime, reach, and damage they can do for its users, and a better unified authentication method that can also be spoofed/faked if websites become hostile. They need to be sandboxed, per URL scopes, not per domain. We need to change the way of thinking of trust. Don't trust any website by default, only trust it once the user regularly visits it, or maybe set an allowed cookie lifetime per website after the user logs in. But the current way of thinking about this problem led to the shithole that is XSS, session stealing and everything related to it. Source: attempted to build my own browser that wanted to fix this and eventually had to give up
- fph 2y agoIf you replace a cookie for eviladcompany.com with one for eviladcompany.domain1.com, there is still an advantage: that this is not shared with eviladcompany.domain2.com, so eviladcompany cannot know that it's the same person visiting both websites. Sure there are browser fingerprinting techniques, but at least you're making privacy invasion harder.
- JoshTriplett 2y ago> Websites will just add a CNAME entry that points to whatever service they were using before. Then it's a second party (subdomain) cookie. That doesn't cause the same problem as a third-party cookie, because it's not shared with other services that use the same third party. A subdomain doesn't let you get tracked across other sites.
- deleted 2y ago[deleted]
- vladvasiliu 2y ago> Websites will just add a CNAME entry that points to whatever service they were using before What do you mean "will"? This is already happening at least for Facebook tracking.
- zx8080 2y agoOne side has money and power over changing the browser behaviour (Google and advertisers). They can use money for lobbying almost anything they need in all contries. They own almost all levels in the web tech stack. Another side has nothing (users). No power, no comparable money. I would not bet even $1 on users.
- RaSoJo 2y agoThis ship has sailed. The deprecation of 3rd party cookies will impact only the small ad-companies (the few that are still afloat) The behemoths of the industry (GOOG, FB, MSFT, AMZN) have moved beyond cookies to tracking users at an ID level. And with data sharing agreements in place [1] the big guys can track users across the spectrum. Personal anecdote: Couple of days back me and a buddy were chatting over WhatsApp about a particular college. Neither of us had any affiliation to this college, and the college had come up in passing. Couple of hours later, I began receiving ads on my Gmail about that _very same college_ Naysayers might refute and put it down to recency bias. But this is just one example. I have noticed many others where my data has moved between GOOG n FB products in almost real time. The deprecation of 3rd party cookies will make the small time companies scramble to figure out alternatives, which will invariably be super expensive. Thereby leading to further deaths of the independent entities. So who is going to benefit from this deprecation? GOOG/FB/MSFT/AMZN again. Yay! [1] https://www.reuters.com/article/technology/google-secretly-gave-facebook-perks-data-in-ad-deal-us-states-allege-idUSKBN28Q37G/ https://www.reuters.com/article/technology/google-secretly-g...
- account42 2y agoUsers also benefit even if only a little. But yes, blocking third-party cookies is not enough on its own. We need even MORE privacy protections, both technological and legislative.
- SahAssar 2y agoSo not only are you alleging that Meta scans your whatsapp messages for advertising purposes (which they strongly claim they don't do), you are also alleging that they are selling your whatsapp messages to Google? That's some serious accusations. Without strong proof I don't believe it.
- ninjanomnom 2y agoI assumed they were saying that they'd received an email ad, not that google served an ad. I could be wrong though. I wouldn't trust what meta says here considering their past history, but there are reasonable alternate sources in this case. Keyboard replacements on phones are notorious for logging, or either participant could have an app logging screenshots.
- account42 2y ago> The unfortunate climb-down will also have secondary effects, as it is likely to delay cross-browser work on effective alternatives to third-party cookies. We don't need "effective" alternatives to third-party cookies. The only reason that's even considered is because the advertising industry has captured the browser market and are using that control to ensure their continued ability to track users. In fact, blocking third-party cookies is not nearly enough. We need to make sure most users have the capability to block all online ads.
- jonkoops 2y agoI agree with you. But I also work on Keycloak and there are legitimate reasons why 3rd-party cookies are needed, they are essential for silent authentication flows and session management, which are part of the OpenID Connect standard. Browser vendors have not yet provided APIs to both block cookies and allow for user consent to let these flows work. The Chrome team seems to be re-inventing the wheel with the Federated Credential Management API, which is not even close to done or feature complete with OAuth/OpenID Connect. This is why their end-of-year deadline was never a realistic. All APIs introduced around the cookie phase-out are either fundamentally broken, or only serve to give established players such as Google more control over the user data. For example, first-party sets are an allowlist curated by Google to determine who gets to set cookies in a third-party context, the FedCM API is barely implemented by a single vendor, the CHIPS API still breaks the most common cross domain authentication flows, and the Storage Access API is an inconsistent mess between vendors.
- MzHN 2y agoCan you give some pointers or what to search for regarding OIDC and 3rd party cookies? I've implemented both OIDC SSO and SLO between a lot of varying services and identity providers and have never needed 3rd party cookies so I'm curious. Only place I've seen it are some really old SAML implementations and even those could be reworked to not use 3rd party cookies.
- jonkoops 2y ago
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- fulldecent2 2y ago[flagged]
- deleted 2y ago[deleted]
- awinter-py 2y ago> They can be helpful for use cases like login and single sign-on, or putting shopping choices into a cart this doesn't make sense. if you're just solving oauth without cookies, solve oauth without cookies. make an oauth spec. (isn't passkeys supposed to solve oauth?) also oauth uses redirects and query params I thought. I wonder if by 'single sign on' they mean 'tracking by google but not rando 3rd parties' let's say SSO is an actual exceptional case where 3p cookies are useful. oauth + similar flows are miserable and nonstandard. make everyone happy with you one time in your life W3 group and standardize oauth. literally take whatever oauthlib and passport support today and encode them into a standard not sure why shopping carts need to be third party; in the shopify case, shopify is hosting the store and the cart. if a cart legit needs to be shared across sites ... use oauth