Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> a significant amount of web content to this day still requires third-party cookies to work.

Not in the corners of the web I frequent. I've been blocking 3rd party cookies for years and the only site that's broken was some Pearson online homework site.



A lot of IDPs break. For example any website that presents "Login with Google" will not work or require a reload after completing the Auth flow before the login is accepted.

This isn't simply "blocking third party cookies", it's "even an iframe has no access to the other state partition". The third party cookie is allowed to exist but it cannot leak to other sites. However, this leak prevention breaks plenty of other things if one is not careful (Mozilla was, there is a heuristic).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: