Third-party cookies have got to go
w3.org
w3.org
The behemoths of the industry (GOOG, FB, MSFT, AMZN) have moved beyond cookies to tracking users at an ID level. And with data sharing agreements in place [1] the big guys can track users across the spectrum.
Personal anecdote: Couple of days back me and a buddy were chatting over WhatsApp about a particular college. Neither of us had any affiliation to this college, and the college had come up in passing. Couple of hours later, I began receiving ads on my Gmail about that _very same college_
Naysayers might refute and put it down to recency bias. But this is just one example. I have noticed many others where my data has moved between GOOG n FB products in almost real time.
The deprecation of 3rd party cookies will make the small time companies scramble to figure out alternatives, which will invariably be super expensive. Thereby leading to further deaths of the independent entities.
So who is going to benefit from this deprecation? GOOG/FB/MSFT/AMZN again. Yay!
[1] https://www.reuters.com/article/technology/google-secretly-g...
That's some serious accusations. Without strong proof I don't believe it.
Not so sure about Facebook analyzing your WhatsApp traffic, because they make such a big thing in their advertising about the secure end-to-end encryption and privacy. Surely they would get roasted if it was found not to be true. Of course it's always possible with a closed source app.
The technique discussed in Darknet Diaries episode 146 (about the ANOM phone) involved duplicating the message to [an] archive endpoint. It mentions Google providing text archival as a service for company phones, and it seems this also happens for WhatsApp. However, are Facebook also purloining your private WhatsApps? Are they using them to target you? Who can say?
https://www.waterstones.com/book/chaos-monkeys/antonio-garci...
https://darknetdiaries.com/transcript/146/
https://www.telemessage.com/mobile-archiver/whatsapp-archive...
So while you and your friend chatted about this college, perhaps your friend googled it.
FB might then share with Google that you connected with your fiend at that particular time, and Google connected your exchange with the search.
Of course this assumes there is some way to tie your FB and Google accounts together - like matching up shared FB & Google tracker journeys across the internet.
But yes, blocking third-party cookies is not enough on its own. We need even MORE privacy protections, both technological and legislative.
The idea of third party cookies being bad is a reflection of the current state, not a methodology.
What happens if third party cookies are blocked?
Websites will just add a CNAME entry that points to whatever service they were using before. Then it's a second party (subdomain) cookie.
We need a different methodology how to keep cookies but limit their lifetime, reach, and damage they can do for its users, and a better unified authentication method that can also be spoofed/faked if websites become hostile. They need to be sandboxed, per URL scopes, not per domain.
We need to change the way of thinking of trust. Don't trust any website by default, only trust it once the user regularly visits it, or maybe set an allowed cookie lifetime per website after the user logs in.
But the current way of thinking about this problem led to the shithole that is XSS, session stealing and everything related to it.
Source: attempted to build my own browser that wanted to fix this and eventually had to give up
That doesn't cause the same problem as a third-party cookie, because it's not shared with other services that use the same third party. A subdomain doesn't let you get tracked across other sites.
A lot of tracking prevention mechanisms have started baking in CNAME uncloaking in the last few years precisely for that reason. Safari/WebKit[1], Brave[2], uBlock Origin (on Firefox only)[3], and NextDNS[4] just to name a few.
At this point the industry has moved onto straight up reverse proxying so it's all first party context. In milder instances it's in the form of server-side tagging[5] (which isn't a true reverse proxy, but can easily be used as one). But at least in those instances the website operators are the ones that typically own the server-side tagging process and have oversight/control/visibility into what they're putting in place.
But that has a high bar for implementation and relatively few companies have the resources or competence for that sort of thing. So it's much easier to persuade website operators to put a pure, dumb reverse proxy in place that gives them an endpoint under the first party domain to load resources from and send hits through[6]. Including being able to use HTTP set-cookie headers in the responses, while they're at it. Which is coincidentally the only long-lived cookie that still exists in Safari/WebKit, since things like "Keep me logged in" functionality would break if they started auto-purging those too.
If it's written in javascript, it's gone in 7 days even if it's first party. And if it's an HTTP header from a CNAME, it's also gone in 7 days. Only cookies set with an HTTP set-cookie header from a first party context are durable anymore. So that's exactly where advertisers are going into as an end-run in the game of cat and mouse - with surprisingly willing adoption from website operators, who are desperate to get their attribution back and don't quite understand the risk profile it exposes them to when they approve letting a third party operator masquarade so deeply as the website operator itself.
[1] https://webkit.org/blog/11338/cname-cloaking-and-bounce-trac...
[2] https://brave.com/privacy-updates/6-cname-trickery/
[3] https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
[4] https://medium.com/nextdns/nextdns-added-cname-uncloaking-su...
[5] https://developers.google.com/tag-platform/tag-manager/serve...
[6] https://developers.google.com/tag-platform/tag-manager/first...
[7] https://webkit.org/tracking-prevention/ (towards the bottom of the page)
Sure there are browser fingerprinting techniques, but at least you're making privacy invasion harder.
What do you mean "will"? This is already happening at least for Facebook tracking.
The change we need is to realise that this is not a technical problem and it can't be solved by technical means.
On the one hand, some of the largest US corporations are interested in subverting people's privacy. Some of those corporations directly control our computers and software running on them. They also spend billions to keep ahead of any non-megacorp competition (there's a business reason why Google keeps extending Chrome at breakneck speed).
On the other, the underlying problem is a kind of a prisoner dilemma. Spying-driven advertising is ultimately zero (or negative) sum for society [1], but any "defecting" company will be punished by relative sales underperformance. It's a coordination problem and it requires disincentives for defectors, which is not something we can engineer our way out of.
The solution has to be well enforced privacy protecting laws. Think GDPR, but with actual teeth and antitrust action, not letting companies get away with malicious compliance like sham "consent" forms directly violating GDPR [2].
Unfortunately, even on this forum there is very little understanding of the necessity of regulation, and I doubt things will change much. It pays very well to destroy privacy and open web (remember AMP?), and there is very little financial gain in going the other way. In fact, it's professionally harmful, since enablers are more likely to gain and hold power over those who object.
My only hope is relative outsiders in the EU legislature.
[1]: We haven't seen an explosion of productivity attributable to FAANG, so ultimately customers have the same pool of disposable money that businesses are competing for. The businesses haven't shrunk their marketing budgets either, so if you step back and look at the before/after state of the system as a whole, nothing changed except the big shift of ad money from old platforms (including print media) towards FAANG.
[2]: GDPR requires consent to be informed and specific. Ask yourself, do you really understand what precisely your data will be used for when you look at a typical "cookie banner"? Have you ever received a notification asking you if you consent to your data being used in a new way, which is absolutely necessary under GDPR if a data controller (i.e., a business collecting your data) decides to onboard a new marketing SaaS? Have you ever heard of a substantial fine for a company collecting consent in a way that is not specific enough?
We don't need "effective" alternatives to third-party cookies. The only reason that's even considered is because the advertising industry has captured the browser market and are using that control to ensure their continued ability to track users.
In fact, blocking third-party cookies is not nearly enough. We need to make sure most users have the capability to block all online ads.
Browser vendors have not yet provided APIs to both block cookies and allow for user consent to let these flows work. The Chrome team seems to be re-inventing the wheel with the Federated Credential Management API, which is not even close to done or feature complete with OAuth/OpenID Connect. This is why their end-of-year deadline was never a realistic.
All APIs introduced around the cookie phase-out are either fundamentally broken, or only serve to give established players such as Google more control over the user data.
For example, first-party sets are an allowlist curated by Google to determine who gets to set cookies in a third-party context, the FedCM API is barely implemented by a single vendor, the CHIPS API still breaks the most common cross domain authentication flows, and the Storage Access API is an inconsistent mess between vendors.
A very healthy % of the explainers Google is working on directly or indirectly relate to 3rd party cookies and/or storage buckets/isolation. https://github.com/orgs/explainers-by-googlers/repositories?...
Yep - the fact that there are hard-coded carve outs in webkit's source code for "theonion.com" and other such websites (and a bucket of heuristics which no one likes but which allow third-party cookies as first party in some scenarios) is why the web hasn't been more broken by this ... yet.
I've implemented both OIDC SSO and SLO between a lot of varying services and identity providers and have never needed 3rd party cookies so I'm curious.
Only place I've seen it are some really old SAML implementations and even those could be reworked to not use 3rd party cookies.
If a user wants to sign in to foo.com through auth.com it is not possible for foo.com to know if the user has a session, so it needs to redirect the user to auth.com to understand if the user has a session. Previously this could be handled by embedding an iframe into foo.com with auth.com that can read the session cookie, this is no longer possible due to cookie protection.
Also if a user is signed into auth.com and foo.com, and then signs out of auth.com it is not possible to detect the user has signed out, as foo.com cannot access cookies set on auth.com.
That said, once you introduce embedding (A embeds B, both A and B want to delegate the user's identity through SSO-C) you find the real pain points of lacking ambient authentication on the web. But even this case is possible if the websites cooperate ... which unfortunately means that techniques that enable cooperating websites can be used for cross-site tracking as well.
There are indeed. But given that 3rd party cookies are most commonly used for nefarious purposes, dispensing with them strikes me as the lesser of two evils. I do that myself with my browser settings.
Says who?
No, it isn't. I've seen a lot of cases when 3rd party cookies were used in complex web based software, especially in enterprise software.
This maximalism is tiresome.
I still find it odd how I'm constantly being asked if I'm fine with a website storing information in a place I have full control over. In theory it's the perfect method, privacy wise, it's just the user-agents who have dropped the ball massively.
I made a minimal Chrome extension for it and I've noticed a few sites are actually compliant: https://chromewebstore.google.com/detail/gpc-enabler/ilknagn...
We're in the weird situation where we're banning what is by far the best and most privacy preserving solution in the name of privacy.
I mean can you come up with a way that is better than letting a user store data locally in their full control?
How can the browser know what the cookie is being used for?
Just make users make the choice, once, and for every website up front when they setup their browser.
The mistake was assuming companies can feel shame.
Why aren't people responding to the law in the way I want them to?! lol
Legislate the behavior you want to see, not the behavior you hope will be a side-effect. You can't say, "the law is fine, it's the children that are wrong" when sites responded to the incentives they were placed under. The system finds an equilibrium at "everyone keeps doing exactly what they were doing before, just with a banner" and that's entirely the fault of the law. The incentives even go to far as to punish defectors because anyone who does right by their users loses money.
Another side has nothing (users). No power, no comparable money.
I would not bet even $1 on users.
this doesn't make sense. if you're just solving oauth without cookies, solve oauth without cookies. make an oauth spec. (isn't passkeys supposed to solve oauth?)
also oauth uses redirects and query params I thought. I wonder if by 'single sign on' they mean 'tracking by google but not rando 3rd parties'
let's say SSO is an actual exceptional case where 3p cookies are useful. oauth + similar flows are miserable and nonstandard. make everyone happy with you one time in your life W3 group and standardize oauth. literally take whatever oauthlib and passport support today and encode them into a standard
not sure why shopping carts need to be third party; in the shopify case, shopify is hosting the store and the cart. if a cart legit needs to be shared across sites ... use oauth
AFAIK this is why the UK's competition authorities were hostile to Google removing third party cookies.
But in practice, the engineering lift and complexity of the solutions is absolutely massive, so many companies simply will not be able to play ball. Additionally, because the internet will be more private the sketchy companies doing things like fingerprinting will cease to exist. Google has never said they will kill off competing solutions that are not privacy safe (UID2), but have explicitly said they will stop any fingerprinting, cross site tracking, etc.