This could have a huge advantage, because if you leave the original service untouched on port 80/443, there is no alert popping up on the defending blueteam side.
This gives me an idea for a project...
At least for some use cases. Of course, it doesn't directly integrate with headers.
On the other hand; the size constraints on storage will be less severe than those on tags in each http request, so perhaps this is being overly clever with risks of accidentally huge payloads suddenly being sent along with each request.
Could you point me to more reading about this? It's the first time I've heard of it
we're stuck with cookies because they exist.
Being anti-ads is a valid opinion. It has less intellectual cover than pro “privacy” though.
I spend a solid month chasing ghosts around iOS Safari arbitrarily eating cookies from domains controlled by our customers. I've never seen Google/Twitter/Facebook/etc domains lose session state like this.
I had hoped when writing this article that Google would look at Safari and see that it was always strict about feel comfortable about changing to be the same. But doing so now would unfortunately break too many things for too many users.
Or to be slightly more serious avoid calling it a cookie and call it something else. Too much baggage surrounding the word cookie.
https://chefjar.com/wp-content/uploads/2021/05/popeyes-biscu...
Is that generally true of scones?
You graduate from consuming cookies to eating...