cookies-over-http-bad
cookies-over-http-bad copied to clipboard
Archived proposal from 2018. Perhaps the approach in mikewest/scheming-cookies will be more successful!
> Should we special-case the cookie value "OPT_OUT"? It would be unfortunate indeed if removing old cookies meant that users who had opted out of interest-based advertising started being targeted...
We had an issue a few years back when setting up tentative HTTPS, in that our login page would be served over HTTPS but the subsequent navigation could go on...
Current phrasing like > those cookies which would actually be sent over HTTP etc. talks all about sending a Cookie header, but we should be clear that this applies to...
I wasn't sure exactly what was meant by this? Isn't rebuilding infrastructure == pain? > Our goal should be to ensure that the friction involved with rebuilding their entire infrastructure...
https://freedom-to-tinker.com/2014/12/19/how-cookies-can-be-used-for-global-surveillance/ https://senglehardt.com/papers/www15_cookie_surveil.pdf