Hacker News new | past | comments | ask | show | jobs | submit login

Hasn't safari always defaulted to no 3rd party cookies?



As I understand it:

No. Rather, Safari uses "Intelligent Tracking Prevention". This blocks SOME (most?) 3rd Party cookies, but not all. For example, single sign on providers will often use cookies, and they are often explicitly 3rd party. ITP tries to let those through.

IIRC Safari can be set to block ALL 3rd party cookies, but it is not the default setting.

SSO providers don't NEED cookies, they can do full page redirects to avoid being 3rd party, but it does complicate matters, and the relationship between you, a site, and a 3rd party identity provider you've presumably agreed to can be a different beast than the tracking cookies that are the focus here, though of course identity providers could always join the dark side as well.


Safari used to allow 3rd party cookies in some circumstances, and of course Google abused that for tracking:

https://nakedsecurity.sophos.com/2017/11/30/google-sued-over...




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: