Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

IIUC the main difference is that third-party cookies are not blocked, but scoped to the top-level domain.

So if you visit games.example which loads tracker.example it can set cookies. However these cookies are only used while you are on games.example. If you start browsing comics.example which also loads tracker.example it will start with no cookies, but can set cookies that only affect comics.example.

This way cross-site cookies can still be used for auth, experiments, spam protection or whatever else. But you can't do cross-site tracking as each top-level site had a separate cookie jar.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: