Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That is when you have sign in and communication on the server side, not place data in the browser for tracking.


How do you suggest implementing "sign in" without setting a cookie?


Sign-in cookies are always first party. That's completely out of context here where we're taking about tracking cookies.


There's absolutely nothing except convenience preventing ad-tech companies from routing their 3rd party cookies through a proxy hosted on the first-party domain. If 3rd party cookies stop working, they'll just start having their customers set up CNAMEs on their own domains.


I’m not familiar with a distinct “sign in cookie” either. Do you mean a server side cookie / HttpOnly?


It's basically a cookie holding your session id, scoped only to the site and used only for auth purposes (or holding the session vars if you're doing client-side sessions)


So, just to reiterate, contrary to the comment I replied to, you are suggesting we "place data in the browser for tracking" a user's authentication state and session.


Ah, I think we're stepping on an overloaded term. I mean tracking as in "identifier connecting visits from unrelated pages used for data collection" and not "identifier used by the site you're connecting to for purpose of holding browsing session variables".


Please stop your gaslighting. You were the only one equating "place data in the browser for tracking" with all use of cookies, nobody else made that "mistake".


How else would you describe a login token? It's literally data in the browser for tracking who that user is and identifying them to the server!

All I'm doing is highlighting is that it's not as simple as some of these jUsT bAN cOoKIes folks would have you believe.

Blocking technologies that are used for invidious ad-tech will make it more difficult to support legitimate use-cases. Sleazy ad-merchants like Google will move on to something else built into the browser https://blog.google/products/ads-commerce/2021-01-privacy-sa... and normal site developers will be left in the lurch.

IMHO there isn't a technological solution to this problem, the only effective answer is regulation & hefty fines that make unethical tracking also unprofitable.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: