Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

which you should disable as soon as you install your browser.

unless you bought into the Google one. since Google also benefit a lot from 3rd party cookie, it paid Mozilla so they enabled it by default (use to be off by default) and i think recently chrome ever removed the option to disable it.

disabling 3rd party cookie is a million times more effective than enabling the joke of the do no track settings in the browser.



> it paid Mozilla so they enabled it by default

Sources please.


It's not true, Mozilla actually tried to block them by default back in 2013 but was threatened by the ad industry and backed down. http://www.computerworld.com/article/2495739/internet/ad-ind...

I think it was mistaken for Google paying Mozilla to keep it as default search engine.


And yet desktop Safari continues to block most third-party cookies, last I checked.


most?


This setting is in the latest versions of desktop and mobile Chrome.


I think it was very revealing that they never had this setting for a long time, despite it being available in just about every other browser before then...


This isn't true. Chrome launched with a setting called "Restrict how third party cookies can be used" which was almost the same thing:

> First-party and third-party cookies can be set by the website you're visiting and websites that have items embedded in the website you're visiting. But when you next visit the website, only first-party cookie information is sent to the website. Third-party cookie information isn't sent back to the websites that originally set the third-party cookies.

As far as I can tell, this difference was due to the fact that Chrome (at the time) was a WebKit fork (see https://bugs.chromium.org/p/chromium/issues/detail?id=12969#... and https://bugs.chromium.org/p/chromium/issues/detail?id=16658#...). Both the comments I mention are from 2009 (less than a year after Chrome was publicly announced).

I searched through chromium's source to see if I could figure out when this option/feature changed. I didn't find it, but I find plenty of examples of Chromium developers adding functionality and features to make blocking and monitoring third-party cookies easier.

I did find a thread on Hacker News from 2011 (https://news.ycombinator.com/item?id=3034295), by which point Chrome's third party cookie blocking was actually stricter than WebKit/Safari due to changes in Chromium's cookie management. Note that the main argument there isn't that Chrome should expose their strict cookie blocking as a setting (their current behavior), but that Chrome should default to Safari's looser handling (which seems similar to Chrome's original "restrict.." setting). It is worth noting that Firefox did eventually implement the latter solution - but two years later, in 2013 (https://blog.mozilla.org/netpolicy/2013/02/25/firefox-gettin...).

It's possible I have missed something and there is evidence somewhere on the Internet that there was a point where Chromium's handling of third party cookie blocking was significantly different than all other major browsers, but I haven't seen it.


> First-party and third-party cookies can be set by the website you're visiting and websites that have items embedded in the website you're visiting. But when you next visit the website, only first-party cookie information is sent to the website. Third-party cookie information isn't sent back to the websites that originally set the third-party cookies.

This mess of words is merely an excuse to say that the 3rd party cookie protection didn't really work. Are you seriously raising this as a feature in some way as good as 'block 3rd party cookies'? As the bugs you linked show, Chrome's behaviour broke sites where Safari worked, yet leaked cookie data to sites.


> Are you seriously raising this as a feature in some way as good as 'block 3rd party cookies'? As the bugs you linked show, Chrome's behaviour broke sites where Safari worked, yet leaked cookie data to sites.

My point was that your previous claim that Chrome didn't have a third-party cookie blocking feature until after other browsers because Google hates privacy is wrong, since Chrome launched with a similar feature and its developers explicitly tried to maintain cookie-blocking parity with Safari.

The site breakage you referenced was because Chrome was blocking cookies where Safari wasn't. The data leakage bug also explicitly states Safari was subject to the same data leakage. Neither issue supports your initial claim, since they are proof that Chrome developers wanted parity with Safari, which suggests the point of Chrome wasn't to create a browser with less privacy protections than the competition.


Chrome still has the option, though they're not disabled by default. I disable them and also set up another person/profile in Chrome that allows 3rd party cookies but deletes all cookies when quitting. If I encounter a site that doesn't work with 3rd party cookies disabled, I can easily launch another window with the other profile and view the site without having to change settings.


There is a cookie icon in the adressbar if 3rd party cookies are blocked. You can click it and go to show cookies or something (first blue link) and unblock the blocked.


I don't even see an option in Firefox ESR 45.4.0 to disable 3rd party cookies.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: