Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. if you disable all third-party cookies in your browser (like where Site A is never allowed to use cookies from Site B), have you noticed that it breaks anything?

if you disable all third-party cookies in your browser (like where Site A is never allowed to use cookies from Site B), have you noticed that it breaks anything?

Scheduled Pinned Locked Moved Uncategorized
27 Posts 16 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • dmerej@mamot.frD dmerej@mamot.fr

    @oleschri @b0rk

    basically *everything* from Microsoft breaks (from Teams to Outlook to Azure)

    duncan_lithgow@mastodon.socialD This user is from outside of this forum
    duncan_lithgow@mastodon.socialD This user is from outside of this forum
    duncan_lithgow@mastodon.social
    wrote last edited by
    #21

    @dmerej
    I find I often have to log in again for different parts of the Microsoft 'experience' but that's no big deal with a password manager (#bitwarden in my case)
    @oleschri @b0rk

    1 Reply Last reply
    0
    • hylomorphism@mastodon.me.ukH hylomorphism@mastodon.me.uk

      @b0rk I've had 3rd party cookies disabled for years, and I use Vivaldi with full blocking turned on and very little breaks. Anything I come across which doesn't work properly I just don't use.

      duncan_lithgow@mastodon.socialD This user is from outside of this forum
      duncan_lithgow@mastodon.socialD This user is from outside of this forum
      duncan_lithgow@mastodon.social
      wrote last edited by
      #22

      @hylomorphism
      Also blocked 3rd party cookies for years. I also use privacy badger.
      @b0rk

      1 Reply Last reply
      0
      • cthos@mastodon.cthos.devC cthos@mastodon.cthos.dev

        @b0rk @Viss In the OIDC/OAuth sense it doesn't, and for a while there Google stopped using them on its own auth flow (using some redirect trickery to get youtube.com to work properly) when they were actively working on disabling them in Chrome (which they backed off of because advertising).

        craigstuntz@discuss.systemsC This user is from outside of this forum
        craigstuntz@discuss.systemsC This user is from outside of this forum
        craigstuntz@discuss.systems
        wrote last edited by
        #23

        @cthos @b0rk @Viss Yes, I block 3rd party cookies and I can still log in with Google to a third party site. This is probably not universally true for all SSO providers, but it does work with Google. @b0rk the main thing I've noticed which breaks (unclear if it's due to 3rd party cookies per se or some other setting I have) is embeds of tweets and Disqus.

        1 Reply Last reply
        0
        • b0rk@social.jvns.caB b0rk@social.jvns.ca

          if you disable all third-party cookies in your browser (like where Site A is never allowed to use cookies from Site B), have you noticed that it breaks anything? What breaks?

          freddy@social.security.plumbingF This user is from outside of this forum
          freddy@social.security.plumbingF This user is from outside of this forum
          freddy@social.security.plumbing
          wrote last edited by
          #24

          @b0rk very few pages break, I used the setting for a long while. I think webkit used to do it by default for some time, even? a good middle-ground is to do cookie-partitioning based on the first party. that's what Firefox does.

          b0rk@social.jvns.caB 1 Reply Last reply
          0
          • viss@mastodon.socialV viss@mastodon.social

            @b0rk well it'd be for things like if you go to like, i dunno, stackoverflow or somewhere else, and you get that popup that says 'login with google'. im not sure if facebook or twitter are still popular methods for this, but those would also fall into the same category. also any place using stuff like okta or nextcloud for auth are gonna suffer the same way

            schrotthaufen@mastodon.socialS This user is from outside of this forum
            schrotthaufen@mastodon.socialS This user is from outside of this forum
            schrotthaufen@mastodon.social
            wrote last edited by
            #25

            @Viss @b0rk Last time I checked, Duo, and SSO with Entra-ID didn’t work when third party cookies were disabled, as well.

            1 Reply Last reply
            0
            • b0rk@social.jvns.caB b0rk@social.jvns.ca

              if you disable all third-party cookies in your browser (like where Site A is never allowed to use cookies from Site B), have you noticed that it breaks anything? What breaks?

              airtower@woem.menA This user is from outside of this forum
              airtower@woem.menA This user is from outside of this forum
              airtower@woem.men
              wrote last edited by
              #26

              @b0rk@social.jvns.ca The only thing I've seen break is MS Teams (for work, unfortunately).

              1 Reply Last reply
              0
              • freddy@social.security.plumbingF freddy@social.security.plumbing

                @b0rk very few pages break, I used the setting for a long while. I think webkit used to do it by default for some time, even? a good middle-ground is to do cookie-partitioning based on the first party. that's what Firefox does.

                b0rk@social.jvns.caB This user is from outside of this forum
                b0rk@social.jvns.caB This user is from outside of this forum
                b0rk@social.jvns.ca
                wrote last edited by
                #27

                @freddy thanks, I think I need to read more of your writing / talks on browser security too 🙂

                1 Reply Last reply
                0
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups