this post was submitted on 04 Jan 2024
152 points (90.4% liked)
Technology
59534 readers
3195 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
You don't need cookies to keep track of the state. JavaScript can do that without cookies, 3rd party clients can do that without cookies.
Still, the use of cookies as key elements used to persist client session identifiers in the browser is too widespread and relied upon by prevalent web powerhouses like PHP for Google to do away with them.
Moreover, as much as there may be more modern, sleek alternatives like browser session and application storage, you can't realistically expect the entire web industry to completely migrate away from cookies just like that.
and if you're working on a site with a ton of subdomains, sharing the local/session storage data between them is a pain when compared with cookies.
deleted
They definitely used to, but haven’t for a long time. It’s been viewed as an unreliable and poor practice, especially with browsers like Safari and Firefox which have already disabled 3rd Party Cookies for some time now (or at least providing the option to, as a privacy feature).
Now CORS, OAUTH, and similar mechanisms do a better, more private, and more secure job of sharing state and authentication across domains and groups of services.
The amount of tech relying on cookies is slowly decreasing. Removing cookie support completely today is not an option, but it will be in the future.
There's also a lot of security gotchas when relying purely on JS.
Just lik with any tech. So what? Stop using internet alltogether?
Nah, cookies + JS is a solid authentication combo. But just JS without cookies is kinda vulnerable. Wouldnt want Paypal or taxes being purely Javascript authenticated.
Heres a fun article
https://betterprogramming.pub/understanding-auth-and-cookies-for-web-applications-33016c588cf9
The article is paywalled. And if someone is incapable of securing their JS app, that's on them. Cookies won't help.
Just because something exists does not mean that it should be used literally everyfuckingwhere
Go live in a cave.
Well there it is, the dumbest thing I’ve read on the internet today.
Go back to basics and start with html.
My guess is, you could say the same thing without the aggression
Lol ok.