Cookies sent over plaintext HTTP are visible to anyone on the network. This visibility exposes substantial amounts of data to network attackers (passive or active). We know, for example, that long-lived and stable cookies have enabled pervasive monitoring in the past (see Google's PREF cookie), and we know that HTTPS provides significant confidentiality protections against this kind of attack. Over time, we should mitigate this risk by capping the lifetime of cookies delivered over HTTP.


Proposed (tracking bug)

Last updated on 2021-12-12