Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> and regulatory-compliance standpoint

One of the main reasons why people can't just turn off Cookies is because they are needed for session management. This makes it very difficult to just disable. If there was a dedicated session management method in HTTP/2.0 then that would remove a lot of the need for Cookies. Then they could be used for what they were intended (local persistent state). This would also give users better methods for managing them (or just disabling them).



Eh... maybe eventually, once nothing uses cookies anymore (including existing HTTP sites). But surely this can be solved today by having browsers force cookies to expire with the session?


And that is what phk is advocating as part of his proposal. Cookies are the wrong tool to be used for session management.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: