Remove promiscuous-cookies-and-their-impending-death-via-the-samesite-policy
article thumbnail

Promiscuous Cookies and Their Impending Death via the SameSite Policy

Troy Hunt

Cookies like to get around. I mean have a think about it: If a website sets a cookie then you click a link to another page on that same site, will the cookie be automatically sent with the request? What if an attacker sends you a link to that same website in a malicious email and you click that link, will the cookie be sent?

Passwords 114