Hacker News new | ask | show | jobs
by londons_explore 2670 days ago
Site B has an iframe back to site A and the 'user 34' cookie can still be read.

All these protections only prevent setting cookies, not reading them again.

1 comments

It does prevent them from reading too: "Domains classified as trackers are not able to access or set cookies, local storage, and other site data when loaded in a third-party context." (emphasis mine)

https://blog.mozilla.org/security/2018/10/23/firefox-63-lets...