Skip to content
Security

Cookies and Privacy: much more than a rumor

Team Host.it 6 min read

Content

What is the difference between Cookies and what are they for? Cookies are classified based on: duration, origin, purpose and technical characteristics.

Session cookie (temporary): it is automatically deleted when the browser is closed

Persistent cookie: remains active until its validity date or deletion by the user.

First-party cookies: these are data sent to the browser by the website you are visiting

Third party cookies: these are data sent to the browser from other websites and not from the one you are visiting.

Initially, the "domain" field linked to the cookie identified whether it was first or third party. Now there is no substantial difference between first or third party cookies, the diversity only exists at execution time, in the context of the visit.

Specifically, it is a first-party cookie if the cookie is associated with a page you are visiting; third-party cookies are contents of other sites and may be present on a web page, such as advertising banners.

A cookie can have more than one purpose, for example in this category we can identify technical and non-technical cookies and below I will indicate the various subcategories.

Technical cookies are useful for making navigation quick and easy, for example they help in some procedures such as online purchases, in the case of authentication in reserved areas or in choosing the language usually used.

navigation/essential/performance/process or security cookies: contributes to the correct functioning of the website. If it is blocked, the website does not work.

functionality/preferences/localization/session state cookies: allows you to save information that varies the appearance of the site such as: the language, character size and font used or geographical position. If it is blocked, the website works correctly but may be less user friendly.

statistical/analytical cookie a) first-party or b) third-party with IP masking, without data crossing: similar to the technical cookie, it is useful for collecting information for statistical purposes on the use of the website.

third-party statistical/analytical cookie without IP masking, without data crossing: generally used by website managers to retrieve information on users and then process and compile statistics on the service and use.

profiling/advertising/advertising/tracking or conversion cookies: they are used to monitor and outline the user's profile while browsing for example: analyzing behaviour, pages consulted on the web, habits, also and not only to send personalized advertisements.

4. TECHNICAL CHARACTERISTICS

Secure Cookie: the cookie goes to https ("Secure" flag inserted in the http header)

httpOnly Cookie : ""httpOnly" flag inserted in the HTTP header, the cookie cannot be used by client scripts or cross-side"

Super Cookies (local shared objects (LSO) / HTML5 DOM Local Storage / Silverlight / pixel hacks…) / browser independent cookies: o Flash cookies are data saved on the device by sites created in Flash. They are generally used to store information about games, online movies etc.

However, these Cookies develop critical issues, for example:

almost all of them do NOT have an expiration date and the data remains stored until the device is formatted or manually deleted.

can be read for marketing purposes by third parties

can sometimes reactivate or recreate zombie cookies*.

*Zombie Cookie: cookie already deleted, sometimes it can be reactivated or recreated by a super cookie.

Which sites are covered by the provision? Sites that do not allow data to be stored on the user's device or access to data already saved (therefore they do not use cookies) are not covered by the provision. While for technical cookies only the release of the information is required without the obligation to create the banner as required by law.

Analytical cookies that monitor the use of the site by users for optimization purposes can be equated with technical cookies, provided that the latter have been created and used without the intervention of third parties.

In cases where analytical cookies are created and made available by third parties for statistical purposes, they are not subject to the obligations established by the provision where suitable tools are adopted to reduce the identifying power of the analytical cookies they use. For example, Google Analytics is considered third-party but to make it technical and not profiling it is necessary to make the IP anonymous and not cross-reference the data.

The use of these cookies must be subject to contractual constraints between websites and third parties and it is necessary to expressly indicate that they will be used exclusively for the provision of the service and to store the data separately and not to incorporate the information contained in the cookies with others already in possession.

We provide a tutorial on how to anonymize Google Analytics and request not to cross-reference the data.

We have seen the role of third parties, but what is the role of first party sites? As regards the responsibility of the managers of first-party sites for the installation of profiling cookies coming from "third-party" domains, it is confirmed that they play the role of technical intermediary.

Furthermore, there is no need for information and consent if there are advertising banners or links to social networks on the website which are simple links to third-party sites that do not install profiling cookies.

The obligation to provide information and consent arises from the website's choice to host targeted advertising based on user profiling via cookies.

In conclusion, this law derives from European legislation and was necessary in order to protect users from profiling considered "intrusions" in the private life of users, therefore they must be informed about their use and express prior consent to the insertion of cookies on the device.

The "Bitter Biscuit" I am of the opinion that clarity was needed on the use of cookies regardless of a European law already in force. Personally I think that this law has conveyed and increased awareness and personal knowledge on the part of users: we are now decidedly more informed about what cookies are and why they are installed on our device, but this amount of information has also generated a lot of confusion.

Browsing the internet in search of more specific information, I was in fact perplexed by the amount of unclear and conflicting news that had come out over the past few months. "Web legends" have gradually developed around the legislation, creating consequent alarmism among all those who manage one or more websites.

Honestly, I don't find it particularly user friendly to have to click "ok" or for example "more information" (which is often missing) on almost every site I visit. On the other hand, however, I think it is right to learn that the next time I browse the web I will find the banner of the IKEA furniture or the summer holiday accommodation facility.

Fortunately, to avoid this continuous clicking to give consent, it is possible to set anonymous browsing on the browser, the operation methods are easily retrieved online. My advice is to often clear your browser cache and cookies but don't do it if you use the joomlahost.it affiliate service as the clicks on the banner, user registration and subsequent purchase, which will earn you money, are recorded through the use of cookies.

SOURCES Il Sole 24Ore "Web and privacy, new rules for cookies from June 2nd"Web and privacy, new rules for cookies from June 2nd"

"Cookies: technological profiles: seminar slides 3 July 2015.pdf"

Security

Protect your site, data and traffic

SSL, firewall, WAF and geographic backup on Host.it infrastructure.

From the blog

Sicurezza

Amici o nemici nascosti?

Il mondo dei bot su internet

Sicurezza

Patch a caldo, sito acceso

CVE kernel senza riavvii a raffica

From the archive

Security

PHP 7.3 – which version of PHP to use?

Security

HTTPS, Google and indexing