HTTP Cookies: How a 1994 Shopping Cart Fix Became Web Surveillance

The early web had no memory. HTTP was stateless, so every click arrived as if from a stranger. In 1994 the telecom company MCI, working with Netscape on an online store, wanted a shopping cart without the cost of storing every half-finished order on its own servers. Netscape programmer Lou Montulli borrowed a Unix idea called the magic cookie: have the server hand the browser a tiny piece of text, and have the browser hand it back with each request.

This episode follows that small text file, capped at about 4096 bytes, from convenience to controversy. It explains session and persistent cookies, the security flags that guard them, and why a stolen cookie works like a stolen backstage pass. Then it turns to third-party cookies that follow people across unrelated sites, zombie cookies that respawn after deletion, the European consent rules behind every pop-up, and the fingerprinting methods now replacing cookies.

  • Browsers accepted cookies silently by default, and the public only learned of them from a Financial Times article in February 1996.
  • The White House drug policy office in 2000, the CIA in 2002, and the NSA in 2005 were each caught leaving persistent cookies on visitors’ computers.
  • A study of 10,000 UK websites found only 11.8 percent met minimal legal requirements for cookie consent.
  • The SameSite flag exists to stop cross-site request forgery, in which a hidden link on another page sends commands to a bank using the victim’s own cookie.
  • A 2010 Electronic Frontier Foundation study found browser fingerprinting yielded 18.1 bits of entropy, enough to single out one browser among roughly 280,000.

Leave a Reply

Discover more from pplpod

Subscribe now to keep reading and get access to the full archive.

Continue reading