Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are you still adding suffixes to the list? If so, wouldn't refusing to add new suffixes help with the issue? If no new organisation can make use of PSL to link their subdomains, then they are only left with SOP. Since the list stays like it is now, no existing websites, depending on the list suddenly break down.


We are. Deliberate sabotage like that would take quite a while before it was noticed, however, and it wouldn’t magically fix cookies and how people use them.

To the extent it is used by cookies, we still want to maintain a fair and equitable solution. However, we also want to actively discourage any new users or use cases, to the extent possible, while we also try to fix cookies.

Ideas like https://github.com/privacycg/first-party-sets provide a possible model. While FPS doesn’t directly address this, as part of keeping a narrow scope, the approach to explicitly expressing boundaries is one that has the best viable path. However, that’s effectively “Deprecate the Host option for cookies”, so... that’s a big task.

Simply sabotaging the PSL doesn’t force the problem to be solved, so mostly, it’s an education campaign of “We made a mistake; learn from ours, rather than repeating it.”




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: