Web Cookies

Stateful Browsing and it’s Security Implications

Alex Rodriguez
5 min readOct 10, 2020
No, not those cookies

A little Cookie History

Before the web cookie, websites had no way of storing relevant information about its customers and thus made creating commercial websites difficult because of the lack of information needed to facilitate customer relations. The cookie was invented in 1994 by Lou Montulli, who at the time was an employee at Netscape Communications. Netscape was tasked with finding a way to retain customer data without having to store it on company servers, which led to the idea of storing each customer’s data on their own computers. This effectively allowed websites to track the behavior of their users and improve the user experience. After the creation of the cookie, they became a must-have feature of every commercial website. Although cookies had been widely used, it was not until three years after the invention of the cookie that the public actually learned about what cookies are and it immediately raised concerns within the security community and also caught the attention of the media because of the obvious potential security implications.

Why Cookies?

Cookies are a way for websites to get to know their customers. Each cookie stores some information about each of its user’s to remember and identify every returning user. This is great…

--

--

Alex Rodriguez

I am an Offensive Security Engineer @ Amazon who writes about cybersecurity and anything related to technology. Opinions are my own.