Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Does this only work if you use the same email across multiple sites? At a huge risk of EU regulars cracking on, it is quite possible to track a user across multiple accounts by simply using a cookie that lives long enough (say, 30 days) to establish the connections between multiple accounts.

For a server-side ID sync, you don't even need user accounts. Just a unique ID set in a cookie will do.



How would this work when the cookie ID is different for every different embedding (first-party) context? That's the whole point of total cookie isolation.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: