SSL Labs ScoreSecurityHeaders.io ScoreHSTS Preloaded

Log in to participate

There is no cost to join RicheyWeb, and membership is a requirement to submit bug reports and participate in the support forums.

× EU e-Privacy Directive needs your help!

A free extension like this survives only by reputation. You can help by submitting a review in the Joomla Extension Directory. Please take the time to make a review by clicking on the link below (opens in a new window)

extensions.joomla.org/write-review/review/add?extension_id=4850

youtube cookie still active, even though I disabled cookies.

More
1 year 6 months ago #2293 by bobptz
Hi

I was testing at your website ( www.richeyweb.com/software/joomla/plugin...nalytics-cookie-free ). At some point I disabled all cookies but I played the video. The youtube cookie appeared in the inspect list. Is this supposed to work like this? I thought that all cookies would be disabled, even if website functionality failed as a result.

Attachments:

Please Log in or Create an account to join the conversation.

More
1 year 6 months ago #2297 by michael
If the page loads any element from youtube.com, your browser will retrieve any youtube.com cookie it has stored and send it with the request to youtube.

The same-origin policy enforced by browsers means that the only thing I cookie I can manipulate are cookies from my own domain. Other cookies I can only block by preventing the resources from loading. The resources I load from youtube on playback don't set cookies, so if one appeared - it was already in your browser and there's no way for me to detect that (same-origin policy)

I believe that if you delete that cookie, you'll find that you're logged out of youtube, which means it's the youtube login/session cookie (set when you log into youtube/google)

Please Log in or Create an account to join the conversation.

More
1 year 6 months ago #2299 by michael
Yay - you're running Ubuntu! I don't see too many fellow Linux folks.

Please Log in or Create an account to join the conversation.

More
1 year 6 months ago - 1 year 6 months ago #2302 by bobptz
Hi Michael

I thought that we are responsible for all third party stuff on our website. So if a user says DECLINE ALL COOKIES, somehow we have to not affect the user's pc with cookies at all. Even if this means to make our website completely dysfunctional.

I made this much simpler test.

I cleaned up all cookies from chrome.

Then I visited your page ( www.richeyweb.com/software/joomla/plugin...nalytics-cookie-free ). Immediately chrome reported those cookies:
i.imgur.com/PDwqHvS.png

Your page was reporting no cookies yet.

Then on your page, I DECLINED cookies. No cookies n your page yet. Then I started playing the youtube video on the page. And here is the cookie again:
i.imgur.com/RHSJIJN.png
Last edit: 1 year 6 months ago by bobptz.

Please Log in or Create an account to join the conversation.

More
1 year 6 months ago #2308 by michael
That just says there is a cookie, doesn't say were it came from.

When you load the page, go to your "network" tab, and down the list of loaded elements until you see a "Set-Cookie" header. for an element coming from youtube-nocookies.com

When I load it in an incognito window - no cookies are delivered. My guess is that it's something already in your browsers cookie jar.

Please Log in or Create an account to join the conversation.

More
1 year 6 months ago - 1 year 6 months ago #2309 by bobptz
Hi Michael

>>>>>
When you load the page, go to your "network" tab, and down the list of loaded elements until you see a "Set-Cookie" header. for an element coming from youtube-nocookies.com
<<<<<
I tried but could not follow your instructions. Here s what I got:
i.imgur.com/xC0EGna.png

Here is what I did:
1) Go to Chrome Incognito mode.
2) Go to chrome settings (cookies) page.
3) Clean all cookies.
4) Add a page tab (google.com)
5) Clean cookies again (obviously created from google.com).
6) In the new tab, paste the url : www.richeyweb.com/software/joomla/plugin...nalytics-cookie-free and Decline Cookies.
7) Chrome-Inspect shows no cookies on this page.
8 ) Go to chrome settings, there are 6 cookie entries. I assume they came from your page, but I am not sure.
9) Start the video on your page.
10) Chrome-Inspect still shows no cookies on this page. Contrary to what I had noticed before ( i.imgur.com/RHSJIJN.png ).
11) Go to chrome settings, there are at least 11 cookie entries. I assume the new ones came from the video that just started, but again I cannot be sure.

Last edit: 1 year 6 months ago by bobptz.

Please Log in or Create an account to join the conversation.

  • Not Allowed: to create new topic.
  • Not Allowed: to reply.
  • Not Allowed: to edit your message.
Powered by Kunena Forum