Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I really hate the lies you see on a lot of new sites that they will send cookies "necessary for basic functionality."

You're serving articles, there's no reason for session tracking!



Without cookies they can't check if you closed the cookie nag.


I can see a need for cookies to mitigate against things like DDoS attacks, session management for paywalled content or just to leave comments on articles, favoriting certain sections. There are several reasons why as a reader you would want the site to be stateful.


How would cookies help mitigate against DDoS attacks?


Helps separate real traffic from DDoS traffic. e.g. traffic from someone that also visited the site prior to the start of the DDoS is vastly more likely to be real traffic.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: