{"id":25118,"date":"2020-01-16T00:00:00","date_gmt":"2020-01-16T00:00:00","guid":{"rendered":"https:\/\/alienroad.com\/google-bilgi-bankasi\/get-ready-for-new-samesitenone-secure-cookie-settings\/"},"modified":"2020-01-16T00:00:00","modified_gmt":"2020-01-16T00:00:00","slug":"get-ready-for-new-samesitenone-secure-cookie-settings","status":"publish","type":"ar_kb","link":"https:\/\/alienroad.com\/google-bilgi-bankasi\/get-ready-for-new-samesitenone-secure-cookie-settings\/","title":{"rendered":"Get Ready for New SameSite=None; Secure Cookie Settings"},"content":{"rendered":"<p class=\"gargardate\">Thursday, January 16, 2020<\/p>\n<p>\n    <i><br \/>\n    This is a cross-post from the<br \/>\n    <a href=\"https:\/\/blog.chromium.org\/2019\/10\/developers-get-ready-for-new.html\" class=\"external-link\">Chromium developer blog<\/a><br \/>\n    and is specific to how changes to Chrome may affect how your website works for your users in the future.<br \/>\n   <\/i>\n   <\/p>\n<p>\n   In May, Chrome <a href=\"https:\/\/blog.chromium.org\/2019\/05\/improving-privacy-and-security-on-web\" class=\"external-link\">announced<\/a><br \/>\n    a secure-by-default model for cookies, enabled by a new cookie classification system<br \/>\n     (<a href=\"https:\/\/tools.ietf.org\/html\/draft-west-cookie-incrementalism-00\" class=\"external-link\">spec<\/a>). This<br \/>\n     initiative is part of our<br \/>\n   <a href=\"https:\/\/www.blog.google\/products\/chrome\/building-a-more-private-web\/\" class=\"external-link\">ongoing effort<\/a><br \/>\n   to improve privacy and security across the web.\n   <\/p>\n<p>\n   Chrome plans to implement the new model with Chrome 80 in February 2020. Mozilla and Microsoft<br \/>\n     have also indicated intent to implement the new model in Firefox and Edge, on their own<br \/>\n     timelines. While the Chrome changes are still a few months away, It&#8217;s important that developers<br \/>\n     who manage cookies assess their readiness today. This blog post outlines high level concepts; please see<br \/>\n   <a href=\"https:\/\/web.dev\/articles\/samesite-cookies-explained\" class=\"external-link\">SameSite Cookies Explained<\/a> on web.dev<br \/>\n     for developer guidance.\n   <\/p>\n<h2 id=\"understanding-cross-site-and-same-site-cookie-context\" tabindex=\"-1\">\n    Understanding Cross-Site and Same-Site Cookie Context<br \/>\n   <\/h2>\n<p>\n   Websites typically integrate external services for advertising, content recommendations, third<br \/>\n     party widgets, social embeds and other features. As you browse the web, these external services<br \/>\n     may store cookies in your browser and subsequently access those cookies to deliver personalized<br \/>\n     experiences or measure audience engagement. Every cookie has a domain associated with it. If<br \/>\n     the domain associated with a cookie matches an external service and not the website in the<br \/>\n     user&#8217;s address bar, this is considered a <b>cross-site<\/b> (or <b>&#8220;third party&#8221;<\/b>) context.\n   <\/p>\n<p>\n   Less obvious cross-site use cases include situations where an entity that owns multiple websites<br \/>\n     uses a cookie across those properties. Although the same entity owns the cookie and the<br \/>\n     websites, this still counts as cross-site or &#8220;third party&#8221; context when the cookie&#8217;s domain<br \/>\n     does not match the site(s) from which the cookie is accessed.\n<\/p>\n<p>   <img decoding=\"async\" alt=\"Site domain doesn't match the cookie domain\" src=\"https:\/\/alienroad.com\/wp-content\/uploads\/kb-gorsel\/g-aa9da0c01a0a.png\" loading=\"lazy\"><\/p>\n<p>\n   <i><br \/>\n    When an external resource on a web page accesses a cookie that does not match the site domain,<br \/>\n     this is cross-site or &#8220;third-party&#8221; context.<br \/>\n   <\/i>\n   <\/p>\n<p>\n   In contrast, cookie access in a<br \/>\n   <b>same-site<\/b> (or <b>&#8220;first party&#8221;<\/b>) context occurs when a cookie&#8217;s domain matches the<br \/>\n     website domain in the user&#8217;s address bar. Same-site cookies are commonly used to keep people<br \/>\n     logged into individual websites, remember their preferences and support site analytics.\n   <\/p>\n<p>   <img decoding=\"async\" alt=\"Site domain matches the cookie domain\" height=\"388\" src=\"https:\/\/alienroad.com\/wp-content\/uploads\/kb-gorsel\/g-a82cbcf669f1.png\" loading=\"lazy\" width=\"414\"><\/p>\n<p>\n   <i><br \/>\n    When a resource on a web page accesses a cookie that matches the site the user is visiting, this<br \/>\n     is same-site or &#8220;first party&#8221; context.<br \/>\n   <\/i>\n   <\/p>\n<h2 id=\"a-new-model-for-cookie-security-and-transparency\" tabindex=\"-1\">\n    A New Model for Cookie Security and Transparency<br \/>\n   <\/h2>\n<p>\n   Today, if a cookie is only intended to be accessed in a first party context, the developer has<br \/>\n     the option to apply one of two settings (<code>SameSite=Lax<\/code> ou<br \/>\n     <code>SameSite=Strict<\/code>) to prevent external access. However, very few<br \/>\n     developers follow this recommended practice, leaving a large number of same-site cookies<br \/>\n     needlessly exposed to threats such as<br \/>\n   <a href=\"https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet\" class=\"external-link\">Cross-Site Request Forgery<\/a><br \/>\n   attacks.\n   <\/p>\n<p>\n   To safeguard more websites and their users, the new secure-by-default model assumes all cookies<br \/>\n     should be protected from external access unless otherwise specified. Developers must use a new<br \/>\n     cookie setting, <code>SameSite=None<\/code>, to designate cookies for cross-site<br \/>\n     access. When the <code>SameSite=None<\/code> attribute is present, an additional<br \/>\n     Secure attribute must be used so cross-site cookies can only be accessed over HTTPS connections.<br \/>\n     This won&#8217;t mitigate all risks associated with cross-site access but it will provide protection<br \/>\n     against network attacks.\n   <\/p>\n<p>\n   Beyond the immediate security benefits, the explicit declaration of cross-site cookies enables<br \/>\n     greater transparency and user choice. For example, browsers could offer users fine-grained<br \/>\n     controls to manage cookies that are only accessed by a single site separately from cookies<br \/>\n     accessed across multiple sites.\n   <\/p>\n<h2 id=\"chrome-enforcement-starting-in-february-2020\" tabindex=\"-1\">\n    Chrome Enforcement Starting in February 2020<br \/>\n   <\/h2>\n<p>\n   With Chrome 80 in February, Chrome will treat cookies that have no declared SameSite value as<br \/>\n     <code>SameSite=Lax<\/code> cookies. Only cookies with the<br \/>\n     <code>SameSite=None; Secure<\/code> setting will be available for external<br \/>\n     access, provided they are being accessed from secure connections. The Chrome Platform Status trackers for<br \/>\n   <a href=\"https:\/\/chromestatus.com\/feature\/5088147346030592\" class=\"external-link\"><code>SameSite=None<\/code><\/a><br \/>\n    and<br \/>\n   <a href=\"https:\/\/chromestatus.com\/feature\/5633521622188032\" class=\"external-link\">Secure<\/a><br \/>\n    will continue to be updated with the latest launch information.\n   <\/p>\n<p>\n   Mozilla has affirmed their support of the new cookie classification model with their<br \/>\n   <a href=\"https:\/\/groups.google.com\/forum\/#!msg\/mozilla.dev.platform\/nx2uP0CzA9k\/BNVPWDHsAQAJ\" class=\"external-link\">intent to implement<\/a><br \/>\n   the <code>SameSite=None; Secure<\/code> requirements for cross-site cookies in Firefox. Microsoft recently<br \/>\n   <a href=\"https:\/\/groups.google.com\/a\/chromium.org\/forum\/#!msg\/blink-dev\/AknSSyQTGYs\/8lMmI5DwEAAJ\" class=\"external-link\">announced<\/a><br \/>\n   plans to begin implementing the model starting as an experiment in Microsoft Edge 80.\n   <\/p>\n<h2 id=\"how-to-prepare;-known-complexities\" tabindex=\"-1\">\n    How to Prepare; Known Complexities<br \/>\n   <\/h2>\n<p>\n   If you manage cross-site cookies, you will need to apply the <code>SameSite=None<\/code>;<br \/>\n     Secure setting to those cookies. Implementation should be straightforward for most developers,<br \/>\n     but we strongly encourage you to begin testing now to identify complexities and special cases,<br \/>\n     such as the following:\n   <\/p>\n<ul>\n<li>\n     Not all languages and libraries support the None value yet, requiring developers to set the<br \/>\n      cookie header directly. This <a href=\"https:\/\/github.com\/GoogleChromeLabs\/samesite-examples\" class=\"external-link\">GitHub repository<\/a><br \/>\n    provides instructions for implementing <code>SameSite=None; Secure<\/code> in a<br \/>\n      variety of languages, libraries and frameworks.\n    <\/li>\n<li>\n      Some browsers, including some versions of Chrome, Safari and UC Browser, might handle the<br \/>\n      <code>None<\/code> value in unintended ways, requiring developers to code<br \/>\n      exceptions for those clients. This includes Android WebViews powered by older versions of<br \/>\n      Chrome. Here&#8217;s a list of known<br \/>\n      <a href=\"https:\/\/www.chromium.org\/updates\/same-site\/incompatible-clients\" class=\"external-link\">incompatible clients<\/a>.\n    <\/li>\n<li>\n      App developers are advised to declare the appropriate <code>SameSite cookie<\/code><br \/>\n      settings for Android <code>WebViews<\/code> based on versions of Chrome that are<br \/>\n      compatible with the <code>None<\/code> value, both for cookies accessed via HTTP(S) headers and via Android<br \/>\n      <code>WebView<\/code>&#8216;s<br \/>\n      <a href=\"https:\/\/developer.android.com\/reference\/android\/webkit\/CookieManager\" class=\"external-link\">CookieManager API<\/a>,<br \/>\n      although the new model will not be enforced on Android WebView until later.\n    <\/li>\n<li>\n     Enterprise IT administrators may need to implement <a href=\"https:\/\/www.chromium.org\/administrators\/policy-list-3\/cookie-legacy-samesite-policies\" class=\"external-link\">special policies<\/a><br \/>\n    to temporarily revert Chrome Browser to legacy behavior if some services such as single sign-on or internal applications are not ready for the February launch.\n    <\/li>\n<li>\n     If you have cookies that you access in both a first and third-party context, you might consider<br \/>\n      using separate cookies to get the security benefits of <code>SameSite=Lax<\/code><br \/>\n      in the first-party context.\n    <\/li>\n<\/ul>\n<p>\n   <a href=\"https:\/\/web.dev\/articles\/samesite-cookies-explained\" class=\"external-link\">SameSite Cookies Explained<\/a><br \/>\n   offers specific guidance for the situations above, and channels for raising issues and questions.\n   <\/p>\n<p>\n   To test the effect of the new Chrome behavior on your site or cookies you manage, you can go to<br \/>\n     <code>chrome:\/\/flags<\/code> in Chrome 76+ and enable the<br \/>\n     &#8220;<span>SameSite by default cookies<\/span>&#8221; and<br \/>\n     &#8220;<span>Cookies without SameSite must be secure<\/span>&#8221; experiments. In addition,<br \/>\n     these experiments will be automatically enabled for a subset of Chrome 79 Beta users. Some Beta<br \/>\n     users with the experiments enabled could experience incompatibility issues with services that<br \/>\n     do not yet support the new model; users can opt out of the Beta experiments by going to<br \/>\n     <code>chrome:\/\/flags<\/code> and disabling them.\n   <\/p>\n<p>\n   If you manage cookies that are only accessed in a same-site context (same-site cookies) there is<br \/>\n     no required action on your part; Chrome will automatically prevent those cookies from being<br \/>\n     accessed by external entities, even if the SameSite attribute is missing or no value is set.<br \/>\n     However we strongly recommend you apply an appropriate SameSite value (Lax or Strict) and not<br \/>\n     rely on default browser behavior since not all browsers protect same-site cookies by default.\n   <\/p>\n<p>\n   Finally, if you&#8217;re concerned about the readiness of vendors and others who provide services to<br \/>\n     your website, you can check for Developer Tools console warnings in Chrome 77+ when a page<br \/>\n     contains cross-site cookies that are missing the required settings:\n   <\/p>\n<p>   <img decoding=\"async\" alt=\"A cookie associated with a cross-site resource at (cookie domain) was set without the 'SameSite' attribute\"\n        src=\"https:\/\/alienroad.com\/wp-content\/uploads\/kb-gorsel\/g-204966b99640.png\" loading=\"lazy\" \/><\/p>\n<p>\n   Some providers (including some Google services) will implement the necessary changes in the<br \/>\n     months leading up to Chrome 80 in February; you may wish to reach out to your partners to<br \/>\n     confirm their readiness.\n   <\/p>\n<p>\n     <span class=\"byline-author\">Posted by Barb Palser, Chrome and Web Platform Partnerships<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Thursday, January 16, 2020 This is a cross-post from the Chromium developer blog and is specific to how changes to Chrome may affect how your website works for your users in the future. In May, Chrome announced a secure-by-default model for cookies, enabled by a new cookie classification system (spec). This initiative is part of [&hellip;]<\/p>\n","protected":false},"menu_order":81723,"template":"","meta":{"footnotes":""},"ar_kb_kategori":[665],"ar_kb_etiket":[],"class_list":["post-25118","ar_kb","type-ar_kb","status-publish","has-post-thumbnail","hentry","ar_kb_kategori-blog"],"_links":{"self":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/25118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb"}],"about":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/types\/ar_kb"}],"version-history":[{"count":0,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/25118\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media\/27242"}],"wp:attachment":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media?parent=25118"}],"wp:term":[{"taxonomy":"ar_kb_kategori","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_kategori?post=25118"},{"taxonomy":"ar_kb_etiket","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_etiket?post=25118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}