Cookies have long been a hot topic in cybersecurity circles, as cybercriminals can use your browser’s cookies to access sensitive information or even hijack your sessions on web platforms such as online banking or cryptocurrency exchanges. By illegally collecting cookies, cybercriminals can trick a website into believing that you are returning to browse and access your profile without even logging in. Cookies can last from a few days to several years, depending on your browser and the server that sends them. Logging out of a website does not delete these cookies, but you can delete them manually in your browser settings as a security measure if they have not already expired.
Cookies are essentially small snippets of data that a website’s server sends to your browser. First-party cookies are essential to the user experience of a website (like shopping cart data or login sessions) and allow the website to remember your shopping cart or preferences when you visit it multiple times. External sources such as social media platforms use third-party cookies to track your browsing behavior across websites, and use this information to serve personalized content on advertising networks. Understanding how cookies work can help you take some simple steps to protect yourself against cybercrime, understand who may collect your information, and opt out of cookies that track your browsing behavior.
How to protect yourself by managing your cookies
Cybercriminals can steal cookies by injecting malicious JavaScript into websites you visit, or they can steal them directly from your computer if the attacker gains access to your device. Connecting to unsecured public Wi-Fi networks could allow an attacker to easily access your device. By illegally extracting cookies from your browser, cybercriminals can copy them to their own computers and trick websites into thinking it’s you visiting the site for another visit.
How can you protect yourself from these malicious actors? First of all, protect your device and avoid connecting to unknown public Wi-Fi networks. Enabling multi-factor authentication, changing your browser settings to regularly delete persistent cookies, and disabling third-party cookies will help secure your device against such threats. Disabling third-party cookies is one of five settings you should check more often. It is also recommended to regularly and manually delete cookies from your browser and avoid clicking on unknown links in emails, which could expose you to malicious scripts designed to capture sensitive information on your computer. If you use Chrome, Do Not Track is one of four settings in Google Chrome that tells websites and apps that you don’t want your information tracked.
Most websites are required to let you choose which cookies you accept and which you do not, depending on the privacy laws in their region. Should we accept or refuse these cookies? Depending on the website, first-party cookies can improve the user experience by storing your preferences and avoiding having to log in repeatedly when you return. You can refuse all cookies that are not essential for the basic functionality of the website.
Myths around cookies
There are many myths about cookies, some based on real concerns and others on misinformation and exaggeration. First, cookies don’t spy on you. As described above, cookies are intended to provide consistent web experiences, and in most cases they do so. They do not contain personal information such as names or contact details, and first-party cookies are only returned to the websites from which they originated.
Second, cookies are not viruses or spyware. This is a common misconception because antivirus software flags cookies during a scan. Indeed, antivirus software can help you track and remove third-party cookies that track your browsing behavior for advertising purposes. Although this is an added value in most antivirus applications, it does not mean that cookies are viruses.
Third, cookies do not create spam or pop-up advertisements. Third-party cookies track web behavior to allow advertisers to serve you relevant ads, but the cookies themselves do not serve ads to you. If you want more visibility into how advertisers are tracking your behavior, this Google Chrome extension will show you how ads are tracking you.
