Home Online Advertising Safari Enables Full-On Third-Party Cookie Blocking By Default (Aka, No More Workarounds Ever)

Safari Enables Full-On Third-Party Cookie Blocking By Default (Aka, No More Workarounds Ever)

SHARE:

Are you sitting down? Because there’s some news that actually isn’t related to the coronavirus.

After years of moving in this direction, Apple said Tuesday that all third-party cookies for cross-site tracking will be blocked by default in Safari 13.1 for iOS and macOS.

You’d be forgiven for scratching your head and saying, “Wait a sec, weren’t third-party cookies already blocked in Safari as part of Intelligent Tracking Prevention?”

The answer is yes. What’s new is Safari going full nuclear on workarounds. It’s been a cat-and-mouse game between trackers and Safari for a while, but ITP means business.

In a blog post, WebKit security engineer John Wilander put it like so: “This is a significant improvement for privacy since it removes any sense of exceptions or [that] ‘a little bit of cross-site tracking is allowed.’”

WebKit will share its experiences with unmitigated third-party cookie blocking with privacy groups within W3C “to help other browsers take the leap,” Wilander wrote.

Chrome said earlier this year that it’s planning to deprecate third-party cookies in its browser beginning in 2022.

Here are a few of the exploits WebKit is cracking down on:

  • Ironically, the way in which a tracking prevention method is carried out can in some cases be manipulated to track a person across sites. Full third-party cookie blocking ensures that there is no ITP state that can be detected through cookie-blocking behavior. Basically, trackers won’t be able to use what is being blocked as a signal for tracking.
  • Login fingerprinting, which allows sites to see where a user was previously logged in, will no longer be possible. Aka, no leakage of a user’s login state across sites.
  • Last year, Apple announced that all client-side cookies would expire after seven days. (Later, this became 24 hours.) As expected, third-party scripts reacted by simply moving to other means of first-party storage, such as LocalStorage, which uses JavaScript to store information on the client side and never expires. Well, now there will be a seven-day cap on all script-writable storage too.

Click here to read the full blog post.

Must Read

FTC Commissioner Mark Meador speaking at the NAD's annual conference in Washington, DC on Sept. 15, 2025. (Photo: Brian O'Doherty)

FTC Commissioner Mark Meador: ‘No Human Society Can Long Survive Without Consumer Trust’

Keeping American kids safe in what FTC Commissioner Mark Meador calls “an increasingly complex and fast-paced technological environment” is a top priority for the agency.

Comic: "Deal ID, please."

Amazon Expands Its Programmatic Integration With SiriusXM

On Tuesday, Amazon DSP announced an expanded integration with satellite radio company SiriusXM.

Rembrand merges with Spaceback

Omar Tawakol Is Merging His AI Startup Rembrand With Spaceback

Rembrand announced that it’s merging with creative automation startup Spaceback to build a unified AI-powered platform for “content-based” CTV, digital video and display.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
A comic depicting people in suits setting money on fire as a reference to incrementality: as in, don't set your money on fire!

Retail Media Is Starting To Come To Grips With The Fact That We All Know Nothing

Retail media is entering what might be called its Socratic phase. The closer we to get to understanding an ad campaign’s real impact and business results, the clearer it is that we have no idea how this thing works.

Meta Reels trending ads

Meta Has New Tools For Brand And Performance Goals, With A Focus On AI (Of Course)

Meta is rolling out Reels trending ads, value rules beyond just conversions, upgrades to Threads and pixel-free landing page optimization.

Comic: Shopper Marketing Data

Google Search Ads 360 Adds Criteo As First On-Site Retail Media Supply Partner

Criteo announced a partnership with Google Search Ads 360 (SA360), Google’s enterprise search advertising platform, making Criteo the first third-party vendor to integrate with Google for on-site retail media supply.