logoalt Hacker News

AdamN01/22/20253 repliesview on HN

People say that but it's not really true. If they just have 1P cookies for basic functionality (login), then I believe there can be a discreet notice at the bottom informing the user of that fact. Groups like IEEE should be the ones pioneering those patterns.


Replies

high_na_euv01/22/2025

Cookies for auth do not need such thing

prerok01/22/2025

AFAIK, only 3rd party cookies require this consent. I am pretty sure you require consent for 2nd party as well. Your own site's cookies? Do what you want.

GDPR, however, also covers other things like your storing user's data, but that is separate from cookies. Cookies are stored on user's device.

show 1 reply
lowercased01/22/2025

Not even sure you need any discreet notice about anything for strictly necessary first party cookies. That's my understanding of GDPR, at any rate.

show 2 replies