Subscribe to our newsletter!

Submit

Thank you for signing up for our newsletter!

We’re excited to have you with us and will keep you updated with the latest news, insights, and updates straight to your inbox.
Oops! Something went wrong while submitting the form.
Back to Blog
October 21, 2020
|
Read time {time} min

What Are Cookies? Types, Uses, & Why They’re Crumbling

Written by
Permission
Stay in the loop

Get the latest insights, product updates, and news from Permission — shaping the future of user-owned data and AI innovation.

Subscribe

It’s the end of the road for third-party cookies—and that’s a good thing.

Perhaps you don’t know what third party cookies are. Let’s begin by explaining why cookies exist at all.

What Is a Cookie?

A cookie is a parcel of data stored in the browser to speed-up and simplify interactions between the browser and a website it is connected to. Any data can be stored in a cookie.

How Do Cookies Work?

The browser provides a place where websites can store data when that website is being accessed, and the browser stores it. The idea was invented by Lou Montulli of Netscape Communications in 1994, the year that the Web was born.

The problem was that a PC could disconnect from a website for many reasons: the PC or the website might crash or the internet could disconnect. So the website cookie could store your identity data, your preferences, and maybe even session information. Then, if anything failed you could restart near to where you left off.

Since then things have become more complex and there are several different types of cookie, as follows.

The Different Types of Internet Cookies

The Session Cookie

These are temporary cookies that last only for the duration of a session. They tend to store mundane data like login credentials and usually evaporate when you reboot the computer or close the browser. They can also be used to help with website performance like ensuring fast page loads.

There’s unlikely to be anything objectionable stored in these cookies.

The Persistent Cookie

Websites that plant these cookies in your browser usually give them an expiration date, which could be any time from seconds to years.

You know you have a persistent identity cookie if you are on a website and reboot your computer only to discover when you return to the website that you are still logged in.

Such cookies are commonly used to track your on-site behavior and to tailor your user experience.

There is unlikely to be anything objectionable about these cookies either.

The Secure Cookie

These cookies assist with encryption and hence are definitely good guys. They are only transmitted securely (via HTTPS) and they are used to implement security on banking and shopping websites.

They keep your financial details secret but allow the site to remember those details.

The First-Party Cookie

All the above are examples of first-party cookies. Technically first-party simply means that it’s a two-way arrangement between you and the website. However, many websites monitor website traffic with help from external vendors, particularly Google with Google Analytics.

The cookies placed by Google for that purpose are usually thought of as first-party cookies because they just monitor the site visit. Think of them as first-party by proxy.

The Third-Party Cookie

Third-party cookies are what drives “behavioral advertising”. They are called third-party because none of the websites you visited put them there. They were slipped into your browser by some advertiser’s ad server.

Advertisers add tags to web pages so that in conjunction with the cookies they place, they can recognize you as you skip from one website to another. They build a user profile of you and your habits in the hope of targeting you more effectively.

Whichever way you look at this, it’s a violation. They do not seek your permission and they are aggressive.

The bad advertiser practices of the web depend on these cookies. They include:

  1. Cookie-bombing: This focuses on quantity over quality, to the detriment of both the user and the advertiser. It is “pray and spray”, matching the ad with neither the website nor the user. Think of, say, feminine hygiene products advertised to men who are visiting a bookstore website. Think of ads appearing in obscure places on a web page that you will never notice, except by accident.
  2. Incessant retargeting: This is where ads seem to follow you around the web from one site to another.

The March of the Ad Blocker

Nowadays, 30% or so of people use ad blockers. The top three reasons for doing so, according to GlobalWebIndex, are: too many ads (48%), ads are annoying or irrelevant (47%), ads are too intrusive (44%). A lot of this can be put down to the kind of ads that third-party cookies thrust upon you.

Ad blockers are a severe problem for the digital advertising industry. It isn’t just that most users would rather see no ads. The digital publishing industry has no easy way of making a profit other than by ads. Web-users visit news and magazine sites page by page rather than go to one or two sites for their news. The web has no equivalent of a newspaper or a magazine.

However, there can be synergy between websites and ads, where ads are found in the context of a website to which they relate. The ads for yachts on a yachting blog, hiking gear on hiking blogs, and so on. Brand advertisers don’t want their brand ads to appear just anywhere, they want the context of the ad to be brand-positive.

Most advertisers, like most web users, do not want what third party cookies deliver, and neither do the software companies that develop browsers.

The Cookie War and the Browsers

As I noted at the beginning of this blog, the days of the third-party cookie will soon be over. It has no useful allies. All the browsers are waging war on it.

Safari

It began with Apple. In 2017, it introduced “intelligent tracking prevention” to stop cross-site tracking by third-party cookies.

Since then, Apple has improved the capability to the point where Safari will tell you which ad trackers are running on the website you’re visiting and will provide a 30-day report of the known trackers it’s identified, and which websites the trackers came from. Safari now blocks most third-party cookies by default.

Of course, Safari has less than 10% of the browser market. So, on its own, that doesn’t spell the death of the third-party cookie.

Firefox

In 2017, the Firefox browser also moved towards stronger privacy adding an optional feature that restricted cookies, cache, and other data access so that only the domain that placed the cookie had access to it.

Since then, Firefox has tightened up its privacy features. Currently, Firefox offers three levels of privacy: “Standard” (the default), “Strict”, and “Custom”. Standard blocks trackers in private (i.e. incognito) windows; it blocks third-party tracking cookies and crypto-jacking. The Strict setting does the same but also blocks fingerprinting and trackers in all windows. The Custom setting allows you to tune your privacy settings in fine detail.

As a side note, perhaps you’ve not heard of crypto-jacking. This is when a website, without so much as a “by-your-leave”, puts a script in your browser which sits there, chugging away mining cryptocurrency for the website owner. Firefox can block that.

Maybe you’ve not heard of fingerprinting either. This is when a server gathers data about your specific configuration of software and hardware in order to “fingerprint” you (i.e. assign a unique technology identity to you).

There are many details that can be gathered: your browser version and type, your OS, the timezone, active plugins, language, screen resolution, browser settings, and so on. It is really unlikely that any two users have identical information.

One study estimated that there is only a 1 in 286,777 chance that another browser will have the same fingerprint as you. The fingerprint is used to track you as you move from website to website.

Firefox’s market share is similar to Safari’s — a little under 10%.

Microsoft’s Edge

A long time ago, Microsoft’s Internet Explorer was the dominant browser. Its market share gradually declined to a few percent and Microsoft decided to reinvent its browser with Edge.

Edge provides 3 privacy settings to choose from: “Basic”, “Balanced” (the default), and “Strict”. Balanced blocks trackers from sites you haven’t visited. Strict blocks almost all trackers. Basic block trackers used for crypto-hijacking and fingerprinting.

How much traction Edge will get is uncertain. Right now it seems to have about 4% of the browser market.

Opera

Despite a fairly low market share, Opera is perhaps the most highly functional browser. It provides configurable security that is as tight as any other, including a configurable built-in ad blocker, a crypto wallet, and a VPN. It has been offering such features since 2017.

Brave

This is another niche browser but with a much smaller user base than Opera.

By default, it blocks all ads, trackers, third-party cookies, crypto-hijacking, and third-party finger-printers. It even has a built-in TOR private browsing mode (TOR stands for “The Onion Router”, open-source software that enables fully anonymous communication).

Brave tends to attract users who care deeply about privacy.

If you add up the market share of the browsers already discussed, you get less than 30%. The market gorilla is Google Chrome with a little under 70% market share.

Google Chrome

The death knell of the third party cookie sounded loud when Google joined the opposition with its Chrome browser. Google has decided to eradicate that scourge over a space of 2 years. Chrome will soon have a Privacy Sandbox, a privacy-preserving API.

Naturally, Google is very pro advertisements — they are its core business. So with Chrome, it is unlikely to shoot itself in the foot. It is far more likely to skew the ad market to its advantage.

Google’s intentions, in outline, are to hold individual user information in Chrome’s Privacy Sandbox and allow ad tech companies to make API calls to it. When they do so they will get access to personalization and measurement data to help them target ads and measure their impact, but they will get no access to your personal details that might help them identify you. The advertisers will get targeting data only.

The question is: if you eliminate third-party cookies how can ad tech companies target users and measure an ad’s effectiveness? The Privacy Sandbox is Google’s answer. It will run trials and make adjustments over the next two years to get it right.

Because Google Chrome is open-source, other browsers will be able to analyze what Google is doing and imitate it, if they choose to.

Publishers are particularly concerned about the Cookie Wars, because they may become collateral damage. Google released a study claiming that removing third-party cookies would reduce publisher ad revenue by 52%.

Making sure the change doesn’t greatly damage publishers is a sensible priority. So Google’s upcoming trials will compare monetization for publishers between the old and new setup for Google’s digital ad business (Google’s search ads and YouTube are unaffected).

The iPhone and iPad, and IDFA

What is an IDFA? The abbreviation stands for IDentifier For Advertisers, Apple’s unique mobile device number provided to ad exchanges to help them track user interactions and behavior.

It is the mobile device’s equivalent of a third-party cookie, enabling user tracking, marketing measurement, attribution, ad targeting, ad monetization, device graphs, retargeting of individuals and audiences, and programmatic advertising from demand-side platforms (DSPs), supply-side platforms (SSPs), and exchanges.

If you were unaware that Apple assigns a number to your iOS device to help track you, I’m not surprised. It may be because it is an opt-out feature you have to notice and opt-out of to prevent its use (if you have an iPhone or iPad and wish to opt-out, go to Settings > Privacy > Advertising and then turn “Limit Ad Tracking” on).

Recently, however, because of Apple’s increasing concern for its customers’ privacy, it decided to make the IDFA opt-in for every single application. Thus, with the release of iOS 14 in September 2020, each app on your device will have to ask you if you want to opt-in and reveal your IDFA.

Apple‘s change of policy will have a negative impact on companies that provide mobile ad targeting, including Google, Facebook, and Twitter. It may also affect apps like Spotify, Uber, and Lyft that invest heavily in user acquisition and depend on user data from their apps.

Apple vs. Google

You can view what’s happening with respect to tracking as a struggle between Apple and Google.

On one side of the net is Apple. It has a very self-contained business model and has pursued it through good times and bad.

When you buy Apple, you tend to go the whole hog — Apple hardware on the desktop running the Mac OS and apps from the App Store. Your mobile phone is an iPhone running iOS with App Store apps and your tablet is an iPad. If you’re into digital watches it will likely be an Apple Watch.

Apple makes the hardware, nowadays even the chip gets a cut of most of the software and builds some of the apps itself. And, of course, it sells music, videos, podcasts, etc.

What it doesn’t care about is advertising revenue. Apple is an ad-free business and has no reason to care whether Google, Facebook, or any other advertising platform gets ad revenue from its devices or not. It is without an ax to grind. It cares about customer satisfaction, and thus its primary goal is to provide its users with bulletproof, but configurable privacy.

On the opposite side of the net, Google clearly wants to maximize its ad revenue. It is the last of the browser companies to prevent third-party cookies and it intends to do so in a way that does not damage its revenues.

But, when it comes to the mobile world it is poorly placed to dominate ad traffic on iOS devices. Right now, the iPhone has about half the cell phone market in the US, and Safari has more than 50% of the browser market on the iPhone. It also dominates browser usage on the iPad. Those Safari browsers have a simple setting to stop third-party cookies dead in their tracks.

Where the IDFA comes in is for placing ads in iOS apps. You probably didn’t know it but Google has an app called AdMob for placing ads in mobile apps. AdMob is installed in 1.5 million iOS apps of which, in total, there have been 375 billion downloads. Those ads generate revenue for the app maker, but now they only work if the user opts-in.

How many users do you think will want to opt-in for such ads? Perhaps none. Facebook plays the same game, by the way, but has less of the market. Its ad distribution app is installed on a whole host of iOS apps of which there have been billions of downloads.

You probably have some of those apps installed. Tim Cook’s point is that nobody asked for your permission to be an ad victim and yet those ad distribution apps are sitting there on your iPhone or iPad anyway. Well from here on in, permission will be required.

It’s All About Permission, Permission, Permission.

Let me explain my perspective on this. I don’t even like Apple’s solution, even though I think what they are doing is not exploitative.

At the birth of the Internet, cookies were an excellent idea that helped to maintain “session integrity”. They made the web work better. Since then, they have been bent badly out of shape and been used by the Internet giants to exploit anyone who ever lifted a mobile phone or touched a keyboard.

Any data stored that can enhance the technology and the user experience is welcome. Let’s not call such data cookies, let’s refer to it as “the performance data cache”. No-one should have any problem with technical innovators adding data to this cache if it improves your digital life.

Beyond that, there is no need whatsoever for cookies of any other kind. Let’s hope they sink into the dustbin of technology and never resurface.

It is crashingly obvious that any interaction between a person and a website should be completely device-independent. It is an interaction between a person, assisted by their stored personal data, and the website with all its capabilities, including its abilities to serve ads.

The user can give permission for the use of the data and the website can interact accordingly. Under these circumstances, the user can retain control and choose to allow the advertiser to examine all their personal data for the sake of targeting, especially if the advertiser is willing to reward the user for their time and data in watching its ads.

Kudos to those that facilitate the asking and granting of permission for use of data for the purpose of targeting. Permission does you one better and ensures that you are compensated for data shared. It’s the only fair and transparent solution. After all, it’s YOUR data.

Recent articles

Your ASK Wallet, Now Powered by Coinbase

Sep 22nd, 2026
|
{time} read time

We've partnered with Coinbase to bring best-in-class wallet technology to our community.

Today we're updating the technology that powers your ASK wallet. Here's what's changing, what it means for you, and what stays exactly the same.

What's changing

We've moved your Permission wallet to Coinbase's platform. What that means in plain language is this: starting today, you are in full control of your ASK. When you click to send, redeem, or manage your balance, the transaction happens from your account, signed by your login. We no longer hold your wallet keys. Coinbase does, on your behalf, under your authority.

We chose Coinbase's embedded wallet specifically because it brings institutional-grade security to our users without requiring you to manage anything yourself. The infrastructure is Coinbase's. The wallet is yours.

Beyond the custody change, our users now have a wallet that can go wherever they go: exportable, cross-chain ready, and backed by a platform that serves millions of people around the world. We're proud to bring that to our community.

What it means to control your own keys

As Permission has grown, we felt strongly that your funds should be held by a platform built specifically for that purpose, with the security standards and regulatory rigor that come with it. Moving to Coinbase's embedded wallet reflects that commitment.

With today's change, Coinbase secures your private key inside their systems, and only your Permission login can authorize transactions. When you click to send or redeem ASK, the transaction is authorized by you, through your login. We are no longer part of that process.

What this means practically: your wallet operates on its own, independent of Permission. Treat your Permission login like you would a bank password. It is now the key to your wallet. If you ever want to take your wallet entirely outside of Permission, Coinbase supports key export and that option is yours.

What Coinbase sees

Because Coinbase is now part of the infrastructure, your email address, account identifier, and wallet information are shared with them for the purpose of operating the wallet. For details on how Coinbase handles this data, you can review their embedded wallet documentation and their privacy information.

For how Permission handles your data, our Terms of Use and our Privacy Policy govern that relationship, as they always have.

What stays the same

Everything you experience in the app. Earning ASK, redeeming it, transferring it, viewing your balance, managing your family. None of that changes.

And, what does change, we're excited about: key export, cross-chain support, and institutional-grade security. These are capabilities that would have taken years to build in-house and that Coinbase has spent that time perfecting. We chose to partner with the best-in-class, and our product and users will be better for it.

If you have questions, support is always here.

The Permission Team 🤝

What Is Family Friendly AI™?

Sep 9th, 2026
|
{time} read time

Only 15% of people globally say they trust AI systems, and 72% of parents are concerned about AI’s impact on their children.

AI is quickly becoming part of everyday family life, but Big Tech wasn’t built with families in mind. Family Friendly AI is technology intentionally designed for families, giving parents visibility into their children’s digital lives, guidance when they need it, and tools to encourage positive behavior.

5 Things That Make AI Family Friendly

1. Your family owns its data.

‍Your family’s data is never sold. It belongs to your family, and you stay in control of it.

2. Parents know what’s happening online.

‍Family Friendly AI gives parents visibility into their children’s digital lives, helping them fully understand how their children use and interact with technology.

3. It motivates children with rewards and incentives.

‍Parents can set rewards and incentives to encourage positive behaviors and help their children build better habits around technology and beyond.

4. It gives parents coaching and inspiration.

‍Parenting in a digital world comes with challenges that screen-time limits alone can’t help with. Family Friendly AI gives parents personalized AI-insights and guidance to help them navigate what their children are doing online and decide what to do next.

5. It earns families' trust.

‍Technology for families should have a higher bar. The companies building it should stand behind it with an unconditional, no-questions-asked money-back guarantee.

It’s time for AI, crypto, and the technology shaping our children’s lives to meet the family-friendly standard.

Big Tobacco Had Its Reckoning. Now It’s Big Tech’s Turn.

Aug 12th, 2026
|
{time} read time

The floodgates are open.

Thousands of lawsuits are moving forward. States are writing new rules for kids online. And lawmakers are beginning to tell AI companies what they can and cannot do when children use their products.

And you don't have to look far to see it happening...

The courts: 3,000+ lawsuits get the green light

On August 10, the Ninth Circuit allowed more than 3,000 lawsuits against Meta, Google/YouTube, TikTok and Snap to move forward.

The cases allege that the companies deliberately designed features of their platforms to be addictive, particularly for young users.

The tech companies had argued that Section 230 of the Communications Decency Act protected them from the claims. The court rejected their attempt to use Section 230 to stop the litigation at this stage, finding that it provides a defense rather than immunity from being sued.

At their core, these cases are allegations about the platforms themselves: how they were designed, how they kept people engaged, and what responsibility the companies bear for the consequences.

The companies will still have the opportunity to defend themselves against those allegations.

But with more than 3,000 cases now getting the chance to be heard, this is getting harder to argue away.

New Jersey: families get a way to enforce the rules

One day later, New Jersey Governor Mikie Sherrill signed the New Jersey Kids Code Act into law.

The law establishes new design and privacy requirements for covered online services likely to be accessed by minors. Among other provisions, it requires high privacy settings by default, restricts certain push notifications, prohibits dark patterns for minors, limits how children's personal data can be used and retained, and places restrictions on targeted advertising.

But one provision in particular changes the accountability equation: a private right of action.

An individual under 18 who is injured by a violation can bring a claim under the law, with statutory damages of $5,000 per violation. Parents may also bring an action on a minor's behalf.

Which is legal language for something pretty simple: families don't have to wait around for a regulator to act. They can take companies to court themselves.

Colorado: AI safety starts becoming a legal requirement

Then there's Colorado.

Earlier this year, Governor Jared Polis signed Colorado HB 26-1263, establishing specific requirements for operators of conversational AI services.

And this one is worth paying attention to because the law doesn't simply tell AI companies to "keep kids safe." It starts defining what that actually means.

Operators must estimate users' ages. When dealing with minors, the law requires recurring disclosures that they are interacting with AI rather than a person and establishes protections around sexually explicit interactions.

It also addresses one of the most unsettling questions surrounding companion-style AI: emotional dependence.

The law requires safeguards designed to prevent conversational AI from producing statements that simulate emotional dependence. It also requires protocols for responding to suicidal ideation and self-harm, privacy and account-management tools for minors and parents or guardians, and reporting requirements intended to help regulators evaluate whether those safeguards are actually working.

The law takes effect January 1, 2027.

For companies building conversational AI, that's a meaningful shift. Child safety is moving beyond a set of voluntary guardrails companies write for themselves. In Colorado, some of those guardrails are becoming law.

It's no coincidence that this is all happening at once.

Big Tobacco didn't wake up one morning and discover the world had changed its mind. The reckoning came piece by piece, until lawsuits became regulation and an industry that had spent decades setting its own standards was finally forced to take responsibility for the harm its products caused.

We're watching that shift happen again.

For years, the responsibility for keeping kids safe online has fallen on parents.

Set the parental controls. Check the privacy settings. Watch the screen time. Know which apps they're using. Figure out who they're talking to. Keep up with every new platform, algorithm and now AI chatbot entering their lives.

All while the technology on the other side of the screen gets more sophisticated by the month.

Now courts and lawmakers are starting to ask the companies building that technology a much more uncomfortable question:

If children are using your products, what are you doing to keep them safe?

For families, that's the shift that matters most.

This isn't another round of false promises to "do better."

This is legislation. These are lawsuits. This is accountability beginning to have teeth.

Parents will always have the role of protecting their children online. We happen to believe they should have far more visibility and control over the technology entering their families' lives, not less.

But parents cannot be the entire safety system.

The law is making clear that the companies designing the products, writing the algorithms and building the AI our kids interact with have a responsibility, too.

And when they fail to meet it, they'll finally be held accountable.

ChatGPTs Births A Parenting Tool That Needs Some Image Repair

Aug 4th, 2026
|
{time} read time

Sam Altman keeps pitching AI as a co-parent. The reason parents aren't buying isn't nostalgia, it's the lawsuits.

Last Friday, Sam Altman had an idea he was excited about. Hook your family calendar up to ChatGPT, tell it what your kids are into, and every morning on the drive to school it'll produce a little podcast: one kid's soccer game that afternoon, another kid's birthday coming up, maybe some news. He called it a "cool use case."

What should’ve felt really innovative, landed like the opening scene of a bleak dystopian movie. Two kids in the back, one parent up front, and a smooth synthetic voice narrating, to everyone present, the lives of everyone present. "Later today, Maya has soccer." Maya, who has soccer, looks out the window. Nobody says anything, because the podcast is saying it for them.

The internet population caught what we caught. The reply that stuck came from Alex Hirsch, creator of Disney’s Animated series, Gravity Falls. It was seven poignant words: "What if you just talked to your children?" That was the entire rebuttal, and it traveled a great deal further than the thing it was rebutting. Altman's post drew somewhere around 9,600 likes. Hirsch's reply cleared 120,000. On the CEO's own platform, the crowd took a vote, and the crowd chose the small talk.

Now, we want to be fair here, because the easy thing is to dunk and move on. But we’re parents here at Permission and anyone who has done the 7:40 a.m. drive on four hours of sleep, refereeing a backseat dispute about who touched whom first, knows the exact fantasy of a button that handles the morning. That instinct isn't a character flaw. It's a Tuesday.

But this wasn't a one-off. Altman has been quietly auditioning AI for the co-parent role for a while now. On The Tonight Show in December 2025 he said he couldn't imagine having to "raise a newborn without ChatGPT" then added that people had managed the trick for a few hundred thousand years without it. Also, last year, in a podcast hosted by Andrew Mayne, Altman admitted that people might form “problematic parasocial relationships” to a chatbot. (You know, the one-sided kind that we usually reserve for celebrities we've never met.) He sees the hazards clearly. He's pitching the product anyway.

When visibility turns into vulnerability.

The reason parents flinched at the idea of carpooling with a chatbot for school drop off isn't that they're allergic to convenience. It's that the company making the offer is, right now, being sued by multiple families who say its chatbot played a role in their loved ones' spiraling delusions and, in the worst cases, their deaths. OpenAI says it is continually improving how its models handle sensitive conversations, and that work genuinely matters. But you can see the problem. "Let me into your calendar, your commute, and your kids personal details" is a big ask from anyone. It is a much bigger ask from a company currently explaining itself in court.

Trust isn't a feature you ship in the next update. It's something people hand you slowly, and take back all at once.

Here's where we should admit an interest. We build Permission on a belief that sounds boring until you sit with it: your data belongs to you. With Permission your kids’ browsing history doesn’t get shipped out to the open internet. Not to a model, not to a growth chart, not to whoever posts the next cool use case. And the closer AI creeps toward our kids (and it is creeping, because kids are already asking it everything) the more one question starts to outrank all the others:

Where is the line between parenting and outsourcing parenting?

Because "parenting tool" is doing a lot of quiet work in that phrase. A tool is a hammer. It lives in a drawer, it does one honest thing, and it does not ask to read your child's messages or move into the family calendar. When a company calls its chatbot a "parenting tool," it's worth asking, gently, which word they mean. The tool part, or the parenting part.

We happen to think AI can be genuinely, unglamorously useful to families. Not by doing the talking for you, but by handing you the context you'd otherwise miss instead of a thousand panicked notifications, and then getting out of the way so you can make the call. That's a real distinction, and it deserves its own piece.

So take this as Part One: the news, the flinch, and the reason the flinch is earned. In Part Two, we'll make the harder and more hopeful argument that you can let AI help you parent without completely handing over your family secrets. There is a version of this where the grown-ups stay in charge. We think it's the only version worth building.

For now, the seven best words anyone has offered on the whole affair still belong to Hirsch. So we'll give him the last one, too.

What if you just talked to your children?

‍