Browser cookies are small text files that a website stores in your web browser to remember information about you between requests and visits. Because the web’s underlying protocol does not remember previous interactions on its own, cookies give sites a way to keep you logged in, hold items in a shopping cart, save preferences and, in some cases, track your activity across the internet. They are defined by an open internet standard, RFC 6265, and are managed entirely by your browser, which you can inspect and control.
Why cookies exist
The web runs on HTTP, a protocol that is stateless: each request a browser makes is, by default, independent and carries no memory of what came before. That design is efficient but inconvenient, because a site would otherwise forget who you are the instant you move to the next page. Cookies solve this by letting a server send a small piece of data that the browser stores and returns with future requests to the same site, allowing the server to maintain state, such as your login session or language choice. This connects closely to the difference between HTTP and HTTPS, since secure cookies are only sent over encrypted connections.
The mechanism is formally described in an open internet standard, RFC 6265, published by the internet’s standards community. That standard specifies exactly what a cookie looks like, how servers set them and how browsers should store and return them. Because cookies are governed by a shared, public specification rather than any single company’s rules, they behave consistently across browsers and websites worldwide, which is part of why they became the web’s default method for remembering users.
It helps to think of a cookie as a coat-check ticket. When you arrive, the site gives you a numbered ticket and keeps the matching record. On each later visit, your browser hands the ticket back, and the site looks up what it knows about you. The ticket itself is small and often meaningless to anyone else; the useful information usually sits on the server, linked to that identifier.
How cookies work
The mechanism is straightforward. When you visit a site, its server can include a Set-Cookie instruction in its response. Your browser stores that cookie and automatically attaches it to subsequent requests to the same site. A cookie is essentially a name and value pair, accompanied by attributes that control its behaviour:
- Domain and path define which site and pages the cookie applies to.
- Expiry determines whether it is a session cookie or a persistent one.
- Secure restricts the cookie to encrypted HTTPS connections.
- HttpOnly hides the cookie from JavaScript, reducing theft via scripting attacks.
- SameSite controls whether the cookie is sent on cross-site requests.
These attributes are the heart of cookie security. The HttpOnly flag, for instance, prevents scripts on a page from reading a cookie, which helps limit the damage if a site is hit by a cross-site scripting attack. The Secure flag ensures a cookie is only ever transmitted over an encrypted connection, guarding against interception. And SameSite, now defaulting to a stricter setting in modern browsers, reduces the risk of a class of attacks where a malicious site tries to make your browser act on another site where you are logged in. A well-configured cookie is therefore not just a convenience but a small but important security control.
Types of cookies
Cookies are often grouped by how long they last and who sets them. The table below summarises the main distinctions.
| Category | Description | Typical use |
|---|---|---|
| Session cookie | Deleted when you close the browser | Keeping you logged in during a visit |
| Persistent cookie | Stored until an expiry date | Remembering preferences and settings |
| First-party cookie | Set by the site you are visiting | Login, cart, language |
| Third-party cookie | Set by another domain on the page | Cross-site advertising and tracking |
First-party vs third-party cookies
The most important distinction for privacy is between first-party and third-party cookies. A first-party cookie is set by the website whose address is in your browser bar, and it powers useful functions like staying signed in. A third-party cookie is set by a different domain whose content, such as an ad, analytics script or embedded widget, is loaded within the page. Because the same third party can appear on many websites, its cookies can follow you across the web to build a profile of your browsing, even on sites you never visited directly.
Concerns about this kind of tracking have driven major browsers to restrict or phase out third-party cookies, and to strengthen defaults such as the SameSite attribute, which limits when cookies are sent across sites.
It is worth stressing that first-party cookies are largely benign and genuinely useful. Without them, you would have to log in on every page, re-enter your language on every visit and lose your shopping cart constantly. The privacy debate is really about the third-party variety, and about first-party data that is later shared with others. That distinction is why blanket cookie deletion is a blunt instrument, and why browsers increasingly aim to preserve helpful first-party functions while curbing cross-site tracking.
Are cookies dangerous?
Cookies themselves are not programs and cannot run code, carry viruses or directly harm your device. The risks are about privacy and misuse rather than infection:
- Tracking: third-party cookies can enable extensive cross-site profiling.
- Session hijacking: if an attacker steals a session cookie, they may impersonate you, which is why HttpOnly and Secure flags matter.
- Over-collection: some sites gather more data than users expect.
Good security practices, including encrypted connections and awareness of phishing, reduce the chance of cookies being stolen. A VPN hides your network location but does not stop cookie-based tracking, which is a common misunderstanding.
Cookie consent and the law
Because cookies can be used to track people, many jurisdictions require websites to inform users and, for non-essential cookies, obtain consent. That is why cookie banners appear so often. Essential cookies needed to make a site work generally do not require consent, while analytics and advertising cookies usually do. The most privacy-preserving choice is typically to decline non-essential cookies where the option is offered.
In practice, consent banners vary in quality. Some make declining as easy as accepting, while others bury the reject option or use confusing wording, a pattern critics call a dark pattern. Regulators in several regions have pushed back, insisting that refusing tracking should be as simple as agreeing to it. As a reader, the practical takeaway is to look for a clear reject or manage option rather than reflexively clicking accept, and to treat scam-like consent prompts on unfamiliar sites with caution.
How to manage and delete cookies
You remain in control of cookies through your browser settings. Common actions include:
- Viewing stored cookies in the browser’s privacy or site-data settings.
- Deleting cookies individually, by site, or all at once.
- Blocking third-party cookies to limit cross-site tracking.
- Using private or incognito windows, which discard cookies when closed.
- Setting the browser to clear cookies on exit for stronger privacy.
Clearing cookies will log you out of sites and reset preferences, which is the trade-off for a cleaner slate. For most people, a balanced approach, allowing first-party cookies while blocking third-party trackers, preserves convenience without excessive tracking. Browser extensions and privacy-focused settings can automate much of this, and using separate browser profiles for different activities can further limit how far any single cookie can follow you.
It is also worth knowing that cookies are not the only way sites remember or track visitors. Techniques such as local storage, device fingerprinting and tracking pixels can persist even when cookies are cleared. This is why privacy is best approached as a combination of tools and habits rather than a single setting, and why regulation increasingly targets tracking behaviour rather than the specific technology used to achieve it.
The future of cookies
The web is gradually moving away from third-party cookies as the default tool for advertising and tracking, pushed by privacy regulation and browser changes. Alternatives being explored include privacy-preserving measurement and first-party data approaches, though these bring their own debates about transparency and competition. First-party cookies, meanwhile, remain essential to how logins and shopping carts work and are not going away.
For context, it helps to see how cookies fit alongside other web-storage methods. The table below summarises the main options a website can use to remember information.
| Method | Sent to server automatically | Typical use |
|---|---|---|
| Cookie | Yes, with each request | Sessions, preferences, tracking |
| Local storage | No, stays in the browser | Larger client-side data |
| Session storage | No, cleared on tab close | Temporary per-tab data |
This is why simply deleting cookies does not always stop every form of tracking, and why a rounded understanding of web storage matters for genuine privacy.
Understanding cookies helps you make informed choices about consent banners and privacy settings rather than clicking through them blindly. Rather than fearing cookies or ignoring them, the healthiest approach is an informed middle path: keep the first-party cookies that make the web usable, curb the third-party tracking that follows you around, and stay aware that privacy online is an ongoing practice. For more plain-language explainers on the web and digital rights, browse our technology section or the wider reporting on newsreverse com.