about website cookies

hello if someone got your website cookies in one website can they use that to access or log in to other websites your log into?

MacBook

Posted on Aug 14, 2019 3:09 PM

Reply
Question marked as Top-ranking reply

Posted on Aug 14, 2019 3:48 PM

So you're asking if a compromise of one (unspecified) web site can lead to compromises of other (unspecified) web sites?


Short answer:


No. Not in the way I suspect you're intending this question.


Cookies are and contain site-specific data.


A cookie for one site won't do much good with another and unrelated web site.



Long answer:


What you're asking about is possible, given sufficiently bad web site implementations or given sufficient web site design flaws. But that depends greatly on the details of the cookies involved, on the motivation and skills and budget of attacker, on your worth to the attacker, on whether there is some form of delegation in use among the web sites, whether the site can be used to harvest access such as your web mail portal, and on the particular implementation mistakes that might exist. Also on what browser extensions and web-related apps might be installed.


Again, cookies are site-specific and one cookie (alone) just doesn't get you to a different web site.



For more reading, and for increased security:


If somebody can more generally access your cookie store, there are far larger security issues lurking.


If the web site offers it, enable and use two-factor authentication.


Reading on cross-site scripting and cookie security available. And the folks at OWASP also have a (PDF) list of common web security vulnerabilities.


1 reply
Question marked as Top-ranking reply

Aug 14, 2019 3:48 PM in response to rina166

So you're asking if a compromise of one (unspecified) web site can lead to compromises of other (unspecified) web sites?


Short answer:


No. Not in the way I suspect you're intending this question.


Cookies are and contain site-specific data.


A cookie for one site won't do much good with another and unrelated web site.



Long answer:


What you're asking about is possible, given sufficiently bad web site implementations or given sufficient web site design flaws. But that depends greatly on the details of the cookies involved, on the motivation and skills and budget of attacker, on your worth to the attacker, on whether there is some form of delegation in use among the web sites, whether the site can be used to harvest access such as your web mail portal, and on the particular implementation mistakes that might exist. Also on what browser extensions and web-related apps might be installed.


Again, cookies are site-specific and one cookie (alone) just doesn't get you to a different web site.



For more reading, and for increased security:


If somebody can more generally access your cookie store, there are far larger security issues lurking.


If the web site offers it, enable and use two-factor authentication.


Reading on cross-site scripting and cookie security available. And the folks at OWASP also have a (PDF) list of common web security vulnerabilities.


This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

about website cookies

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.