Third-party cookie access in Waterfox
Cookies are small pieces of data that a website asks the browser to store. They can remember preferences, shopping carts and signed-in sessions. A cookie is considered third-party when it belongs to a site other than the one shown in the address bar.
Third-party cookies can support features such as federated sign-in and payment processing. They can also be used to follow activity across sites.
How Waterfox handles cross-site cookies
Enhanced Tracking Protection blocks cookies from known cross-site trackers. Total Cookie Protection keeps other third-party cookies in a separate cookie jar for each top-level site, which prevents one site from reading the same third party’s cookies from another site.
Some embedded services need unpartitioned cookie access to work. Waterfox can grant that access for the current top-level site without allowing the third party to use the same cookies everywhere.
Cookie access requests
An eligible third party can request access only after you interact with the page. For example, selecting a payment or sign-in control can allow the embedded provider to request its existing cookies.
Waterfox automatically approves a limited number of eligible requests before it begins prompting. By default, the limit is at least five concurrent automatic grants or about 1% of the unique top-level domains visited during the current session, measured over no more than the past 24 hours, whichever is greater. This lets common embedded services work while limiting broad cross-site access.
Review access for a site
Open the site information panel from the icon at the left of the address bar. When cross-site cookie permissions exist, the panel lists the third parties that can use cookies and site data while you are on the current site.
Deny a request
If you deny a request, the third party cannot use its unpartitioned cross-site cookies for that request. It may ask again after the page is reloaded or during a later interaction.
Revoke access
Open the site information panel and remove the cross-site cookie permission for the listed third party. Reload the page if the change is not applied immediately.
Automatic and heuristic access
In addition to the limited automatic grants, Waterfox uses compatibility rules for cases such as single sign-on. These rules generally require direct interaction or a top-level redirect and grant access only for a limited context or duration.
Removing access can break sign-in, payment or embedded content. Grant it only when you trust both the site in the address bar and the third party requesting access.
Copyright and Licensing
Adapted for Waterfox from the original Firefox article Third-party trackers. Original content by Mozilla Contributors. Licensed under the CC BY-SA 3.0.