World Wide Web
Internet and Its Uses
A cookie is a small text file stored on the user's device by a website, used to remember information about the user across page loads and visits.
Cookies are set by the web server (sent in an HTTP response) and stored by the browser on the user's device. The browser sends them back with future requests to the same site, so the server can recognise the user.
What cookies typically hold:
- Login state: which user is currently signed in.
- Session data: items in a shopping cart, in-progress form data.
- Preferences: language, dark mode, font size.
- Tracking IDs: a unique identifier for analytics or advertising.
A cookie is a plain text file, not a program. Cookies cannot themselves run code or directly attack the user's computer. (Whether the information they carry is privacy-friendly is a separate question; see "Privacy concerns" below.)
Two types of cookie
Cookies come in two types: session and persistent cookies.
| Session cookie | Persistent cookie | |
|---|---|---|
| Stored in | RAM (the browser's memory) | Hard disk / SSD (a file on the user's device) |
| Lifespan | Lasts only while the browser is open | Has an expiry date; can survive for days, weeks or years |
| Discarded | Once the user closes the browser | When the expiry date passes, or when the user clears them manually |
| Typical use | Keeping the user logged in for one visit; remembering shopping-cart contents during the same browsing session | Remembering login between visits ("remember me"); remembering preferences (e.g. language, theme); long-term analytics and advertising IDs |
Common exam question
Completing statements about cookies and giving their uses
Question: Complete a passage about cookies from a list of terms (6–7 marks), then give three uses of a cookie (3 marks).
Asked in 3 of the 17 papers: twice as the gap-fill plus three uses, once as a table row naming the cookie from its description. Every gap is one mark. Cookies are small text files, sent between web browser and web server and stored by the browser. A session cookie is a temporary file, held in memory, not secondary storage, and lost when the browser (or session) closes. A persistent cookie is a permanent file kept on secondary storage until it is deleted manually or expires. A term may be needed twice (both schemes repeat one), so do not rule out a term you have already placed.
For the uses, any three of: storing login details, saving personal details, holding the items in an online shopping cart, tracking user preferences, storing payment details and targeted advertising.
Privacy concerns
Cookies started out as simple tools for site convenience. Over time, they became a major privacy issue:
- Third-party tracking cookies: cookies set by advertising or analytics companies can be read on every site that includes their tracker (e.g. an ad network). This lets the third party build a profile of the user's browsing across many sites, even ones the user did not realise were linked.
- Personal information storage: some cookies hold names, email addresses, login tokens or other personal data. If the device is shared or compromised, this data may be exposed.
- Session hijacking: if an attacker can read a logged-in user's session cookie (e.g. on an unencrypted connection), they can pretend to be that user. This is one reason every login page should use rather than plain HTTP.
- Lack of transparency: most users do not know exactly what each cookie stores or what the site does with the data.
Legal and technical responses
- Browsers offer cookie controls: settings to block all cookies, third-party cookies, or specific sites.
- Modern browsers are starting to block third-party by default.
- Laws such as the EU's GDPR and the UK's PECR require websites to ask for consent before setting non-essential cookies. This is why most sites now show a cookie banner on first visit.
- Users can manually clear cookies at any time from the browser's settings.
Cookies vs cache
Two related ideas often confused:
- Cookies are small text files that hold information about the user (state, preferences, IDs).
- The browser cache is a temporary store of downloaded resources (images, scripts, stylesheets) so they do not have to be downloaded again on the next visit.
Both improve the browsing experience, but they do different jobs.