Aggressive Cookie Strategy

For most of us, we have a single sign-on  (SSO) solution in place to enable our visitors/members to access pages and functionality across all of our various applications (content management, connected community, ams e-commerce , etc...).  Cookies are the glue that hold this single sign-on experience together.  A "cookie" is dropped by your main authentication process, and within this "cookie" is the information needed by your other applications when you hand a visitor/member over from one application to the other.

Most "cookies" have relatively short life spans (just like in real life).  It is common for "cookies" to expire after 20 minutes.  An aggressive cookie strategy, therefore, is simply choosing to increase the lifespan of a "cookie" to an hour, a day, a week, a year or for a very, very long time.   The benefit to this approach is that as long as a visitor/member comes back to your site using the same machine and the same browser, their "cookie" will be recognized and they will not be asked to log in.

Obviously, an aggressive cookie strategy emphasizes member convenience over security (although the overall security risk is minimal), so you should never implement it unless you have thought thru the trade-offs.

(Thanks, Brett!)

#Being Considered


Related Links

No Related Resource entered.