Although internet cookies may improve a user’s browsing experience, they can collect more information than most people realize. Without knowing, users may be giving away valuable information that can lead to cybersecurity threats. Understanding what cookies are before clicking “accept” is the first step to being safe online.
Introduction
When a person is surfing the web, they are most likely going to come across a simple question asking the user to allow or reject cookies. Oftentimes, web users are quick to accept the cookies without fully understanding what information they are giving away and how this could affect their internet safety. The name ‘cookies’ can be deceiving, reminding users of a delicious and harmless dessert. In reality, they are tiny pieces of data that identify the user and may improve the browsing experience. Furthermore, companies use these cookies to help with marketing strategies. Although these cookies could improve the user’s experience on the web, they may collect more information than many people realize.
The Danger of Cookies
What are cookies
Cookies build the foundation for the online user experience. When we are on a browser, internet cookies tailor our experience to match our interests. On the surface, cookies seem to be beneficial, as they are meant to help us. However, it is easy for users to overlook the security concerns that may arise with giving away our information to online databases, such as identity theft and access to personal information. There are two main types of Internet cookies: authentication cookies and tracking cookies. Authentication cookies save a user’s login information on a website. These types of cookies allow users to access the website without having to log in again. Tracking cookies monitor a user’s web usage, personalizing the user’s searches and content based on their interests and browsing history.

The Information Being Given Away
Unfortunately, third-party cookies — placed by a third party for a specific purpose — present the highest cybersecurity risks because they permit external sources to gain access to a user’s information. Accepting these cookies allows third-party companies to have access to a user’s online information. This can be risky because external companies may sell this data to suspicious companies, resulting in security issues. These types of exploitative cookies are closely linked to ransomware attacks, which is when a software takes over a user’s computer systems and disables access to the user’s files. The software will then ask the user for money as a ransom. These types of attacks can look like a malicious link or a file attachment. It is important to understand the risks to blindly accepting cookies because our cybersecurity is essential to protect. According to the World Economic Forum, 72% of businesses see that cybersecurity risks are rising. If we want to safeguard our private information, such as passwords or banking information, intentionally thinking before clicking “allow cookies” is the first step. Users also need to understand that these risks can lead to national security breaches and company shutdowns, which not only affect the user, but people worldwide.
Ethics of Cookies
There are several laws put into place to protect users from online privacy breaches. For example, the General Data Protection Regulation (GDPR) has specific cookie requirements: users must give consent to non-essential cookies and websites must explain what cookies will be used. Having these built in protections are important because they allow users to have greater control over what data they are giving away. There are many ethical concerns surrounding cookies; people argue that online data collection violates the four pillars of ethics: autonomy, justice, non-maleficence, and justice. This is because cookies often track web users without the users fully knowing what information they are giving over.
Take Home Points
- Cookies are tiny pieces of data that identify the user and may improve the browsing experience.
- Accepting third-party cookies allows third-party companies to have access to a user’s online information, which can be risky because external companies may sell this data to suspicious companies, resulting in security issues.
- 72% of businesses see that cybersecurity risks are rising
