That question came up to me, when recently working on one project I needed to restart my PC several times. And therefore, while I used 3-5 web apps I needed to log back in to each one of them again, after each restart. And I started wondering if privacy-wise that auto-clear feature is worth it or not? Has anyone maybe tested that?

  • printf("%s", name);@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    1 day ago

    If you’re sharing the computer with others and you don’t delete cookies after having logged in to whatever website/service that you were using, the browser could automatically log another person in with your credentials. This is because cookies can store “sessions”. While I’m not a fan of Linus himself - and I do implore you to make up your own mind on that -, one time, at bandcamp, they almost lost their whole YouTube channel because their session tokens were grabbed, and they made a great breakdown of the incident, which can be educational: https://www.youtube.com/watch?v=yGXaAWbzl5A

    I make my browsers either not save cookies at all or delete them on exit by default and manually tweak site settings for specific sites if and when I want to be able to log in “automatically”.