Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

lylemo

macrumors member
Original poster
Nov 28, 2008
47
1
After updating to MacOS 10.14.4, I have found many (!) cookies labelled "HSTS Policy" for websites that I have never visited. I found these when I have gone to Safari Security, where I regularly delete unwanted cookies. Going to Develop>Empty Caches doesn't eliminate these cookies. Why am I getting these cookies? Is there a problem? There are several websites, for which I allow cookies, also have the "HSTS Policy" added to them. What does this mean?
 
In a nutshell, “HSTS Policy” is a particular kind of cookie that stops Safari from accessing an insecure version of a website if it has accessed a safe version in the past. Like any other cookie it can be used to track you. Apple seems to list it under cookies now, though the feature itself is older.

It might be that this website was loaded while you visited another that loaded a resource from it. This might trigger the HSTS cookie. Clearing caches generally won’t clear cookies.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.