Company
Date Published
Author
Jeffrey Hung
Word count
3498
Language
English
Hacker News points
None

Summary

Sentry recently completed a multi-month project to remove all non-essential cookies and trackers from their public websites. The company's primary motivation for this effort was to align with its corporate privacy values, aiming to provide the Sentry experience as secure as possible. To identify which cookies were on their site, they used specialized tools, including Content Security Policy (CSP), a feature that helps detect and mitigate security threats. CSP allowed them to identify most, if not all, third-party scripts on their websites, enabling them to put together a comprehensive picture of the cookies and trackers being dropped by these scripts. The company removed cookies entirely, disabled tracking in tools, or used privacy-centric tools as alternatives. To ensure compliance with privacy laws and prevent new cookies from dropping, they implemented CSP and continuously monitored for unapproved cookies using custom scripts and cookie scanners. With this approach, Sentry aims to provide a secure experience for its users while promoting transparency and accountability in the use of tracking technologies.