Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  Imperva Advanced Bot Protection and the cookieless era

    Posted 01-28-2022 02:33
    Edited by Sarah Lamont 02-02-2022 07:29
    What is the impact of a) cookieless browsers and b) clients blocking cookies on Imperva Bot Protection traffic flow? From Imperva Documentation Portal, you see that after the fingerprinting step (Identify?), ABP sends back a token, which the client stores as a cookie.

    Thanks
    Johan Genbrugge
    #AdvancedBotProtection

    ------------------------------
    Johan Genbrugge
    IT Solution Architect
    Halle
    ------------------------------


  • 2.  RE: Imperva Advanced Bot Protection and the cookieless era

    Posted 02-02-2022 05:20
    Hi Johan,

    It is worth noting that cookies are quite an important part of ABP and we do use them. When we don't accept cookies it's quite difficult to mitigate using the identify condition, simply because cookies are used in that case. The other OOTB conditions such as Bad User Agents, Known Violator Data Center, Automation
    etc. and self created conditions (where we block on signatures) can be used without a problem. Bots with no_token can be blocked but it is worth noting this could cause FPs.

    I hope this helps.



    ------------------------------
    Stephen Dickson(csp)
    ------------------------------



  • 3.  RE: Imperva Advanced Bot Protection and the cookieless era

    Posted 02-02-2022 07:27

    Thanks, @Stephen Dickson.

    Johan - if you search "ABP" in our video hub, you may find some more useful info. 

    We have this "Ask Me Anything" webinar where our community members grilled our Imperva Experts on all things ABP!

     



    ------------------------------
    Sarah Lamont(csp)
    Digital Community Manager
    ------------------------------



  • 4.  RE: Imperva Advanced Bot Protection and the cookieless era

    Posted 02-07-2022 04:43
    Thanks Sarah, Stephen, I had a look at that Webinar yes. If my memory serves me right the cookieless question did not come up. I understand now that cookies are absolutely necessary for the identify condition (still learning!). And that makes the broader question more relevant, which I'll rephrase:

    "You hear a lot of talk about the cookieless era. As far as I can tell now, Google Chrome will (or plans to) block 3rdf party cookies as of this year. I also assume that the Imperva token is NOT a 3rd party cookie, so no worries for now. But is the trend towards a full cookieless era somethign that keeps you up a night? i.e. Are engineer at Imperva already thinking, what if we can't use a token anymore and how will the identify condition then work?".

    Thanks
    Johan

    ------------------------------
    Johan Genbrugge
    IT Solution Architect
    Halle
    ------------------------------



  • 5.  RE: Imperva Advanced Bot Protection and the cookieless era
    Best Answer

    Posted 02-09-2022 06:13
    Hi Johan,

    Thanks for this really interesting question. For the first part, you are correct... ABP is set up to be first party, so third-party efforts generally don't impact us.

    For your broader question, I had to check in with the engineers about this. At this time, they say it is hard to believe that cookies will actually be completely removed, as they are so fundamental to much of the web. We continue to monitor the industry and if it did start gaining traction, we would need to figure out next steps. It is unlikely that this would be a rapid change.

    I hope this helps.

    Thanks,



    ------------------------------
    Sarah Lamont(csp)
    Digital Community Manager
    ------------------------------



  • 6.  RE: Imperva Advanced Bot Protection and the cookieless era

    Posted 02-14-2022 02:18
    Yes Sarah, always good and helpful to get feedback on questions. And indeed, cookies are difficult to imagine "away". (but then so were ashtrays on your desk at work in the 80ies :)). I do have confidence that Imperva cannot ignore an industry trend should things really go that way and I also agree this would not be a rapid change. So thanks for the helpful feedback!

    Johan

    ------------------------------
    Johan Genbrugge
    IT Solution Architect
    Halle
    ------------------------------



  • 7.  RE: Imperva Advanced Bot Protection and the cookieless era

    Posted 02-15-2022 12:23
    Absolutely, Johan. This is what community is all about.

    In terms of industry trends etc, I thought you might find this podcast episode interesting: Podcast - Imperva Customer Community

    Essentially, it's an audio version of a recent webinar from Imperva's Office of the CTO that looks at Cybersecurity trends and Predictions for 2022. It may give you some more insight into which current trends Imperva is focusing on.

    Enjoy!


    ------------------------------
    Sarah Lamont(csp)
    Digital Community Manager
    ------------------------------