DMA15

Direct marketing, 1872 to the cookie

The Wire

Netscape Shipped the Cookie

Lou Montulli wrote the HTTP cookie specification at Netscape in 1994 to solve a shopping-basket problem — a small text file that let a server recognise a returning browser.

More in The Wire

Wikidata page for Netscape Navigator showing a browser screenshot, aliases, and logo

A few bytes handed back on the next request, written in 1994 to hold a shopping basket together.Photo: Wikidata for Digital Preservation - custom-built Wikidata interface with Netscape Navigator item Q235419 · Wikimedia Commons

A small text file meant to hold a shopping basket became the tracking mechanism of the entire commercial web.

The Problem Montulli Was Solving

In 1994, Lou Montulli was a programmer at Netscape Communications in Mountain View, California, working on the infrastructure of early commercial browsing. The web's underlying protocol, HTTP, was stateless — meaning each request a browser made to a server was treated as entirely new. No memory persisted between page loads. For a news site, statelessness was tolerable. For a shopping application, it was fatal: a server had no way to know that the person adding a second item to a basket was the same person who had added the first.

An early Netscape Navigator browser window on a mid-1990s CRT monitor, an adult seated at the keyboard

Navigator, 1994.

Photo: Ruben Boekeloo / Pexels

Montulli's solution was a small text file, stored on the user's machine and passed back to the server with each subsequent request. The server could write a value into this file and read it on the next visit, creating the illusion of a continuous session across a protocol that had none. The name he chose — cookie — was borrowed from an older computing concept, the "magic cookie," a token passed between programs to establish context. Netscape's implementation shipped with Navigator 1.0 in late 1994, and the mechanism was folded into the browser with no notification to users that it existed.

The initial specification kept the scope narrow. A cookie could only be read by the domain that set it, a constraint called same-origin scoping. It could carry an expiry date, meaning it could persist beyond a single browsing session and recognise a returning visitor days or weeks later. And it was deliberately small — limited to a few kilobytes — so the overhead of passing it back and forth remained trivial.

From Session State to Surveillance Infrastructure

The advertising industry noticed the persistence property almost immediately. What Montulli had built to remember a shopping basket could equally remember that a particular browser had visited a particular page, clicked a particular link, or spent a particular number of minutes on a particular article. By 1996, ad-serving networks had begun placing cookies not just from the site a visitor was on, but from the networks' own servers embedded within that page — a technique that exploited a loophole in same-origin rules when a page loaded third-party content. These "third-party cookies" could track a browser across every site that carried the same advertising network's tags, assembling a dossier of behaviour that no single publisher could have gathered alone.

A desk lamp illuminates stacked paperwork beside an old CRT monitor in a dim office

CAN-SPAM set the floor for commercial email: a working opt-out, accurate headers, an identified sender.

DoubleClick, founded in 1996, built its core business on exactly this architecture. By placing its tracking pixel on thousands of publisher pages, each carrying a DoubleClick cookie, the company could link a user's path across the web and price advertising inventory on the basis of observed behaviour rather than assumed audience. The model that Claritas and PRIZM had applied to postal ZIP codes — inferring individual propensity from aggregate demographic data — was now applied in real time to demonstrated behaviour, at individual resolution, without the subject's knowledge.

The Internet Engineering Task Force formalised the cookie specification as RFC 2109 ↗ in 1997, acknowledging in the document itself that the mechanism raised privacy concerns. The specification included provisions for user agents to block cookies from third parties, but no browser enforced this consistently for years. A revised specification, RFC 2965, followed in 2000 and was itself superseded by RFC 6265 ↗ in 2011, which remains the operative standard. None of these revisions resolved the third-party tracking problem; they clarified the protocol while leaving commercial practice largely undisturbed.

By the time data-protection regulators turned their sustained attention to cookies — the EU's ePrivacy Directive of 2002 requiring disclosure, the GDPR of 2018 requiring consent — the cookie had been the primary instrument of behavioural targeting for nearly two decades. What had begun as a session-management convenience became, in the intervening years, the technical foundation of an industry measuring and monetising attention at a scale that no earlier form of direct marketing, from the mailing list to the toll-free number, had ever approached.