I can make an HTML page with image tags that point at other people’s images: a page of Rembrandts from different art museums. If those images are open then it doesn’t matter whether my browser sends cookies for the publisher’s domain. The images will be served with or without those cookies.

But if the images are access-controlled, the publisher will expect to see a session cookie or similar credential in the request. My page of Rembrandts could include a note for the user: “log in over at example-museum.org, if you want to see this image”. …

Tom Crane

Technology Director, Digirati

