in a static protocol like http if you want to maintain a login, cookies are the only option. So, if you want to use webmail, your asking for a miracle. Cookies are a security risk only if you take every single you get. Theres no harm in accepting a session cookie. So I suggest that if youre so paranoid you hate yummy cookies, disable em, but manually add excludes for your email provider. Atleast firefox has this feature, I bet most other browsers too..
But disabling all cookies, thats just paranoia.. get over it
|