Skip to content

Comment on Cookie Bomb or Let's Break the Internetparent

Comments

Your idea would likely break any site on the internet that uses authentication and subdomins, isn't it clear why this isn't being considered?

Or sites could opt-in to this with a header?

EDIT: homakov says the same thing down thread.

Yes, it is backwards incompatible. Perhaps it could be enforced in HTTP 2?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.