Skip to content

Comment on Cookie Bomb or Let's Break the Internetparent

Comments

Couldn't a solution be something stored in DNS, that tells browsers not to let subdomains' JS do this?

So if I own example.com I could set something in my DNS that would prevent subdomain.example.com from setting cookies on example.com.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.