3 ms·
There are many high profile websites that use the cookieless domain approach: Google, Facebook, and Reddit off the top of my head. I wouldn't say they are poorl
by valverde 11y ago
There are many high profile websites that use the cookieless domain approach: Google, Facebook, and Reddit off the top of my head. I wouldn't say they are poorly written - it's more of a design decision to have cookies in the top-level domain.
- dogma1138 11y agoI didn't say the sites would be poorly written, the browsers would be if they do not obey the cookie set domain and set path restrictions. And the fact that big sites use it doesn't mean that they were "well written", Google mostly issues only tracking cookies for wildcard domains like .google.com as far as private cookies go they usually would be issued for each domain individually (play.google.com etc.). Issuing authentication cookies to wildcard domains and root paths isn't advisable even if some big sites do it doesn't mean you should take it as an example :) P.S. I really hate "Google and Facebook are doing it" as an example, even if they are you most likely aren't either of them, not even close they have quite different considerations than you. Even when they do things which aren't best practice or common sense it doesn't mean that you should decide to take the same path, both Google and Facebook have plethora of ways to ensure account security including quite decent activity heuristics, they have many ways of detecting attacks such as XSS, and they have most likely a much better process of ensuring that vulnerable pages do not go live or do so quite rarely. Unless you can say the same then do not use them as an excuse, you do not need to issue cookies to wildcard domains and you can restrict them to certain paths, and you better do so because you do not have many other mitigating controls in place as the big players do.
- valverde 11y agoAh, sorry, I misread your comment. Indeed, a browser that doesn't respect cross-domain restrictions is a poorly written browser. My point still stands, though: the point of cookieless domains is not security, but bandwidth. And there are legitimate reasons to have top-level domain cookies - sharing authentication state between subdomains is a common example - which would prevent a subdomain from being used as a CDN, without receiving cookies.