3 ms·
Ah, sorry, I misread your comment. Indeed, a browser that doesn't respect cross-domain restrictions is a poorly written browser. My point still stands, though:
by valverde 11y ago
Ah, sorry, I misread your comment. Indeed, a browser that doesn't respect cross-domain restrictions is a poorly written browser.
My point still stands, though: the point of cookieless domains is not security, but bandwidth. And there are legitimate reasons to have top-level domain cookies - sharing authentication state between subdomains is a common example - which would prevent a subdomain from being used as a CDN, without receiving cookies.