4 ms·
You'd be surprised by how many organizations completely disregard the security of their non-essential subdomains. The point of my post is that one subdomain tak
by jub0bs 6y ago
You'd be surprised by how many organizations completely disregard the security of their non-essential subdomains. The point of my post is that one subdomain takeover (or some XSS or some HTML injection) on a different subdomain of the same site is enough to bypass the protection that SameSite provides to the origin of interest. And I feel that is something worth understanding well.