3 ms·
Nope, not super screwed at all. Safari even limits http cookies if the cname doesnt match. „On Safari 14 (requires Big Sur) and on all major iOS and iPadOS 14.
by volderette 6y ago
Nope, not super screwed at all. Safari even limits http cookies if the cname doesnt match.
„On Safari 14 (requires Big Sur) and on all major iOS and iPadOS 14.2+ browser apps, expiration of cookies set with Set-Cookie HTTP response headers is 7 days at most, if the response originates from a subdomain that has a CNAME alias to a cross-site origin“
https://www.cookiestatus.com/ https://www.cookiestatus.com/
- Krisando 6y agoYou should read the paper, it literally discusses how they were getting around that and discovered vulnerabilities because of it.