5 ms·Why is cookie based auth a problem?by mcovalt 6y agoWhy is cookie based auth a problem?cdjk 6y agoThe *.example.com cookie is the problem. A malicious subdomain under example.com will get that cookie and can use it to impersonate users.