3 ms·
It sounds like there's two cases: 1. Multi-tenant domains that probably should've always been in the PSL (ex. to provide cookie silos) but are only realizing n
by devrand 5y ago
It sounds like there's two cases:
1. Multi-tenant domains that probably should've always been in the PSL (ex. to provide cookie silos) but are only realizing now that they should be in it due to the arrival of PCM.
2. Sites that want to abuse an eTLD to do something like give all users on their social network a custom subdomain so that they're not polluting the same pool.
--
I think it was actually reasonable for Apple to consider the PSL as it's basically the most comprehensive eTLD list that we have and would allow them to match browser behavior.
The problem now is that case (1) is sending a bunch of requests at once as something will now actually break for these sites. Before now it was really just them being lax with security and not considering that cookies should be siloed. This isn't a unique situation btw, PSL also saw a large increase in inclusion requests when LetsEncrypt added rate limits based on eTLDs.
(2) is obviously bad and there's really no other justification for these sites being in the PSL.
Therefore I think it's reasonable for PSL to deny inclusion requests that are solely for PCM reasons.
This all being said, the PSL is a massive hack [1] and really needs to be replaced by something else. It probably is about time for these companies to invest in a replacement.
[1]: https://github.com/sleevi/psl-problems https://github.com/sleevi/psl-problems
- TechBro8615 5y agoNice link to the GitHub issue which explains the problems clearly. Can anyone explain why something like this wasn't implemented in the first place via DNS TXT records or tied to SSL somehow?
- deleted 5y ago[deleted]
- gumby 5y ago> Can anyone explain why something like this wasn't implemented in the first place via DNS TXT records or tied to SSL somehow? The idea is to be able to use it without a network access, such as looking for unstructured URLs in text (e.g. "get a discount code at example.com/hn-reader"), formatting a URL in a browser bar (e.g. put the non-eDLD+1 in bold, or at least show the site name properly and not abbreviate all UK sites to "co.uk") or managing the cookie name properly (again, so everyone in co.uk doesn't share the same cookie). Presumption is that the eTLDs are a tiny fraction (by orders of magnitude) from the domains registered under them so this db doesn't have to get too large. I am not sure how to manage these strings automatically without them being spammed. They aren't all under the control of the TLD administrators (com.au is but cheapo-shop-hosting.com.au is not).
- merb 5y ago1. Multi-tenant domains that probably should've always been in the PSL (ex. to provide cookie silos) but are only realizing now that they should be in it due to the arrival of PCM. uff, well I did not know about that list and we have a domain that uses multi-tenacy. I mean I'm unsure to include it but it probably adds a security benefit, so that it is impossible to add bad cookies from subdomains. edit: can't add it anyway I'm not sure but our provider only allows to renew for 1 year (I'm not sure if that is a tld limit, since I also do not see other additional domains with de inside the list)