3 ms·
As someone who used to work on Facebook open source, that makes sense! After all, an insecure subdomain could lead to all sorts of problems on facebook.com. Phi
by lacker 4y ago
As someone who used to work on Facebook open source, that makes sense! After all, an insecure subdomain could lead to all sorts of problems on facebook.com. Phishing, stealing cookies, there's a lot of ways it could go wrong.
Whereas, if one engineer spins up some random static open source documentation website on AWS, it really can't go wrong in a way that causes trouble for the rest of the company.
- iambateman 4y agoMy initial comment was sardonic but this is a good point. My IT experiences elsewhere have left me a little jaded. :)
- nonoob 4y agoI wasn't aware of that, but it's intriguing! Eager to learn more about subdomains and vulnerabilities - any resources you'd recommend?
- MF-DOOM 4y agoRead about the Same origin Policy and Content Security Policy. MDN is a canonical resource for this.
- benatkin 4y agoAnd you would learn that if you don't have wildcard cookies, which I generally wouldn't recommend, subdomains are isolated from each other. But with meta if the brand weren't tarnished, a new domain for subdomains like Google's withgoogle.com and web.dev would be a good place to add sites like this rather than subdomain.facebook.com