3 ms·
Correct, but only if you don't set any *.domain.com cookies, which as it turns out most do.
by moot 13y ago
Correct, but only if you don't set any *.domain.com cookies, which as it turns out most do.
- cheald 13y agoRight -- if you're serving your website off of the root, then you're going to have this problem. If you serve it off of www (which, as it turns out, is how domains were originally intended to be used!) then you don't. It's not an inherent flaw of the tech. It's a flaw in how we use it.
- chrisweekly 13y ago+1 Use of a subdomain prefix is absolutely the right thing to do, trendy root-domain-only sites notwithstanding. CNAMEs are inherently more flexible and more resilient in the face of various load challenges or DoS attacks: "Root domains are aesthetically pleasing, but the nature of DNS prevents them from being a robust solution for web apps. Root domains don't allow CNAMEs, which requires hardcoding IP addresses, which in turn prevents flexibility on updates to IPs which may need to change over time to handle new load or divert denial-of-service attacks. We strongly recommend against using root domains. Use a subdomain that can be CNAME aliased... " - Heroku [https://status.heroku.com/incident/156 https://status.heroku.com/incident/156]