Hacker News new | ask | show | jobs
by thisacctforreal 2806 days ago
However, the browser can choose not to send any cookies to google.com when making requests to google from mycuteblog.com.

It's known as blocking third-party cookies, a setting in most browsers. It does sometimes break when auth flows use separate domains to hold auth cookies, and other valid use-cases.