Hacker News new | ask | show | jobs
by volderette 1929 days ago
Nope, not super screwed at all. Safari even limits http cookies if the cname doesnt match.

„On Safari 14 (requires Big Sur) and on all major iOS and iPadOS 14.2+ browser apps, expiration of cookies set with Set-Cookie HTTP response headers is 7 days at most, if the response originates from a subdomain that has a CNAME alias to a cross-site origin“

https://www.cookiestatus.com/

1 comments

You should read the paper, it literally discusses how they were getting around that and discovered vulnerabilities because of it.