Hacker News new | ask | show | jobs
by lolinder 1149 days ago
Subdomains don't solve the problem, because Google very much intentionally puts the user session cookie on the root of .google.com, thereby sharing with all subdomains.
1 comments

The tld he is talking about is different though right?
Yes, but I read that as suggesting they could use their own tld OR use subdomains. If you open a new domain on that tld, you don't need subdomains to protect Google account cookies.