Hacker News new | ask | show | jobs
by tinus_hn 1122 days ago
It requires specific care because in the DOM security model, third level sites are all in the same security domain and can read each others cookies and control each others pages. The browsers have a special list with gov.uk, co.uk etc so it knows these are special.

That wasn’t a concern in 2002 but today it should be.