|
|
|
|
|
by rgj
248 days ago
|
|
So… you were hosting user generated content on the same TLD as your website, without using the PSL, and you blamed G when things went south? By putting UGC on the same TLD you also put your own security at risk, so they basically did you a favor… |
|
Do you think I'm reading/writing sensitive data to/from subdomain-wide cookies?
Also, yes, the PSL is a great tool to mitigate (in practice eliminate) the problem of cross-domain cookies between mutually untrusting parties. But getting on that list is non-trivial and they (voluntary maintainers) even explicitly state that you can forget getting on there before your service is big enough.