Hacker News new | ask | show | jobs
by pixelcort 4529 days ago
Couldn't a solution be something stored in DNS, that tells browsers not to let subdomains' JS do this?

So if I own example.com I could set something in my DNS that would prevent subdomain.example.com from setting cookies on example.com.