Hacker Newsnew | past | comments | ask | show | jobs | submitlogin



Any idea why people would want their tld removed from that? e.g. nsw.gov.au


My guess would be that they want to be able to share cookies across their sub-domains.

That file is saying that we should effectively treat:

education.vic.gov.au and courts.vic.gov.au as being independent entities that happen to both use the "vic.gov.au" domain, but otherwise have nothing in common (as far as same-origin policies go)

But

fairtrading.nsw.gov.au and housing.nsw.gov.au as being separate sub-domains operated by the same entity (in this case the NSW gov't)

It's certainly easier for those who operate site on that domain if they can implement single sign on, and cross-(sub)-domain resource loading without needing to jump through hoops like CORS.

However, since nsw.gov.au is also farmed out to every local council in the state as well as every government department, it's putting the security of your cookies into the hands a lot of organisations over which you have very limited control.


Really don't try to guess our governments actions. You'll end up broken.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: