[thelist] P3P, thrid-party cookies, and iframes

Bill Moseley moseley at hank.org
Tue Mar 30 10:39:22 CDT 2010


On Tue, Mar 30, 2010 at 8:31 AM, James Hardy <evolt at weeb.biz> wrote:

> If you are www.bills-site.com and the partner is www.partners-site.netthen
> at the moment you have an iframe on www.partners-site.net pointing to
> www.bills-site.com.
>
> What if you make your site work for the DNS name of
> bills-site.partners-site.net and get www.partners-site.net to link to this
> rather than your normal domain, possibly even setting your cookies to
> domain: *.partners-site.net (assuming you trust your partner with your
> cookies)
>

Interesting idea, yes.  Not sure how IE would treat that.

It would mean the partner would need to update their DNS (since they own
partner-site.net). It would also mean that they would be sending their
user's cookies to our site (if they are using wildcard cookies).   That's
probably a show stopper.

Thanks,



-- 
Bill Moseley
moseley at hank.org


More information about the thelist mailing list