[thelist] P3P, thrid-party cookies, and iframes

Bill Moseley moseley at hank.org
Tue Mar 30 10:39:22 CDT 2010

On Tue, Mar 30, 2010 at 8:31 AM, James Hardy <evolt at weeb.biz> wrote:

> If you are www.bills-site.com and the partner is www.partners-site.netthen
> at the moment you have an iframe on www.partners-site.net pointing to
> www.bills-site.com.
> What if you make your site work for the DNS name of
> bills-site.partners-site.net and get www.partners-site.net to link to this
> rather than your normal domain, possibly even setting your cookies to
> domain: *.partners-site.net (assuming you trust your partner with your
> cookies)

Interesting idea, yes.  Not sure how IE would treat that.

It would mean the partner would need to update their DNS (since they own
partner-site.net). It would also mean that they would be sending their
user's cookies to our site (if they are using wildcard cookies).   That's
probably a show stopper.


Bill Moseley
moseley at hank.org

More information about the thelist mailing list