I like your idea but it's based on false assumptions. See RFC6265. Depending on the implementation on the backend side (specifically the "Set-Cookie" header) it's possible to handle a cookie generated on "www.example.com" on "example.com" or "sub.example.com" ... and all other possible combinations.