If subdomains of your domain should be treated as independent sites, the public suffix list is (sadly) how you communicate that to browsers.
(Disclosure: I work for Google, speaking only for myself)
If subdomains of your domain should be treated as independent sites, the public suffix list is (sadly) how you communicate that to browsers.
(Disclosure: I work for Google, speaking only for myself)
Is there any downside to being on this list?
If example.com were on list then a cookie set on a.example.com couldn't be read on b.example.com. In this case that would probably be a good thing, since the subdomains represent independent sites, but if a site were erroneously added that could be a problem (mail.yahoo.com and groups.yahoo.com should share login cookies, for example).
The list was originally created to handle cookies, but more recently it's been used for other notions of "site", like cache sharding.
Sadly, indeed. Had they never heard of DNS?
* a.example.com and b.example.com are the same site
* a.co.uk and b.co.uk are not the same site
* a.cloudfront.net and b.cloudfront.net are not the same site
* a.higashikawa.hokkaido.jp and b.higashikawa.hokkaido.jp are not the same site
* a.example.higashikawa.hokkaido.jp and b.example.higashikawa.hokkaido.jp are the same site
There is a proposal to do something similar using response headers and .well-known urls: https://github.com/privacycg/first-party-sets
_i_am_tld.cloudfront.net IN TXT "yes"
_i_am_tld.higashikawa.hokkaido.jp IN TXT "yes"Have a look: https://publicsuffix.org/list/public_suffix_list.dat