... or serve cookies via first-party subdomain ...
Also, hasn't Safari already killed third party cookies?
... or serve cookies via first-party subdomain ...
Also, hasn't Safari already killed third party cookies?
This is the same reason Facebook is throwing such a fit over apple's new prompt. It makes it easy and likely for the average user to disable something without having to dig through settings.
I would strongly prefer that everyone restrict themselves to the capabilities of first-party cookies. But it's still true that Google is not holding themselves to the same restrictions that they're trying to enforce on other parties.
Google is lagging everyone else on this issue because it'll hit their advertising income.
The goal is that advertisers will eventually be far better off working with a system like Private Click Measurement (in Safari betas now and set to be in next releases) than insecure things like CNAME cloaking.
I think we should just make cookies only work when the domain matches exactly.
Advertisers can't trust content people to forward requests because it would be too easy to fake them.
However a server like nginx can be set up to proxy requests matching a specific url pattern to another server. This would be a bit more work than adding a DNS entry and referencing that though.
That's why the ad industry used third-party domains in the first place, BTW - it's a zero-setup solution. Subdomains are minimal-setup; subdirectories are a huge hassle.
Another reason is ad provider doesn't have to trust first party, if ads are served from their server.
I'm not sure which reason is more important.
Easier than changing a cname.