ParentFull threadcdjk·The *.example.com cookie is the problem. A malicious subdomain under example.com will get that cookie and can use it to impersonate users.View on HN