As in, even if the "evil script" set it's domain to yourdomain.com, unless your pages on yourdomain.com ALSO do
document.domain = 'yourdomain.com';
The script on the subdomain can't access that content.
[EDIT] Whoever is downvoting this, can you demonstrate otherwise?
It's also crazy enough that I wouldn't want to trust that every browser in the world will always share that same behaviour.
http://www.whatwg.org/specs/web-apps/current-work/multipage/...
Listen, if you don't trust Stripe's JavaScript, just use their HTTP API instead from your server: https://stripe.com/docs/api
The best answer is "don't link to Javascript URLs that you don't control and audit on your website". Nobody likes that answer, but that doesn't make the second-best answer any more meaningful.
Exactly. There's no way I would be serving up third party javascript to a logged-in Tarsnap user, even inside an iframe, if it weren't for the fact that dealing with PCI auditing would irreparably damage my sanity.