logoalt Hacker News

staticassertionyesterday at 3:37 AM2 repliesview on HN

This is what it really comes down to. Browsers are built around origins as the major security boundary. When you use a separate origin, safety comes for free.


Replies

integralidyesterday at 12:25 PM

And you open another can of worms which is phishing. If you run your marketing campaigns from yourcompany-deals-2025.com don't be surprised when people click yourcompany-login.com links

mock-possumyesterday at 8:45 AM

Trust doesn’t though - discord.com/docs looks legit, as does docs.discord.com - discord-docs.com immediately sets off red flags

show 1 reply