Earlier quoted context omitted.
> A single entity manages multiple domains and shares cookie auth across them. The issue is we (the users) really want a more nuanced concept of "third party": something like "different domain that's controlled by the first party." Unfortunately, any declaration that relies on the first party will immediately be abused to hell ("All these tracking domains are controlled by me, so plz allow them!"), and we'd be right…
I think you're falling into the same trap. Some things are not solved in the appropriate manner through a technological solution. They are misuses (and abuses) of a perfectly acceptable system. Don't undo the system, address the misuse. Take your example: >Unfortunately, any declaration that relies on the first party will immediately be abused to hell ("All these tracking domains are controlled by me, so plz allow th…
If I put a custom domain on an S3/cloudfront that's part of my system, so it appears as `storage.mysystem.com`, is there something nefarious going on?
Who decides what is allowable declaration of a domain to be mine? And who enforces this with fines? Is there currently any way to fine someone on the internet for violating a rule? What would you imagine this looking like, an organization that has the ability to fine people globally, and enforce the payment of those fines (by... taking domains back I guess?), and who would control it? (and who would pay for it, how?) It's a lot of global legal infrastructure we don't really have now, I think. It would be a pretty huge step.