I noticed logging in over there is taking us to authentication.win which uses a completely different SSL cert that doesn't include a SAN for the q site. Is this legit? Why separate the authentication site under a different domain? Thats gonna screw with CORS and any password managers.
Comments (2)
sorted by:
Can be SSO cookies, like when you login to Google and automatically signed in to YouTube as well
Good point, I wonder if they are moving to an SSO between the .WIN sites in anticipation of more of them. That would be nice, though I kinda like the anonymity of multiple accounts.