13
posted ago by antimatter ago by antimatter +13 / -0

I noticed logging in over there is taking us to authentication.win which uses a completely different SSL cert that doesn't include a SAN for the q site. Is this legit? Why separate the authentication site under a different domain? Thats gonna screw with CORS and any password managers.

Comments (2)
sorted by:
2
nomoremasks 2 points ago +2 / -0

Can be SSO cookies, like when you login to Google and automatically signed in to YouTube as well

1
antimatter [S] 1 point ago +1 / -0

Good point, I wonder if they are moving to an SSO between the .WIN sites in anticipation of more of them. That would be nice, though I kinda like the anonymity of multiple accounts.