{"id":85892,"date":"2025-02-13T14:21:51","date_gmt":"2025-02-13T14:21:51","guid":{"rendered":"https:\/\/peraltafinancing.com\/analytics\/whats-in-a-cname-simo-ahavas-blog\/"},"modified":"2025-02-13T14:21:51","modified_gmt":"2025-02-13T14:21:51","slug":"whats-in-a-cname-simo-ahavas-blog","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=85892","title":{"rendered":"What&#8217;s In A CNAME | Simo Ahava&#8217;s blog"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>With the rise of <strong>ad and content blockers<\/strong> (think <a href=\"https:\/\/www.ghostery.com\/\">Ghostery<\/a> and <a href=\"https:\/\/chrome.google.com\/webstore\/detail\/ublock-origin\/cjpalhdlnbpafiamejdnhcphjbkeiagm?hl=fi\">uBlock Origin<\/a>), as well as <strong>browser tracking protections<\/strong> (see <a href=\"https:\/\/www.cookiestatus.com\/\">www.cookiestatus.com<\/a>), marketing technology vendors have their work cut out for them. And when I refer to <strong>\u201ctheir work\u201d<\/strong>, I mean they have to proactively identify and exploit any loopholes they can find to keep on collecting their precious data.<\/p>\n<div style=\"aspect-ratio: 3056 \/ 1198;\" class=\"figure nocaption\">\n<p>    <a href=\"https:\/\/www.simoahava.com\/images\/2020\/06\/whats-in-a-cname.jpg\" title=\"What's in a CNAME\"><\/p>\n<p>    <img decoding=\"async\" class=\"fig-img\" height=\"1198\" width=\"3056\" loading=\"lazy\" src=\"https:\/\/www.simoahava.com\/images\/2020\/06\/whats-in-a-cname.jpg#ZgotmplZ\" alt=\"What's in a CNAME\"\/><\/p>\n<p>    <\/a><\/p>\n<\/div>\n<p>In this article, I\u2019ll take a look at one such exploit vector, the Canonical Name (<code>CNAME<\/code>) DNS record, in particular.<\/p>\n<p>The phenomenon of mapping subdomains to third-party services isn\u2019t confined to just advertising and marketing technology industries, though. In this article, I\u2019ll also introduce you to the extensive body of research collected by <a href=\"https:\/\/medium.com\/@thezedwards\">Zach Edwards<\/a>.<\/p>\n<p>This research shows how countless subdomains of high value and importance (think government, education) have been compromised and primed for stealing credentials written in first-party cookies.<\/p>\n<p>It\u2019s important to raise awareness of the risks involved with mapping subdomains to third party servers. Even though much of Zach\u2019s research concerns scenarios where subdomains have been taken over by attackers, the end result is the same: the third party has access to data beyond what the site owner or business might have considered.<\/p>\n<p>But before we dig into the risks themselves, it\u2019s important to understand how we got to the point of surrendering our own domain namespace to third-party vendors and services.<\/p>\n<p>                <span class=\"simmer\"><br \/>\n  <span class=\"close\">X<\/span><\/p>\n<p>\n    <span class=\"fa fa-md fa-bell\"\/><br \/>\n    <strong>The Simmer Newsletter<\/strong>\n  <\/p>\n<p>\n    Subscribe to the <a href=\"https:\/\/www.simoahava.com\/newsletter\/\">Simmer newsletter<\/a> to get the latest news and content from Simo Ahava into your email inbox!\n  <\/p>\n<p>  <\/span><\/p>\n<h2 id=\"the-perils-of-the-third-party\">The perils of the third-party<\/h2>\n<p>The fact is that <a href=\"https:\/\/www.cookiestatus.com\/introduction\/tracking-protection\/#first-party-and-third-party-context\">storage access in third-party context<\/a>, colloquially referred to as \u201cthird-party cookies\u201d, has become unstable and unreliable as the foundation for any data collection scheme, regardless of browser vendor:<\/p>\n<ul>\n<li><strong>Safari<\/strong> blocks all third-party cookies. Sites and services can request access to third-party storage from the browser user with the <a href=\"https:\/\/www.cookiestatus.com\/safari\/#storage-access-api\">Storage Access API<\/a>.<\/li>\n<li><strong>Brave<\/strong> blocks all third-party cookies.<\/li>\n<li><strong>Firefox<\/strong> blocks third-party cookies on domains that are in their <a href=\"https:\/\/www.cookiestatus.com\/firefox\/#classification-of-known-trackers\">blocklist<\/a>.<\/li>\n<li><strong>Edge<\/strong> blocks third-party cookies on domains that are in their <a href=\"https:\/\/www.cookiestatus.com\/edge\/#classification-of-known-trackers\">blocklist<\/a>, with some mitigations.<\/li>\n<li><strong>Chrome<\/strong> is planning to <a href=\"https:\/\/blog.chromium.org\/2020\/01\/building-more-private-web-path-towards.html\">phase out support for third-party cookies by 2022<\/a>. They are also <a href=\"https:\/\/www.chromium.org\/updates\/same-site\">rolling out<\/a> a change to how browser cookies are processed in the browser, by defaulting all cookies to <a href=\"https:\/\/web.dev\/samesite-cookies-explained\/\"><code>SameSite=Lax<\/code><\/a> unless the cookie is manually updated with the appropriate flag when set.<\/li>\n<\/ul>\n<blockquote>\n<p><code>SameSite=Lax<\/code> is an attribute that specifies the cookie can only be accessed in first-party context. While not a tracking protection per se, it\u2019s still a fairly significant move in helping auditors identify which cookies have been flagged for potential cross-site access.<\/p>\n<\/blockquote>\n<div style=\"aspect-ratio: 1326 \/ 906;\" class=\"figure nocaption\">\n<p>    <a href=\"https:\/\/www.simoahava.com\/images\/2020\/06\/firefox-report.jpg\" title=\"Firefox report\"><\/p>\n<p>    <img decoding=\"async\" class=\"fig-img\" height=\"906\" width=\"1326\" loading=\"lazy\" src=\"https:\/\/www.simoahava.com\/images\/2020\/06\/firefox-report.jpg#ZgotmplZ\" alt=\"Firefox report\"\/><\/p>\n<p>    <\/a><\/p>\n<\/div>\n<p>What\u2019s the solution for vendors that want to continue with their <a href=\"https:\/\/www.cookiestatus.com\/introduction\/tracking-protection\/#cross-site-tracking\">cross-site tracking<\/a> shenanigans? Well, if <strong>third-party context<\/strong> is too unreliable to build any business logic for, it\u2019s time to take a look at <strong>first-party context<\/strong>.<\/p>\n<h2 id=\"the-bliss-of-the-first-party\">The bliss of the first-party<\/h2>\n<p>When a vendor decides to move from third-party to first-party context, it typically means one or more of the following.<\/p>\n<p><strong>They start <a href=\"https:\/\/fbclid.com\/\">decorating incoming links<\/a><\/strong> to the site from the vendor\u2019s platform where the user has been identified e.g. via a login.<\/p>\n<p>This is how <strong>Facebook<\/strong> works, for example, as every single link you click in Facebook will be appended with the <code>fbclid<\/code> parameter. After that, any Facebook (or partner) script running on the site can take that parameter from the URL and send it back to the vendor. Thus Facebook will know that the person for whom the hash was created visited your site.<\/p>\n<div style=\"aspect-ratio: 1770 \/ 80;\" class=\"figure nocaption\">\n<p>    <a href=\"https:\/\/www.simoahava.com\/images\/2020\/06\/facebook-link.jpg\" title=\"Facebook link\"><\/p>\n<p>    <img decoding=\"async\" class=\"fig-img\" height=\"80\" width=\"1770\" loading=\"lazy\" src=\"https:\/\/www.simoahava.com\/images\/2020\/06\/facebook-link.jpg#ZgotmplZ\" alt=\"Facebook link\"\/><\/p>\n<p>    <\/a><\/p>\n<\/div>\n<p><strong>They start utilizing <a href=\"https:\/\/www.cookiestatus.com\/introduction\/summary-of-exploits\/#fingerprinting\">browser fingerprints<\/a><\/strong> to identify the user from one HTTP request to the next. Fingerprinting is dangerous because it is completely stateless &#8211; there\u2019s no need to persist any information in the browser.<\/p>\n<p>The user is disarmed of options to actively prevent this. This has led fingerprinting to become one of the rare areas where there is practically universal consensus among browser vendors that it is a Bad Thing and must be prevented.<\/p>\n<div style=\"aspect-ratio: 1594 \/ 366;\" class=\"figure nocaption\">\n<p>    <a href=\"https:\/\/www.simoahava.com\/images\/2020\/06\/browser-fingerprint.jpg\" title=\"Browser fingerprint\"><\/p>\n<p>    <img decoding=\"async\" class=\"fig-img\" height=\"366\" width=\"1594\" loading=\"lazy\" src=\"https:\/\/www.simoahava.com\/images\/2020\/06\/browser-fingerprint.jpg#ZgotmplZ\" alt=\"Browser fingerprint\"\/><\/p>\n<p>    <\/a><\/p>\n<\/div>\n<p><strong>They request the site owner to run their scripts locally or to use local routers<\/strong>. This way they can circumvent ad blockers targeting the vendor domains.<\/p>\n<div style=\"aspect-ratio: 1554 \/ 440;\" class=\"figure nocaption\">\n<p>    <a href=\"https:\/\/www.simoahava.com\/images\/2020\/06\/router-script.jpg\" title=\"Router script\"><\/p>\n<p>    <img decoding=\"async\" class=\"fig-img\" height=\"440\" width=\"1554\" loading=\"lazy\" src=\"https:\/\/www.simoahava.com\/images\/2020\/06\/router-script.jpg#ZgotmplZ\" alt=\"Router script\"\/><\/p>\n<p>    <\/a><\/p>\n<\/div>\n<p><strong>They request the site owners to reserve a <em>subdomain<\/em> in their domain namespace<\/strong>, which is configured to point to the vendor\u2019s servers.<\/p>\n<p>All of these approaches have been designed to avoid the heuristics in browsers and browser extensions that target third-party trackers. The reliability of these workarounds depends on how easy the site owner is to hoodwink into actively participating in setting them up.<\/p>\n<p>Link decoration, for example, doesn\u2019t require the site owner to do anything but add the vendor JavaScript to the site. However, it\u2019s not the most reliable exploit since blockers are most likely already preventing access to the most popular CDNs owned by the tracking vendors.<\/p>\n<p>The last option in the list ends up being the most robust one because it requires the site owner to actively and knowingly collude with the third party to improve the quality of the data collection. This is the exploit we\u2019ll be discussing in the rest of the article, as it has the biggest ramifications for end-user privacy and data security.<\/p>\n<h2 id=\"subdomain-mappings\">Subdomain mappings<\/h2>\n<p><a href=\"https:\/\/medium.com\/nextdns\/cname-cloaking-the-dangerous-disguise-of-third-party-trackers-195205dc522a\">This article<\/a> shows you how some vendors in the advertising and marketing technology space are approaching the restrictions to third-party context. They are directly contacting their customers and asking for their help in keeping the service alive.<\/p>\n<p>The gist is typically that the site needs to reserve a subdomain (e.g. <code>tracking.domain.com<\/code>), which is then set to point to a vendor domain name (e.g. <code>identity.vendor.com<\/code>) using a Canonical Name (<code>CNAME<\/code>) DNS record.<\/p>\n<blockquote>\n<p>Alternatively, the site can set up <code>A\/AAAA<\/code> records that point directly to the vendor server IP address, but this is rare. With a <code>CNAME<\/code>, the vendor has the liberty of shuffling around the IP ranges of their servers without breaking the link to the mapped domain names.<\/p>\n<\/blockquote>\n<p>Once the DNS record resolves, all requests to <code>tracking.domain.com<\/code> are received by the vendor server behind <code>identity.vendor.com<\/code>.<\/p>\n<p>So, why go through all this trouble? Well, there are a couple of reasons:<\/p>\n<ol>\n<li>\n<p>The site doesn\u2019t have to relax its <a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/CSP\">Content Security Policies<\/a> to allow third-party domains to load and run their scripts on the site. This reduces the friction in deploying the third-party service on the site.<\/p>\n<\/li>\n<li>\n<p>It\u2019s <em>so easy<\/em> to setup a <code>CNAME<\/code> record. There\u2019s no need to configure complicated reverse proxies or to create multiple A\/AAAA records. It\u2019s (typically) just a single DNS change that anyone with adequate access can do.<\/p>\n<\/li>\n<li>\n<p>While <code>identity.vendor.com<\/code> is most likely in most of the blocklists for browsers and browser extensions, <code>tracking.domain.com<\/code> most likely isn\u2019t. This is a pretty solid way to circumvent ad blockers.<\/p>\n<\/li>\n<li>\n<p>Since the service is now running in first-party context with the rest of the site, the service can leverage <strong>first-party cookies<\/strong>, even those set with the <a href=\"https:\/\/owasp.org\/www-community\/HttpOnly\"><code>HttpOnly<\/code> flag<\/a>.<\/p>\n<\/li>\n<\/ol>\n<h2 id=\"first-party-cookies-and-data-leaks\">First-party cookies and data leaks<\/h2>\n<p>When the browser sends an HTTP request to a target address, that request will include <strong>all the cookies<\/strong> written on the target domain and any domains \u201chigher\u201d in the hierarchy, all the way to the top-most privately controlled domain name.<\/p>\n<p>For example, when <code>owned.domain<\/code> sends an HTTP request to <code>sub.sub.owned.domain<\/code>, that request will include all the cookies written on <code>sub.sub.owned.domain<\/code>, <code>sub.owned.domain<\/code>, and <code>owned.domain<\/code>.<\/p>\n<p>If the source and target of the request are <strong>same-site<\/strong> (i.e. they share the top-most privately controlled domain name), the request happens in <strong>first-party context<\/strong>, which is largely <strong>unrestricted<\/strong> by browsers and plugins today.<\/p>\n<p>When you surrender, either willingly by mapping the domain yourself or inadvertently via a takeover, a subdomain to a third party, you open your business for potentially horrendous data and credential leaks.<\/p>\n<div style=\"aspect-ratio: 2772 \/ 280;\" class=\"figure \">\n<p>    <a href=\"https:\/\/www.simoahava.com\/images\/2020\/06\/sacsid.jpg\" title=\"Authentication cookie with which the browser is logged in with my Google ID\"><\/p>\n<p>    <img decoding=\"async\" class=\"fig-img\" height=\"280\" width=\"2772\" loading=\"lazy\" src=\"https:\/\/www.simoahava.com\/images\/2020\/06\/sacsid.jpg#ZgotmplZ\" alt=\"Authentication cookie with which the browser is logged in with my Google ID\"\/><\/p>\n<p>    <\/a><\/p>\n<p>    <span class=\"caption\">Authentication cookie with which the browser is logged in with my Google ID<\/span><\/p>\n<\/div>\n<p>Since the web server at the end of an HTTP request is privy to a large subset of first-party cookies set on any given site, things like <strong>state<\/strong> and <strong>authentication tokens<\/strong> are automatically logged by the web server owned by the vendor. This is because many sites still set them on <code>owned.domain<\/code>, making them available to <em>all<\/em> subdomains of the domain name.<\/p>\n<p>Gaining control of a subdomain also opens up possibilities for a <a href=\"https:\/\/github.com\/bugcrowd\/vulnerability-rating-taxonomy\/issues\/183\">number of different, very dangerous exploits<\/a>, ranging from cross-site scripting attacks to intentional brand defamation.<\/p>\n<p>Sometimes these cookies contain personally identifiable information such as <strong>email addresses<\/strong> and <strong>user names<\/strong>, allowing vendors to enhance the user\u2019s cross-site tracking profile without them being able to do anything about it.<\/p>\n<div style=\"aspect-ratio: 4052 \/ 132;\" class=\"figure \">\n<p>    <a href=\"https:\/\/www.simoahava.com\/images\/2020\/06\/cookies.jpg\" title=\"PII and authentication information in first-party cookies\"><\/p>\n<p>    <img decoding=\"async\" class=\"fig-img\" height=\"132\" width=\"4052\" loading=\"lazy\" src=\"https:\/\/www.simoahava.com\/images\/2020\/06\/cookies.jpg#ZgotmplZ\" alt=\"PII and authentication information in first-party cookies\"\/><\/p>\n<p>    <\/a><\/p>\n<p>    <span class=\"caption\">PII and authentication information in first-party cookies<\/span><\/p>\n<\/div>\n<p>Typically, there are privacy policies and lots of red tape in place, where the vendors offer complicated promises that they will not misuse the information logged by their web servers. But these practices vary wildly.<\/p>\n<p>Furthermore, because everything happens behind the curtains of server-to-server communications, it\u2019s practically impossible for independent auditors to know what\u2019s going on.<\/p>\n<p>And this is the main warning of this article:<\/p>\n<p><strong>When you map your subdomain to a third-party service, you are sending much more data to the third party than you might have bargained for.<\/strong><\/p>\n<p>Compare this with sending the request directly to the vendor-specific domain. By default, these requests would only include (third-party) cookies written on the vendor domain. Any other information would need to be encoded with JavaScript, which can be parsed and audited by anyone visiting the site.<\/p>\n<p>But with a subdomain mapping, all first-party cookies available on that domain will be sent, including those flagged as <code>HttpOnly<\/code>. These <code>HttpOnly<\/code> cookies can\u2019t be accessed with client-side script at all, which might lull site owners to a false sense of security.<\/p>\n<p><a href=\"https:\/\/twitter.com\/thezedwards\">Zach Edwards<\/a> is one of those people on Twitter you simply <strong>must<\/strong> follow. He\u2019s been conducting <strong>exhaustive<\/strong> research into many areas intersecting internet security and digital marketing and analytics. One of his pet peeves at the moment is something he\u2019s dubbed the <strong>PickaFlick.com<\/strong> attacks.<\/p>\n<p>In these scenarios, an attacker takes control of subdomains (usually DNS records left <a href=\"https:\/\/shhaos.github.io\/papers\/ccs16-dares.pdf\">dangling<\/a>), and then starts stuffing <strong>search engine results<\/strong> with bogus links, hoping the visitor will click one of them.<\/p>\n<div style=\"aspect-ratio: 1930 \/ 1066;\" class=\"figure \">\n<p>    <a href=\"https:\/\/www.simoahava.com\/images\/2020\/06\/epic-games-hack.jpg\" title=\"From https:\/\/bit.ly\/epic-games-hack\"><\/p>\n<p>    <img decoding=\"async\" class=\"fig-img\" height=\"1066\" width=\"1930\" loading=\"lazy\" src=\"https:\/\/www.simoahava.com\/images\/2020\/06\/epic-games-hack.jpg#ZgotmplZ\" alt=\"From https:\/\/bit.ly\/epic-games-hack\"\/><\/p>\n<p>    <\/a><\/p>\n<p>    <span class=\"caption\">From https:\/\/bit.ly\/epic-games-hack<\/span><\/p>\n<\/div>\n<p>If the visitor does click such a link, that HTTP request will include all the first-party cookies available on that particular subdomain. See the previous chapter for examples of what type of information can be encoded in these cookies.<\/p>\n<p>The screenshot above is from <code>thehousepartyapp.com<\/code>, which Zach <a href=\"https:\/\/medium.com\/@thezedwards\/epic-games-ignored-epic-subdomain-takeover-on-their-authentication-domain-promoted-1-million-b4d809039b0e\">quite elaborately<\/a> reported to Epic Games as having been compromised by subdomain takeovers. This was initially in response to Epic Games\u2019 ludicrous <strong>$1,000,000<\/strong> bounty for proof of a smear campaign related to a possible hacking incident.<\/p>\n<p>I recommend you read Zach\u2019s article, as it shows how widespread and long-standing the PickaFlick.com attacks (and similar) are. It\u2019s also shocking how oblivious so many site and service owners are to trouble brewing in their own backyards.<\/p>\n<p>Go through your site\u2019s search results with a search query like <code>site:mydomain.com \"free ebook\"<\/code> and see if bogus results turn up. If they do, it\u2019s time for a DNS record audit. Make sure to eliminate any that you don\u2019t recognize or control the endpoint for anymore.<\/p>\n<div style=\"aspect-ratio: 1496 \/ 1054;\" class=\"figure nocaption\">\n<p>    <a href=\"https:\/\/www.simoahava.com\/images\/2020\/06\/wichita-gov-attack.jpg\" title=\"Wichita.gov subdomains taken over\"><\/p>\n<p>    <img decoding=\"async\" class=\"fig-img\" height=\"1054\" width=\"1496\" loading=\"lazy\" src=\"https:\/\/www.simoahava.com\/images\/2020\/06\/wichita-gov-attack.jpg#ZgotmplZ\" alt=\"Wichita.gov subdomains taken over\"\/><\/p>\n<p>    <\/a><\/p>\n<\/div>\n<p>This diversion to Zach\u2019s research isn\u2019t necessarily an indictment of <code>CNAME<\/code> exploits themselves, but they do exemplify how perilous and fragile this aspect of the HTTP protocol is.<\/p>\n<h2 id=\"prevention-measures\">Prevention measures<\/h2>\n<p>To avoid subdomain mappings from harming your business, there are some mitigations you can act upon.<\/p>\n<ol>\n<li>\n<p>Follow the instructions in the previous chapter to see if you have <strong>compromised subdomains<\/strong>. If so, make sure you remove these subdomains from your DNS registry. It would be a good idea to report this to the service you use for your DNS, so that they can take appropriate action with their other customers as well.<\/p>\n<\/li>\n<li>\n<p>Make sure all state and authentication tokens, and really <strong>anything that can be used to impersonate a user<\/strong>, are written on a subdomain that you have <strong>control over<\/strong>. Make sure they are <strong>not<\/strong> written directly on the top-most privately controlled domain name. Make sure they are <code>httpOnly<\/code> and <code>secure<\/code>. Make sure they are <code>SameSite=Strict<\/code>, unless you need them in a third-party context.<\/p>\n<\/li>\n<li>\n<p>Make sure your Content Security Policy doesn\u2019t just <strong>wildcard<\/strong> all your subdomains (<code>*.owned.domain<\/code>). Allow only those domains that you have <strong>vetted and have governance over<\/strong>.<\/p>\n<\/li>\n<li>\n<p>Periodically <a href=\"https:\/\/www.simoahava.com\/google-cloud\/cookie-audit-with-google-bigquery\/\"><strong>audit<\/strong><\/a> cookies accessed in both first- and third-party contexts across your sites.<\/p>\n<\/li>\n<\/ol>\n<p>It really boils down to the <strong>trust<\/strong> you place in the vendors to whom you are mapping subdomains, the <strong>governance<\/strong> you have over the data flows, assets, and storage access across your sites, and <strong>processes<\/strong> you have in place for periodically auditing these perilous gateways to potentially brand-decimating leaks.<\/p>\n<h2 id=\"closing-thoughts\">Closing thoughts<\/h2>\n<p>Why go through the trouble of ranting about <code>CNAME<\/code> redirects, when they\u2019ve been so eloquently covered by <a href=\"https:\/\/medium.com\/nextdns\/cname-cloaking-the-dangerous-disguise-of-third-party-trackers-195205dc522a\">this incredible article by Romain Cointepas<\/a>? Why discuss subdomain takeover attacks when Zach Edwards has already done <a href=\"https:\/\/medium.com\/@thezedwards\/epic-games-ignored-epic-subdomain-takeover-on-their-authentication-domain-promoted-1-million-b4d809039b0e\">all the legwork<\/a>?<\/p>\n<p>Well, this is an insidious attack vector because it can be orchestrated with the best of intentions. It needs more exposure. More and more vendors are requesting subdomain mappings, and it\u2019s important that site owners know what they\u2019re subscribing to.<\/p>\n<p>Moving vendor services to first-party context isn\u2019t necessarily a <em>universally bad thing<\/em>. As a site owner, you are actively participating in vetting the services integrated on your site, and by mapping DNS records to third parties, you are proactively taking responsibility for the data streams and flows to and from your site. At least, in theory.<\/p>\n<p>The problem isn\u2019t necessarily related to the contracts and terms of services you sign with the vendors, which promise to restrict the types of data accessed in these requests. No, the problem is with this aspect of the HTTP protocol in general.<\/p>\n<p>Allowing cookies to pass unchecked through <code>CNAME<\/code> redirects to possible tracking domains is where the problem lies. Browsers don\u2019t (yet) have the capability to detect hazardous <code>CNAME<\/code> chains, but it is a feature set I wouldn\u2019t be surprised to see in their roadmaps.<\/p>\n<p>In the European Union, the <strong>ePrivacy Directive<\/strong> guides businesses to be aware and audit <em>all<\/em> keys and values stored in <em>all<\/em> browser storage at <em>all<\/em> times. Having an up-to-date audit of first-party cookies, for example, reduces the risk of leaking this information to third parties.<\/p>\n<p>If you need to manage state, authentication, and\/or personally identifiable information in cookies, make sure they\u2019re not set in the root of the domain namespace you control. That way you mitigate the risk of this information leaking to server endpoints you have no control over.<\/p>\n<p>Just <strong>be vigilant<\/strong> and <strong>map those data flows<\/strong>. That\u2019s a good way to reduce a <em>huge<\/em> amount of risk embedded in how your site, app, or service persists and processes user data.<\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the rise of ad and content blockers (think Ghostery and uBlock Origin), as well as browser tracking protections (see www.cookiestatus.com), marketing technology vendors have their work cut out for them. And when I refer to \u201ctheir work\u201d, I mean they have to proactively identify and exploit any loopholes they can find to keep on [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":85893,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12033],"tags":[27402,3767,42265,27401,5614],"dealstore":[],"offerexpiration":[],"class_list":["post-85892","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analytics","tag-ahavas","tag-blog","tag-cname","tag-simo","tag-whats"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>What&#039;s In A CNAME | Simo Ahava&#039;s blog - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=85892\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What&#039;s In A CNAME | Simo Ahava&#039;s blog - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"With the rise of ad and content blockers (think Ghostery and uBlock Origin), as well as browser tracking protections (see www.cookiestatus.com), marketing technology vendors have their work cut out for them. And when I refer to \u201ctheir work\u201d, I mean they have to proactively identify and exploit any loopholes they can find to keep on [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=85892\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-13T14:21:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/whats-in-a-cname-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1004\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=85892#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=85892\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"What&#8217;s In A CNAME | Simo Ahava&#8217;s blog\",\"datePublished\":\"2025-02-13T14:21:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=85892\"},\"wordCount\":2440,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=85892#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/whats-in-a-cname-scaled.jpg\",\"keywords\":[\"Ahavas\",\"Blog\",\"CNAME\",\"Simo\",\"Whats\"],\"articleSection\":[\"Analytics\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=85892#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=85892\",\"url\":\"https:\/\/fivemor.com\/?p=85892\",\"name\":\"What's In A CNAME | Simo Ahava's blog - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=85892#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=85892#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/whats-in-a-cname-scaled.jpg\",\"datePublished\":\"2025-02-13T14:21:51+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=85892#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=85892\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=85892#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/whats-in-a-cname-scaled.jpg\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/whats-in-a-cname-scaled.jpg\",\"width\":2560,\"height\":1004},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=85892#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What&#8217;s In A CNAME | Simo Ahava&#8217;s blog\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What's In A CNAME | Simo Ahava's blog - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=85892","og_locale":"en_US","og_type":"article","og_title":"What's In A CNAME | Simo Ahava's blog - Som2ny Network","og_description":"With the rise of ad and content blockers (think Ghostery and uBlock Origin), as well as browser tracking protections (see www.cookiestatus.com), marketing technology vendors have their work cut out for them. And when I refer to \u201ctheir work\u201d, I mean they have to proactively identify and exploit any loopholes they can find to keep on [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=85892","og_site_name":"Som2ny Network","article_published_time":"2025-02-13T14:21:51+00:00","og_image":[{"width":2560,"height":1004,"url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/whats-in-a-cname-scaled.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=85892#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=85892"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"What&#8217;s In A CNAME | Simo Ahava&#8217;s blog","datePublished":"2025-02-13T14:21:51+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=85892"},"wordCount":2440,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=85892#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/whats-in-a-cname-scaled.jpg","keywords":["Ahavas","Blog","CNAME","Simo","Whats"],"articleSection":["Analytics"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=85892#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=85892","url":"https:\/\/fivemor.com\/?p=85892","name":"What's In A CNAME | Simo Ahava's blog - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=85892#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=85892#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/whats-in-a-cname-scaled.jpg","datePublished":"2025-02-13T14:21:51+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=85892#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=85892"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=85892#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/whats-in-a-cname-scaled.jpg","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/whats-in-a-cname-scaled.jpg","width":2560,"height":1004},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=85892#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"What&#8217;s In A CNAME | Simo Ahava&#8217;s blog"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/85892","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=85892"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/85892\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/85893"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=85892"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=85892"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=85892"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=85892"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=85892"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}