Re: [web-nfc] Define "sub-domain match"

They're not secure against each other. For a very few things 
([maxScopeString in 
ServiceWorkers](https://slightlyoff.github.io/ServiceWorker/spec/service_worker/index.html#update-algorithm))
 there's some attempt to let servers segregate paths, but that's only 
when the impact from cross-path attacks is big (persistently 
overwriting the other path's contents, for SWs). In NFC, the impact is
 small (reading another path's data), and could also be accomplished 
with any of the other storage APIs, so it's not worth worrying about.

-- 
GitHub Notif of comment by jyasskin
See https://github.com/w3c/web-nfc/issues/33#issuecomment-132271444

Received on Tuesday, 18 August 2015 16:44:36 UTC