Contrary to conventional wisdom, due to the way browsers handle cookies, an attack on a company's subdomain can net an attacker free reign over the principal production domain.