Actually I've heard of it being possible to "hack" the cookie protection of only allowing the domain that set the cookie to access it.