If I log into Facebook.com and then in another tab log into domain x.com, which uses some Facebook widget, how does the Facebook widget installed on x.com know I'm logged into Facebook and not require re-authentication to use it?
It seems that from x.com a script is able to read a cookie created under Facebook.com and that defies the consensus that cookies can't be read across domains. How is Facebook circumventing the consensus?