Cross Domain Authentication
authentication, cross-domain, web-applications
Solution
This link might be helpful.
http://code.google.com/apis/accounts/docs/AuthForWebApps.html
Keep in mind, Orkut is one of the Google services.
OpenID is another solution which actually used in SO.
Problem
I am Curious about how cross domain authentication work? for example. To sign into Orkut.com you need to to sign in via Google.com. So the authentication happens at Google.com and it sets the cookie. So my question now is how does Orkut.com able to read this cookie or authenticate the user with no other information ? What can possibly go wrong?