Served from a different origin than the comments it embeds, and over https, which is the only way the widget's cookies can carry Secure, SameSite=None and Partitioned.