So does that mean that in practice, .name domains were always treated by browsers like regular 2LDs, meaning the cookie and origin protection was always broken for those domains?
Doesn't sound like good news for the guy in the OP...
IIRC orgs like letsencrypt also use the PSL for rate limits, so there are probably more issues that are not browser-based.