Unless disabling cookies means treating all cookies as session cookies (meaning you can still be followed within a session), this has the fun side effect of breaking pretty much every CAPTCHA firewall like Anubis, Cloudflare Turnstile, and any other that relies on cookies.
Unfortunately this means you have to view a lot of the web through archive.today or web.archive.org - I would know because I have uMatrix configured this way.
Honestly I've found that it's often the local businesses that shoot themselves in the foot more by this.
I disable cookies for Amazon because I need to login; if a local business wants me to buy from them directly they need to:
1. Not give me a CAPTCHA or cloudflare shit
2. Give me free shipping and a lower price than Amazon minus 5% cashback that I would get on Amazon
3. No registration needed to check out
and I'll buy from the local website. It's really not a high bar, they need to learn to not shoot themselves in the foot.
As for the news websites -- bleh. If they want me to read it, make it easy to read. As in, I click into it, show me the content. If I get a popup, banner, anything that covers up the content, I bounce. I'll get the news from social media anyway. If they'd rather I get it from their news website, they need to learn to not make me bounce.
I'm not opposed to advertising if they want to get revenue from that, but it should not track me, not cover up content, and not load megabytes of JavaScript to do it.
Session cookies for non-whitelisted sites is a nice balance between usability and privacy.
Session cookies for all sites would be fine if passkeys weren't like "We support passkeys. Do you want to use a passkey? Press ok again to use your passkey. Do you consent to using your passkey? Now please authenticate yourself to use the passkey... √ Thank you for using passkeys. Press ok to continue."
Malicious compliance. You do not need a cookie to "store" the fact you have rejected them. They can simply assume you have rejected them from the lack of cookies. They can store a cookie once you (have gone out of your way to) accept them.
You would presumably be logged in to your favorite store site, and they would be using your identifying session to make recommendations, not anonymous tracking cookies.
> he EU Commission finally proposed a solution to the cookie banner problem: automated signals that would communicate your privacy preferences between your device and websites or apps.
It wasn't on EU Commission to "finally propose a solution". The soluton has always been there.
Somehow, Google, aka world's largest tracking and advertising company incidentally making the worlds' dominant browser and completely dominating all web standards, couldn't be bothered, and instead was pushing crap like FLoC
Google knows if you can set this once it's game over for their adverting business. At least with the cookie banners, there's a possibly you won't refuse every banner.
Especially those banners that only have "Accept" or "More options" with all those checkboxes to clear.
The insanity around cookie banners is a good target.
> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.
Fortunately, if you have uBlock Origin, you can enable Easylist cookie notices under annoyances and avoid most of them. Combine with blocking third-party cookies, and the problem pretty much disappears.
The fact that the EU tried to regulate this stuff is a shame, because regulation is not a good remedy. End-users have agency here. The solution is to enable end-users to have control in their browser (which they always did, so it's an issue of education, like so many things).
Shame that Google is trying to kill uBO though. Extremely pleased that Brave continues to support it.
Didn't know that about Brave, but it's moot for me since Firefox also supports it and these days I find that Firefox is the better experience, not Chrome or even Chromium.
uBlock Origin -> allows blocking dialogs (legally implies refusal of everything not necessary, because you don't agree to something requiring agreement)
Consent-O-Matic -> automated configuration to your preferences using the dialog provided.
I still don't care about cookies -> least privacy friendliest option, because it may opt into undesired tracking (its goal is just to remove the annoyance of the dialogs)
Sloppy, non-privacy-preserving "analytics" set up by some communications intern ≠ malice. They can mean well and still do a poor job. True privacy on the internet is notoriously hard.
Sorry, no. Code doesn't magically go from the intern's workstation to live. If the chain of incompetence is that long, then the most generous read is that they don't care
One of our sites that don't use any kind of tracking or cookies other then a site preference cookie, got so many complaints that we had to put up a cookie banner that simply says "we do not use any tracking cookies"...
Literally the point is that sites are showing the banner by default practice even when they are not tracking. You understand this!
Your kind comes into every one of these threads and says some version of "well if they weren't tracking then they'd have nothing to worry about and no need to show a banner", but that is so obviously not true to anyone who uses the web. You absolutely do not need to defend a law that is not working.
Just step back and ask yourself what each side of that debate is trying to achieve and why. What is motivating them? Why are they motivated in that way?
Don't just recite what you "know", think, look, research, figure it out. It might sound good to have a one-liner like this in your back pocket, but do you really believe it after looking at the publicly available information that it is their real intention to conduct a "crusade to destroy the internet"?
Advertising funds large parts of the open internet. Killing ad means killing independent content creators for example.
Over-regulation and censorship like "chat-control", that only benefits big players like Amazon, Meta etc. is what kills the internet.
Wow, finally. This would be a major quality of life update for browsing the web. As others have stated, not all sites merit the same preferences. Hopefully they can adapt a middleground of default settings with the ability to customize site by site.
under what circumstances as user would I want to explicitly agree to have my browsing history sent to tens or hundreds of third party tracking aggregators?
Devil's advocate argument: if they were giving you something in return, and that could be cash, but it might also be "you can have this content for free".
In the UK a few news sites have changed cookie banners to "you can accept and see this stuff for free, or you can sign up for a subscription, which would you prefer?". It's the only time I hit accept (and then clear browser history).
If blanket preferences from browser signals became the norm, a segment might open up where you would configure preferences and a data broker would make sure you get something in return for your data. At minimum it might force paywalled publishers to consider that as a "lite" subscription option.
You seem to have missed the point. No ads dont require those things, but companies could start offering content in return for those things instead of ads.
As I understand it, it is the position of several DPAs that denial of access entirely (i.e. "consent or pay") could contravene the "freely given" requirement of GDPR in most cases, though this has thus far not been tested in court.
> but companies could start offering content in return for those things instead of ads.
Again, that is not a requirement. If your argument is that they give us content for free because of ads, ads don't require pervasive and invasive tracking. Or hiding stuff behind paywalls (since ads pay for it).
No my arguement is not that they give us free content for ads. It is that in the future it is entirely possible that they offer us free content in return for us allowing pervasive and invasive tracking.
Im pretty sure if a company said something like "Here have free netflix for life, as long as you install this browser plugin that provides us with information about your shopping habits" millions of people would bite their hand off.
Effective ads absolutely require knowing more about the user than the context on the page it's a 1-2 orders of magnitude revenue difference for the publisher per-impression.
The effectiveness of ads is highly doubtful in general - especially when you're looking at impressions rather than clicks. And that's before we consider advertising mostly being mostly a zero-sum game.
Advertisers are willing to pay more for privacy-invading ads because they believe they are more effective. If privacy-invading ads were illegal they'd just go back to context-dependent ads like they have been using for the thousands of years before the internet was invented, and after an adjustment period the revenue will just bounce back to where it was before.
Most advertisers know this already. If privacy-invading ads were so effective, why are all the major brands now using influencers to market their products? Why go through the effort of finding a specific Instagram channel which might be a good fit and convincing the operator to enter a brand deal, when you could also just directly pay Instagram for a highly-targeted ad one swipe away?
That's been ruled illegal in the EU, but EU sites still do it. Basically, the consent exception only applies if the user isn't coerced into it. Because coerced consent isn't consent.
I don't disagree. The ideal state here is really layers of customation for the defaults. Options like reject all, or strictly necessary would be at the forefront. And then it's really up to the individual how they want to proceed when those options are not available.
I'm again reminded that a significant percentage of HN readership are those working in US AdTech, who's very salaries are dependent on abusing peoples privacy. Hardly surprising a hefty part of the HN demographic slants towards opposing privacy laws.
I don't trust anyone who is against "relevant ads," because I always think what they want isn't "irrelevant ads," they want "no ads." But no ads isn't an option.
Why? Plenty of websites operate just fine with no or near-zero ads. Just look at the one you are currently on!
And what's with confusing "relevant ads" with "privacy-invading targeted ads"? There's still plenty of ads in print media, on television, and on billboards: none of them are invading my privacy, yet they still manage to be relevant by choosing a medium with a certain target demographic. Websites used to do the same, there's no technical reason we can't return to this.
Yet somehow print/TV worked for decades just fine without spying on their users.
I do not want the gas station, or the airplane I'm on, spying on me to build relevant advertising. That is the end game of "relevant ads": my gas pump already serves me ads, the airplane I'm on serves me ads, my own car now (via a software update that occurred after purchase) serves me ads. Monitors now serve ads. TVs are abusing people's Internet connections, which isn't ads, but it's basically the same problem: if I can abuse the customer without consequence, why shouldn't I?
Just no. The problem is, I as a consumer cannot vote with my wallet: companies can and will go "I could take your money, and earn $X, or I could do that and ads and earn $X + $Y."; there is not reason for them to choose the former, and most markets are so concentrated (e.g., airlines) that there is not ample competition for the market to provide ample "vote with wallet" choices. Further, in the car example, it's just bait and switch: even when I think I can vote with my wallet, the company can just alter the terms of the deal, knowing full well the switching price of a car makes me subservient to them.
People want free content online. More than that, they just expect it.
Any future law in regards to this will likely just lead to the companies that already got consent (companies you already have accounts with) becoming even deeper entrenched.
Non targeted ads pay a small percentage of targeted ads.
As long as it's some automated signal, the User-Agent can use any logic it wants to send it without cooperation. The specifics of how to send the signal don't have to be legislated. E.g. Firefox's Tracking Protection has a global default a site-specific overrides, so it's very likely that they would do the same for this or just combine those features.
> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.
So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...
The problem there is that parent's won't know how to do it, or won't care. Many can hardly operate the most user-friendly phone, let alone manage accounts.
The online safety acts and its EU counterparts are somewhat risky, but nobody wants the mention the only proper alternative: a total ban on "social media." Not just for kids, but for everyone. Or a ban on smart phones, that would work too, at least short term. But: money.
Yes, you can't make parents care, but make it easy for the ones who do, and you'll also pick up some number of those who care but only if it's not too difficult. There's no reason a parent should have to set permissions separately in 10 differents apps on a child's device.
That’s not true. Every TV app has a parent setting. That’s really easy to use browser support profiles just like TV apps do bad. UX doesn’t mean that it can’t be set up easily for parents. Windows itself could have profiles for kids that has all this set automatically. It’s not hard. There’s just no will to do it.
You miss my point. It is that parents dont care. However good the parental controls are, there are millions of parents who just dont and wont ever care.
> The problem there is that parent's won't know how to do it, or won't care.
This is unfortunately the reality.
The other day a friend asked me to help her make her phone safer for her kids to use. I started by asking if she set permissions on the apps she downloaded. She looked at me blankly, "What permissions?". I proceeded to show her how you can granularly control what you allow each app to do on your phone and what access it is allowed. Her head blew up, she had no idea any of this existed and after gong through a few menus, she didn't care any more. It was all too complicated and too much to think about for a busy mum.
This is why governments unfortunately are having to try to protect people from themselves. As tech competent people it all seems so simple to us, but we need to remember the majority of the population just click 'Allow All' and blow past all permission and security questions as they have no idea what any of it means.
Is there a term for agreeing with someone's stance but disagreeing with the person because they're so insufferable and sarcastic in the way they present the argument?
“I don’t want to be seen agreeing with someone who combats obvious bad faith arguments with sarcasm - please think of me as being better than that, even though we would end up in a pissing contest about nuance or a digression away from the main point”.
It is probably technically possible, but as almost twenty years hasn't been enough to implement this feature in either of the big mobile systems, it's obviously a huge practical challenge for Apple and Google.
Windows phone had this exact feature. Obviously it didn't survive the duopoly of iOS and Android, but the feature was alive and well for many years before the whole OS was killed.
it's very simpler, i recently got an android tablet for my child and it would take a lot of effort to miss all the stuff about setting it up for a child
That's why the setting should be on the device, not the browser or individual apps. One setting that you could even get pre-configured when you buy the phone.
Right, this is the big picture nobody acknowledges. I'm not paying the price for your kid because I don't know them. I couldn't care about them even if I wanted, because their existence doesn't even intersect with my life.
Yes, as a parent, you are required to put in more effort into parenting your kid than random hypothetical people. That's obvious, and has been the case forever.
I understand the concept of community, but community is not me sacrificing my privacy for someone 1000 miles away.
If parents don't want to do X, Y, and Z to lock down their devices then that is their right. And I support their rights, so the conversation is over right then and there IMO.
I've build some moderately sophisticated server systems up on "bare metal" (as the kids say), know my way around a shell better than most programmers, understand networking better than most programmers, et c., and I still find restricting and monitoring kids' devices to be a huge pain in the ass. The only places it's not extremely shitty are the Switch (which still isn't great) and Apple devices.
Options between "we don't have tech in the house" and "wide-open tech, we have it all" are all some amount of painful, usually for no good reason.
(I remember once investigating how to do some pretty basic stuff for this in Linux, hoping to find something nicer than manually setting some executable permissions and firewall rules and then having to go back and change them all the time, and the closest thing to a guide I found was an old article from Red Hat that basically lead with "LOL, good luck you poor sap, Linux sucks at this" before going on to explain the various bad ways available to sort-of, but not entirely, accomplish it with a lot of work, and significant ongoing time-burden)
UK mobile operators already defaulted to blocking adult sites before OSA, and lets the subscriber turn it off, which seems like a reasonable option.
It'd be even better if there was a way for people to selectively turn it off for specific devices without MITM the connections. It wouldn't be that hard to come up with a mechanism for that.
Because children shouldn't be the ones paying for the crime of having bad parents. Children should be safe regardless of what the parents do, because they're independent people and not property.
you can say that about a lot of things, but we do largely trust parents. but all these social media bans seem to stem from parents who claim to be helpless, when really they are lazy and the wider impact of these laws is massive. no technical way exists to do this without taking the privacy of everyone
Don't fall for the "we are just stupid" propaganda, which is used constantly by governments acting in bad faith.
Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.
This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.
No, but it's the obvious starting point. You can then put additional laws on top banning fingerprinting out of band (if you care about window dressing), fund development of anti-fingerprinting technologies, fund Tor, run exit nodes in a transparent and publicly auditable fashion, etc.
It's not hard to make privacy work when you are the government rather than working against a hostile one.
I think it's because every single website breaks if you don't allow cookies at the browser level. Some knowledge of what the specific cookie does was necessary.
Is there any reason to believe that the current laws being passed by the UK, EU are against the will of the people? Everything I have seen makes the "anti-porn" laws or whatever seem extremely popular.
But I don't want to delete cookies? I want websites to use cookies that are technically necessary e.g. for keeping me logged in. I just don't want them to use it to track my behavior especially inter-website.
> You think the average user is going to explicitly whitelist
When prompted by the browser on first login/signup, yes, the same way the password manager works. With stored passwords, keeping the login cookie doesn't even add much value.
... or cargo culted a site that did. I think this is far more common. It's almost like you're not a serious web site if you don't have a cookie popup of some kind.
And BYW, browser headers can even be a violation if it's determined that you are using them for tracking users in a way that violates ePrivacy demands.
Exactly. Nobody wants to go to a news website/entertainment website/informational website that relies on ad revenue because they will get bombarded by banners and then by a huge number of ads that were increased because those banners slashed their ad revenue.
So instead everyone stays on Facebook, Instagram, Reddit, and Twitter, which ALSO operate on ads and have far more information on their users than any third-party ad tracker could ever have.
None of this has gotten rid of the privacy problems. It just consolidated them into the worst offenders while jeopardizing the plurality of the web. Now instead of people being tracked by Facebook on a website with a third-party cookie in a like button, they are tracked by Facebook on Facebook in a Facebook page because they never leave Facebook.
This framing of the banners as cookie banners is a dodge. It's not about cookies.
The cookie banner isn't about the usage of cookies, it's about _the underlying tracking_. You're allowed to "just" use cookies for normal shit! You can make a website where you use cookies to store login state for a user, without a single banner.
The thing is that every company in the world feels the need to add 1000 tracking cookies to anonymous users to track them through conversion funnels (on top of the ad stuff). That's what you have to inform people about
You can use cookies normally without a banner! You can't track without consent! Every cookie banner is actually a "we want to track you" banner. Calling it a cookie banner is playing into the confusion about what those banners actually are meant to communicate
>>>>>>> now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...
THIS
Holy shit. This is such an obvious fix. And it shuts up those surveillance state goons immediately.
My God, why have we tried to summon up the ghost of 1984 when such a simple fix as this will do.
Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.
The blast radius is zero.
Good God, we need to fast track this into browsers right now. If we hurry we might be able to point to this as the technical fix.
Once some of the infrastructure exists, OS vendors can hook into it.
Firefox devs - please do this right now. Please spearhead this.
I might have to vibe code an advocacy site for the spec and set up a GitHub / RFC process.
I agree, and I agree with the enthusiasm on which you bring in.
I've long since considered that the efforts for online child safety should be pointed at educating parents and spearheading some kind of certification of compliance for child safety of software and websites.
[this product is certified to adhere to EU:CSA]
Then you can block everything not certified, and the software that does the blocking would also be certified, the two major prongs you need (endpoints and sites working together: else they're blocked). The rest of the money goes to education for parents about this fact, and the dangers of not doing it, and how to do it.
This is super "easy" (when comparing to the effort it would take for putting backdoors in everything).
Which is why I think that the reason is definitely not child safety, and more about crime control.
That works well for controlled devices like phones, tablets, and TVs, but it’s much harder on desktops unless you expect parents to become IT administrators.
It'd need to be vertically integrated from OS to user space apps, and restricting what can be installed.
I'm not sure to understand the proposed solution here, but it seems someone could just use a different web browser client who don't inherit these restrictions.
> Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.
CA tried this with AB 1856. I wasn't a fan of this (neither was EFF) because of the privacy and tracking concerns of blasting the fact that the user is a child to all websites.
It would better for the block to happen at the device level. That is, the browser knows it's on a child's device and has a whitelist of allowed sites.
There is already an RTA (Restriced to Adults) header where the website self-labels that it's for adults only and the browser can block it while protecting the user's privacy. I'd prefer expanding the use of RTA.
No offense but if you're proposing a solution that involves whitelists... that solution has already failed.
The web is too big and changes too much and that's before we get to the issue of applying laws to a whitelist based on different juristictions worldwide.
And I have to question, who would administer it? The parents? They won't. Google or Apple? Why do they want to deal with irate parents or culture wars around what is or is not on the list?
There is obvious increasing demand for this from parents, politicians are going to act on it, I think a "this is a child" header is the only one that actually really works. It works for the parents because it's easy to setup. It works for websites because they can cleanly identify a child and filter content if appropriate.
It seems to me that every other solution than a "this is a child" header is either impractical or way worse.
Yes, granted, a globally enforced whitelist probably wouldn't work. I'm referring to bespoke lists that parents control. I know plenty of parents that use this. e.g. here's Apple's feature:
> It works for websites because they can cleanly identify a child and filter content if appropriate.
This still doesn't solve the problem of different jurisdictions and culture wars of what is or isn't appropriate for kids. All this does is move the liability upstream to websites instead of the devices. That is, instead of the browser deciding what's appropriate, now Youtube, Reddit, etc have to decide. And, as we've seen with the OSA in the UK, typically smaller platforms can't handle the enforcement cost so they just shut down entirely.
The larger platforms often use overbroad CYA measures and throw up age verification where they don't need to (Reddit has done this in the EU), or just ban minors (Anthropic and character.ai did this).
As far as blocking explicit content, a self-labeling requirement like RTA accomplishes the same thing as a "this is a child" header but without the liability CYA and without the privacy concerns.
Where the "this is a child" header solution could theoretically win is allowing kids to access websites in a limited child-safe way, e.g. going to Reddit in child mode automatically shuts off certain subreddits. But, as we've seen, it just doesn't work well in practice and usually frustrates parents by overly broad content policing and liability theater. Kids are also at different levels of maturity and I've seen them get frustrated when they're binned into age categories that they feel they don't deserve. e.g. a 12 year old might be plenty mature enough for the 13-16 age category.
But my real objection to the "this is a child header" is the privacy risk and surveillance risk. I don't think it's worth it.
You are confusing a lot of different lines of argument, and in the end I'm not even sure what you are arguing against. I think you are mostly agreeing with the proposed solution by echelon?
You mentioned AB1856 which seems waaaaay broader than emitting an age bracket header based on user settings. It puts the onus on the website operator to not only prevent presenting content to wrong age bracket users, but also to determine the age bracket of the user.
Websites are shutting down wholesale because they cannot reasonably afford the CYA, or dont want to out of principle.
In echelons scheme the parent would be voluntarily setting the age bracket on the childs device right, so if a 12 year old is more mature, then go ahead and set their device to emit the 13-16 age bracket header. If you as a parent dont believe in this, then leave the bracket unset.
For a website operator it would be trivial to block the user from accessing the site if the suggested age bracket is too low (as long as we can agree on a single way of doing things, of course). Larger operators can do more heavy content moderation and present a filtered view to those same age bracketed users.
It is true you are adding more tracking signals, and I am sensitive to the free speech issues, but children are not fully emancipated members of society yet and parents need tools to deal with the difficulties of raising children in a digital society. The alternative now seems to be OSA-like, which is even more intrusive and a risk to privacy and perhaps free society as a whole.
Of course, OSA is really the goal and not the method, and we have to remember it is never about the children. Would children have been protected from e.g. andrew mountbatten if OSA had been around at that time?
It reads like AB1856 needs website operators to prove they didnt serve their content to the wrong age bracket, which requires way heavier methods than simply trusting the emitted "user is child" header (or rather, trusting that the lack of such header is not a false negative)
Usually government mandating something is concerning cause it seems to favor the government for its existence. However with EU commission its actually interesting combination, its representing multiple individual governments at once which somehow works good for the citizens.
Overall this is a common sense solution. The challenge is that a significant industry makes money by collecting and selling data. It makes it harder for businesses who depend on it, they are going to get creative and will eventually come up with some dark pattern to circumvent it.
I still don't get why every website has a cookie banner by default. I am data controller for several companies and have lots of exposure to GDPR. All my websites have no cookie banner, as they are not required.
I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies? Who knows.
I’ve made a few sites for work that aren’t our primary focus. The sites used cookies for login and for “required purposes” (storing in progress state). We did all the tracking on the backend, no cookies or client side trackers.
On our go-live form there’s a question “do you use cookies” and it’s yes/no. If you say yes legal block the site from going live without the pre approved cookie banner…
That's why the usual phrasing is some variation of "Are we allowed to track you? We use cookies for that".
It was never about the cookies themselves. That just happened to be the most common form of tracking in use when the GDPR was originally written. Cookie-less tracking still requires a consent prompt, tracking-less cookies never required one.
Sounds like your legal department is broken. You should fix that.
I mean that both in the sense of "you, plural" (your company should fix that) and "you, personally" (because diffusion of responsibility is a real issue, and someone needs to actually do it).
> I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies?
That has been my guess as well. If you run npm install half-the-internet you have no idea what's in there, so just slap on that cookie banner for good measure. Of course the real problem is not knowing what's inside your application, but the thought process is "eh, if a blanket cookie banner does the job then that's good enough for me".
Don't underestimate the argument of "just to be on the safe side". Someone running a business who doesn't know a lot about cookies will often just put a banner on as an easy arse covering mechanism even when not required.
If you use social media pixels, ad tracking, or performance analytics tools like Google Analytics a cookie banner and consent is required. If not, then not.
Side note: there’s plenty of Analytics tools that don’t require cookies. Plausible (https://plausible.io) is one of them, there are many others.
Not affiliated, just a happy customer.
I'm not convinced this is a real concern. Bots, maybe, but then again even fancy analytics will be fucked by that because they use hundreds or thousands of high-reputation residential IPs. So, you're optimizing for the wrong thing I think.
No, you don't need consent for that. It falls under the legitimate interest exception.
You need to disclose it in your privacy policy, you need to delete it after a reasonable retention period and you can't use those logs for other purposes like ad targeting, but you don't need a consent banner to track things that you are legitimately using for security purposes.
> I guess that most companies just chuck it up there as a default so they dont have to read the law
I think most companies just don't give a fuck about user privacy and therefor have to show one. There are of course exceptions. But I don't know how many of them have been actual (for-profit) companies.
Also I wanna know when websites don't give a shit about my privacy and therefor have to show a cookie banner. While theoretically not consenting should mean not collecting blocking it altogether and modifying page content might mean "all bets are off". If the website expects you to have made a decision that might wrongly consider it consent.
The other approach to killing the cookie banner is simply to declare that such a thing cannot constitute “informed consent”. (Perhaps: “ticking a checkbox and/or clicking a button cannot constitute informed consent”; and see what they try next.) From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way. Just as shrink-wrap licenses and even simple contracts have at times in some jurisdictions essentially been neutered, so that only terms that a reasonable person would expect to be there are enforceable, at which point it becomes obvious that the whole thing needs tearing down in favour of standard licenses/contracts. In the Australian state Victoria, for example, there are standard rent and property sale contracts; for renting you must use that contract <https://www.consumer.vic.gov.au/housing/renting/starting-and...>, and I got the impression that residential sales practically always use the standard contract.
But of course it’s impossible to convince someone of something when their livelihood depends on their not understanding it.
> From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way
There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened.
There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
Of you need a nonstandard contract then you need to provide proof that it was understood. These are not provided in a context where I would expect anyone reading it to have a lawyer to advise so they obviously don't understand it
No, but I do believe that if the jury doesn't find it was obviously a crime without any being told the law then it wasn't a crime. That is the text of the law isn't important until guilty is decided. (So the jury can decide degree if that is a question for the jury, otherwise the judge needs to know for sentencing but the jury doesn't care)
> There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
The value is derived from the people consuming the product. Placing the "incentive to produce value" above the people who presumably are the source of this value seems...misaligned.
If there’s no product or service to be consumed, there’s no value produced either. That’s the point: it’s harmful to eliminate the incentive to produce.
How did you arrive at that conclusion? Laws are the result of debate between sides and the prevailing opinion. The fact that laws aren’t identical in every jurisdiction worldwide reflects that there isn’t universal agreement on every question.
Also, sarcasm isn’t welcome here. Please read the HN guidelines.
Ah yes, I didn't couch my post in any of the various, rampant HN-friendly versions of shitposting. I'll try to follow your example from here on out. Excellent touch citing the guidelines at me after your role in this thread, A+.
I abandon accounts when they get way into the hundreds of karma, generally, or a couple times I’ve let it get a ways into the thousands before destroying the password. I prefer not to become attached to it, and find the minor clout of recognition (upvoted comments that probably ought not have been…) kinda gross.
Meh. I never have more than one at once, and destroy my access to old ones before creating a new one (often taking weeks or months off from posting in between). I'd be a lot more "dangerous" or "risky" if I were sitting on an old tens-of-thousands-of-karma account, which is what I'd have otherwise.
People routinely create alts just to post sensitive stuff and seem to do fine, and presumably they are keeping multiple accounts active at once.
[EDIT] I mean plus if I gave that many shits about being able to post on HN, I'd probably care a lot more about holding on to my precious karma in the first place, no?
HN is supposed to have higher than typical standards for participation than most internet fora and is largely self policing. It’s not condescending to tell people when they are misbehaving. Nor is it condescending to explain to people the law and how things work, provided you’re not insulting them in the process. Which I’m not doing.
I find much more concerning people’s certainty of their mistaken understandings and beliefs, combined with the most ludicrous possible interpretation of other’s positions.
People will _always_ need things. There are very few things that will eliminate people's need for things and producers will of course adapt to the environment.
What we need is an environment that does not give the producers asymmetric power over consumers and the products will naturally align with that.
That argument has actually worked in some cases, especially when you need to click away to actually access the document. I assume it's why we see more and more examples where you need to scroll the full body of text in order to "agree".
> “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement
Only engineers have trouble understanding this. It can be a reasonable defense, and it has successfully been used in courts of law many times. The law is not a machine that compiles text like code literally. Imagine someone who coerces a dying or sick person to sign an agreement they couldn’t possibly be in a reasonable state of mind to understand what they were doing -- the law can and does invalidate such “contracts”. That is the same principle behind age of consent laws. The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
I am an attorney, and am aware of certain exceptions. But these are exceptions and not the general rule, which is what I am speaking of.
> The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
I haven’t heard of a single case where an agreement was voided because “no one could reasonably be expected to understand it.” Unless the language was so impenetrable or vague that the agreement itself could not be discerned. Lawyers tend not to write such agreements.
But it is complicated, no? Even if you click you agree, if the you thought you were agreeing to one thing but actually agreed to another because they buried the lede, “I didn’t read it” is a reasonable defense.
It really depends on the term they're trying to rely on. We have the "red hand rule" in England and Wales that means that unusual and onerous terms will not be incorporated unless it can be expressly shown they were fairly brought to the parties attention.
I think that means one of three things: the court system is broken, you are wrong, or I failed to be clear and you misunderstood me.
So, to be clear, if a company buries or obscures terms while making it seem like they have presented them, so you agree without reading the actual terms, you cannot defend yourself by explaining that situation?
One possibility you failed to enumerate was that you are wrong.
But anyway. What exactly do you mean by “buried or obscured”?
As I said above, if the parties cannot be said to have an agreement because the terms of the agreement itself are inscrutable, then that would probably result in no contract being formed, or the terms at issue interpreted in the light most favorable to the non-drafting party. Like if the terms were presented in so small a font that only someone with a microscope could have read them, or it was written cryptographically or is gibberish.
Basically you have to successfully argue that no reasonable person could have read and understood the agreement. You’re unlikely to prevail if you argue only that you, the individual, did not. (Unless the court also finds you are incapable of entering into any contract because you’re a minor, are non compos mentis, etc.)
A more concrete example may be useful to explain what I’m thinking.
A company has you click to agree to their TOS. They link a doc, which is of course quite long. That doc has a footnote which links to another doc. You do not read the secondary doc, and it is the contents of that doc that allows the company to sell you data/prevent you from suing them/harvest your organs/abduct your family/whatever.
My point is that “I did not read the document” should be a valid defense, such that if it is not I believe the law around this is wrong.
I suppose you can claim I am wrong to believe that, but it is accurate for me to state that I _do_ believe it, which is why I didn’t list me being wrong as one of the possibilities. Practically speaking, that is the first possibility I enumerated.
I should note that in my example, imagine neither doc is any more inscrutable than all the TOS we encounter in the wild, instead it is the construction (the fact it is a footnote link) that makes it easy to miss the additional doc.
Incorporations by reference are not unusual in contracts. A contract is unlikely to be voided merely because the contract has references and the counterparty didn't read them.
Why would you claim the false "I didn't read it" ahead of the true "I read it but understood it differently"? The latter allows for adding the fault shifting claim "because the other party wrote it deceptively", while "intentionally didn't read" makes it much harder to blame the other guy.
I just visited theguardian.com to see their cookie banner. The banner says this:
> Your Privacy (`x` button to close the tab)
> US residents have certain rights with regard to the sale or sharing of personal information to third parties.
> Guardian News and Media and our partners use information collected through cookies or in other forms to improve experience on our site and pages, analyze how it is used and show personalized advertising.
> You can opt out of the sale of all of your personal information by pressing
> <button>Do not sell or share my personal information</button>
It's 3 sentences, plus a button that says "Do not sell or share my personal information". I actually don't even think this is GDPR compliant, because my layman's understanding says that GDPR consent must be presented as opt-in, rather than opt-out. (I guess they are going for CCPA/CPRA compliance?) But anyway, I would think that a reasonable person could be expected to notice a button that says "Do not sell or share my personal information" and then click it, especially when it's portrayed prominently at the bottom of the page.
The GDPR doesn’t allow opt-out consent to count as consent. The only consent it recognizes as valid consent is opt-in.
However, since we are discussing the banner that The Guardian website shows to US viewers, I assume they’re trying to comply with California privacy law, which does allow opt-out regarding the sale of personal information.
You've muddled the definitions again. "opt" signifies an action by the user.
If I am "in a group" by default, then I can take an action to "opt out", requesting to be removed from the list.
If I am not initially joined to the group, then I can take an action to "opt in" and be added to the list.
There is no such thing as "opt by default". That is not a user action. It also makes no sense for the same list or group to be both "opt in" and "opt out" because, as adjectives, they imply the default states and they describe the user action taken to change that default.
Because this is there 1 millionth cookie banner, because every site and their momma has one.
Also, 90% of cookie banners are not this good. They tell you nothing, hide the "reject" button behind multiple screens, etc. At that point the consumer is trained to click accept.
> Independent, quality original journalism needs your support.
> Please choose an option.
> * Accept personalised advertising and all cookies
> We use cookies and similar technologies to support the Guardian and personalise your experience in other ways. To do this we work with a cross section of [139 partners].
> - or -
> * Reject all and subscribe to Guardian Ad-Lite for €5 per month
> Read the Guardian website without personalised advertising. This does not include ad-free. You will still see non-personalised advertising and we may still use cookies and similar technologies to improve our site.
Followed by:
> Some cookies are necessary to help our website work properly and can’t be switched off. Find out more in our privacy policy and cookie policy, and manage the choices available to you at any time by going to ‘Privacy settings’ at the bottom of any page.
> Cookies and similar technologies collect information from your device and may be used to access personal data about you including page visits and IP addresses. We use this information about you, your devices and your online interactions with us to provide, analyse and improve our services. We use cookies and similar technologies for the following purposes:
> * Store and/or access information on a device
> * Personalised advertising, advertising measurement, audience research and services development
> * Personalised content and content measurement
And finally the buttons:
> ( Accept all ) ( Reject all and subscribe )
> If you already have Guardian Ad-Lite or read the Guardian ad-free, [sign in]
Notice how they show you those three sentences and don't just put a bunch of small print at the bottom of the page. Because if they did, it would be invalid.
It can and has been in many cases in many legal systems. For example, let’s say you walk into my store to buy a dish washer. I say ”here is an extended warranty that I will give you. Just sign” you sign it instead of reading 15 pages of boilerplate. In the end of the document it says you now owe me 10 billion dollars. Doubt I will be able to enforce it in most legal systems.
That’s not an “I didn’t read it” defense. That’s a “term is this contract is unconscionable” defense. They’re not the same thing. I was speaking strictly of the former.
Also, striking an unconscionable term typically does not void the whole contract. Just the term in question.
As a general rule I believe many online terms of use, eulas and similar online contracts are examples of procedural unconscionability, in that length is often too long that one can be expected to read it in the day to day action of "surfing the web", I believe this is also the opinion of the EU and many of its member states, hence the limitations found on enforcement of such contracts.
Aside from that many of these contract have terms that might be considered substantive unconscionability - for example if terms state that what you post can be used by the company that owns the service for marketing of the company or the service I feel this would not make it through most legal systems that I feel before the attempt are not inherently corrupt.
I would personally be shocked if the EU voids click-wrap agreements for unconscionableness based on the process alone. I’m not super familiar with EU law; is that what it truly says? I rather doubt it because I do business in the EU and have been asked to agree to terms as a condition of making purchases online there.
Online retailers in the nordics occasionally try to post terms and conditions that contradict consumer protection laws, for instance retailers being on the hook for warrantying product(ion) defects for 5 years after purchases of products that ought to be durable, like electronics. The retailers win out on a substantial amount of the population not contesting it, but if you as a consumer go through the process the findings is basically always in your favor, despite there being agreements to something else. Telecommunications providers also have a long history of having their consumer invoices being voided for being unconscionable despite service agreements, especially in cases with children playing with devices (but otherwise also), going all the way back to the landline age.
sorry I did not phrase that very well, when I said as a general rule I believe I meant that if put to the test it could be often won on length alone in conjunction with the activity being done, but almost always these contracts are substantively unconsionable and of course people contest that, because most people don't get angry and want to fight for no reason, they do it because it is violating their rights.
As an example I have an email account with site A. I go to site A and log in, they suddenly spring a large new contract for me to read, I cannot get through to do what I came to do, it will take me 5 minutes to read so I click OK because I am on my way to check my email with site A. Procedurally this is not reasonable behavior.
What would be reasonable?
"Hi, we are changing our terms of service, you can see it at this link and agree. If you don't have the time right now you can do it later, but in three days you will lose access to the service unless you agree to terms."
There are however lots of other laws in the EU which may in fact make this behavior substantively unconscionable anyway. I certainly believe there would also be substantive arguments to be made in this case.
The council directive on unfair terms in consumer contracts puts every pre-canned contract in scope, and unfair provisions on a contract are rule non-binding (if the contract can keep existing after the unfair bits are taken out).
All of these cookie forms have the same set of toggles. At a high level all anyone is saying is that we should just declare any kind of tracking cookies unconscionable terms for this kind of dialog box. Caching, shopping carts, explicit log in, these are totally fine and you don't need a dialog. The tracking stuff is not that hard to define and it should just be declared unconscionable.
No, it is literally ”I didn’t read the contract”. Let me guess you don’t have a law degree in Swedish law and you are just making statements on every legal system in the whole world?
Just read avtalslagen paragraf 30. It says just that. And it is different from paragraf 36.
I read it. The law expressed therein appears to be consistent with typical contract law in the West, including the UK (from which US law is derived) and other European countries. I don't see any major differences. (Also, I'm not sure why you brought up paragraph 30 as that is about fraudulent inducement.)
See also https://svjt.se/svjt/1959/497 "En person borde sålunda bli bunden av ordalagen i det dokument han undertecknat utan att äga att ursäkta sig med att han icke läst igenom dokumentet."
No, I have a Swedish law degree and you have totally misunderstood article 30 if you claim it is about unjust contracts. You are mixing it up with art 36.
You are referring to a 60 year article and the sentence you highlighted is NOT his opinion on the old contract law (the contract law currently in effect is from 2020) but rather he is explaining the opinion on German law from another person.
Of course you as an American sees no difference between contract law in continental European law and common law.
This is what the Swedish Supreme Court said recently on the paragraph.
Enligt 30 § avtalslagen kan en rättshandling inte göras gällande om den,
gentemot vilken en rättshandling företagits, framkallat rättshandlingen genom
svikligt förledande eller bort inse att den som företog rättshandlingen blivit
svikligen förledd av någon annan. Det finns en presumtion för att det svikliga
förfarandet har framkallat rättshandlingen, om omständigheter som svikligen
uppgetts eller förtigits kan antas vara av betydelse för rättshandlingen.
bad Google Translate:
According to Section 30 of the Contracts Act, a legal act cannot be enforced if the party against whom the legal act was performed caused the legal act by fraudulent misrepresentation or Should have realized that the party performing the legal act had been fraudulently misled by someone else. There is a presumption that the fraudulent misrepresentation has caused the legal act if circumstances that were fraudulently stated or omitted can be assumed to be of significance for the legal act.
> you have totally misunderstood article 30 if you claim it is about unjust contracts
Fraudulent inducement is not about unjust terms in contracts. The elements of fraudulent inducement in the US are:
1. The other party falsely represented something to you regarding a material fact;
2. They knew that it was false;
3. They made the representation in order to induce you to rely on it;
4. You did actually rely on it;
5. You did not know that it was false; and
6. You sustained damages as a result.
I imagine it's not significantly different in Sweden.
> According to Section 30 of the Contracts Act, a legal act cannot be enforced if the party against whom the legal act was performed caused the legal act by fraudulent misrepresentation.
OK. We have the same law. But I don't understand what this has to do with an "I didn't read the contract" defense. Since you possess a Swedish law degree, can you cite a single case wherein a party to a contract escaped their duty to perform merely because they didn't read the contract? Assume no fraud, clear language, no misrepresentation, no unconscionable/unlawful terms, both parties are competent to enter a contract, etc.
"Disney is trying to have a widower's wrongful death lawsuit dismissed and sent to arbitration because the man had signed up for a Disney+ account several years ago."
Now what happened was that Disney quit fighting over really bad PR. But the court challenge would have liteky succeeded.
I don’t see how we could possibly prove that the person who clicked “I agree” is still the person using the computer.
Or that any actual human is aware that an agreement was made (since an AI can find a checkbox nowadays or software can be configured to bypass it). One way to add balance could be to require people asking for contracts to actually treat them like real serious legal documents, show up for the signing, and figure out who they are making an agreement with.
That doesn’t matter. If you authorize an agent—human or mechanical—to enter into agreements on your behalf (even by mistake), and the agent presents itself as operating on your behalf, the agent’s decisions will be treated as though they were your own.
Prinicipal-agent law predates computers by a very long time.
Websites need cookies.
I don't get why I have to suffer through this for a few puritans who literally lose nothing in the process of this transaction but act as if Stasi is watching them.
Aggregated analytics do, and you can't run a serious website without some kind of analytics. Preference-storing does as well, despite any reasonable user expecting that, if they set a preference, it will be saved.
There are many analytics solutions that dont require cookies. You can do aggregated analytics just fine without. Saving preferences does not require consent either.
My understanding is that any front-end analytics solution will require consent. You're right about explicitly set preferences. I was mixing that up with inferred preferences.
How many requests per second are being served? How many error codes were delivered to clients? How quickly the service responded? Service logs without PII? All perfectly fine to aggregate and analyze without consent.
How long did it take x user to navigate from x screen to y screen is one of the most valuable metrics for any site, and most people consider this to require consent. Or at least it not being worth the risk to not ask.
Acting dense like this isn't productive... And literally this information would be stores as anonymous user 12345, but that still would require consent (probably, or at least arguably).
>How long did it take x user to navigate from x screen to y screen is one of the most valuable metrics for any site
Stats like that are only used to implement dark patterns better and justify user hostile decisions since pretty much the time the idea of telemetry was introduced. Otherwise, we'd live in the world of perfect web ui and we're not.
That can be implemented. Within a session you don't need to know it's the same person tomorrow, so a per-day key derived server-side is enough to measure that someone took 40 seconds from x to y. No cookie, no localStorage, nothing stored on the device, nothing to consent to. Hash ip + user agent + your domain with a secret salt that rotates and is destroyed every 24 hours, and you are on the safe side.
Of course, recognizing users across days requires consent. But is that really necessary?
Or use some JS to put the time-on-page in the next request, right?
Is it a violation to send data that could theoretically be used for more invasive tracking than you actually do? I don't think so, or else you'd need consent just to receive an IP packet.
You don't need cookies for basic aggregated analytics. Now if you want to track and record mouse movement, you do, and that's a privacy concern.
The law really has nothing to do with cookies, it has to do with privacy, tracking, and PII. You can absolutely save preferences and perform analytics. What you can't do is hoard data that is personally identifiable for purposes that are not obvious to the consumer.
Actually you can't send any cookie that is not essential to the operation of the website without consent and that would include analytics regardless of PII. same for pixel tracking / fingerprinting, it's all a no-no.
Practical: Supposedly-aggregated stats have a history of actually being perfectly possible to analyze back into individually identifiable information. Also, it's conveniently the same tech stack in a way that makes it easier to make an actual slippery slope.
The practical argument I can understand. From the abstract argument though, it sounds like you'd be opposed even if the anonymization could be guaranteed, which I don't understand. Why is it "spying" to try to understand in aggregate how users are using your website? How are you supposed to eg. identify usability problems without this information? And what is the harm to users? (Again, in the abstract case where we leave aside any possibility of individual users being identified.)
Cookie control always should have been a browser control. The legal route always should have been to force it to be built into browsers that provide sane defaults, and make it illegal to circumvent what the browser declares as far as fingerprinting etc.
any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.
If people really cared, they’d choose browsers that have better control, but that’s obviously not a priority for them. Why do you think this sort of thing should be regulated to suit your preferences when most people don’t seem to agree with you?
I think that's a stretch. People can care, but be unwilling to spend the time researching it or accept the trade offs that come with small browsers (which are often unsupported for applications you might want to use).
There are many things someone might care about and at some point you have to prioritize. This topic in particular is practically a cold war where you always have to catch up on how things are, lest you loose it all. The required effort is disproportionate to the result.
Because everyone agrees - cookies banners are annoying and need to go away. Everyone is on the same page about this. The easiest way to make that happen is "move them into the browser".
How often do you get prompted for, say, secure DNS or HTTP? Almost never, because your browser has sane defaults and controls that. So, there you go.
Yeah I think it probably does mean you should be banned from asking in most cases. If you have a legitimate interest you don't need to ask. If you need to ask your interest is not actually legitimate and you know it.
Legitimate interest is not currently enough to read or write cookies. You need either consent or it must be "strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service." (or "sole purpose of carrying out the transmission of a communication over an electronic communications network", but that's harder to apply to cookies)
"legitimate interest" is legal basis in GDPR. ePD (which governs access to cookies) does not have such legal basis, only consent and the two exceptions.
Other processing (like after value is read) can happen under GDPR if the data is personal data.
My understanding is that ePD was obsoleted by GDPR.
Note that you don't comply with EU directives anyway - you comply with actual laws of actual countries, and the EU process helps them to mostly agree with each other. Did countries replace their ePD-based laws with GDPR-based laws? My understanding is they did.
They are asked _once_ during browser setup, same way on iOS users are asked once during setup if they want to allow Apps to track unique IDs (memory is hazy, they did that a couple years ago). And surprise surprise IIRC 96% of users said no.
> it’s well-understood that very few people actually read those things, they just want to get them out of the way.
This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data mining, profiling, and other privacy-related aspects. But in many cases, you could just click "reject" and the banner would also disappear...
To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
Some variant on "reject" takes more effort like 70% of the time. Which is on purpose, of course. The ones that aren't maliciously-complying have a "necessary only" button that insta-closes it, but tons pretend that you might want to allow some spying but not all of it and make you go through another screen if you don't just "accept all".
> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
Then it'd be possible to default it to "nope" (Firefox, and perhaps Safari, might do this) or to allow a "never, anywhere" setting the first time the question is asked, and malware and spyware vendors know that'd mean a much larger proportion of denials.
"necessary only" also tends to have a malicious compliance aspect where they don't store a cookie recording your preference and show the banner on every single page until you click accept.
Yes, you are. The legislative process around EPD/EPR fully anticipated the malicious compliance and it became a back-and-forth political football long before anything was passed. The legislators were never dumb and the corporations were always greedy+powerful.
I had one of the providers recommending us that we leave the "Decline All" button out of Europe, since it's not widely prosecuted, buy recommended that we add it to California, since chances are slimmer.
Naturally in a camera meeting with a "don't tell anyone we said that" appended right before.
The marketing people in the meeting were very angry that California was "doing it to them".
If they fully anticipated this then surely they could've fully anticipated how annoying and useless cookie banners are?
There is nothing stopping a website from using cookies regardless of the banner. If they are outside EU jurisdiction then there won't be any consequences either.
The legislators were and are dumb. They have wasted an enormous amount of collective time for no benefit. Big corporations continued doing what they were doing and nefarious third parties could still track you.
> surely they could've fully anticipated how annoying and useless cookie banners are
They did. The laws were airtight in this regard. They simply lost -- whether through a last minute "tweak" or undermined enforcement mechanism I do not know, but I do know that the current state of affairs was fully anticipated and headed off at the point where I reviewed the proposal. Your vitriol is bass ackwards -- the lesson is to strengthen the walls between corporations and the legislative process and support enforcement mechanisms, because those were the places where the process failed. Not the intelligence of legislators. Otherwise you will keep losing to the corporations, and you will deserve to.
The law is airtight. Acceptance must be informed and freely given (this includes forcing through dark patterns and annoying banners that force you not to read), and withdrawal should be as simple as acceptance.
GDPR article 7 and its various recital already include that. GDPR wisely doesn't get into technical details like "cookie banners" anywhere, but various national agencies did set guidance and it's usually quite explicit: Rejection must be as simple as acceptance and reject buttons or link must be as prominent as the accept buttons and links.
For example, CNIL, the French data privacy authority, clearly says[1]:
"The CNIL has received complaints about dark patterns on cookie consent banners encouraging data subjects to accept cookies.
As a reminder, with certain exceptions, cookies can only be used with the consent of data subjects. Moreover, rejecting cookies should be just as easy as accepting them."
And gives examples of dark patterns such as different button sizes, multiple accept buttons, hidden reject buttons, etc.
The law and specific guidance is pretty unambiguous. This purely an enforcement problem. The regulatory bodies do not have the resources to go and chase most individual companies, and the non-profit NGOs that go after the violators apparently don't have the budget to make enough impact and scare companies into
compliance.
Well, maybe it is... but then the PM never prioritizes testing or fixing the problem. They're not intentionally trying to get more people to accept cookies, it's just that there are always more important features to build and fires to fight, and fixing the cookie banner won't move any of the metrics executives are breathing down their necks about, and it won't look good in the perf packet...
But of course, designing the system that pushes people to make this sort of decision was absolutely intentional.
So even when it's incompetence, it's still malicious, just in a way that obscures the explicit decision-making that led to the result.
I don't see that as malicious. Is my consent record "strictly necessary"? No. Don’t get me wrong. I’m sure they love that, but if sites saved that preference when only necessary was selected, I’m sure a bunch of people would be screaming that they weren’t following the law.
I don't think anything is actually "necessary" if you want to be strict on definitions.
I think it's absolutely fair and unlikely to be illegal to use a cookie to remember cookie preferences. Unless the cookie value was not yes/no, but something like a precise timestamp that could be used for uniquely identifying.
Yes, it is strictly necessary to properly honour the user's choice. Not storing a rejection of consent but storing acceptance violates the GDPR because it creates an asymmetry between the effort required to accept vs the effort required to reject user data processing.
The entire banner is malicious. They don't need consent for necessary or functional cookies. They only need consent to track you - at no benefit to you ever.
The malicious compliance aspect is that they're not offering a choice between "tracking" and "no tracking", but bundling "no tracking" + "painfully degraded functionality" (like repeating the question on every page) = "strictly necessary cookies only"
> But in many cases, you could just click "reject" and the banner would also disappear...
Oftentimes the reject flow is substantially more annoying than the accept flow. I click reject myself when it's an option, but I can absolutely understand how people might get conditioned to click accept when clicking reject might result in more popups.
The UK is somewhat famously no longer part of the EU (you may have heard of a thing called "Brexit" a few years back).
However the UK does have its own GDPR regulation (see: <https://www.gov.uk/data-protection>), though my understanding is that it may be less strict in requiring equivalence between "accept" and "reject" actions. (I may be wrong on this.)
UK sites accessed from the EU would have to be under EU GDPR compliance.
It's wild to me that anyone thinks that would be a reasonable law (whether or not it is law, I have no clue, I don't live in UK or EU).
If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway."
Note that I used "sign any name" as the metaphor, not "show ID," since it is trivial to not allow any important information exchange if you simply delete the cookies yourself, which is easy to configure a browser to do. The end-user has the choice, if it's so important to them, to configure their browser. Even Chrome can be configured for which sites to allow cookies, which to disallow, and which to clear when the browser closes (the smart choice, since accepting them and throwing them away soon after is the undetectable option that accomplishes your main aim).
Allowing bad actors to act badly against all but the most sophisticated users is exactly where lawmakers should be stepping in. Sorry you find that controversial.
We ask more sophistication of drivers to understand the rules of right of way than we would be asking of users to hit Settings -> Privacy and Cookies and read the plain language there.
Sorry that you need the government to "help" people in this way, by forcing other people to give them free things.
No, I'm just saying that it's okay to burden humans with the responsibility to learn a few basic ideas about how to operate their own computers if they want to control their data privacy.
Simple, easy tools are already there, such as the Clear Browsing Data menu item in Chrome, Edge, and Safari. For more complicated intents, the browser settings are no more complicated to navigate than the actual customization UI in the CMPs, anyway.
Then I don't understand the driver analogy. Drivers are forced to take lessons and get licensed for the precise reason that we know people can't take the responsibility on their own.
Clearing browser data is anything but easy for people who aren't certain what is "browser data". Is this going to delete all my google sheets? Those are in the browser. And it's not a bad question, some apps actually use IndexedDB or whatever to store user data.
YouTube is a site that pretty much everyone has an account already for (and therefore have already consented), but say you make YouTube 2, you can only make money if people allow personalized ads (they pay 10-20x untargeted ads). 90% less revenue means your business model doesn't work. The government in the area has decided you can't refuse service to customers that cost you money (people who don't consent).
You simply will have to go out of business.
This is also why you see many large companies fighting for more regulation. It's harder for a competitor to emerge if they have to navigate mountains of red tape.
What if I want to start a restaurant that can only make money if I use expired ingredients, run the fridge at a higher temperature to save on electricity, and don't waste my employee's time by washing their hands? These food safety laws mean my business model doesn't work.
This is just a strawman, these aren't equivalent and I'm not going to waste time pretending they are. Might as well just compare ads to nuclear weapons at this point.
There are enough libertarians out there that believe that the government should not be involved in food safety inspections to establish that regulations like this ARE on a related spectrum. Do you have a right to trust that food you buy is safe or should you get to choose to buy raw milk? Do you have a right to consume online services while retaining privacy? It's a debate society constantly has, and the EU electorate has chosen the side of privacy over a specific business model, just like most developed societies have chosen food safety.
> Do you have a right to consume online services while retaining privacy?
This is the part I don't understand. I'm actually all for regulations like being able to demand they delete the saved data they have on you, restrictions on transferring data to the control of third parties without disclosure/permission, etc.
But if your definition of "privacy" extends to not wanting cookies to work like they were designed to, why can't it be your responsibility to use a browser (a User-Agent) that carries out your intentions?
With services that are mandatory for all of us to use (e.g. government), I can see how being stringent makes sense because the users have no choice. But I can't understand applying the same burdensome requirements to things that people can simply choose to use or not use, such as a restaurant or some random guy's blog. I could be convinced that large platforms (tough to define properly, but things like Amazon, Uber or Meta) may be subjected to additional rules, but the tough rules being applied to even tiny one-person startups does nothing but advantage the giant platforms who have hundreds of lawyers and can devote entire dev teams to building complicated compliance features.
This is a false analogy. The cookie banner stuff is explicitly about sharing data with third parties. If that were the case in your example, it'd be a different thing, right.
> If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway."
More: "To view the private content on my website, you have to either pay me, or let more businesses connect the dots between this content and the rest of your internet browsing habits, than there were students and teachers combined in your high school."
Yes, it is technically possible to fake this content, or to auto-delete it.
But https://xkcd.com/2501/ applies. "It's easy to forget that the average person probably only knows the privacy settings for Safari and one or two Chromium derivatives."
>This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept"
There's a mismatch between the velocity at which people visit sites and the time it takes to navigate the cookie particulars of each site.
And, we can dismiss this as people being uninformed or lazy but the reality it is that's actually not so unreasonable. Cookies are in some ways near the bottom of the list where privacy is concerned, given everything else from breaches to search dossiers to device finger-printing to mobile device location-tracking to the ubiquity of cameras in the real world, and on and on.
The idea that we're clawing back privacy in any meaningful sense by blocking a few cookies here and there is kind of quaint.
I believe myself to be fairly well-informed, and usually accept the cookies, because I don’t foresee any potential harms, and it helps the people running the website. I am worried about many things like phishing and hacking/data leaks, but the valuable data isn’t cookie-related.
These popups aren't about cookies but really about spying. It seems you have nothing to hide. I understand: I also don't. However, the problem with spying is not about individual secrets but about the society and democracy.
Lack of privacy harms journalism and activism, making the government too powerful and not accountable. If only activists and journalists will try to have the privacy, it will be much easier to target them. Everyone should have privacy to protect them. It’s sort of like freedom of speech is necessary not just for journalists, but for everyone, even if you have nothing to say.
Tracking usually happens across websites, meaning the information is shared with third parties outside the people running the website where you accepted the cookies. Knowing your interests, behavior and preferences makes you prone to manipulation. The selection of information shown to you will be crafted such as it maximizes engagement. For example, showing you information that upsets you, in order to get you to react. Or just information with a slant or spin to influence your opinion. Nobody is immune to being affected by the distribution of what they are being shown.
The banner is not just about cookies, but also about data sharing, so by accepting you increase the amount of your data that can be leaked.
These banners handle both ePrivacy consent for cookies etc, but also GDPR Art. 6(1)(a) for processing purposes (personalised ads, measurement, audience insights, precise geolocation, even device fingerprinting).
It's a nag-box that appears every time someone visits a new website.
Of course people are going to click it away as fast as possible.
In the few cases you repeatedly visit a website one might want to reconsider, but by then it's out of mind due to not being shown after giving consent.
It is known that warnings and pop-ups that show up almost all the time yield diminishing returns.
I think it was named "normalization of deviation" by some folks in a blog a while ago, and I believe that name fits.
If you get warned about missing https all the time, or that something might be dangerous (even though it does precisely what you want it to do), it will loose its effect by the time you actually need it.
You can argue this is malicious compliance, but if you want it to go away it would probably be easier to go for banning tracking and personalized ads altogether. Eliminate the reason for this behavior, so to speak.
That is for Y Combinator. I would characterize HN as less than a fair bit;
> Hacker News Information: If you create a Hacker News account (ID and profile), we do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field (“HN Information”). Your submissions to, and comments you make on, the Hacker News site are not Personal Information and are not "HN Information" as defined in this Privacy Policy.
Because it doesn't mean anything specific and breaks entire business models (merely logging that you landed from an ad click and seeing if you check out counts as 'tracking,' doesn't it?) if interpreted purely literally. So, the only way to treat it is to either ignore it or to just send back an error code and message that says "Sorry, having some tracking is the condition to get this free content. Accept or don't."
Like it or not, the Web is a two-way street, meaning that the server end of the transaction doesn't owe the client end anything in particular unless there's some relationship in place (like a payment). It appears the "just ignore it" matches the intent of most web users, though, since an overwhelming majority of web visitors accept a bunch of spammy ads + free 'content,' and a slim minority pay for ad-free alternatives.
> "Sorry, having some tracking is the condition to get this free content. Accept or don't."
The law that caused the cookie banners also says companies cannot block access to the site if the cookies are not required for the functioning of the site.
Some German news sites have broken this and have "accept or pay" and I think this leaked to news sites in other countries. Facebook even tried it.
So, sure, if DNT is true, try to make people pay. Fine by me.
The most annoying thing about that is not even the "accept or pay" banners. There are more:
- even if you accept the tracking, you might still not be able to read the article, because while the site may be free in principle if you accept ads, that specific article is not.
- and the most annoying thing is that such paywalled articles show up on Google News. Not sure if they're tricking Google into showing them (by showing the full article to search crawlers, but the paywall to actual users), or if this is some understanding between Google and EU news providers, but it's annoying...
I'm not convinced this is a business model I want to exist. We had an internet before it, and Google, and Facebook. I'm increasingly sad we can't return to it.
Let me be clear, I can't stand the social-media industrial complex and the advertising universe. I've seen the bottom that we've raced to, with absolute bullshit popping up everywhere and entire sites full of slop with clickbait "headlines" just rigged to get ad impressions.
And I'd gladly trade today's BS for any version of "The Internet" pre-2007.
But the "Before" Internet wasn't some natural sustainable state.
Before 1997 or so, "the Internet" was being paid for by academic institutions and big companies, and wasn't really all that commercial at all. It was also pretty tiny and blessedly simple. Honestly this version is the most achievable (re-creatable?) today since we can set up indie websites much easier today than we could then. Instead of using your free webspace from your university or employer, 20 of us could share a $5 a month instance, and link to each other's webpages, and add an IRC server to that instance just for fun.
In the 1998-2007 era, the Internet got a lot bigger, but was also still pretty fun and not that enshittified, but that's just because it was being paid for by VC money being burned.
Today we are where we are in terms of business model[1] because Google and Facebook achieved great success with ad-based business models because of the ability to target ads better, and because consumers of The Internet have spoken, loudly, with their closed wallets. They've said "We will only pay for content if it's All The Music and ~$10 a month flat rate, or if it's a big/interesting enough video on-demand service and under $20 a month. We'll never pay for news or text content of any kind." So, the businesses with other types of content do what the public wants them to do: have cost-free content whose access is conditional on being advertised to very annoyingly, or they marginalize themselves with paywalls, subscribed to by only a small minority of users.
[1] i'm setting aside the non-business aspects of our mess, namely the poison that social media, 'engagement' optimization, and ragebait-as-news has wrought on society.
Their targeted ads suck. I've been a professional developer for quite a while and fb keeps peddling me programming courses for beginners to become a developer.
Or, I liked one single page of an amputee woman (I am myself) and now all I see are amputee women.
They just buy all the competitors, but they aren't good at all.
The supposed benefit of the current model is to find and eliminate that wasted half.
Facebook has shown me ads for dick pills and boob surgery, ads I can't read because I don't know the Cyrillic alphabet, and ads for services that only apply to citizens of nations I've never been a citizen of who moved to a country I had in fact moved out of.
The reports I hear from people who buy ad slots are mostly unimpressed with the results; the word on the grapevine is that the "success" cases are not even average customers, but those who are vulnerable to getting scammed.
Good. No one is entitled to a business model working in perpetuity. Doubly so when it's ethically dubious.
The very thing entrepreneurs are glorified for - their ability to invent and execute on new business models. They'll manage, don't worry about them. Hopefully they'll settle on more honest models this time.
Agreeing to terms and contracts without reading or at least skimming them is not responsible adult behavior and should not be used as a model for legislation, no matter how many people do it. I agree that we do have a culture where private law is not taken very seriously, and that's very unfortunate.
People do not have a right (morally speaking, not legally) to access or use a service (or a website) etc without having to read/agree to the terms (applies to analog and digital).
Try to get anything done then, there's so many places these days where you have to approve 300 page legal documents to e.g. record day care times, pick up packages and so forth. There is literally not enough time in the day. The option for me would be to not put my kid in daycare (I lose the spot if I don't put in the daycare times, and the only way to do that is a 3rd party service) and not pick up packages (have to agree to the EULA to get the app that I need to unlock the pickup locker) and dozens of other places.
We really need to stop companies from putting up these insanely complicated legal texts to use basic services when they could all be behind standard contracts.
They're usually not that complicated. And most of them say usually almost the same things with some edits thrown here and there. E.g. compare the disclaimer of warranty/liability sections of two different EULAs. E.g. this kind of text in Apple macOS Tahoe EULA is found almost everywhere:
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE APPLE SOFTWARE AND
SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE”
The same point applies to most of the text. But yes, some text is specific to the service. E.g. the same doc above says in bold:
"By using the Content Caching Features of the Apple Software, you agree that Apple may download and cache such Apple Eligible Content on your Caching Enabled Mac."
I'd say that's something worth knowing if you use that OS.
Terms of services and contracts are written for lawyers and not the average people.
If your terms require people to get a law degree and take a week to parse the 400 page document, then I would argue that it's a tactic to get people to sign up for the service without fully understanding it.
We need legislation that forces companies to communicate the terms in a way that an average person can comprehend.
I'm an average person and I read them all the time. It's not usually 400 pages long. More like 3-4 pages. If a person genuinely can't understand, they should not use the service. That's not sarcasm, I, myself, do not like to sign contracts I cannot understand -- but that's rare when you can look up stuff.
Because 90% don't even do anything? It turns out it's actually one of those really annoying problems to delay cookies which were supposed to be sent already in the HTTP request response until a user interaction has happened. And on a lot of pages, non technical people embed random 3rd party resources. And these 3rd party resources might claim to use only "technically necessary" cookies, but of course that's nonsense; I'm not visiting the 3rd party.
People expect visiting a website to be read only or contained within a sandbox to not read other files on their computer which is correct. Most people just don’t care about tracking and want to get to the content.
"To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning."
This is exactly what browsers did back the 90s, they asked about every single cookie.
Then browsers got configurable options to simply accept either all cookies, no cookies, or only first party cookies (excluding third party sites unrelated to the domain you visited).
For now well over 20 years I have disabled 3rd party cookies in all browsers I use, and only in a few cases overall did I need to make exemptions.
It literally does not matter what you pick on these things - most of them don't work anyway. Think about it: Of course they don't. All the third-party javascript is already on the page. Anything you do inside the sandbox with UI provided by, usually, some other third-party, can't just magically force all that other code to behave in a specific way, unless someone has done a great deal of work to integrate the cookie banner code. If the first-party site were that competent at instrumenting every bit of third-party code the marketing department threw at the website department, they wouldn't even need the third-party cookie banner vendor in the first place.
Clicking those "REJECT!" buttons might make you feel empowered, but it's pointless. Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you.
The whole thing has always been a problem to be properly solved by the browser, and it's probably just the fact that Google makes the only browser that matters, that it's been foisted upon every website owner, who mostly just wants basic analytics and to track conversions from the ads they run, and isn't "selling your data."
The browser is your user agent. If it's sending any information up to web servers on every request that isn't okay with you, why are you using it?
> Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you
Exactly. I use the "I don't care about cookies" extension, which rejects most cookies automatically without me having to see the popups. But even accepting cookies is fine - I'll be closing my browser soon anyway and they'll be gone.
I'll be closing my browser soon anyway and they'll be gone
Sure, your browser cookie will be gone. But you have already allowed the server-side identifiers of your session to be used for whatever purpose, including reconstituting increasingly larger parts of your identity over multiple disconnected sessions. Please don't make the mistake of thinking that clearing your cookies afterwards is the same as rejecting all server-side processing.
Despite this being called a "cookie banner", this is not _just_ about cookie. When you click "Accept all" you are giving your consent to any form of tracking and information sharing mentioned in the details. The site you visit may share everything they know about you with any third party they mentioned. They can even use fingerprinting (if you've agreed to it) to keep tracking you after you've deleted the cookies.
And then? What's the practical, concrete, real-life consequence for me? Nothing, not even a bit more relevant ads as these run into my adblocker anyway.
I think you're right that many (most?) CMPs are broken, though usually not deliberately. Most try to gate analytics and ad tracking on consent, just often misconfigured. The common exception is companies that deliberately hide Reject All, which is not complaint
My company scanned 209 European regulated sites in June, and roughly 7 in 10 had tracking that wasn't correctly gated by consent. It's rarely indifference, though. DPOs in the EU hold too much weight for that. It's usually a tag added that was never wired into the CMP or something added by a dev or LLM without going through proper review
Full disclosure: I run https://consentmark.com, which measures what tags actually fire under each consent state to create evidence packs companies can show regulators
I don't buy it. 70% of the CMPs being "misconfigured" tells us that even if these panels were broken by design, the companies using them must all conveniently not notice this. Strange, given that even a small risk of large fines or prolonged legal process with public entities would warrant someone paying at least a moment of attention to this. I suspect they are, and the choice of leaving things misconfigured is deliberate.
> something added by a dev or LLM without going through proper review
FWIW, this was a problem long before LLMs were a thing, and it didn't get worse with LLMs. If anything, I'd expect LLMs to get it right by default, because ones ~everyone is using are all trained straight, they won't just silently read between the lines and write code/configs to facilitate one's illegal business model.
> I suspect they are, and the choice of leaving things misconfigured is deliberate.
That honestly doesn't fit our data or my experience. In our scanning, about 60% of the misconfigured sites had a CMP with blocking active but one or two tags bypassing consent controls
Generally those misconfigurations aren't valuable to the business. We don't see for example lots of ad targeting and conversion tracking firing without consent on an otherwise compliant site.
What we do see is things like sites with CMPs generally working, but one or two analytics events tags firing because consent wasn't properly added to a trigger, or embedded Youtube cookies set without consent, or unexpected data from a URL or query param being accidentally ingested by tracking, or devs adding performance monitoring or observability tools to applications without realising the compliance implications
There's not much business logic in paying for a CMP, blocking your own ad stack, but then letting three analytics events pass through
> FWIW, this was a problem long before LLMs were a thing, and it didn't get worse with LLMs.
This isn't supported by our experience. In the last 18 months, we've seen a big increase in ungated tracking that we catch in CI (albeit with overall much higher velocity in general). LLMs will happily add non-compliant tracking to sites, often following defaults that might be acceptable in the US but not EU. If you push back, they'll also happily implement compliant tracking, but it's definitely not the natural default you can rely on
But your comment left me curious, so I just ran an experiment via Codex -p (gpt-5.6-sol) and Opus 5 via Bedrock
Codex returned the vendor quickstart on 5 of 5 neutral prompts. It gated properly when told the company is Irish, with full Consent Mode v2 defaults denied, GA4 only mounting after consent, with a reject button
So models can produce compliant/non-compliant code based on the context you give them, which reflects what we've seen in industry
Our business is giving devs and increasingly LLMs efficient tests to check the tracking they add is as expected for the EU and then providing signed evidence packs that prove that behaviour at a given time
Well, the whole thing is theater anyway. It does not matter what you choose.
They will fingerprint you with or without cookies. They may or not try to honor your preferences, but their "partners" will not try, and by the time you see that banner, it's all out there.
There is also the fact that by rejecting, the cookie that remembers that preference expires after like a day, so you have to click that dumb banner almost every time you visit the site.
This happens when countless websites continue to do the illegal thing of making rejection take more effort than accepting, without being sued into oblivion for repeat offenders. Roughly 9 out of 10 websites today will be doing this illegal shit, and we are too timid to tear them down.
The amount of sites that don’t persist rejecting feels very high, or it’s extremely painful when encountering. The cost of clicking reject is extreme if you have to do it on every page load as you navigate a site.
Well, you would be surprised how many people think that blocking cookies means "no or fewer ads", even people in IT. No tracking, of course, just means it will show less relevant ads, not fewer of them.
So I'm not onboard with the "just block everything by default" crowd. If you frame the question as "Would you like ads to be more relevant to you" instead of "Do you want to allow tracking" you probably get a very different answer from users.
I would like the cookie banner to be changed to a browser setting, but I also would like the option to allow some sites to show relevant ads to me.
IMO any contract, waver, etc., shouldn't be legally enforceable unless the signatory has actually read it. It's always seemed to me to be one hell of a pathway of abuse (in a way) to just be able to bind someone to be legally required to do anything you want, for example, by just relying on them not reading the thing they signed.
How to know if they actually read it? The signature implies that the contract has been read, understood, and accepted. I see no need for any alternative mechanism.
For example, in The Netherlands there is a legally mandated three-day period after signing the contract for purchasing a home during which the buyer can still call off the deal.
The reasoning for this is that it is a seller's market, with demand far outnumbering supply. In practice it is very common these days to end up in a bidding war, and even forego any kind of "sale is void if home inspection turns up issues" clause. Want to think about it for a day or two before signing the biggest contract of your life? Too bad, another buyer is willing to sign today.
With the mandatory three-day waiting period you avoid buyers being locked into a contract they basically immediately regret. It gives them some time to do due diligence, reducing the risk of buying a complete lemon. The seller can ask for a similar clause to be inserted, but it is less common. After all, the only risk to the seller is getting slightly less money for it, and that's already mostly dealt with during the bidding process.
Your specific example is not intended to address buyer's remorse, but mortgage financing. After agreeing to a house sale, the buyer has three days to have their bank sign off on it. Yes, it's nice that it slightly alleviates pressure but the primary goal is to streamline house sales by making the financing details part of the finalization instead of the decision-making process.
I don't believe you’re correct. Certainly in Australia the cooling-off period is all about buyer’s remorse; “subject to finance” is a completely unrelated condition commonly added to the contract, and even with pre-approval it’s probably seldom resolved within three days.
Is that not what the courts are for? I imagine that if a court had to enforce a requirement like this, knowledge would generally be the best kind of proof. If you know what the contract said (or even it's terms in general) that would be enough.
The reason this isn't done is because corporations legal departments love writing 10-100 page contracts that absolutely nobody is going to read.
Well, if you presented them with list of 100 partners each with 20 page of privacy policies and they accept it within 10 seconds it should be tricky to argue that user actually read it all.
You could, for example, require that user answers very specific questions regarding 10 randomly selected partners and how exactly they can use the data ("is partner x allowed to build very detailed profile of you and target you with political adverts that are designed to manipulate you?").
If you did this people would only use the same half dozen sites and competitors would emerge.
We're borderline already there today when the cost of switching is typing a different url at the top of the screen. You add some mandatory 20 minute wait and you'll never see a new site again.
If someone does not read a contract or a legal agreement, before accepting or signing, it's on them, as long as they were provided an opportunity to do so. Dissolving legal agreements because people didn't bother them to read them is not conducive to a society. This also harms people who would like to be able to form contracts with others and enjoy the benefits that come with that (for instance, you usually get something in return for agreeing to something you wouldn't otherwise). The government should not have such a big role to play here and decide which contracts are not allowed to go through.
>If someone does not read a contract or a legal agreement, before accepting or signing, it's on them
When was the last time you read an entire EULA before installing software?
I'm going to guess the time frame is somewhere around "never."
These are nuisance contracts designed to jade people with legalese while stealing their rights to things like class action and enforcing binding arbitration.
I skim or read all the time, and so should people -- but ultimately they're adults and if they want to agree to them without reading, it's their choice (they shouldn't expect to later say they didn't read - this doesn't work, and that's how the current American legal cases were decided as well, thankfully, see e.g. regarding arbitration). Btw, regarding class action and arbitration, many of us already know that these are present in bold in the terms of many services we use or are going to use without even actually reading them.
Good grief no. Using websites in the UK and the EU is an exercise in pain. Every single one of them has the doorway effect where you follow a link to them and you’re faced with some Subway sandwich grade range of choices to be made and you’ve forgotten why you were there in the first place.
As it stands I just hit Accept on literally everything and that’s fine for me.
I used this for a bit and then some sites would just not work. I get it. It’s a hard thing to do and I admire it but getting blank result is far more frustrating than clicking accept each time.
The solution for the problem caused by regulation is more regulation. Sure, we didn't anticipate the negative consequences the first dozen times, but this time there will absolutely not be any unanticipated consequences.
So, what, have no regulations whatsoever then? What an absurd suggestion. It’s a cat and mouse game, sure, but that’s like saying “there was a security hole in the software, might as well give up on trying to secure it.”
It's great. The current law forces people that don't give a shit about user privacy to have a banner (or any other way of asking for consent first) while giving everyone that cares and everyone not wanting to spy on their visitor a free pass.
People click yes too often because it's the easier way to make it go away. This new thing could actually result in a 0% tracking cookie consent rate, effectively making them illegal.
Also there's a big difference between the sites that easily allow you to simply reject whatever their premade cookie settings are. And, the sites that only allow you to use them after you've accepted (example, politico.eu). Or, the sites that do have a 'reject' option, but you have to click through multiple screens and then manually reject each individual option.
Sites that easily allow you to simply reject everything are then a short hop, skip and a jump into browser settings where you auto-reject all cookie/tracking nonsense
And guess who makes the most of devices and the most popular browser, I already see post install "Get most of the browsing experience by agreeing to these defaults."
> automated signals that would communicate your privacy preferences between your device and websites or apps0
Sounds good, as long as it covers the "legitimate interest" bollocks⁰ that is often hidden in inconvenient UI nests as well as the basic preference.
-------
[0] "we see your preference not to be stalked, but we want to anyway, click again for every partner to reconfirm you don't want them following you around"
> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful.
> ...
> You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default.
I've wanted the option to select your cookie preferences once and forget in a brower for ever.
I assume the reason this wasn't done initially was corporate pressure (most people would opt-out of everything by default).
1.2 billion exposed users × 8.17 years×365×3 banners/day×4 seconds÷36 is roughly 10-15 billion human hours lost to dealing with damn cookies since GDPR took effect on May 2018.
I always wondered though why a website in the eu, for the love of their users, won't just drop cookie usage and instrusive third party scripts. Just do analytics on the backend and don't set any cookie, except for tokens in authenticated areas
You can't even save user preferences (like language or other settings) without showing a cookie banner. Edit: I was mistaken. You can't save inferred preferences, but can save explicit user-saved options.
And for a serious website, front end analytics are kind of a necessity to understand how users interact with pages and improve the experience. Note that it certainly doesn't require tracking the behaviour of individual users, just understanding how controls are used in aggregate.
I know it seems like you could work around this with careful design and maybe focus groups and such, but I can tell you we regularly uncover surprising insights from (aggregate) trends in front-end events.
That's not true and is a very common misinformation people repeat online. You can save user preferences in cookies without any consent banner, if the cookie isn't used for tracking.
See here[0], page 6:
> As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’
As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen
You're right; I haven't looked into this in detail in some time. You can't save inferred preferences, but can save things that the user has explicitly selected to save.
They don't love you. They want to track you and make a tiny amount of money off that. Also, they want to hire cheap incompetent staff who don't understand what all the analytics shit they are putting on the website even does.
They don't want love, they want money. Tracking people is an effective way to make money. You can make some money with non-tracking ads, but these websites want more money than that.
Good websites sharing stuff for the fun of it rarely ever add these obnoxious banners. They probably should if they embed other trackers (like Youtube or Google Fonts) but often just don't. It's only the ones that want to make money off you that bother putting in the obnoxious banners.
Even if you only use first-party analytics, you're still tracking users and may still pipe that data to third parties, so you still need a lawful basis for processing PII (of which consent is the least useful one).
Even the use of the word "cookie" is framing by industry to confuse people.
I think this would be a net benefit, but I can see an issue. A lot of news sites today do "accept tracking, or pay us, or you can't access the page". The orgs doing this are reputable-ish so I assume it's considered legal, on some level at least.
So now they'd have a new popup that says "reconfigure your browser to accept tracking, or pay us, or you can't access the page". Which isn't really an improvement.
I am old enough to remember Do Not Track and its failure and problems associated with it. What's new here? Why wasn't it adopted in the first place for GDPR?
Even if you communicated your preferences sites would still want to ask for an exception to them. At least you won't see them ask for consent if you preapprove it.
No need to kill the cookie banner. Just change the system so that everyone in every organization who supports cookies and other forms of user tracking and engagement will have every detail of their own existence and their family's existence broadcast in real time globally 24/7/365. Anyone who tries to opt out is jailed under 24 hour surveillance for a minimum of one year.
EDIT: It's obvious that people really hate this option. Maybe too many here have their incomes too closely tied to the metrics that cookies are designed to collect. It could also be that it is an unrealistic option for everything except the most extreme societal changes.
If you are old enough and look back far enough you may remember the time before all this bullshit like I do. Once marketing and advertising get involved and gain power in an organization, things tend to go to shit fast.
Hypocrisy is the name of the game in SillyCon valley. Push YouTube autoplay slop on kids globally, but no ipads for children of the tech elite. Computer-based instruction for public schools, but 2:1 teacher:student ratios in the local private grade schools that cost as much as an Ivy League University. Etcetera.
It's YOUR browser, a locally running software on a physical computer YOU own which memorize the cookie key-value pair a remote host told YOU to memorize and YOU return the same value later. It's YOU who allowed the cookie. If YOU don't want to allow the cookie, YOU simply not allow it.
You are technically 100% control on cookie. These JavaScript implemented in-page UI has no guarantee to respect your wish. But you have a power to disable it.
It's not quite the same thing since the same cookie used for login (doesn't require consent) could be used for tracking (requires consent). But also, basically nobody cares.
how about:
-if we really don't like targeted advertising, just outlaw it
-then let websites do whatever they want with our cookies so long as they aren't targeted advertising
instead of building websites and writing laws over the span of decades that just seem to want to ban targeted advertising but don't actually do it. FFS.
Okay, but you can quite literally just delete the cookie banner. Cookie banner forces websites to ask for consent, no cookie banner = no consent = less tracking since they usually hold off on ALL tracking until you interact with the cookie prompt.
I have personally never ever had any problems with the cookie banner since Brave deletes them with 100% accuracy, there's sometimes where a site will refuse to function properly, but it's usually sites I don't care about anyway and if I HAVE to get it working I disable brave shield, turn off all tracking, consent and turn the shields back on.
It is unfortunate that most browsers cannot implement this as it goes against what the companies behind the browsers want. Deleting the cookie prompt would stop people from occasionally just accepting all cookies and opting into tracking after getting tired of it.
As written, this doesn't eliminate cookie banners completely, only if your browser is sending a Do Not Track header or similar. That's unfortunate news if you use fingerprint protection - those send default headers, so you'll still be bombarded with cookie banners. Hopefully existing anti-fingerprinting solutions will offer a "default headers but with Do Not Track" option.
Cookie banners are just a kind of ad. If you're at the site, the demand you have for the content on the site is probably close to inelastic (especially on services websites). The site exploits its effective monopoly on the content to raise prices to the user (in this case your time, attention, and experience).
There is ZERO cost to abusing the user over, and over, and over again by asking for permission to track them.
We shouldn't have the cookie banners at all because NO company should be able to do anything with tracking data. Just ban the use of user data by companies and most of SillyCon Valley's garbage behaviors are fixed.
Similarly, I should never get "terms of service updates" from digital companies because there should be no changes that they can make. You can provide the obvious service that you're providing; you can't aggregate my data for any purpose other than directly serving me; you can't aggregate my data with that of other users; if you retain my data for any other purpose, the government should take percentages of your revenue. I shouldn't have to wade through the BS that the mercenary corporate lawyers cook up to extract value from me.
All browser providers have been required by international law[1] to send such a cookie popup suppression signal as set by the user, or one substantially like it, since July 18, 2026 and all web sites have been required to obey it or a superseding Internet standard:
This is not a proposal, it is duly ratified international law that applies to "Every Browser Maker making a Browser available anywhere" and "Any site anywhere that receives a valid signal".
The EU Commission had until July 18, 2026 to modify its laws:
>"The site shall not display a banner, modal, interstitial, or other prompt requesting a choice already expressed by the signal. It may optionally provide a “Cookie Settings” or “Privacy Settings” link. This Law overrides all laws requiring such a display. Where any country or supernational entity has a conflicting law, it must rectify the Law within 30 days not to require such notification."
Therefore, insofar as it has not rectified its laws not to require such a notification, the EU Commission is in violation of international law as of 8 days ago.
Under section 7.3, "The State of Utopia may order compliance, require corrective updates, suspend non-compliant distribution, and impose civil penalties. Fines may be levied in any amount for continued non-compliance." so we can fine the EU Commission whatever you guys want ($1 billion? $10 billion? whatever four and a half millennia are worth) and just distribute the collected fines among you all as cash payments.
Would have gone harder without the Corporate Memphis/Alegria art which is the art always used to try and convince you to hand over your tracking rights.
Not wrong in the EU, you don't need to ask for consent nor notify about cookies which are required to make the site functional. Tracking and ads don't fall under that though, which is why every site these days does need to ask for your consent.
No, you need to always ask for consent for cookies if they come from a third party, regardless if they are only required to enable functionality.
You also need to ask for consent each time data leaves the website (for example when loading an image from a third party host). You can't even load a font file from a third party server because the users IP reaches that server without consent.
Cookie banners don't just handle third party tracking cookies, the are needed to record consent for a huge variety of cases. "Banning tracking cookies" does not remove the need for cookie banners.
Well if the cookie comes from a third party it implicitly allows tracking.
Also AFAIK the Google Fonts question (is the IP alone already PII, if Google has no way of tying the IP to a person) has not been decided by the ECJ yet. There've only been decisions by lower level German courts that are still in dispute.
IP addresses are PII according to german law, that debate has been settled long ago by final court-rulings afaik.
"Well if the cookie comes from a third party it implicitly allows tracking."
Yes, because this makes tracking possible you have to gather consent first, regardless if tracking actually happens. Very bad solution, they could just define how data can be legally used, instead of also overreaching by defining how data can be legally transmitted.
That's the problem with the regulation: It defines how data can be legally transmitted instead of defining only how data can be legally used, resulting in nasty side-effects like making embedding third-party content illegal even if its not used for tracking.
This is actually slightly narrower exception than people (and regulators) think. The exception is:
> strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
One very ignored qualifier here is "information society service". This is defined in Directive 2015/1535 and one of the requirements is that the service is "normally provided for remuneration". That is usually understood to mean that the service needs to be tied to provider's economic activity. This effectively excludes, for example, public authorities websites which are for their own public duties. It does however include e.g. ad supported websites.
And yes, I'm aware that many national implementations actually miss that qualifier. That can save the non-commercial private sector websites, but public authorities do not benefit from Member States failing to transpose Directive correctly.
What I hate about EU laws is they tend to word these things like this.
People act shocked when it leads to unintended side effects, but companies legal teams are just telling them they have no idea how a judge will interpret these broad wordings in regards to their business.
People say this fixes "future loopholes" but as you see with the cookie banner, it just leads to every company assuming the worst case scenario.
Going back years of conversation on cookie banners you'll see a constant argument on when they're required or not precisely because it's not defined explicitly.
Apparently the eu official website really needs to track you then. For what’s essentially just static content. I’ll consider dropping cookies banner when their website can work without. Stop the “do as I say not as I do”
They apparently hired incapable people to build that. Very silly to build it in a way that kind runs contrary to what the intentions of the very laws they are making are.
I get similarly upset, when I see Google tracking on official websites of government or public institutions.
This ones a little tough. Advertising through trackers is a massive portion of how sites get revenue. Going back to the old days would decimate this space, and have widespread effects on the internet (though im not sure it would be noticed by most of us anymore with how dead the internet feels now)
I guess what I'm saying is, there is no good solution here. I don't want every site I visit to require a usage fee just to browse. Imagine if slashdot turned into WSJ with a paywall for every article.
Kagi already does something like this, and cool - if you use it enough, maybe its worth a subscription. I dont find myself googling (searching) much anymore, so paying to do so just becomes something i need to find a way around. Like API token usage for AI, using it is like making a new recipe in the oven every time. You expect it to work but you have to invest the time and money into the attempt before you can find out the results (whereas you dont have to do this on free chatgpt, google search with ai, etc as comparison). Too much investment without guarantee of results. I'm fine without that guarantee as long as im not wasting my time and money upfront.
Every website that you visit and decide the article is worth reading, means a human spent time working on the content, and people spent time building the website. Reading on the Internet has a cost associated with it, whether its your privacy or your dollars.
I kinda of agree with you - there is no good solutions if we are only changing one or two things at a time .
I am kind of wanting to f around and found out. I missed the old internet were most of the big websites are run by hobbyist. I know some of them may not be able to pay the bill without ad.
May we can figure out something once we leveled the playing field
> Advertising through trackers is a massive portion of how sites get revenue
Sure, but magazines get a massive portion of their revenue through advertising without trackers. Same with television, or radio, or billboards.
And the ad space isn't exactly very healthy either. Take a large Youtube channel like Linus Tech Tips, for example: AdSense only accounts for 10% of their revenue! Youtube has been drowning people in ads and it still barely pays any money.
I think we should seriously consider the possibility that targeted ads might be less profitable overall. Ad blockers didn't become a thing solely because ads appeared on the web. Ad blockers became popular when ads became obnoxious and privacy-invading. With the current state of the web ad blockers are a hard requirement for a reasonable browsing experience, so the only people seeing ads are the handful of suckers too ignorant to install them.
But if ads aren't as invasive and obnoxious, people would have far fewer reasons to install ad blockers. See for example the Acceptable Ads program of Adblock Plus. If switching to user-respecting ads resulted in a significant portion of people turning off their ad blockers, it could very well result in an increase in ad revenue!
The companies want to track everything you do on the web. EU passes a law that says they have to ask for permission first. They all comply maliciously because they still just want to track you.
No, its the website's choice. They want to track you. The government said they need permission to do that. They could offer a better experience by just not tracking you.
This should just be a browser setting with a per site opt-in when more data collection is needed. Just like you can enable notifications, webcam etc... or set it to always deny.
Why the fuck do people have to keep stating the same preference over and over again. This is a hellscape of bad government AND corporate policy colliding.
Yeah, the "do not track" setting I think was the browser based solution that sadly never took off. Better government policy should have required respecting that setting instead of the cookie banners.
It's great they're talking about it, but they should just do like California and DO something about it.[1]
> When the law takes effect in January 2027, Californians will see new privacy options in web browsers. When enabled, these controls will automatically inform websites of their privacy preferences, helping to protect personal information from being sold to data brokers and other third parties. This means they will be able to protect their data — like their browsing history, location data, purchase history, and personal interests — across the entire internet with a single step.
This initiative is ignorant and idiotic.
The authors don't even understand the purpose of cookie banners.
1. Making tracking impossible/illegal would NOT kill cookie banners, since you need them to record consent for other purposes as well, such as embedding a video from a third party like YouTube.
2. The GDPR explicitly prohibits site-owners from making cookie banners misleading. The law is already there, it is just not very well enforced.
3. "This results in up to 90% of people saying “YES” – even though only around 3% actually want to be tracked online"
This claim is grabbed out of thin air and can be dismissed as such.
4. "The solution: automatically communicate your privacy preference"
This is nonsense because it does not actually solve anything, because you need to record consent for a variety of purposes, not just analytics/tracking.
5. Killing tracking would kill the value of ads (since they are not targeted anymore), resulting in a reduced ability for small businesses to advertise and a hugely increased amount of ad spam everywhere.
Few targeted ads > Many untargeted ads
Unless you want an internet where advertising is no longer possible, this solves nothing apart from stroking a few activists ego.
This just doesn't make sense. EU regulations are already making progress in improving online privacy: (a) No cookie banner required for functionally necessary cookies, (b) there needs to be an option to refuse tracking cookies in the cookie banner, (c) the dreaded cookie banner appears only the first time you visit a site.
I would say, we are like 80% there. Yes, there are still some dark patterns employed by cookie banners, trying to trick you into accepting tracking. But they are not too hard to make out. And they can be fixed by tuning the regulation a bit: Require the opt-out to be the first choice and the only one with highlighting.
Ad tracking is not going away tomorrow. If we ever are going to get rid of it, we first need legislation to defang it so it stops being a cash-cow. "Tracking prohibited by default" is a great end-goal, but we are not there yet.
Reading between the lines, it appears that there is some new solution proposed to "automatically communicate your privacy preference". That's nice, but when e.g. the Do Not Track header was tried, it just fell flat. So until this new solution is implemented and adopted, I'll take my websites with a cookie banner, thank you.
It is an unfortunate choice that the campaign obsesses over the cookie banner, instead of trying to actually advance the solution that would make it obsolete.
> Yes, there are still some dark patterns employed by cookie banners, trying to trick you into accepting tracking. But they are not too hard to make out. And they can be fixed by tuning the regulation a bit: Require the opt-out to be the first choice and the only one with highlighting.
The fact that we are still talking about this literally a decade after the GDPR was adopted shows that this isn't working. It has turned into a cat-and-mouse game, and the regulators just don't have the manpower to effectively rules-lawyer every tiny change.
> when e.g. the Do Not Track header was tried, it just fell flat.
... because there was no reason to follow it. There was literally zero consequence for ignoring it.
This new proposal makes the Do-Not-Track v2 header legally binding. User sends the header and you still show a consent popup? You're breaking the law, simple as that. No weaseling yourself out of it, a simple screenshot is enough.
Any regulator could build a fully-automated scanner in half a day: ask the local TLD registrar for a mapping of websites to companies, have some script request the page and do a regex search for "cookie" (or use AI if you are feeling fancy), take a screenshot, pass it to an intern to double-check, then automatically send out a €100 fine. Double it every X weeks they haven't fixed it yet. Want to fight it in court? They have screenshot, you lose, now pay.
Actual title: "Stop the tracking circus. Kill the cookie banner!"
;dr
The "cookie banner" is an interactive method used by "adtech" companies to try to get user consent, as required by EU law. The forced interaction makes this method annoying
Google and other "adtech" companies are lobbying EU Member States to vote against giving users a means to non-interactively deny consent
I'm from France, and when browsing, I often get paywalled when I reject all non-essential cookies. The CNIL (who is in charge of the application of GDPR) ruled that this was compliant with GDPR as long as another website was offering an alternative without cookies[1].
Are there similar rulings in other EU states?
The most frustrating thing about the cookie banner is that the solution was always obvious: just use the DNT setting on your browser (Do Not Track). It already existed.
However, powerful interest groups like ad companies that profit from your attention (which hysterically virtually powers the Internet today) were able to stop it from happening.
It was debated way back in 2009 when the GDPR was being developed. Iirc the argument was that browsers accept cookies by default so users do not get a fair consent moment. This is obviously easily fixed by regulation requiring browsers to ask users once.
Seems extremely backwards that we chose to forever darken the entire Web browsing experience just so users can "benefit" from a per-site option to let Google profit from them, with virtually zero payoff for the end user (ad relevance?).
P.S. If ad revenue is an essential pillar of Internet survival and fruition, the clear alternative seems to be sharing a fraction of that revenue with the tracked consumer.
Do Not Track cannot satisfy the GDPR, it requires that you obtain informed and specific consent so even if a user had the DNT bit set to consenting you would still need to show the banner.
Perhaps it would be simpler to make all non-essential cookies illegal. I cannot imagine why any reasonable person would want to accept non-essential cookies, other than in the course of following a path of least resistance.
This is the only way. They'd also have to make all third-party assets illegal as well though and that may break some legit use cases, and make it a lot harder to use CDNs.
I've wondered for a while what value is assigned if a user ignores or dismisses (when possible) a cookie banner without actively selecting accept or decline. Anyone know?
> Stop the tracking circus.
Kill the cookie banner!
Perhaps the EU Commission could start by stopping the circus on its own website and killing its own cookie banner: https://commission.europa.eu/index_en
Got news for you... California now has its own laws around similar things, and the trolling lawyers are out there sending threatening letters to our clients. I manage a few thousand websites that operate across the US, and things are getting a little crazy with the lawyers lately.
It's just like ADA compliance and trolling lawyers all over again.
I find the cookie banner always ironically wrongly labeled. Everyone claims to "respect your privacy" while actually disrespecting the privacy. If they did actually respect the privacy they would not use non functional tracking cookies and there would be no need to display the banner.
The cookie banner is a significant accessibility problem, for blind and low vision users, among others. I would like to see a stronger push to attack it from that angle.
I am a builder in the same space(tracking analytics) and I agree with killing the cookie banner. It is really annoying and most of the time, sites don't even respect the decision, they just track it nonetheless. Setting up a consent stance once per browser is way better, also I think there should be fines for the websites that don't follow the same.
* "This proposal for privacy signals is part of an EU law reform called the Digital Omnibus. Most other parts of this reform are problematic and would weaken people’s rights. We want to make clear that we do not support these other aspects of the proposed reform."
I never understood why visited websites and all their first and third party cookies are not isolated by default in browsers.
There are so few sites where I really need cross-site logins to work that an opt-in would be much more preferable.
Have all sites set cookies on whichever third party they want, but don't share those cookies over. Add an explicit "Do you really want foo.com to share data with bar.com?" if you really need to see those facebook comments on your news site.
My request to the owner/promoter of the site: provide an email template that we can send to our representatives. I'm willing to send such email, I've the list of the people I want to reach. But what is too complex is to write the appropriate email... Can you help me with this ?
I have been successfully using the Consent-O-Matic extension [1] to auto-decline all cookie and GDPR banners. As much as I'm not comfortable giving potential access to every website to some extension developers, this improved my internet experience almost as much as AdBlock.
It probably depends on how people interpret it right? I doubt anyone is saying "I love being tracked" - but some people might choose personalized ads over anonymous ones.
I don't really use youtube natively a lot anymore, but I used to with Google's "personalised ads" turned off. I don't know if you've tried that, but the ads Google serves you if you opt out of personalised adds are sketchy, creepy and mostly not child appropriate (a lot of medical stuff, plus adverts for mail order brides etc). Back then I opted in to personalised ads because being tracked seemed a better option to me than being served inappropriate material without my consent.
Anyway, that's a long rant, but my point is, there's edge-cases and weird contexts in which I can imagine people saying something like "of the options I see as likely to happen, I'd most like to be tracked".
Well if the conclusion is "3% of people want to be tracked online", I'd expect the question to be "do you want to be tracked online" or similar, not "do you want to receive personalised ads"?
I dunno, the people I've talked to about it (small sample) have said they don't mind because then they get more relevant ads. It's very hard to reason with that sort of thing!
Can the proposed consent automation kill the 'legitimate interest' abuse is the most important question. Even getting towards a single click refuse all requirement would eliminate the majority of dark patterns endemic today.
paulddraper | a day ago
I don't want randomnewssite to track me. But a favorite online store...I do want help with recommendations.
dymk | a day ago
frollogaston | a day ago
amelius | a day ago
qurren | a day ago
Ironically, this has the effect of cookie banners reappearing every time because they cannot place a cookie that says that you have rejected them.
mzajc | a day ago
Unfortunately this means you have to view a lot of the web through archive.today or web.archive.org - I would know because I have uMatrix configured this way.
qurren | a day ago
I disable cookies for Amazon because I need to login; if a local business wants me to buy from them directly they need to:
1. Not give me a CAPTCHA or cloudflare shit
2. Give me free shipping and a lower price than Amazon minus 5% cashback that I would get on Amazon
3. No registration needed to check out
and I'll buy from the local website. It's really not a high bar, they need to learn to not shoot themselves in the foot.
As for the news websites -- bleh. If they want me to read it, make it easy to read. As in, I click into it, show me the content. If I get a popup, banner, anything that covers up the content, I bounce. I'll get the news from social media anyway. If they'd rather I get it from their news website, they need to learn to not make me bounce.
I'm not opposed to advertising if they want to get revenue from that, but it should not track me, not cover up content, and not load megabytes of JavaScript to do it.
frollogaston | a day ago
Session cookies for all sites would be fine if passkeys weren't like "We support passkeys. Do you want to use a passkey? Press ok again to use your passkey. Do you consent to using your passkey? Now please authenticate yourself to use the passkey... √ Thank you for using passkeys. Press ok to continue."
tcfhgj | a day ago
-> not really sensible
Phemist | a day ago
frollogaston | a day ago
Phemist | a day ago
joeframbach | a day ago
paulddraper | a day ago
It's easier to click a single button than hunt for how to create/access an account for the brand.
hieKVj2ECC | a day ago
troupo | a day ago
It wasn't on EU Commission to "finally propose a solution". The soluton has always been there.
Somehow, Google, aka world's largest tracking and advertising company incidentally making the worlds' dominant browser and completely dominating all web standards, couldn't be bothered, and instead was pushing crap like FLoC
cube00 | a day ago
Google knows if you can set this once it's game over for their adverting business. At least with the cookie banners, there's a possibly you won't refuse every banner.
Especially those banners that only have "Accept" or "More options" with all those checkboxes to clear.
rpdillon | a day ago
> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.
Fortunately, if you have uBlock Origin, you can enable Easylist cookie notices under annoyances and avoid most of them. Combine with blocking third-party cookies, and the problem pretty much disappears.
The fact that the EU tried to regulate this stuff is a shame, because regulation is not a good remedy. End-users have agency here. The solution is to enable end-users to have control in their browser (which they always did, so it's an issue of education, like so many things).
Shame that Google is trying to kill uBO though. Extremely pleased that Brave continues to support it.
mrkeen | a day ago
The Do Not Track header is the only technology needed. The rest is compelling companies to obey it.
cwnyth | a day ago
the__alchemist | a day ago
hborscht | a day ago
the__alchemist | a day ago
tcfhgj | a day ago
Consent-O-Matic -> automated configuration to your preferences using the dialog provided.
I still don't care about cookies -> least privacy friendliest option, because it may opt into undesired tracking (its goal is just to remove the annoyance of the dialogs)
pndy | a day ago
tezza | a day ago
Need to look up a bus time? Full screen cookie consent with accept buttons drawn OFF THE SCREEN.
inigyou | a day ago
igregoryca | a day ago
ehnto | 20 hours ago
4thguy | 11 hours ago
Jtarii | a day ago
inigyou | a day ago
debazel | a day ago
inigyou | 11 hours ago
albedoa | 18 hours ago
Your kind comes into every one of these threads and says some version of "well if they weren't tracking then they'd have nothing to worry about and no need to show a banner", but that is so obviously not true to anyone who uses the web. You absolutely do not need to defend a law that is not working.
TechSquidTV | a day ago
PaulRobinson | a day ago
Just step back and ask yourself what each side of that debate is trying to achieve and why. What is motivating them? Why are they motivated in that way?
Don't just recite what you "know", think, look, research, figure it out. It might sound good to have a one-liner like this in your back pocket, but do you really believe it after looking at the publicly available information that it is their real intention to conduct a "crusade to destroy the internet"?
tcfhgj | a day ago
amelius | a day ago
(because it drives consumerism)
jebronie2 | a day ago
tcfhgj | 7 hours ago
jebronie2 | 7 hours ago
tcfhgj | 6 hours ago
tysilva | a day ago
convolvatron | a day ago
PaulRobinson | a day ago
In the UK a few news sites have changed cookie banners to "you can accept and see this stuff for free, or you can sign up for a subscription, which would you prefer?". It's the only time I hit accept (and then clear browser history).
If blanket preferences from browser signals became the norm, a segment might open up where you would configure preferences and a data broker would make sure you get something in return for your data. At minimum it might force paywalled publishers to consider that as a "lite" subscription option.
troupo | a day ago
ads don't require invasve and pervasive tracking
alt227 | a day ago
Alpha3031 | a day ago
(see e.g. https://iapp.org/news/a/cjeu-clarifies-cookie-consent-requir... https://www.edpb.europa.eu/news/edpb-consent-or-pay-models-s... )
troupo | a day ago
Again, that is not a requirement. If your argument is that they give us content for free because of ads, ads don't require pervasive and invasive tracking. Or hiding stuff behind paywalls (since ads pay for it).
alt227 | 12 hours ago
Im pretty sure if a company said something like "Here have free netflix for life, as long as you install this browser plugin that provides us with information about your shopping habits" millions of people would bite their hand off.
jamiequint | a day ago
crote | 23 hours ago
Advertisers are willing to pay more for privacy-invading ads because they believe they are more effective. If privacy-invading ads were illegal they'd just go back to context-dependent ads like they have been using for the thousands of years before the internet was invented, and after an adjustment period the revenue will just bounce back to where it was before.
Most advertisers know this already. If privacy-invading ads were so effective, why are all the major brands now using influencers to market their products? Why go through the effort of finding a specific Instagram channel which might be a good fit and convincing the operator to enter a brand deal, when you could also just directly pay Instagram for a highly-targeted ad one swipe away?
troupo | 15 hours ago
That's what the tracking industry keeps telling you with zero evidence it's true.
And then there are studies like this one: https://www.sciencedirect.com/science/article/pii/S016781162 which say that targeted ads need to be 100% to 700% more effective to be as profitable as non-targeted ads
inigyou | a day ago
broken-kebab | a day ago
alt227 | a day ago
fmbb | a day ago
They did not read the text to agree.
It was the fastest way to get the banner to go away. Sometimes they force you to confirm multiple times if you click ”none” or ”minimal”.
tysilva | a day ago
scbrg | a day ago
jsrozner | a day ago
lucianbr | a day ago
GJim | 11 hours ago
AlienRobot | 23 hours ago
crote | 23 hours ago
Why? Plenty of websites operate just fine with no or near-zero ads. Just look at the one you are currently on!
And what's with confusing "relevant ads" with "privacy-invading targeted ads"? There's still plenty of ads in print media, on television, and on billboards: none of them are invading my privacy, yet they still manage to be relevant by choosing a medium with a certain target demographic. Websites used to do the same, there's no technical reason we can't return to this.
deathanatos | 23 hours ago
I do not want the gas station, or the airplane I'm on, spying on me to build relevant advertising. That is the end game of "relevant ads": my gas pump already serves me ads, the airplane I'm on serves me ads, my own car now (via a software update that occurred after purchase) serves me ads. Monitors now serve ads. TVs are abusing people's Internet connections, which isn't ads, but it's basically the same problem: if I can abuse the customer without consequence, why shouldn't I?
Just no. The problem is, I as a consumer cannot vote with my wallet: companies can and will go "I could take your money, and earn $X, or I could do that and ads and earn $X + $Y."; there is not reason for them to choose the former, and most markets are so concentrated (e.g., airlines) that there is not ample competition for the market to provide ample "vote with wallet" choices. Further, in the car example, it's just bait and switch: even when I think I can vote with my wallet, the company can just alter the terms of the deal, knowing full well the switching price of a car makes me subservient to them.
albedoa | 18 hours ago
fsflover | 5 hours ago
Of course it is: https://news.ycombinator.com/item?id=43595269
inigyou | a day ago
ApolloFortyNine | 19 hours ago
Any future law in regards to this will likely just lead to the companies that already got consent (companies you already have accounts with) becoming even deeper entrenched.
Non targeted ads pay a small percentage of targeted ads.
singron | a day ago
ktosobcy | a day ago
micromacrofoot | 21 hours ago
Phemist | a day ago
So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...
tgv | a day ago
The online safety acts and its EU counterparts are somewhat risky, but nobody wants the mention the only proper alternative: a total ban on "social media." Not just for kids, but for everyone. Or a ban on smart phones, that would work too, at least short term. But: money.
broken-kebab | a day ago
SoftTalker | a day ago
Kuyawa | a day ago
When restoring factory defaults, the same question, just in case the phone is sold, gifted, stolen or whatever.
If you are going to give a phone to a minor you should set that option right from the start.
conception | a day ago
alt227 | a day ago
Exactly. The problem is its from the parents side.
monkpit | a day ago
alt227 | 12 hours ago
alt227 | a day ago
This is unfortunately the reality.
The other day a friend asked me to help her make her phone safer for her kids to use. I started by asking if she set permissions on the apps she downloaded. She looked at me blankly, "What permissions?". I proceeded to show her how you can granularly control what you allow each app to do on your phone and what access it is allowed. Her head blew up, she had no idea any of this existed and after gong through a few menus, she didn't care any more. It was all too complicated and too much to think about for a busy mum.
This is why governments unfortunately are having to try to protect people from themselves. As tech competent people it all seems so simple to us, but we need to remember the majority of the population just click 'Allow All' and blow past all permission and security questions as they have no idea what any of it means.
dijit | a day ago
I haven't set up an Android in a while, but, I doubt it's massively different.
alt227 | a day ago
dijit | a day ago
We should just give up and give random individuals access to everyone's camera roll.. no other way.
dwedge | a day ago
dijit | a day ago
Bit of a mouthful though.
Latitude7973 | 10 hours ago
dwedge | 7 hours ago
SiempreViernes | a day ago
dijit | a day ago
Greatest minds of our generation couldn’t possibly invent fast profile switching.
Lost technology.
fuzzzerd | 19 hours ago
mcfedr | a day ago
SoftTalker | a day ago
SoftTalker | a day ago
alt227 | a day ago
SoftTalker | a day ago
GaryBluto | a day ago
preg_match | a day ago
Yes, as a parent, you are required to put in more effort into parenting your kid than random hypothetical people. That's obvious, and has been the case forever.
I understand the concept of community, but community is not me sacrificing my privacy for someone 1000 miles away.
If parents don't want to do X, Y, and Z to lock down their devices then that is their right. And I support their rights, so the conversation is over right then and there IMO.
djaro | 23 hours ago
The aim here is to protect the children. "Just let parents protect them" doesn't work when there's millions of parents that won't care.
BiteCode_dev | a day ago
readread | a day ago
Options between "we don't have tech in the house" and "wide-open tech, we have it all" are all some amount of painful, usually for no good reason.
(I remember once investigating how to do some pretty basic stuff for this in Linux, hoping to find something nicer than manually setting some executable permissions and firewall rules and then having to go back and change them all the time, and the closest thing to a guide I found was an old article from Red Hat that basically lead with "LOL, good luck you poor sap, Linux sucks at this" before going on to explain the various bad ways available to sort-of, but not entirely, accomplish it with a lot of work, and significant ongoing time-burden)
vidarh | a day ago
It'd be even better if there was a way for people to selectively turn it off for specific devices without MITM the connections. It wouldn't be that hard to come up with a mechanism for that.
mcfedr | a day ago
tgv | a day ago
djaro | 23 hours ago
mcfedr | 15 hours ago
throwawayk7h | 14 hours ago
mike_hock | a day ago
Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.
This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.
aspbee555 | a day ago
https://creepjs.org/checker
mike_hock | a day ago
It's not hard to make privacy work when you are the government rather than working against a hostile one.
inigyou | a day ago
Jtarii | a day ago
morsch | a day ago
mike_hock | a day ago
inigyou | a day ago
mike_hock | a day ago
When prompted by the browser on first login/signup, yes, the same way the password manager works. With stored passwords, keeping the login cookie doesn't even add much value.
inigyou | a day ago
Well, there is a skip button. It's labelled "accept all"
bhaak | 12 hours ago
Every time you get a cookie banner with options, the website wants to know more about you than the law permits by default.
toxik | 12 hours ago
croes | a day ago
IanCal | a day ago
It’s baffling we’re having this misunderstanding on this site in 2026 still.
TurdF3rguson | 19 hours ago
dredmorbius | 15 hours ago
Browser fingerprinting / Panopticlick: <https://ssd.eff.org/module/what-fingerprinting> <https://panopticlick.org/>
On-device identifiers --- Google AdID (GAID), Apple IDFA, etc.: <https://developer.transmitsecurity.com/guides/risk/secure_de...> <https://geraguard.com/blog/how-device-fingerprinting-works-m...> <https://alejandrocordon.com/blog/2025/01/18/unique-identifie...>.
TurdF3rguson | 14 hours ago
And BYW, browser headers can even be a violation if it's determined that you are using them for tracking users in a way that violates ePrivacy demands.
It's still a cookies thing.
AlienRobot | 23 hours ago
So instead everyone stays on Facebook, Instagram, Reddit, and Twitter, which ALSO operate on ads and have far more information on their users than any third-party ad tracker could ever have.
None of this has gotten rid of the privacy problems. It just consolidated them into the worst offenders while jeopardizing the plurality of the web. Now instead of people being tracked by Facebook on a website with a third-party cookie in a like button, they are tracked by Facebook on Facebook in a Facebook page because they never leave Facebook.
rtpg | 22 hours ago
The cookie banner isn't about the usage of cookies, it's about _the underlying tracking_. You're allowed to "just" use cookies for normal shit! You can make a website where you use cookies to store login state for a user, without a single banner.
The thing is that every company in the world feels the need to add 1000 tracking cookies to anonymous users to track them through conversion funnels (on top of the ad stuff). That's what you have to inform people about
You can use cookies normally without a banner! You can't track without consent! Every cookie banner is actually a "we want to track you" banner. Calling it a cookie banner is playing into the confusion about what those banners actually are meant to communicate
echelon | a day ago
THIS
Holy shit. This is such an obvious fix. And it shuts up those surveillance state goons immediately.
My God, why have we tried to summon up the ghost of 1984 when such a simple fix as this will do.
Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.
The blast radius is zero.
Good God, we need to fast track this into browsers right now. If we hurry we might be able to point to this as the technical fix.
Once some of the infrastructure exists, OS vendors can hook into it.
Firefox devs - please do this right now. Please spearhead this.
I might have to vibe code an advocacy site for the spec and set up a GitHub / RFC process.
spiderfarmer | a day ago
inigyou | a day ago
dijit | a day ago
I've long since considered that the efforts for online child safety should be pointed at educating parents and spearheading some kind of certification of compliance for child safety of software and websites.
[this product is certified to adhere to EU:CSA]
Then you can block everything not certified, and the software that does the blocking would also be certified, the two major prongs you need (endpoints and sites working together: else they're blocked). The rest of the money goes to education for parents about this fact, and the dangers of not doing it, and how to do it.
This is super "easy" (when comparing to the effort it would take for putting backdoors in everything).
Which is why I think that the reason is definitely not child safety, and more about crime control.
Me talking about UK blocking people unless they ID themselves in 2013: https://news.ycombinator.com/item?id=6979295
Me talking about how its disingenuous because we have superior technical solutions to this particular issue last year: https://news.ycombinator.com/item?id=45010902
alexandre_m | a day ago
Paracompact | a day ago
alexandre_m | 23 hours ago
I'm not sure to understand the proposed solution here, but it seems someone could just use a different web browser client who don't inherit these restrictions.
tangotaylor | a day ago
CA tried this with AB 1856. I wasn't a fan of this (neither was EFF) because of the privacy and tracking concerns of blasting the fact that the user is a child to all websites.
https://www.eff.org/deeplinks/2026/05/one-step-forward-two-s...
It would better for the block to happen at the device level. That is, the browser knows it's on a child's device and has a whitelist of allowed sites.
There is already an RTA (Restriced to Adults) header where the website self-labels that it's for adults only and the browser can block it while protecting the user's privacy. I'd prefer expanding the use of RTA.
dageshi | a day ago
The web is too big and changes too much and that's before we get to the issue of applying laws to a whitelist based on different juristictions worldwide.
And I have to question, who would administer it? The parents? They won't. Google or Apple? Why do they want to deal with irate parents or culture wars around what is or is not on the list?
There is obvious increasing demand for this from parents, politicians are going to act on it, I think a "this is a child" header is the only one that actually really works. It works for the parents because it's easy to setup. It works for websites because they can cleanly identify a child and filter content if appropriate.
It seems to me that every other solution than a "this is a child" header is either impractical or way worse.
tangotaylor | a day ago
Yes, granted, a globally enforced whitelist probably wouldn't work. I'm referring to bespoke lists that parents control. I know plenty of parents that use this. e.g. here's Apple's feature:
https://support.apple.com/en-us/105121#:~:text=Prevent%20ina...
> It works for websites because they can cleanly identify a child and filter content if appropriate.
This still doesn't solve the problem of different jurisdictions and culture wars of what is or isn't appropriate for kids. All this does is move the liability upstream to websites instead of the devices. That is, instead of the browser deciding what's appropriate, now Youtube, Reddit, etc have to decide. And, as we've seen with the OSA in the UK, typically smaller platforms can't handle the enforcement cost so they just shut down entirely.
https://onlinesafetyact.co.uk/in_memoriam/
The larger platforms often use overbroad CYA measures and throw up age verification where they don't need to (Reddit has done this in the EU), or just ban minors (Anthropic and character.ai did this).
As far as blocking explicit content, a self-labeling requirement like RTA accomplishes the same thing as a "this is a child" header but without the liability CYA and without the privacy concerns.
Where the "this is a child" header solution could theoretically win is allowing kids to access websites in a limited child-safe way, e.g. going to Reddit in child mode automatically shuts off certain subreddits. But, as we've seen, it just doesn't work well in practice and usually frustrates parents by overly broad content policing and liability theater. Kids are also at different levels of maturity and I've seen them get frustrated when they're binned into age categories that they feel they don't deserve. e.g. a 12 year old might be plenty mature enough for the 13-16 age category.
But my real objection to the "this is a child header" is the privacy risk and surveillance risk. I don't think it's worth it.
Phemist | 11 hours ago
You mentioned AB1856 which seems waaaaay broader than emitting an age bracket header based on user settings. It puts the onus on the website operator to not only prevent presenting content to wrong age bracket users, but also to determine the age bracket of the user.
Websites are shutting down wholesale because they cannot reasonably afford the CYA, or dont want to out of principle.
In echelons scheme the parent would be voluntarily setting the age bracket on the childs device right, so if a 12 year old is more mature, then go ahead and set their device to emit the 13-16 age bracket header. If you as a parent dont believe in this, then leave the bracket unset.
For a website operator it would be trivial to block the user from accessing the site if the suggested age bracket is too low (as long as we can agree on a single way of doing things, of course). Larger operators can do more heavy content moderation and present a filtered view to those same age bracketed users.
It is true you are adding more tracking signals, and I am sensitive to the free speech issues, but children are not fully emancipated members of society yet and parents need tools to deal with the difficulties of raising children in a digital society. The alternative now seems to be OSA-like, which is even more intrusive and a risk to privacy and perhaps free society as a whole.
Of course, OSA is really the goal and not the method, and we have to remember it is never about the children. Would children have been protected from e.g. andrew mountbatten if OSA had been around at that time?
Phemist | 12 hours ago
bonoboTP | a day ago
Levitating | a day ago
sandeepkd | a day ago
Overall this is a common sense solution. The challenge is that a significant industry makes money by collecting and selling data. It makes it harder for businesses who depend on it, they are going to get creative and will eventually come up with some dark pattern to circumvent it.
mmarq | a day ago
IshKebab | a day ago
reddalo | a day ago
pndy | a day ago
In 2024 Mozilla acquired Anonym from former Meta executives and decided to introduce PPA: https://hn.algolia.com/?q=privacy+preserving+attribution
alt227 | a day ago
I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies? Who knows.
maccard | a day ago
On our go-live form there’s a question “do you use cookies” and it’s yes/no. If you say yes legal block the site from going live without the pre approved cookie banner…
jarofgreen | a day ago
Just checking, you do know that still counts as tracking and may fall under GDPR rules? GDPR was never just about cookies.
maccard | a day ago
crote | 23 hours ago
It was never about the cookies themselves. That just happened to be the most common form of tracking in use when the GDPR was originally written. Cookie-less tracking still requires a consent prompt, tracking-less cookies never required one.
maccard | 13 hours ago
> it was never about the cookies themselves.
The ePrivacy directive was about cookies. GDPR is about user consent and data handling - the cookie banner is from the ePrivacy directive.
> Cookie-less tracking still requires a consent prompt, tracking-less cookies never required one.
Where in the GDPR or ePrivacy directive does it say cookie less tracking requires a consent prompt?
And on tracking-less cookies not requiring one - that’s my entire point.
JoshTriplett | a day ago
I mean that both in the sense of "you, plural" (your company should fix that) and "you, personally" (because diffusion of responsibility is a real issue, and someone needs to actually do it).
maccard | a day ago
esperent | a day ago
50% that, and 50% that way more companies than you expect are harvesting and profiting from your data.
HiPhish | a day ago
That has been my guess as well. If you run npm install half-the-internet you have no idea what's in there, so just slap on that cookie banner for good measure. Of course the real problem is not knowing what's inside your application, but the thought process is "eh, if a blanket cookie banner does the job then that's good enough for me".
reorder9695 | a day ago
SoftTalker | a day ago
inigyou | a day ago
JoshTriplett | a day ago
NopIdoN | 22 hours ago
If the banner's not required, it ends up saying stuff like "we'd like permission to share your data with 0 partners". Ever see that?
The fact is most website operators want to use your data for non-essential purposes.
kuerbel | a day ago
alex_suzuki | a day ago
charcircuit | a day ago
preg_match | a day ago
TheCoelacanth | a day ago
You need to disclose it in your privacy policy, you need to delete it after a reasonable retention period and you can't use those logs for other purposes like ad targeting, but you don't need a consent banner to track things that you are legitimately using for security purposes.
charcircuit | 16 hours ago
What makes that a legitimate interest and not advertising?
srdjanr | 14 hours ago
This part I guess
tete | a day ago
I think most companies just don't give a fuck about user privacy and therefor have to show one. There are of course exceptions. But I don't know how many of them have been actual (for-profit) companies.
W3cUYxYwmXb5c | a day ago
Cookies were never a problem. Just get rid of the banner.
This other legislation should pass/fail on its own merit.
drnick1 | a day ago
Another good one to have the "hide Youtube shorts" filter, featured on HN a while back.
tete | a day ago
Also I wanna know when websites don't give a shit about my privacy and therefor have to show a cookie banner. While theoretically not consenting should mean not collecting blocking it altogether and modifying page content might mean "all bets are off". If the website expects you to have made a decision that might wrongly consider it consent.
Consent-O-Matic says "I don't consent".
alex1138 | a day ago
jsrozner | a day ago
drnick1 | a day ago
qilo | a day ago
ChadMoran | a day ago
chrismorgan | a day ago
But of course it’s impossible to convince someone of something when their livelihood depends on their not understanding it.
otterley | a day ago
There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened.
There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
bluGill | a day ago
otterley | a day ago
bluGill | a day ago
Avicebron | a day ago
The value is derived from the people consuming the product. Placing the "incentive to produce value" above the people who presumably are the source of this value seems...misaligned.
otterley | a day ago
inigyou | a day ago
monkpit | a day ago
inigyou | a day ago
otterley | a day ago
readread | a day ago
otterley | a day ago
Also, sarcasm isn’t welcome here. Please read the HN guidelines.
readread | a day ago
Ah yes, I didn't couch my post in any of the various, rampant HN-friendly versions of shitposting. I'll try to follow your example from here on out. Excellent touch citing the guidelines at me after your role in this thread, A+.
Re-reads this thread, taking notes
Y_Y | a day ago
readread | a day ago
inigyou | 11 hours ago
readread | 7 hours ago
People routinely create alts just to post sensitive stuff and seem to do fine, and presumably they are keeping multiple accounts active at once.
[EDIT] I mean plus if I gave that many shits about being able to post on HN, I'd probably care a lot more about holding on to my precious karma in the first place, no?
Fraterkes | a day ago
otterley | 23 hours ago
HN is supposed to have higher than typical standards for participation than most internet fora and is largely self policing. It’s not condescending to tell people when they are misbehaving. Nor is it condescending to explain to people the law and how things work, provided you’re not insulting them in the process. Which I’m not doing.
I find much more concerning people’s certainty of their mistaken understandings and beliefs, combined with the most ludicrous possible interpretation of other’s positions.
inigyou | a day ago
otterley | a day ago
inigyou | 11 hours ago
Avicebron | a day ago
What we need is an environment that does not give the producers asymmetric power over consumers and the products will naturally align with that.
c0_0p_ | a day ago
znnajdla | a day ago
Only engineers have trouble understanding this. It can be a reasonable defense, and it has successfully been used in courts of law many times. The law is not a machine that compiles text like code literally. Imagine someone who coerces a dying or sick person to sign an agreement they couldn’t possibly be in a reasonable state of mind to understand what they were doing -- the law can and does invalidate such “contracts”. That is the same principle behind age of consent laws. The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
otterley | a day ago
> The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
I haven’t heard of a single case where an agreement was voided because “no one could reasonably be expected to understand it.” Unless the language was so impenetrable or vague that the agreement itself could not be discerned. Lawyers tend not to write such agreements.
IsTom | a day ago
tacitusarc | a day ago
otterley | a day ago
ferngodfather | a day ago
tacitusarc | 22 hours ago
otterley | 21 hours ago
But anyway. What exactly do you mean by “buried or obscured”?
As I said above, if the parties cannot be said to have an agreement because the terms of the agreement itself are inscrutable, then that would probably result in no contract being formed, or the terms at issue interpreted in the light most favorable to the non-drafting party. Like if the terms were presented in so small a font that only someone with a microscope could have read them, or it was written cryptographically or is gibberish.
Basically you have to successfully argue that no reasonable person could have read and understood the agreement. You’re unlikely to prevail if you argue only that you, the individual, did not. (Unless the court also finds you are incapable of entering into any contract because you’re a minor, are non compos mentis, etc.)
tacitusarc | 17 hours ago
I suppose you can claim I am wrong to believe that, but it is accurate for me to state that I _do_ believe it, which is why I didn’t list me being wrong as one of the possibilities. Practically speaking, that is the first possibility I enumerated.
I should note that in my example, imagine neither doc is any more inscrutable than all the TOS we encounter in the wild, instead it is the construction (the fact it is a footnote link) that makes it easy to miss the additional doc.
otterley | 15 hours ago
SiempreViernes | a day ago
tempestn | a day ago
ChadNauseam | a day ago
I just visited theguardian.com to see their cookie banner. The banner says this:
> Your Privacy (`x` button to close the tab)
> US residents have certain rights with regard to the sale or sharing of personal information to third parties.
> Guardian News and Media and our partners use information collected through cookies or in other forms to improve experience on our site and pages, analyze how it is used and show personalized advertising.
> You can opt out of the sale of all of your personal information by pressing
> <button>Do not sell or share my personal information</button>
It's 3 sentences, plus a button that says "Do not sell or share my personal information". I actually don't even think this is GDPR compliant, because my layman's understanding says that GDPR consent must be presented as opt-in, rather than opt-out. (I guess they are going for CCPA/CPRA compliance?) But anyway, I would think that a reasonable person could be expected to notice a button that says "Do not sell or share my personal information" and then click it, especially when it's portrayed prominently at the bottom of the page.
troupo | a day ago
This is the definition of informed consent
jkaplowitz | a day ago
However, since we are discussing the banner that The Guardian website shows to US viewers, I assume they’re trying to comply with California privacy law, which does allow opt-out regarding the sale of personal information.
troupo | 15 hours ago
wat
GDPR says that opt-out is the default, and if you are asking for consent, it had to be clear, unambiguous, and with both chouces clearly present.
inigyou | 10 hours ago
Not legal: you have to click a button to be opted out, otherwise you're opted in. (Opt-out as a verb)
Legal: you are opted out by default (opt-out as an adjective describing the default situation)
ButlerianJihad | 9 hours ago
https://en.wiktionary.org/wiki/opt-in
You've muddled the definitions again. "opt" signifies an action by the user.
If I am "in a group" by default, then I can take an action to "opt out", requesting to be removed from the list.
If I am not initially joined to the group, then I can take an action to "opt in" and be added to the list.
There is no such thing as "opt by default". That is not a user action. It also makes no sense for the same list or group to be both "opt in" and "opt out" because, as adjectives, they imply the default states and they describe the user action taken to change that default.
opt-in: default state is out
opt-out: default state is in
inigyou | 4 hours ago
> GDPR says that opt-out is the default
do you see how these relate? The second one quite explicitly talks about being opted out by default, i.e. what most of us call opt-in.
preg_match | a day ago
Because this is there 1 millionth cookie banner, because every site and their momma has one.
Also, 90% of cookie banners are not this good. They tell you nothing, hide the "reject" button behind multiple screens, etc. At that point the consumer is trained to click accept.
zenalt | 10 hours ago
> Personalised advertising - it's your choice
> Independent, quality original journalism needs your support.
> Please choose an option.
> * Accept personalised advertising and all cookies
> We use cookies and similar technologies to support the Guardian and personalise your experience in other ways. To do this we work with a cross section of [139 partners].
> - or -
> * Reject all and subscribe to Guardian Ad-Lite for €5 per month
> Read the Guardian website without personalised advertising. This does not include ad-free. You will still see non-personalised advertising and we may still use cookies and similar technologies to improve our site.
Followed by:
> Some cookies are necessary to help our website work properly and can’t be switched off. Find out more in our privacy policy and cookie policy, and manage the choices available to you at any time by going to ‘Privacy settings’ at the bottom of any page.
> Cookies and similar technologies collect information from your device and may be used to access personal data about you including page visits and IP addresses. We use this information about you, your devices and your online interactions with us to provide, analyse and improve our services. We use cookies and similar technologies for the following purposes:
> * Store and/or access information on a device
> * Personalised advertising, advertising measurement, audience research and services development
> * Personalised content and content measurement
And finally the buttons:
> ( Accept all ) ( Reject all and subscribe )
> If you already have Guardian Ad-Lite or read the Guardian ad-free, [sign in]
inigyou | 10 hours ago
deaton | a day ago
otterley | a day ago
victorbjorklund | a day ago
otterley | a day ago
Also, striking an unconscionable term typically does not void the whole contract. Just the term in question.
bryanrasmussen | a day ago
Aside from that many of these contract have terms that might be considered substantive unconscionability - for example if terms state that what you post can be used by the company that owns the service for marketing of the company or the service I feel this would not make it through most legal systems that I feel before the attempt are not inherently corrupt.
otterley | a day ago
simonra | a day ago
otterley | a day ago
bryanrasmussen | a day ago
As an example I have an email account with site A. I go to site A and log in, they suddenly spring a large new contract for me to read, I cannot get through to do what I came to do, it will take me 5 minutes to read so I click OK because I am on my way to check my email with site A. Procedurally this is not reasonable behavior.
What would be reasonable?
"Hi, we are changing our terms of service, you can see it at this link and agree. If you don't have the time right now you can do it later, but in three days you will lose access to the service unless you agree to terms."
There are however lots of other laws in the EU which may in fact make this behavior substantively unconscionable anyway. I certainly believe there would also be substantive arguments to be made in this case.
SiempreViernes | a day ago
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
otterley | a day ago
Y_Y | a day ago
lukeschlather | a day ago
victorbjorklund | 11 hours ago
Just read avtalslagen paragraf 30. It says just that. And it is different from paragraf 36.
otterley | 6 hours ago
See also https://svjt.se/svjt/1959/497 "En person borde sålunda bli bunden av ordalagen i det dokument han undertecknat utan att äga att ursäkta sig med att han icke läst igenom dokumentet."
victorbjorklund | 5 hours ago
You are referring to a 60 year article and the sentence you highlighted is NOT his opinion on the old contract law (the contract law currently in effect is from 2020) but rather he is explaining the opinion on German law from another person.
Of course you as an American sees no difference between contract law in continental European law and common law.
victorbjorklund | 4 hours ago
Enligt 30 § avtalslagen kan en rättshandling inte göras gällande om den, gentemot vilken en rättshandling företagits, framkallat rättshandlingen genom svikligt förledande eller bort inse att den som företog rättshandlingen blivit svikligen förledd av någon annan. Det finns en presumtion för att det svikliga förfarandet har framkallat rättshandlingen, om omständigheter som svikligen uppgetts eller förtigits kan antas vara av betydelse för rättshandlingen.
bad Google Translate:
According to Section 30 of the Contracts Act, a legal act cannot be enforced if the party against whom the legal act was performed caused the legal act by fraudulent misrepresentation or Should have realized that the party performing the legal act had been fraudulently misled by someone else. There is a presumption that the fraudulent misrepresentation has caused the legal act if circumstances that were fraudulently stated or omitted can be assumed to be of significance for the legal act.
otterley | 4 hours ago
Fraudulent inducement is not about unjust terms in contracts. The elements of fraudulent inducement in the US are:
I imagine it's not significantly different in Sweden.> According to Section 30 of the Contracts Act, a legal act cannot be enforced if the party against whom the legal act was performed caused the legal act by fraudulent misrepresentation.
OK. We have the same law. But I don't understand what this has to do with an "I didn't read the contract" defense. Since you possess a Swedish law degree, can you cite a single case wherein a party to a contract escaped their duty to perform merely because they didn't read the contract? Assume no fraud, clear language, no misrepresentation, no unconscionable/unlawful terms, both parties are competent to enter a contract, etc.
nekusar | a day ago
https://www.nbcnews.com/news/us-news/disney-says-man-cant-su...
"Disney is trying to have a widower's wrongful death lawsuit dismissed and sent to arbitration because the man had signed up for a Disney+ account several years ago."
Now what happened was that Disney quit fighting over really bad PR. But the court challenge would have liteky succeeded.
Paracompact | a day ago
nekusar | 23 hours ago
Mozilla with their Thundermail just tried saying in their ToS that if you're mentioned at all in anything legal, you agree to pay their legal fees.
bee_rider | a day ago
Or that any actual human is aware that an agreement was made (since an AI can find a checkbox nowadays or software can be configured to bypass it). One way to add balance could be to require people asking for contracts to actually treat them like real serious legal documents, show up for the signing, and figure out who they are making an agreement with.
otterley | a day ago
Prinicipal-agent law predates computers by a very long time.
bee_rider | 17 hours ago
ymolodtsov | a day ago
estebarb | a day ago
tempestn | a day ago
tappio | a day ago
tempestn | a day ago
jason_oster | a day ago
How many requests per second are being served? How many error codes were delivered to clients? How quickly the service responded? Service logs without PII? All perfectly fine to aggregate and analyze without consent.
ApolloFortyNine | 20 hours ago
Acting dense like this isn't productive... And literally this information would be stores as anonymous user 12345, but that still would require consent (probably, or at least arguably).
literallywho | 18 hours ago
Stats like that are only used to implement dark patterns better and justify user hostile decisions since pretty much the time the idea of telemetry was introduced. Otherwise, we'd live in the world of perfect web ui and we're not.
tappio | 16 hours ago
anonreplier | 12 hours ago
inigyou | 10 hours ago
Is it a violation to send data that could theoretically be used for more invasive tracking than you actually do? I don't think so, or else you'd need consent just to receive an IP packet.
micromacrofoot | 21 hours ago
preg_match | a day ago
The law really has nothing to do with cookies, it has to do with privacy, tracking, and PII. You can absolutely save preferences and perform analytics. What you can't do is hoard data that is personally identifiable for purposes that are not obvious to the consumer.
TurdF3rguson | 19 hours ago
inigyou | 10 hours ago
evcaldera | 12 hours ago
yjftsjthsd-h | 23 hours ago
Good.
> and you can't run a serious website without some kind of analytics.
I don't believe you.
> Preference-storing does as well, despite any reasonable user expecting that, if they set a preference, it will be saved.
IANAL, but I'm given to understand that this is untrue.
tempestn | 22 hours ago
What do you see as the harm in website owners using aggregated analytics data to improve their sites?
yjftsjthsd-h | 21 hours ago
Practical: Supposedly-aggregated stats have a history of actually being perfectly possible to analyze back into individually identifiable information. Also, it's conveniently the same tech stack in a way that makes it easier to make an actual slippery slope.
tempestn | 19 hours ago
micromacrofoot | 8 hours ago
micromacrofoot | 21 hours ago
inigyou | 10 hours ago
micromacrofoot | 8 hours ago
basch | a day ago
any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.
MassiveQuasar | a day ago
quantumwannabe | a day ago
nickff | a day ago
ablob | a day ago
P.S.: No true Scotsman spotted
ClumsyPilot | a day ago
If people really cared, they’d chose reputable suppliers that sell non toxic food. If they are eating food with lead, they don’t care.
Don’t force your wordview on people through regulation
whstl | a day ago
As opposed to enforcing your worldview with a lack of regulation?
Because that's precisely what's happening, with the advertisement industry enforcing their worldview through lack of compliance.
ClumsyPilot | 10 hours ago
whstl | 9 hours ago
preg_match | a day ago
How often do you get prompted for, say, secure DNS or HTTP? Almost never, because your browser has sane defaults and controls that. So, there you go.
tsukikage | 11 hours ago
I mean, it's even the literal truth: they value your privacy in the sense of having their software do a little internal auction to put a price on it.
yjftsjthsd-h | 23 hours ago
What browsers would those be?
IanCal | a day ago
The default is “no”. Without explicit consent you can’t do a lot of things.
You can’t have a default yes, because how can you agree with consent but automatically to everything?
And if it’s a no, are you saying you can’t ask a user for permission to use their data for a specific purpose?
And if you can ask, that’s what we have right now.
lukeschlather | a day ago
buzer | 22 hours ago
inigyou | 10 hours ago
buzer | 7 hours ago
Other processing (like after value is read) can happen under GDPR if the data is personal data.
inigyou | 4 hours ago
Note that you don't comply with EU directives anyway - you comply with actual laws of actual countries, and the EU process helps them to mostly agree with each other. Did countries replace their ePD-based laws with GDPR-based laws? My understanding is they did.
Voultapher | 10 hours ago
kleiba2 | a day ago
This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data mining, profiling, and other privacy-related aspects. But in many cases, you could just click "reject" and the banner would also disappear...
To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
readread | a day ago
Some variant on "reject" takes more effort like 70% of the time. Which is on purpose, of course. The ones that aren't maliciously-complying have a "necessary only" button that insta-closes it, but tons pretend that you might want to allow some spying but not all of it and make you go through another screen if you don't just "accept all".
> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
Then it'd be possible to default it to "nope" (Firefox, and perhaps Safari, might do this) or to allow a "never, anywhere" setting the first time the question is asked, and malware and spyware vendors know that'd mean a much larger proportion of denials.
jackson1442 | a day ago
remus | a day ago
smallmancontrov | a day ago
whstl | a day ago
Naturally in a camera meeting with a "don't tell anyone we said that" appended right before.
The marketing people in the meeting were very angry that California was "doing it to them".
Aerroon | 21 hours ago
There is nothing stopping a website from using cookies regardless of the banner. If they are outside EU jurisdiction then there won't be any consequences either.
The legislators were and are dumb. They have wasted an enormous amount of collective time for no benefit. Big corporations continued doing what they were doing and nefarious third parties could still track you.
smallmancontrov | 20 hours ago
They did. The laws were airtight in this regard. They simply lost -- whether through a last minute "tweak" or undermined enforcement mechanism I do not know, but I do know that the current state of affairs was fully anticipated and headed off at the point where I reviewed the proposal. Your vitriol is bass ackwards -- the lesson is to strengthen the walls between corporations and the legislative process and support enforcement mechanisms, because those were the places where the process failed. Not the intelligence of legislators. Otherwise you will keep losing to the corporations, and you will deserve to.
unscaled | 16 hours ago
GDPR article 7 and its various recital already include that. GDPR wisely doesn't get into technical details like "cookie banners" anywhere, but various national agencies did set guidance and it's usually quite explicit: Rejection must be as simple as acceptance and reject buttons or link must be as prominent as the accept buttons and links.
For example, CNIL, the French data privacy authority, clearly says[1]:
"The CNIL has received complaints about dark patterns on cookie consent banners encouraging data subjects to accept cookies.
As a reminder, with certain exceptions, cookies can only be used with the consent of data subjects. Moreover, rejecting cookies should be just as easy as accepting them."
And gives examples of dark patterns such as different button sizes, multiple accept buttons, hidden reject buttons, etc.
The law and specific guidance is pretty unambiguous. This purely an enforcement problem. The regulatory bodies do not have the resources to go and chase most individual companies, and the non-profit NGOs that go after the violators apparently don't have the budget to make enough impact and scare companies into compliance.
[1] https://www.cnil.fr/en/dark-patterns-cookie-banners-cnil-iss...
soco | 12 hours ago
inigyou | 10 hours ago
tikhonj | a day ago
But of course, designing the system that pushes people to make this sort of decision was absolutely intentional.
So even when it's incompetence, it's still malicious, just in a way that obscures the explicit decision-making that led to the result.
PunchyHamster | a day ago
bshacklett | 22 hours ago
novafunc | 22 hours ago
I think it's absolutely fair and unlikely to be illegal to use a cookie to remember cookie preferences. Unless the cookie value was not yes/no, but something like a precise timestamp that could be used for uniquely identifying.
tremon | 22 hours ago
Gigachad | 20 hours ago
jeremyjh | 20 hours ago
flotzam | 9 hours ago
inigyou | 10 hours ago
ryukafalz | a day ago
Oftentimes the reject flow is substantially more annoying than the accept flow. I click reject myself when it's an option, but I can absolutely understand how people might get conditioned to click accept when clicking reject might result in more popups.
thom | a day ago
roelschroeven | a day ago
dredmorbius | a day ago
However the UK does have its own GDPR regulation (see: <https://www.gov.uk/data-protection>), though my understanding is that it may be less strict in requiring equivalence between "accept" and "reject" actions. (I may be wrong on this.)
UK sites accessed from the EU would have to be under EU GDPR compliance.
xp84 | a day ago
If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway."
Note that I used "sign any name" as the metaphor, not "show ID," since it is trivial to not allow any important information exchange if you simply delete the cookies yourself, which is easy to configure a browser to do. The end-user has the choice, if it's so important to them, to configure their browser. Even Chrome can be configured for which sites to allow cookies, which to disallow, and which to clear when the browser closes (the smart choice, since accepting them and throwing them away soon after is the undetectable option that accomplishes your main aim).
thom | 22 hours ago
xp84 | 21 hours ago
Sorry that you need the government to "help" people in this way, by forcing other people to give them free things.
kalleboo | 17 hours ago
xp84 | 5 hours ago
Simple, easy tools are already there, such as the Clear Browsing Data menu item in Chrome, Edge, and Safari. For more complicated intents, the browser settings are no more complicated to navigate than the actual customization UI in the CMPs, anyway.
kalleboo | 5 hours ago
Clearing browser data is anything but easy for people who aren't certain what is "browser data". Is this going to delete all my google sheets? Those are in the browser. And it's not a bad question, some apps actually use IndexedDB or whatever to store user data.
ApolloFortyNine | 20 hours ago
You simply will have to go out of business.
This is also why you see many large companies fighting for more regulation. It's harder for a competitor to emerge if they have to navigate mountains of red tape.
kalleboo | 19 hours ago
I simply will have to go out of business.
ApolloFortyNine | 18 hours ago
kalleboo | 17 hours ago
xp84 | 4 hours ago
This is the part I don't understand. I'm actually all for regulations like being able to demand they delete the saved data they have on you, restrictions on transferring data to the control of third parties without disclosure/permission, etc.
But if your definition of "privacy" extends to not wanting cookies to work like they were designed to, why can't it be your responsibility to use a browser (a User-Agent) that carries out your intentions?
With services that are mandatory for all of us to use (e.g. government), I can see how being stringent makes sense because the users have no choice. But I can't understand applying the same burdensome requirements to things that people can simply choose to use or not use, such as a restaurant or some random guy's blog. I could be convinced that large platforms (tough to define properly, but things like Amazon, Uber or Meta) may be subjected to additional rules, but the tough rules being applied to even tiny one-person startups does nothing but advantage the giant platforms who have hundreds of lawyers and can devote entire dev teams to building complicated compliance features.
kalleboo | 19 hours ago
tripzilch | 12 hours ago
ben_w | 11 hours ago
More: "To view the private content on my website, you have to either pay me, or let more businesses connect the dots between this content and the rest of your internet browsing habits, than there were students and teachers combined in your high school."
Yes, it is technically possible to fake this content, or to auto-delete it.
But https://xkcd.com/2501/ applies. "It's easy to forget that the average person probably only knows the privacy settings for Safari and one or two Chromium derivatives."
(Real world user familiarity with software is much, much worse; this is an old survey now, but look at the chart near the bottom: https://www.nngroup.com/articles/computer-skill-levels/)
inigyou | 10 hours ago
account42 | 7 hours ago
unclebucknasty | a day ago
There's a mismatch between the velocity at which people visit sites and the time it takes to navigate the cookie particulars of each site.
And, we can dismiss this as people being uninformed or lazy but the reality it is that's actually not so unreasonable. Cookies are in some ways near the bottom of the list where privacy is concerned, given everything else from breaches to search dossiers to device finger-printing to mobile device location-tracking to the ubiquity of cameras in the real world, and on and on.
The idea that we're clawing back privacy in any meaningful sense by blocking a few cookies here and there is kind of quaint.
nickff | a day ago
What harm are you worried about?
fsflover | a day ago
Lack of privacy harms journalism and activism, making the government too powerful and not accountable. If only activists and journalists will try to have the privacy, it will be much easier to target them. Everyone should have privacy to protect them. It’s sort of like freedom of speech is necessary not just for journalists, but for everyone, even if you have nothing to say.
tqi | 21 hours ago
kalleboo | 19 hours ago
inigyou | 10 hours ago
layer8 | a day ago
tqi | 21 hours ago
layer8 | 5 hours ago
whstl | a day ago
These banners handle both ePrivacy consent for cookies etc, but also GDPR Art. 6(1)(a) for processing purposes (personalised ads, measurement, audience insights, precise geolocation, even device fingerprinting).
inigyou | 10 hours ago
ablob | a day ago
It is known that warnings and pop-ups that show up almost all the time yield diminishing returns. I think it was named "normalization of deviation" by some folks in a blog a while ago, and I believe that name fits. If you get warned about missing https all the time, or that something might be dangerous (even though it does precisely what you want it to do), it will loose its effect by the time you actually need it.
You can argue this is malicious compliance, but if you want it to go away it would probably be easier to go for banning tracking and personalized ads altogether. Eliminate the reason for this behavior, so to speak.
dv_dt | a day ago
cuu508 | a day ago
agos | a day ago
dv_dt | 13 hours ago
fnord123 | a day ago
There is one. It's a DNT header. Knucklehead websites ignore it.
sumeno | a day ago
yjftsjthsd-h | 23 hours ago
sumeno | 21 hours ago
yjftsjthsd-h | 21 hours ago
> Hacker News Information: If you create a Hacker News account (ID and profile), we do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field (“HN Information”). Your submissions to, and comments you make on, the Hacker News site are not Personal Information and are not "HN Information" as defined in this Privacy Policy.
xp84 | a day ago
Like it or not, the Web is a two-way street, meaning that the server end of the transaction doesn't owe the client end anything in particular unless there's some relationship in place (like a payment). It appears the "just ignore it" matches the intent of most web users, though, since an overwhelming majority of web visitors accept a bunch of spammy ads + free 'content,' and a slim minority pay for ad-free alternatives.
fnord123 | 23 hours ago
The law that caused the cookie banners also says companies cannot block access to the site if the cookies are not required for the functioning of the site.
Some German news sites have broken this and have "accept or pay" and I think this leaked to news sites in other countries. Facebook even tried it.
So, sure, if DNT is true, try to make people pay. Fine by me.
rob74 | 13 hours ago
- even if you accept the tracking, you might still not be able to read the article, because while the site may be free in principle if you accept ads, that specific article is not.
- and the most annoying thing is that such paywalled articles show up on Google News. Not sure if they're tricking Google into showing them (by showing the full article to search crawlers, but the paywall to actual users), or if this is some understanding between Google and EU news providers, but it's annoying...
windward | 23 hours ago
So do car alarms.
I'm not convinced this is a business model I want to exist. We had an internet before it, and Google, and Facebook. I'm increasingly sad we can't return to it.
xp84 | 21 hours ago
And I'd gladly trade today's BS for any version of "The Internet" pre-2007.
But the "Before" Internet wasn't some natural sustainable state.
Before 1997 or so, "the Internet" was being paid for by academic institutions and big companies, and wasn't really all that commercial at all. It was also pretty tiny and blessedly simple. Honestly this version is the most achievable (re-creatable?) today since we can set up indie websites much easier today than we could then. Instead of using your free webspace from your university or employer, 20 of us could share a $5 a month instance, and link to each other's webpages, and add an IRC server to that instance just for fun.
In the 1998-2007 era, the Internet got a lot bigger, but was also still pretty fun and not that enshittified, but that's just because it was being paid for by VC money being burned.
Today we are where we are in terms of business model[1] because Google and Facebook achieved great success with ad-based business models because of the ability to target ads better, and because consumers of The Internet have spoken, loudly, with their closed wallets. They've said "We will only pay for content if it's All The Music and ~$10 a month flat rate, or if it's a big/interesting enough video on-demand service and under $20 a month. We'll never pay for news or text content of any kind." So, the businesses with other types of content do what the public wants them to do: have cost-free content whose access is conditional on being advertised to very annoyingly, or they marginalize themselves with paywalls, subscribed to by only a small minority of users.
[1] i'm setting aside the non-business aspects of our mess, namely the poison that social media, 'engagement' optimization, and ragebait-as-news has wrought on society.
dullcrisp | 13 hours ago
Now, if you want to read an article you have to pay $20/month to that news organization in perpetuity. I don’t see how that can be expected to work.
LtWorf | 13 hours ago
Or, I liked one single page of an amputee woman (I am myself) and now all I see are amputee women.
They just buy all the competitors, but they aren't good at all.
ben_w | 11 hours ago
There's an old saying in advertising, "Half the money I spend on advertising is wasted, and the trouble is I don’t know which half." - https://quoteinvestigator.com/2022/04/11/advertising/
The supposed benefit of the current model is to find and eliminate that wasted half.
Facebook has shown me ads for dick pills and boob surgery, ads I can't read because I don't know the Cyrillic alphabet, and ads for services that only apply to citizens of nations I've never been a citizen of who moved to a country I had in fact moved out of.
The reports I hear from people who buy ad slots are mostly unimpressed with the results; the word on the grapevine is that the "success" cases are not even average customers, but those who are vulnerable to getting scammed.
inigyou | 10 hours ago
TeMPOraL | 10 hours ago
Good. No one is entitled to a business model working in perpetuity. Doubly so when it's ethically dubious.
The very thing entrepreneurs are glorified for - their ability to invent and execute on new business models. They'll manage, don't worry about them. Hopefully they'll settle on more honest models this time.
goodrubyist | a day ago
People do not have a right (morally speaking, not legally) to access or use a service (or a website) etc without having to read/agree to the terms (applies to analog and digital).
Maxion | a day ago
We really need to stop companies from putting up these insanely complicated legal texts to use basic services when they could all be behind standard contracts.
goodrubyist | 22 hours ago
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE APPLE SOFTWARE AND SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE”
https://www.apple.com/legal/sla/docs/macOSTahoe.pdf
The same point applies to most of the text. But yes, some text is specific to the service. E.g. the same doc above says in bold:
"By using the Content Caching Features of the Apple Software, you agree that Apple may download and cache such Apple Eligible Content on your Caching Enabled Mac."
I'd say that's something worth knowing if you use that OS.
swat535 | a day ago
If your terms require people to get a law degree and take a week to parse the 400 page document, then I would argue that it's a tactic to get people to sign up for the service without fully understanding it.
We need legislation that forces companies to communicate the terms in a way that an average person can comprehend.
goodrubyist | 22 hours ago
inigyou | 10 hours ago
sumeno | a day ago
stefan_ | a day ago
inigyou | 10 hours ago
aetch | a day ago
hobo123 | a day ago
This is exactly what browsers did back the 90s, they asked about every single cookie.
Then browsers got configurable options to simply accept either all cookies, no cookies, or only first party cookies (excluding third party sites unrelated to the domain you visited).
For now well over 20 years I have disabled 3rd party cookies in all browsers I use, and only in a few cases overall did I need to make exemptions.
xp84 | a day ago
Clicking those "REJECT!" buttons might make you feel empowered, but it's pointless. Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you.
The whole thing has always been a problem to be properly solved by the browser, and it's probably just the fact that Google makes the only browser that matters, that it's been foisted upon every website owner, who mostly just wants basic analytics and to track conversions from the ads they run, and isn't "selling your data."
The browser is your user agent. If it's sending any information up to web servers on every request that isn't okay with you, why are you using it?
zugi | a day ago
Exactly. I use the "I don't care about cookies" extension, which rejects most cookies automatically without me having to see the popups. But even accepting cookies is fine - I'll be closing my browser soon anyway and they'll be gone.
tremon | 22 hours ago
Sure, your browser cookie will be gone. But you have already allowed the server-side identifiers of your session to be used for whatever purpose, including reconstituting increasingly larger parts of your identity over multiple disconnected sessions. Please don't make the mistake of thinking that clearing your cookies afterwards is the same as rejecting all server-side processing.
unscaled | 16 hours ago
badestrand | 10 hours ago
cowboylowrez | 8 hours ago
donaltroddyn | a day ago
My company scanned 209 European regulated sites in June, and roughly 7 in 10 had tracking that wasn't correctly gated by consent. It's rarely indifference, though. DPOs in the EU hold too much weight for that. It's usually a tag added that was never wired into the CMP or something added by a dev or LLM without going through proper review
Full disclosure: I run https://consentmark.com, which measures what tags actually fire under each consent state to create evidence packs companies can show regulators
TeMPOraL | 10 hours ago
> something added by a dev or LLM without going through proper review
FWIW, this was a problem long before LLMs were a thing, and it didn't get worse with LLMs. If anything, I'd expect LLMs to get it right by default, because ones ~everyone is using are all trained straight, they won't just silently read between the lines and write code/configs to facilitate one's illegal business model.
donaltroddyn | 4 hours ago
That honestly doesn't fit our data or my experience. In our scanning, about 60% of the misconfigured sites had a CMP with blocking active but one or two tags bypassing consent controls
Generally those misconfigurations aren't valuable to the business. We don't see for example lots of ad targeting and conversion tracking firing without consent on an otherwise compliant site.
What we do see is things like sites with CMPs generally working, but one or two analytics events tags firing because consent wasn't properly added to a trigger, or embedded Youtube cookies set without consent, or unexpected data from a URL or query param being accidentally ingested by tracking, or devs adding performance monitoring or observability tools to applications without realising the compliance implications
There's not much business logic in paying for a CMP, blocking your own ad stack, but then letting three analytics events pass through
> FWIW, this was a problem long before LLMs were a thing, and it didn't get worse with LLMs.
This isn't supported by our experience. In the last 18 months, we've seen a big increase in ungated tracking that we catch in CI (albeit with overall much higher velocity in general). LLMs will happily add non-compliant tracking to sites, often following defaults that might be acceptable in the US but not EU. If you push back, they'll also happily implement compliant tracking, but it's definitely not the natural default you can rely on
But your comment left me curious, so I just ran an experiment via Codex -p (gpt-5.6-sol) and Opus 5 via Bedrock
Codex returned the vendor quickstart on 5 of 5 neutral prompts. It gated properly when told the company is Irish, with full Consent Mode v2 defaults denied, GA4 only mounting after consent, with a reject button
So models can produce compliant/non-compliant code based on the context you give them, which reflects what we've seen in industry
Our business is giving devs and increasingly LLMs efficient tests to check the tracking they add is as expected for the EU and then providing signed evidence packs that prove that behaviour at a given time
gnatolf | 22 hours ago
inigyou | 10 hours ago
WheatMillington | a day ago
montroser | a day ago
They will fingerprint you with or without cookies. They may or not try to honor your preferences, but their "partners" will not try, and by the time you see that banner, it's all out there.
"Accept" is the close button.
SlightlyLeftPad | a day ago
gbalduzzi | 23 hours ago
zelphirkalt | 23 hours ago
Gigachad | 20 hours ago
Robotbeat | 19 hours ago
chillfox | 16 hours ago
speleding | 10 hours ago
So I'm not onboard with the "just block everything by default" crowd. If you frame the question as "Would you like ads to be more relevant to you" instead of "Do you want to allow tracking" you probably get a very different answer from users.
I would like the cookie banner to be changed to a browser setting, but I also would like the option to allow some sites to show relevant ads to me.
bwb | 10 hours ago
ethin | a day ago
dotancohen | a day ago
inigyou | a day ago
dotancohen | a day ago
inigyou | a day ago
crote | 23 hours ago
For example, in The Netherlands there is a legally mandated three-day period after signing the contract for purchasing a home during which the buyer can still call off the deal.
The reasoning for this is that it is a seller's market, with demand far outnumbering supply. In practice it is very common these days to end up in a bidding war, and even forego any kind of "sale is void if home inspection turns up issues" clause. Want to think about it for a day or two before signing the biggest contract of your life? Too bad, another buyer is willing to sign today.
With the mandatory three-day waiting period you avoid buyers being locked into a contract they basically immediately regret. It gives them some time to do due diligence, reducing the risk of buying a complete lemon. The seller can ask for a similar clause to be inserted, but it is less common. After all, the only risk to the seller is getting slightly less money for it, and that's already mostly dealt with during the bidding process.
tremon | 21 hours ago
chrismorgan | 21 hours ago
ethin | 22 hours ago
The reason this isn't done is because corporations legal departments love writing 10-100 page contracts that absolutely nobody is going to read.
buzer | 21 hours ago
You could, for example, require that user answers very specific questions regarding 10 randomly selected partners and how exactly they can use the data ("is partner x allowed to build very detailed profile of you and target you with political adverts that are designed to manipulate you?").
ApolloFortyNine | 20 hours ago
We're borderline already there today when the cost of switching is typing a different url at the top of the screen. You add some mandatory 20 minute wait and you'll never see a new site again.
Google and Facebook would love it though.
inigyou | 10 hours ago
goodrubyist | a day ago
TheScaryOne | a day ago
When was the last time you read an entire EULA before installing software?
I'm going to guess the time frame is somewhere around "never."
These are nuisance contracts designed to jade people with legalese while stealing their rights to things like class action and enforcing binding arbitration.
Standard contracts sounds like the way to go.
goodrubyist | 22 hours ago
arjie | a day ago
As it stands I just hit Accept on literally everything and that’s fine for me.
j1elo | a day ago
It already pushes the correct "Reject" button for you on a lot of sites (not all; it works based on rule lists)
arjie | a day ago
bbg2401 | a day ago
Ferret7446 | 21 hours ago
LadyCailin | 21 hours ago
tete | a day ago
It's great. The current law forces people that don't give a shit about user privacy to have a banner (or any other way of asking for consent first) while giving everyone that cares and everyone not wanting to spy on their visitor a free pass.
inigyou | a day ago
SeriousM | a day ago
reddalo | a day ago
hash872 | a day ago
Sites that easily allow you to simply reject everything are then a short hop, skip and a jump into browser settings where you auto-reject all cookie/tracking nonsense
imhoguy | a day ago
dspillett | a day ago
Sounds good, as long as it covers the "legitimate interest" bollocks⁰ that is often hidden in inconvenient UI nests as well as the basic preference.
-------
[0] "we see your preference not to be stalked, but we want to anyway, click again for every partner to reconfirm you don't want them following you around"
rusk | a day ago
https://en.wikipedia.org/wiki/P3P
jeroenhd | 12 hours ago
shagie | a day ago
> ...
> You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default.
That's an excellent idea... lets see how its implemented on https://european-union.europa.eu/index_en
Oh... there's a cookie banner.
Cyberdog | a day ago
nicbou | 13 hours ago
wrqvrwvq | a day ago
openquery | a day ago
I've wanted the option to select your cookie preferences once and forget in a brower for ever.
I assume the reason this wasn't done initially was corporate pressure (most people would opt-out of everything by default).
1.2 billion exposed users × 8.17 years×365×3 banners/day×4 seconds÷36 is roughly 10-15 billion human hours lost to dealing with damn cookies since GDPR took effect on May 2018.
That's about 17,000 human lives.
hollowturtle | a day ago
reddalo | a day ago
tappio | a day ago
tempestn | a day ago
And for a serious website, front end analytics are kind of a necessity to understand how users interact with pages and improve the experience. Note that it certainly doesn't require tracking the behaviour of individual users, just understanding how controls are used in aggregate.
I know it seems like you could work around this with careful design and maybe focus groups and such, but I can tell you we regularly uncover surprising insights from (aggregate) trends in front-end events.
dgellow | a day ago
See here[0], page 6:
> As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’
0: https://www.edpb.europa.eu/system/files/documents/2024-10/ed...
As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen
tempestn | a day ago
jeremyjh | 20 hours ago
jeroenhd | 11 hours ago
Good websites sharing stuff for the fun of it rarely ever add these obnoxious banners. They probably should if they embed other trackers (like Youtube or Google Fonts) but often just don't. It's only the ones that want to make money off you that bother putting in the obnoxious banners.
bux93 | 10 hours ago
Even the use of the word "cookie" is framing by industry to confuse people.
Retr0id | a day ago
So now they'd have a new popup that says "reconfigure your browser to accept tracking, or pay us, or you can't access the page". Which isn't really an improvement.
JoshTriplett | a day ago
richard_chase | a day ago
tgma | a day ago
pmlnr | a day ago
People not reading back on history is still very much a thing.
charcircuit | a day ago
doodlebugging | a day ago
EDIT: It's obvious that people really hate this option. Maybe too many here have their incomes too closely tied to the metrics that cookies are designed to collect. It could also be that it is an unrealistic option for everything except the most extreme societal changes.
If you are old enough and look back far enough you may remember the time before all this bullshit like I do. Once marketing and advertising get involved and gain power in an organization, things tend to go to shit fast.
jsrozner | a day ago
ezoe | a day ago
It's YOUR browser, a locally running software on a physical computer YOU own which memorize the cookie key-value pair a remote host told YOU to memorize and YOU return the same value later. It's YOU who allowed the cookie. If YOU don't want to allow the cookie, YOU simply not allow it.
You are technically 100% control on cookie. These JavaScript implemented in-page UI has no guarantee to respect your wish. But you have a power to disable it.
frollogaston | a day ago
troupo | a day ago
E.g. storing your precise geolocation for 12 years: https://x.com/dmitriid/status/1817122117093056541
TheCoelacanth | a day ago
GDPR is not about cookies; it is about tracking. Whether the tracking is done through cookies or through other means makes absolutely no difference.
You can prevent some tracking via your browser, but definitely not all of it.
ktosobcy | a day ago
> The solution: automatically communicate your privacy preference
Would be lovely and would happen if it weren't for… wait for it… Google and whole effed up ad-busines:
https://ppc.land/eu-council-drops-cookie-signal-after-google...
F*ck google and other BigTech…
johndhi | a day ago
instead of building websites and writing laws over the span of decades that just seem to want to ban targeted advertising but don't actually do it. FFS.
nektro | a day ago
jebronie2 | a day ago
himata4113 | a day ago
I have personally never ever had any problems with the cookie banner since Brave deletes them with 100% accuracy, there's sometimes where a site will refuse to function properly, but it's usually sites I don't care about anyway and if I HAVE to get it working I disable brave shield, turn off all tracking, consent and turn the shields back on.
It is unfortunate that most browsers cannot implement this as it goes against what the companies behind the browsers want. Deleting the cookie prompt would stop people from occasionally just accepting all cookies and opting into tracking after getting tired of it.
righthand | a day ago
pverheggen | a day ago
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
As written, this doesn't eliminate cookie banners completely, only if your browser is sending a Do Not Track header or similar. That's unfortunate news if you use fingerprint protection - those send default headers, so you'll still be bombarded with cookie banners. Hopefully existing anti-fingerprinting solutions will offer a "default headers but with Do Not Track" option.
MetaWhirledPeas | a day ago
jsrozner | a day ago
There is ZERO cost to abusing the user over, and over, and over again by asking for permission to track them.
We shouldn't have the cookie banners at all because NO company should be able to do anything with tracking data. Just ban the use of user data by companies and most of SillyCon Valley's garbage behaviors are fixed.
Similarly, I should never get "terms of service updates" from digital companies because there should be no changes that they can make. You can provide the obvious service that you're providing; you can't aggregate my data for any purpose other than directly serving me; you can't aggregate my data with that of other users; if you retain my data for any other purpose, the government should take percentages of your revenue. I shouldn't have to wade through the BS that the mercenary corporate lawyers cook up to extract value from me.
joelthelion | a day ago
I don't have a lot of confidence for legislative solutions. Although I admire people who keep trying.
minaguib | a day ago
Biganon | a day ago
whatcd | a day ago
logicallee | a day ago
https://stateofutopia.com/laws/2/law2.html
This is not a proposal, it is duly ratified international law that applies to "Every Browser Maker making a Browser available anywhere" and "Any site anywhere that receives a valid signal".
The EU Commission had until July 18, 2026 to modify its laws:
>"The site shall not display a banner, modal, interstitial, or other prompt requesting a choice already expressed by the signal. It may optionally provide a “Cookie Settings” or “Privacy Settings” link. This Law overrides all laws requiring such a display. Where any country or supernational entity has a conflicting law, it must rectify the Law within 30 days not to require such notification."
Therefore, insofar as it has not rectified its laws not to require such a notification, the EU Commission is in violation of international law as of 8 days ago.
Under section 7.3, "The State of Utopia may order compliance, require corrective updates, suspend non-compliant distribution, and impose civil penalties. Fines may be levied in any amount for continued non-compliance." so we can fine the EU Commission whatever you guys want ($1 billion? $10 billion? whatever four and a half millennia are worth) and just distribute the collected fines among you all as cash payments.
[1] Here is the announcement of the law 38 days ago: https://news.ycombinator.com/item?id=48585778
whywhywhywhy | a day ago
tomp | a day ago
No cookie banner is required for functionally necessary cookies.
jebronie2 | a day ago
Etheryte | a day ago
jebronie2 | a day ago
kodebach | 23 hours ago
Also AFAIK the Google Fonts question (is the IP alone already PII, if Google has no way of tying the IP to a person) has not been decided by the ECJ yet. There've only been decisions by lower level German courts that are still in dispute.
jebronie2 | 16 hours ago
"Well if the cookie comes from a third party it implicitly allows tracking."
Yes, because this makes tracking possible you have to gather consent first, regardless if tracking actually happens. Very bad solution, they could just define how data can be legally used, instead of also overreaching by defining how data can be legally transmitted.
jeremyjh | 20 hours ago
jebronie2 | 16 hours ago
buzer | 21 hours ago
> strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
One very ignored qualifier here is "information society service". This is defined in Directive 2015/1535 and one of the requirements is that the service is "normally provided for remuneration". That is usually understood to mean that the service needs to be tied to provider's economic activity. This effectively excludes, for example, public authorities websites which are for their own public duties. It does however include e.g. ad supported websites.
And yes, I'm aware that many national implementations actually miss that qualifier. That can save the non-commercial private sector websites, but public authorities do not benefit from Member States failing to transpose Directive correctly.
ApolloFortyNine | 19 hours ago
People act shocked when it leads to unintended side effects, but companies legal teams are just telling them they have no idea how a judge will interpret these broad wordings in regards to their business.
People say this fixes "future loopholes" but as you see with the cookie banner, it just leads to every company assuming the worst case scenario.
Going back years of conversation on cookie banners you'll see a constant argument on when they're required or not precisely because it's not defined explicitly.
GJim | 12 hours ago
IMTDb | a day ago
EU official website in it’s cookie banner glory: https://european-union.europa.eu/index_fr
zelphirkalt | 23 hours ago
I get similarly upset, when I see Google tracking on official websites of government or public institutions.
micromacrofoot | 21 hours ago
if they didn't use third party cookies they wouldn't need it
TurdF3rguson | 18 hours ago
No, they don't really need to track you, that's why it requires consent to do it.
They are doing exactly what they say.
In other words, they're not saying don't track your visitors. They're saying get consent first.
latexr | 11 hours ago
https://commission.europa.eu/resources/europa-web-guide/desi...
> Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.
iammrpayments | 16 hours ago
ThatMedicIsASpy | 11 hours ago
lacoolj | a day ago
I guess what I'm saying is, there is no good solution here. I don't want every site I visit to require a usage fee just to browse. Imagine if slashdot turned into WSJ with a paywall for every article.
Kagi already does something like this, and cool - if you use it enough, maybe its worth a subscription. I dont find myself googling (searching) much anymore, so paying to do so just becomes something i need to find a way around. Like API token usage for AI, using it is like making a new recipe in the oven every time. You expect it to work but you have to invest the time and money into the attempt before you can find out the results (whereas you dont have to do this on free chatgpt, google search with ai, etc as comparison). Too much investment without guarantee of results. I'm fine without that guarantee as long as im not wasting my time and money upfront.
Anyways, thanks for letting me rant
websap | a day ago
j16sdiz | a day ago
I am kind of wanting to f around and found out. I missed the old internet were most of the big websites are run by hobbyist. I know some of them may not be able to pay the bill without ad. May we can figure out something once we leveled the playing field
crote | 22 hours ago
Sure, but magazines get a massive portion of their revenue through advertising without trackers. Same with television, or radio, or billboards.
And the ad space isn't exactly very healthy either. Take a large Youtube channel like Linus Tech Tips, for example: AdSense only accounts for 10% of their revenue! Youtube has been drowning people in ads and it still barely pays any money.
I think we should seriously consider the possibility that targeted ads might be less profitable overall. Ad blockers didn't become a thing solely because ads appeared on the web. Ad blockers became popular when ads became obnoxious and privacy-invading. With the current state of the web ad blockers are a hard requirement for a reasonable browsing experience, so the only people seeing ads are the handful of suckers too ignorant to install them.
But if ads aren't as invasive and obnoxious, people would have far fewer reasons to install ad blockers. See for example the Acceptable Ads program of Adblock Plus. If switching to user-respecting ads resulted in a significant portion of people turning off their ad blockers, it could very well result in an increase in ad revenue!
duxup | a day ago
I'm visiting a website, i don't want to make a legal agreement with every website ...
Social media bad for kids? Everyone hand over your ID at the door ...
jeremyjh | 20 hours ago
Then you blame the government.
duxup | 19 hours ago
jeremyjh | 19 hours ago
duxup | 19 hours ago
nicbou | 13 hours ago
inigyou | 10 hours ago
buildwrangler | a day ago
Why the fuck do people have to keep stating the same preference over and over again. This is a hellscape of bad government AND corporate policy colliding.
haute_cuisine | a day ago
buildwrangler | a day ago
croes | a day ago
mullingitover | a day ago
> When the law takes effect in January 2027, Californians will see new privacy options in web browsers. When enabled, these controls will automatically inform websites of their privacy preferences, helping to protect personal information from being sold to data brokers and other third parties. This means they will be able to protect their data — like their browsing history, location data, purchase history, and personal interests — across the entire internet with a single step.
[1] https://cppa.ca.gov/announcements/2025/20251008_2.html
TurdF3rguson | 18 hours ago
jebronie2 | a day ago
1. Making tracking impossible/illegal would NOT kill cookie banners, since you need them to record consent for other purposes as well, such as embedding a video from a third party like YouTube.
2. The GDPR explicitly prohibits site-owners from making cookie banners misleading. The law is already there, it is just not very well enforced.
3. "This results in up to 90% of people saying “YES” – even though only around 3% actually want to be tracked online" This claim is grabbed out of thin air and can be dismissed as such.
4. "The solution: automatically communicate your privacy preference" This is nonsense because it does not actually solve anything, because you need to record consent for a variety of purposes, not just analytics/tracking.
5. Killing tracking would kill the value of ads (since they are not targeted anymore), resulting in a reduced ability for small businesses to advertise and a hugely increased amount of ad spam everywhere. Few targeted ads > Many untargeted ads
Unless you want an internet where advertising is no longer possible, this solves nothing apart from stroking a few activists ego.
m000 | a day ago
I would say, we are like 80% there. Yes, there are still some dark patterns employed by cookie banners, trying to trick you into accepting tracking. But they are not too hard to make out. And they can be fixed by tuning the regulation a bit: Require the opt-out to be the first choice and the only one with highlighting.
Ad tracking is not going away tomorrow. If we ever are going to get rid of it, we first need legislation to defang it so it stops being a cash-cow. "Tracking prohibited by default" is a great end-goal, but we are not there yet.
Reading between the lines, it appears that there is some new solution proposed to "automatically communicate your privacy preference". That's nice, but when e.g. the Do Not Track header was tried, it just fell flat. So until this new solution is implemented and adopted, I'll take my websites with a cookie banner, thank you.
It is an unfortunate choice that the campaign obsesses over the cookie banner, instead of trying to actually advance the solution that would make it obsolete.
crote | 22 hours ago
The fact that we are still talking about this literally a decade after the GDPR was adopted shows that this isn't working. It has turned into a cat-and-mouse game, and the regulators just don't have the manpower to effectively rules-lawyer every tiny change.
> when e.g. the Do Not Track header was tried, it just fell flat.
... because there was no reason to follow it. There was literally zero consequence for ignoring it.
This new proposal makes the Do-Not-Track v2 header legally binding. User sends the header and you still show a consent popup? You're breaking the law, simple as that. No weaseling yourself out of it, a simple screenshot is enough.
Any regulator could build a fully-automated scanner in half a day: ask the local TLD registrar for a mapping of websites to companies, have some script request the page and do a regex search for "cookie" (or use AI if you are feeling fancy), take a screenshot, pass it to an intern to double-check, then automatically send out a €100 fine. Double it every X weeks they haven't fixed it yet. Want to fight it in court? They have screenshot, you lose, now pay.
gitowiec | a day ago
PunchyHamster | a day ago
But we can't have that, can we ? They will lobby to hell and back for that to not happen
fhn | a day ago
1vuio0pswjnm7 | a day ago
;dr
The "cookie banner" is an interactive method used by "adtech" companies to try to get user consent, as required by EU law. The forced interaction makes this method annoying
Google and other "adtech" companies are lobbying EU Member States to vote against giving users a means to non-interactively deny consent
wazdra | a day ago
1: https://www.cnil.fr/fr/cookie-walls-la-cnil-publie-des-premi... (in french, sorry)
jchook | 22 hours ago
However, powerful interest groups like ad companies that profit from your attention (which hysterically virtually powers the Internet today) were able to stop it from happening.
It was debated way back in 2009 when the GDPR was being developed. Iirc the argument was that browsers accept cookies by default so users do not get a fair consent moment. This is obviously easily fixed by regulation requiring browsers to ask users once.
Seems extremely backwards that we chose to forever darken the entire Web browsing experience just so users can "benefit" from a per-site option to let Google profit from them, with virtually zero payoff for the end user (ad relevance?).
P.S. If ad revenue is an essential pillar of Internet survival and fruition, the clear alternative seems to be sharing a fraction of that revenue with the tracked consumer.
_moof | 21 hours ago
This industry is a paperclip maximizer, and it needs to be dealt with accordingly.
voxic11 | 16 hours ago
jchook | 14 hours ago
cure_42 | 22 hours ago
kjgkjhfkjf | 21 hours ago
jeremyjh | 20 hours ago
crusty | 21 hours ago
micromacrofoot | 21 hours ago
but the proper functionality would be no cookies that require consent until consent is given
giancarlostoro | 21 hours ago
unmole | 19 hours ago
Perhaps the EU Commission could start by stopping the circus on its own website and killing its own cookie banner: https://commission.europa.eu/index_en
orangelimetea | 19 hours ago
At all.
sflicht | 18 hours ago
leptons | 18 hours ago
It's just like ADA compliance and trolling lawyers all over again.
vivzkestrel | 17 hours ago
- for the love of god please do this
- please get rid of every cookie banner on every website on this planet once and for all
- you ll be doing humanity a huge favor
nihonde | 17 hours ago
Browser-based privacy controls were proposed in the late-90s/early-2000's as P3P, and were killed by corporate interests.
https://www.w3.org/P3P/
samiv | 16 hours ago
The answer is simple. Don't use tracking cookies.
sholladay | 15 hours ago
getfluxly | 15 hours ago
pcollins123 | 15 hours ago
He asked me "So, how would you make the Internet better at Google?".
My response, "Setup preferences in Chrome to eliminate all popups including Cookie banners".
I never got a call back for the second interview.
alibarber | 14 hours ago
Oh.
eru | 14 hours ago
nottorp | 14 hours ago
Is there any reason for allowing this tracking browser side besides a little convenience for the web devs?
grumbelbart2 | 13 hours ago
There are so few sites where I really need cross-site logins to work that an opt-in would be much more preferable.
Have all sites set cookies on whichever third party they want, but don't share those cookies over. Add an explicit "Do you really want foo.com to share data with bar.com?" if you really need to see those facebook comments on your news site.
melicerte | 13 hours ago
inigyou | 10 hours ago
mFixman | 13 hours ago
Does anybody here know of a better solution?
[1] https://addons.mozilla.org/en-GB/firefox/addon/consent-o-mat...
pjio | 13 hours ago
inigyou | 10 hours ago
richrichardsson | 12 hours ago
voidUpdate | 12 hours ago
3% of people want to be tracked online? I think it's more likely that 3% of people misunderstood the survey question
benrutter | 12 hours ago
I don't really use youtube natively a lot anymore, but I used to with Google's "personalised ads" turned off. I don't know if you've tried that, but the ads Google serves you if you opt out of personalised adds are sketchy, creepy and mostly not child appropriate (a lot of medical stuff, plus adverts for mail order brides etc). Back then I opted in to personalised ads because being tracked seemed a better option to me than being served inappropriate material without my consent.
Anyway, that's a long rant, but my point is, there's edge-cases and weird contexts in which I can imagine people saying something like "of the options I see as likely to happen, I'd most like to be tracked".
voidUpdate | 11 hours ago
billynomates | 12 hours ago
PeterStuer | 12 hours ago
aucisson_masque | 11 hours ago
Put a note in your calendar, write a letter and send it then.
btw, the link say it's around 3% of people who want to be tracked when the reports state it's between 3 and 10%. it's misleading.
ghtbircshotbe | 9 hours ago
luquimarti | 5 hours ago