Rendered at 17:05:44 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
chrismorgan 44 minutes ago [-]
The other approach to killing the cookie banner is simply to declare that such a thing cannot constitute “informed consent”. (Perhaps: “ticking a checkbox and/or clicking a button cannot constitute informed consent”; and see what they try next.) From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way. Just as shrink-wrap licenses and even simple contracts have at times in some jurisdictions essentially been neutered, so that only terms that a reasonable person would expect to be there are enforceable, at which point it becomes obvious that the whole thing needs tearing down in favour of standard licenses/contracts. In the Australian state Victoria, for example, there are standard rent and property sale contracts; for renting you must use that contract <https://www.consumer.vic.gov.au/housing/renting/starting-and...>, and I got the impression that residential sales practically always use the standard contract.
But of course it’s impossible to convince someone of something when their livelihood depends on their not understanding it.
basch 3 minutes ago [-]
Cookie control always should have been a browser control. The legal route always should have been to force it to be built into browsers that provide sane defaults, and make it illegal to circumvent what the browser declares as far as fingerprinting etc.
any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.
otterley 33 minutes ago [-]
> From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way
There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened.
There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
znnajdla 20 minutes ago [-]
> “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement
Only engineers have trouble understanding this. It can be a reasonable defense, and it has successfully been used in courts of law many times. The law is not a machine that compiles text like code literally. Imagine someone who coerces a dying or sick person to sign an agreement they couldn’t possibly be in a reasonable state of mind to understand what they were doing -- the law can and does invalidate such “contracts”. That is the same principle behind age of consent laws. The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
otterley 19 minutes ago [-]
I am an attorney, and am aware of certain exceptions. But these are exceptions and not the general rule, which is what I am speaking of.
> The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
I haven’t heard of a single case where an agreement was voided because “no one could reasonably be expected to understand it.” Unless the language was so impenetrable or vague that the agreement itself could not be discerned. Lawyers tend not to write such agreements.
IsTom 10 minutes ago [-]
EULAs are restricted in power in EU and at least to me these cookie banners are similar in spirit.
tempestn 9 minutes ago [-]
"I didn't read it," sure. But, "A reasonable person would not read it?"
tacitusarc 9 minutes ago [-]
[dead]
bluGill 26 minutes ago [-]
Of you need a nonstandard contract then you need to provide proof that it was understood. These are not provided in a context where I would expect anyone reading it to have a lawyer to advise so they obviously don't understand it
otterley 23 minutes ago [-]
By that same logic, do you believe ignorance of the law is a valid defense to a criminal charge? Laws are also written by lawyers.
Avicebron 26 minutes ago [-]
> There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
The value is derived from the people consuming the product. Placing the "incentive to produce value" above the people who presumably are the source of this value seems...misaligned.
otterley 24 minutes ago [-]
If there’s no product to be consumed, there’s no value produced either. That’s the point: it’s harmful to eliminate the incentive to produce.
Avicebron 17 minutes ago [-]
People will _always_ need things. There are very few things that will eliminate people's need for things and producers will of course adapt to the environment.
What we need is an environment that does not give the producers asymmetric power over consumers and the products will naturally align with that.
inigyou 23 minutes ago [-]
What if only the incentive to produce bad things is eliminated
monkpit 6 minutes ago [-]
* definition of bad is subjective and may vary depending upon which lobby group has the most cash to throw around
inigyou 5 minutes ago [-]
no, I referred to actual bad things
otterley 1 minutes ago [-]
The point is still correct. People often disagree on what is good and what is bad. It’s a judgement, not an indisputable fact.
c0_0p_ 25 minutes ago [-]
That argument has actually worked in some cases, especially when you need to click away to actually access the document. I assume it's why we see more and more examples where you need to scroll the full body of text in order to "agree".
36 minutes ago [-]
ymolodtsov 15 minutes ago [-]
Websites need cookies.
I don't get why I have to suffer through this for a few puritans who literally lose nothing in the process of this transaction but act as if Stasi is watching them.
estebarb 12 minutes ago [-]
Session cookies do not require a banner.
tempestn 4 minutes ago [-]
Aggregated analytics do, and you can't run a serious website without some kind of analytics. Preference-storing does as well, despite any reasonable user expecting that, if they set a preference, it will be saved.
Phemist 1 hours ago [-]
> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.
So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...
mike_hock 1 hours ago [-]
Don't fall for the "we are just stupid" propaganda, which is used constantly by governments acting in bad faith.
Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.
This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.
inigyou 22 minutes ago [-]
I think it's because every single website breaks if you don't allow cookies at the browser level. Some knowledge of what the specific cookie does was necessary.
aspbee555 42 minutes ago [-]
changing IP is not really enough for privacy, there is many ways to fingerprint your machine/browser and uniquely identify you across networks
The problem there is that parent's won't know how to do it, or won't care. Many can hardly operate the most user-friendly phone, let alone manage accounts.
The online safety acts and its EU counterparts are somewhat risky, but nobody wants the mention the only proper alternative: a total ban on "social media." Not just for kids, but for everyone. Or a ban on smart phones, that would work too, at least short term. But: money.
alt227 57 minutes ago [-]
> The problem there is that parent's won't know how to do it, or won't care.
This is unfortunately the reality.
The other day a friend asked me to help her make her phone safer for her kids to use. I started by asking if she set permissions on the apps she downloaded. She looked at me blankly, "What permissions?". I proceeded to show her how you can granularly control what you allow each app to do on your phone and what access it is allowed. Her head blew up, she had no idea any of this existed and after gong through a few menus, she didn't care any more. It was all too complicated and too much to think about for a busy mum.
This is why governments unfortunately are having to try to protect people from themselves. As tech competent people it all seems so simple to us, but we need to remember the majority of the population just click 'Allow All' and blow past all permission and security questions as they have no idea what any of it means.
dijit 50 minutes ago [-]
"is this device for you, or a child" is one of the first options when setting up an iphone.
I haven't set up an Android in a while, but, I doubt it's massively different.
alt227 47 minutes ago [-]
Yeah but most parents devices are for them, they just let their kid use it too.
dijit 2 minutes ago [-]
Ah, I guess it's impossible to have a quick enable kids mode then.
We should just give up and give random individuals access to everyone's camera roll.. no other way.
SoftTalker 45 minutes ago [-]
Make the default "allow none" or "child-safe" and then if the parent does nothing that's what they get.
Kuyawa 60 minutes ago [-]
When we buy a new phone, the configuration process should ask if the device will be used by a kid. Easy and simple.
When restoring factory defaults, the same question, just in case the phone is sold, gifted, stolen or whatever.
If you are going to give a phone to a minor you should set that option right from the start.
broken-kebab 60 minutes ago [-]
It's ok if parents won't care. It's a choice too.
SoftTalker 39 minutes ago [-]
Yes, you can't make parents care, but make it easy for the ones who do, and you'll also pick up some number of those who care but only if it's not too difficult. There's no reason a parent should have to set permissions separately in 10 differents apps on a child's device.
conception 59 minutes ago [-]
That’s not true. Every TV app has a parent setting. That’s really easy to use browser support profiles just like TV apps do bad. UX doesn’t mean that it can’t be set up easily for parents. Windows itself could have profiles for kids that has all this set automatically. It’s not hard. There’s just no will to do it.
alt227 55 minutes ago [-]
> There’s just no will to do it.
Exactly. The problem is its from the parents side.
monkpit 3 minutes ago [-]
Spoken like someone who has never used parental controls. They’re a shitshow.
13 minutes ago [-]
SoftTalker 47 minutes ago [-]
That's why the setting should be on the device, not the browser or individual apps. One setting that you could even get pre-configured when you buy the phone.
alt227 46 minutes ago [-]
It still doesnt solve the problem of the millions of parents that just dont care.
GaryBluto 8 minutes ago [-]
Why should I care that they don't?
SoftTalker 36 minutes ago [-]
More parents will care if you make it easier.
BiteCode_dev 40 minutes ago [-]
A child can still access knives if the parents don't care.
echelon 58 minutes ago [-]
>>>>>>> now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...
THIS
Holy shit. This is such an obvious fix. And it shuts up those surveillance state goons immediately.
My God, why have we tried to summon up the ghost of 1984 when such a simple fix as this will do.
Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.
The blast radius is zero.
Good God, we need to fast track this into browsers right now. If we hurry we might be able to point to this as the technical fix.
Once some of the infrastructure exists, OS vendors can hook into it.
Firefox devs - please do this right now. Please spearhead this.
I might have to vibe code an advocacy site for the spec and set up a GitHub / RFC process.
dijit 18 minutes ago [-]
I agree, and I agree with the enthusiasm on which you bring in.
I've long since considered that the efforts for online child safety should be pointed at educating parents and spearheading some kind of certification of compliance for child safety of software and websites.
[this product is certified to adhere to EU:CSA]
Then you can block everything not certified, and the software that does the blocking would also be certified, the two major prongs you need (endpoints and sites working together: else they're blocked). The rest of the money goes to education for parents about this fact, and the dangers of not doing it, and how to do it.
This is super "easy" (when comparing to the effort it would take for putting backdoors in everything).
Which is why I think that the reason is definitely not child safety, and more about crime control.
I think this would be a net benefit, but I can see an issue. A lot of news sites today do "accept tracking, or pay us, or you can't access the page". The orgs doing this are reputable-ish so I assume it's considered legal, on some level at least.
So now they'd have a new popup that says "reconfigure your browser to accept tracking, or pay us, or you can't access the page". Which isn't really an improvement.
richard_chase 1 minutes ago [-]
It would have been funny to get a cookie banner on this site. They missed a good opportunity.
shagie 20 minutes ago [-]
> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful.
> ...
> You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default.
I always wondered though why a website in the eu, for the love of their users, won't just drop cookie usage and instrusive third party scripts. Just do analytics on the backend and don't set any cookie, except for tokens in authenticated areas
tysilva 2 hours ago [-]
Wow, finally. This would be a major quality of life update for browsing the web. As others have stated, not all sites merit the same preferences. Hopefully they can adapt a middleground of default settings with the ability to customize site by site.
convolvatron 1 hours ago [-]
under what circumstances as user would I want to explicitly agree to have my browsing history sent to tens or hundreds of third party tracking aggregators?
scbrg 24 minutes ago [-]
I've seen people argue, with a straight face, that they prefer to get ads that are "relevant to them". Including here on Hacker News.
tysilva 44 minutes ago [-]
I don't disagree. The ideal state here is really layers of customation for the defaults. Options like reject all, or strictly necessary would be at the forefront. And then it's really up to the individual how they want to proceed when those options are not available.
broken-kebab 59 minutes ago [-]
If offered something in return, I guess
PaulRobinson 1 hours ago [-]
Devil's advocate argument: if they were giving you something in return, and that could be cash, but it might also be "you can have this content for free".
In the UK a few news sites have changed cookie banners to "you can accept and see this stuff for free, or you can sign up for a subscription, which would you prefer?". It's the only time I hit accept (and then clear browser history).
If blanket preferences from browser signals became the norm, a segment might open up where you would configure preferences and a data broker would make sure you get something in return for your data. At minimum it might force paywalled publishers to consider that as a "lite" subscription option.
inigyou 20 minutes ago [-]
That's been ruled illegal in the EU, but EU sites still do it. Basically, the consent exception only applies if the user isn't coerced into it. Because coerced consent isn't consent.
troupo 1 hours ago [-]
> but it might also be "you can have this content for free".
ads don't require invasve and pervasive tracking
alt227 51 minutes ago [-]
You seem to have missed the point. No ads dont require those things, but companies could start offering content in return for those things instead of ads.
Alpha3031 30 minutes ago [-]
As I understand it, it is the position of several DPAs that denial of access entirely (i.e. "consent or pay") could contravene the "freely given" requirement of GDPR in most cases, though this has thus far not been tested in court.
Ask that question to the 99% of people who click 'Allow All' on cookie banners.
fmbb 39 minutes ago [-]
Its the biggest button.
They did not read the text to agree.
It was the fastest way to get the banner to go away. Sometimes they force you to confirm multiple times if you click ”none” or ”minimal”.
inigyou 20 minutes ago [-]
Sometimes I do it to reward the website for being less shit than most websites.
dspillett 25 minutes ago [-]
> automated signals that would communicate your privacy preferences between your device and websites or apps0
Sounds good, as long as it covers the "legitimate interest" bollocks⁰ that is often hidden in inconvenient UI nests as well as the basic preference.
-------
[0] "we see your preference not to be stalked, but we want to anyway, click again for every partner to reconfirm you don't want them following you around"
rusk 16 minutes ago [-]
This was tried before but was presumably scuppered by the market intelligence and surveillance communities
Even well meaning bodies like TFL (Transport for London) have cookie warnings that impede the actual access of the website.
Need to look up a bus time? Full screen cookie consent with accept buttons drawn OFF THE SCREEN.
inigyou 21 minutes ago [-]
They obviously aren't well-meaning if they're endlessly tracking everything you do
hash872 26 minutes ago [-]
Also there's a big difference between the sites that easily allow you to simply reject whatever their premade cookie settings are. And, the sites that only allow you to use them after you've accepted (example, politico.eu). Or, the sites that do have a 'reject' option, but you have to click through multiple screens and then manually reject each individual option.
Sites that easily allow you to simply reject everything are then a short hop, skip and a jump into browser settings where you auto-reject all cookie/tracking nonsense
n0on3 38 minutes ago [-]
Nice try but it won’t work, unless they were to also make it illegal to diversify the experience based on these settings and periodically but consistently issue massive fines to those who do (or who ignore such settings), which unfortunately ain’t happening.
An easier step forward could be to make the too often present ridiculous use of dark patterns and endless process to express your lack of consent illegal (and issue colossal fines…)
imhoguy 25 minutes ago [-]
And guess who makes the most of devices and the most popular browser, I already see post install "Get most of the browsing experience by agreeing to these defaults."
ChadMoran 48 minutes ago [-]
What does enforcement of not having these banners look like? Wha tif people just... didn't.
alt227 1 hours ago [-]
I still don't get why every website has a cookie banner by default. I am data controller for several companies and have lots of exposure to GDPR. All my websites have no cookie banner, as they are not required.
I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies? Who knows.
reorder9695 56 minutes ago [-]
Don't underestimate the argument of "just to be on the safe side". Someone running a business who doesn't know a lot about cookies will often just put a banner on as an easy arse covering mechanism even when not required.
inigyou 19 minutes ago [-]
Let businesses who don't know what they're doing be outcompeted by businesses who know what they're doing.
SoftTalker 38 minutes ago [-]
Or they had their site developed by an agency and the cookie banner is just part of their standard scaffolding for a new site.
tete 36 minutes ago [-]
> I guess that most companies just chuck it up there as a default so they dont have to read the law
I think most companies just don't give a fuck about user privacy and therefor have to show one. There are of course exceptions. But I don't know how many of them have been actual (for-profit) companies.
kuerbel 39 minutes ago [-]
If you use social media pixels, ad tracking, or performance analytics tools like Google Analytics a cookie banner and consent is required. If not, then not.
alex_suzuki 5 minutes ago [-]
Side note: there’s plenty of Analytics tools that don’t require cookies. Plausible (https://plausible.io) is one of them, there are many others.
Not affiliated, just a happy customer.
esperent 58 minutes ago [-]
> I guess that most companies just chuck it up there as a default
50% that, and 50% that way more companies than you expect are harvesting and profiting from your data.
HiPhish 57 minutes ago [-]
> I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies?
That has been my guess as well. If you run npm install half-the-internet you have no idea what's in there, so just slap on that cookie banner for good measure. Of course the real problem is not knowing what's inside your application, but the thought process is "eh, if a blanket cookie banner does the job then that's good enough for me".
maccard 1 hours ago [-]
I’ve made a few sites for work that aren’t our primary focus. The sites used cookies for login and for “required purposes” (storing in progress state). We did all the tracking on the backend, no cookies or client side trackers.
On our go-live form there’s a question “do you use cookies” and it’s yes/no. If you say yes legal block the site from going live without the pre approved cookie banner…
jarofgreen 43 minutes ago [-]
> We did all the tracking on the backend
Just checking, you do know that still counts as tracking and may fall under GDPR rules? GDPR was never just about cookies.
maccard 28 minutes ago [-]
I do but we shouldn’t be talking about cookies in our cookie banner then.
SeriousM 29 minutes ago [-]
It's a "Dick over".
sandeepkd 1 hours ago [-]
Usually government mandating something is concerning cause it seems to favor the government for its existence. However with EU commission its actually interesting combination, its representing multiple individual governments at once which somehow works good for the citizens.
Overall this is a common sense solution. The challenge is that a significant industry makes money by collecting and selling data. It makes it harder for businesses who depend on it, they are going to get creative and will eventually come up with some dark pattern to circumvent it.
rpdillon 2 hours ago [-]
The insanity around cookie banners is a good target.
> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.
Fortunately, if you have uBlock Origin, you can enable Easylist cookie notices under annoyances and avoid most of them. Combine with blocking third-party cookies, and the problem pretty much disappears.
The fact that the EU tried to regulate this stuff is a shame, because regulation is not a good remedy. End-users have agency here. The solution is to enable end-users to have control in their browser (which they always did, so it's an issue of education, like so many things).
Shame that Google is trying to kill uBO though. Extremely pleased that Brave continues to support it.
mrkeen 2 hours ago [-]
If it's not cookies, it will be something else. IP addresses, tracking pixels, browser fingerprinting.
The Do Not Track header is the only technology needed. The rest is compelling companies to obey it.
cwnyth 1 hours ago [-]
Didn't know that about Brave, but it's moot for me since Firefox also supports it and these days I find that Firefox is the better experience, not Chrome or even Chromium.
mmarq 1 hours ago [-]
As if the DNT thingy didn’t exist…
IshKebab 16 minutes ago [-]
DNT tried to do this without any legal backing which was obviously stupid.
drnick1 59 minutes ago [-]
uBlock Origin with all "annoyance" filters enabled. I haven't seen a cookie banner in years.
Another good one to have the "hide Youtube shorts" filter, featured on HN a while back.
tete 38 minutes ago [-]
There is Consent-O-Matic.
Also I wanna know when websites don't give a shit about my privacy and therefor have to show a cookie banner. While theoretically not consenting should mean not collecting blocking it altogether and modifying page content might mean "all bets are off". If the website expects you to have made a decision that might wrongly consider it consent.
Consent-O-Matic says "I don't consent".
openquery 6 minutes ago [-]
Finally yes yes yes.
I've wanted the option to select your cookie preferences once and forget in a brower for ever.
I assume the reason this wasn't done initially was corporate pressure (most people would opt-out of everything by default).
1.2 billion exposed users × 8.17 years×365×3 banners/day×4 seconds÷36 is roughly 10-15 billion human hours lost to dealing with damn cookies since GDPR took effect on May 2018.
That's about 17,000 human lives.
hieKVj2ECC 2 hours ago [-]
Yes please!
troupo 2 hours ago [-]
> he EU Commission finally proposed a solution to the cookie banner problem: automated signals that would communicate your privacy preferences between your device and websites or apps.
It wasn't on EU Commission to "finally propose a solution". The soluton has always been there.
Somehow, Google, aka world's largest tracking and advertising company incidentally making the worlds' dominant browser and completely dominating all web standards, couldn't be bothered, and instead was pushing crap like FLoC
the__alchemist 2 hours ago [-]
Keep fighting! For now: browser plugins.
hborscht 2 hours ago [-]
is there a specific one you would recommend?
tcfhgj 1 hours ago [-]
uBlock Origin -> allows blocking dialogs (legally implies refusal of everything not necessary, because you don't agree to something requiring agreement)
Consent-O-Matic -> automated configuration to your preferences using the dialog provided.
I still don't care about cookies -> least privacy friendliest option, because it may opt into undesired tracking (its goal is just to remove the annoyance of the dialogs)
the__alchemist 1 hours ago [-]
I use "I still don't care about cookies"; it works well, but I don't have a current comparison to other options.
1 hours ago [-]
wrqvrwvq 20 minutes ago [-]
or we could glass the continent
paulddraper 2 hours ago [-]
Doesn't this lead to an all-or-nothing approach?
I don't want randomnewssite to track me. But a favorite online store...I do want help with recommendations.
joeframbach 2 hours ago [-]
You would presumably be logged in to your favorite store site, and they would be using your identifying session to make recommendations, not anonymous tracking cookies.
paulddraper 1 hours ago [-]
Eh, maybe.
It's easier to click a single button than hunt for how to create/access an account for the brand.
dymk 2 hours ago [-]
Then sign in, thats enough signal for them to track you
qurren 2 hours ago [-]
Just disable cookies on your browser by default, and enable it for the sites that you need to log in to.
Ironically, this has the effect of cookie banners reappearing every time because they cannot place a cookie that says that you have rejected them.
Phemist 1 hours ago [-]
Malicious compliance. You do not need a cookie to "store" the fact you have rejected them. They can simply assume you have rejected them from the lack of cookies. They can store a cookie once you (have gone out of your way to) accept them.
mzajc 2 hours ago [-]
Unless disabling cookies means treating all cookies as session cookies (meaning you can still be followed within a session), this has the fun side effect of breaking pretty much every CAPTCHA firewall like Anubis, Cloudflare Turnstile, and any other that relies on cookies.
Unfortunately this means you have to view a lot of the web through archive.today or web.archive.org - I would know because I have uMatrix configured this way.
tcfhgj 1 hours ago [-]
you can be tracked without cookies - the cookie dialogs are about tracking and processing of personal data in general.
-> not really sensible
amelius 2 hours ago [-]
Just configure your browser to ask for cookies for that store only?
srijanbaniyal 53 minutes ago [-]
[flagged]
SadErn 12 minutes ago [-]
[dead]
dfaoidsoi 2 hours ago [-]
[dead]
TechSquidTV 2 hours ago [-]
The EU has been on a decade-long crusade to destroy the internet.
PaulRobinson 1 hours ago [-]
I think you'll find that's Google and Meta.
Just step back and ask yourself what each side of that debate is trying to achieve and why. What is motivating them? Why are they motivated in that way?
Don't just recite what you "know", think, look, research, figure it out. It might sound good to have a one-liner like this in your back pocket, but do you really believe it after looking at the publicly available information that it is their real intention to conduct a "crusade to destroy the internet"?
tcfhgj 1 hours ago [-]
Advertisement has been on a decade-long crusade to destroy the internet.
amelius 35 minutes ago [-]
You mean: the planet.
(because it drives consumerism)
yankfatigue 2 hours ago [-]
OK yank.
W3cUYxYwmXb5c 1 hours ago [-]
This is conflating different things. They are trying to use people's annoyance with the banner THEY caused to build support for another legislation.
Cookies were never a problem. Just get rid of the banner.
This other legislation should pass/fail on its own merit.
tete 40 minutes ago [-]
No, please don't!
It's great. The current law forces people that don't give a shit about user privacy to have a banner (or any other way of asking for consent first) while giving everyone that cares and everyone not wanting to spy on their visitor a free pass.
inigyou 17 minutes ago [-]
People click yes too often because it's the easier way to make it go away. This new thing could actually result in a 0% tracking cookie consent rate, effectively making them illegal.
But of course it’s impossible to convince someone of something when their livelihood depends on their not understanding it.
any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.
There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened.
There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
Only engineers have trouble understanding this. It can be a reasonable defense, and it has successfully been used in courts of law many times. The law is not a machine that compiles text like code literally. Imagine someone who coerces a dying or sick person to sign an agreement they couldn’t possibly be in a reasonable state of mind to understand what they were doing -- the law can and does invalidate such “contracts”. That is the same principle behind age of consent laws. The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
> The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
I haven’t heard of a single case where an agreement was voided because “no one could reasonably be expected to understand it.” Unless the language was so impenetrable or vague that the agreement itself could not be discerned. Lawyers tend not to write such agreements.
The value is derived from the people consuming the product. Placing the "incentive to produce value" above the people who presumably are the source of this value seems...misaligned.
What we need is an environment that does not give the producers asymmetric power over consumers and the products will naturally align with that.
So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...
Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.
This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.
https://creepjs.org/checker
The online safety acts and its EU counterparts are somewhat risky, but nobody wants the mention the only proper alternative: a total ban on "social media." Not just for kids, but for everyone. Or a ban on smart phones, that would work too, at least short term. But: money.
This is unfortunately the reality.
The other day a friend asked me to help her make her phone safer for her kids to use. I started by asking if she set permissions on the apps she downloaded. She looked at me blankly, "What permissions?". I proceeded to show her how you can granularly control what you allow each app to do on your phone and what access it is allowed. Her head blew up, she had no idea any of this existed and after gong through a few menus, she didn't care any more. It was all too complicated and too much to think about for a busy mum.
This is why governments unfortunately are having to try to protect people from themselves. As tech competent people it all seems so simple to us, but we need to remember the majority of the population just click 'Allow All' and blow past all permission and security questions as they have no idea what any of it means.
I haven't set up an Android in a while, but, I doubt it's massively different.
We should just give up and give random individuals access to everyone's camera roll.. no other way.
When restoring factory defaults, the same question, just in case the phone is sold, gifted, stolen or whatever.
If you are going to give a phone to a minor you should set that option right from the start.
Exactly. The problem is its from the parents side.
THIS
Holy shit. This is such an obvious fix. And it shuts up those surveillance state goons immediately.
My God, why have we tried to summon up the ghost of 1984 when such a simple fix as this will do.
Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.
The blast radius is zero.
Good God, we need to fast track this into browsers right now. If we hurry we might be able to point to this as the technical fix.
Once some of the infrastructure exists, OS vendors can hook into it.
Firefox devs - please do this right now. Please spearhead this.
I might have to vibe code an advocacy site for the spec and set up a GitHub / RFC process.
I've long since considered that the efforts for online child safety should be pointed at educating parents and spearheading some kind of certification of compliance for child safety of software and websites.
[this product is certified to adhere to EU:CSA]
Then you can block everything not certified, and the software that does the blocking would also be certified, the two major prongs you need (endpoints and sites working together: else they're blocked). The rest of the money goes to education for parents about this fact, and the dangers of not doing it, and how to do it.
This is super "easy" (when comparing to the effort it would take for putting backdoors in everything).
Which is why I think that the reason is definitely not child safety, and more about crime control.
Me talking about UK blocking people unless they ID themselves in 2013: https://news.ycombinator.com/item?id=6979295
Me talking about how its disingenuous because we have superior technical solutions to this particular issue last year: https://news.ycombinator.com/item?id=45010902
So now they'd have a new popup that says "reconfigure your browser to accept tracking, or pay us, or you can't access the page". Which isn't really an improvement.
> ...
> You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default.
That's an excellent idea... lets see how its implemented on https://european-union.europa.eu/index_en
Oh... there's a cookie banner.
In the UK a few news sites have changed cookie banners to "you can accept and see this stuff for free, or you can sign up for a subscription, which would you prefer?". It's the only time I hit accept (and then clear browser history).
If blanket preferences from browser signals became the norm, a segment might open up where you would configure preferences and a data broker would make sure you get something in return for your data. At minimum it might force paywalled publishers to consider that as a "lite" subscription option.
ads don't require invasve and pervasive tracking
(see e.g. https://iapp.org/news/a/cjeu-clarifies-cookie-consent-requir... https://www.edpb.europa.eu/news/edpb-consent-or-pay-models-s... )
They did not read the text to agree.
It was the fastest way to get the banner to go away. Sometimes they force you to confirm multiple times if you click ”none” or ”minimal”.
Sounds good, as long as it covers the "legitimate interest" bollocks⁰ that is often hidden in inconvenient UI nests as well as the basic preference.
-------
[0] "we see your preference not to be stalked, but we want to anyway, click again for every partner to reconfirm you don't want them following you around"
https://en.wikipedia.org/wiki/P3P
Need to look up a bus time? Full screen cookie consent with accept buttons drawn OFF THE SCREEN.
Sites that easily allow you to simply reject everything are then a short hop, skip and a jump into browser settings where you auto-reject all cookie/tracking nonsense
An easier step forward could be to make the too often present ridiculous use of dark patterns and endless process to express your lack of consent illegal (and issue colossal fines…)
I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies? Who knows.
I think most companies just don't give a fuck about user privacy and therefor have to show one. There are of course exceptions. But I don't know how many of them have been actual (for-profit) companies.
50% that, and 50% that way more companies than you expect are harvesting and profiting from your data.
That has been my guess as well. If you run npm install half-the-internet you have no idea what's in there, so just slap on that cookie banner for good measure. Of course the real problem is not knowing what's inside your application, but the thought process is "eh, if a blanket cookie banner does the job then that's good enough for me".
On our go-live form there’s a question “do you use cookies” and it’s yes/no. If you say yes legal block the site from going live without the pre approved cookie banner…
Just checking, you do know that still counts as tracking and may fall under GDPR rules? GDPR was never just about cookies.
Overall this is a common sense solution. The challenge is that a significant industry makes money by collecting and selling data. It makes it harder for businesses who depend on it, they are going to get creative and will eventually come up with some dark pattern to circumvent it.
> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.
Fortunately, if you have uBlock Origin, you can enable Easylist cookie notices under annoyances and avoid most of them. Combine with blocking third-party cookies, and the problem pretty much disappears.
The fact that the EU tried to regulate this stuff is a shame, because regulation is not a good remedy. End-users have agency here. The solution is to enable end-users to have control in their browser (which they always did, so it's an issue of education, like so many things).
Shame that Google is trying to kill uBO though. Extremely pleased that Brave continues to support it.
The Do Not Track header is the only technology needed. The rest is compelling companies to obey it.
Another good one to have the "hide Youtube shorts" filter, featured on HN a while back.
Also I wanna know when websites don't give a shit about my privacy and therefor have to show a cookie banner. While theoretically not consenting should mean not collecting blocking it altogether and modifying page content might mean "all bets are off". If the website expects you to have made a decision that might wrongly consider it consent.
Consent-O-Matic says "I don't consent".
I've wanted the option to select your cookie preferences once and forget in a brower for ever.
I assume the reason this wasn't done initially was corporate pressure (most people would opt-out of everything by default).
1.2 billion exposed users × 8.17 years×365×3 banners/day×4 seconds÷36 is roughly 10-15 billion human hours lost to dealing with damn cookies since GDPR took effect on May 2018.
That's about 17,000 human lives.
It wasn't on EU Commission to "finally propose a solution". The soluton has always been there.
Somehow, Google, aka world's largest tracking and advertising company incidentally making the worlds' dominant browser and completely dominating all web standards, couldn't be bothered, and instead was pushing crap like FLoC
Consent-O-Matic -> automated configuration to your preferences using the dialog provided.
I still don't care about cookies -> least privacy friendliest option, because it may opt into undesired tracking (its goal is just to remove the annoyance of the dialogs)
I don't want randomnewssite to track me. But a favorite online store...I do want help with recommendations.
It's easier to click a single button than hunt for how to create/access an account for the brand.
Ironically, this has the effect of cookie banners reappearing every time because they cannot place a cookie that says that you have rejected them.
Unfortunately this means you have to view a lot of the web through archive.today or web.archive.org - I would know because I have uMatrix configured this way.
-> not really sensible
Just step back and ask yourself what each side of that debate is trying to achieve and why. What is motivating them? Why are they motivated in that way?
Don't just recite what you "know", think, look, research, figure it out. It might sound good to have a one-liner like this in your back pocket, but do you really believe it after looking at the publicly available information that it is their real intention to conduct a "crusade to destroy the internet"?
(because it drives consumerism)
Cookies were never a problem. Just get rid of the banner.
This other legislation should pass/fail on its own merit.
It's great. The current law forces people that don't give a shit about user privacy to have a banner (or any other way of asking for consent first) while giving everyone that cares and everyone not wanting to spy on their visitor a free pass.