11 ms·
Sigh, this is what browsing the web in the EU looks like nowadays (2021)
- bux93 3y agoDon't shoot the messenger. 99% of cookie/tracking dialogues are illegal, and are only there as a fig leaf because the website itself is engaged in illegal data processing in the first place.
- flir 3y agoIs there an easy way (firefox) to whitelist a few sites I care about, and have anything else just dumped out of the cache the moment I close the tab? Kind of a context-aware private browsing mode, I guess.
- rany_ 3y agoThis is what malicious compliance looks like.
- deadeye 3y agoWhat could you possibly mean? Government made it so much better. How else would you know that the cookies (you're going to consent to anyway) are being put on your computer?
- dr_dshiv 3y agoIt’s more about training people to automatically click “accept” without reading anything. That’s security best practice for a continent?
- jkaplowitz 3y agoIt’s also not what EU law requires. All the many websites that make it easier for people in the EU to accept the tracking than to decline it, as common as that pattern is, are non-compliant. Under-enforcement of these rules is sadly the norm. Compliant websites, such as that of the European Commission, don’t make it any harder to dismiss the dialog by accepting only essential cookies than by accepting all of them. I agree with you that the non-compliant approach teaches a bad security practice to the general population. The fix is better enforcement of existing law, without a new law actually being needed except possibly a better procedure for more effective enforcement. Unfortunately, achieving that is hard for political reasons. The EU’s politicians, and therefore the data protection authorities whom they oversee, care mostly about seeming to protect privacy, whatever the reality, and don’t want to deal with the economic + lobbying + PR + political donation + therefore electoral consequences of routinely taking proper and timely action. This is especially true for some of the most regulatorily captured data protection authorities in the EU, such as Ireland’s.
- tester756 3y agoYea, let's blame EU for websites spying on you If website uses cookies just for legit purposes (e.g auth, language choice), then it doesn't need to show cookie consent. Webmasters should get awarness on this or stop spying
- brookst 3y agoSo you’re a company with a web property. Your lawyers tell you you have two options: 1. Ensure that you’re perfectly abiding by all “legit purposes” and be prepared to update your policies and software each time those change, at the risk of huge fines. Or, 2. Just put an annoying banner up and have no risk. Which do you do? Government created this problem. Yes, it was in response to bad behavior from industry, but that doesn’t absolve the bureaucrats from responsibility for the results of their “solution”. If someone lights your kitchen on fire and the fire department’s response is to burn down the entire house, there is plenty of blame to go around.
- gizmo 3y agoThis is nonsense. You can't just put any kind of cookie banner up and magically be in compliance. You'd still have to explain what kind of data is being shared with with parties and why. And you have to update your privacy policy to keep it accurate in any case! In fact, many of the websites that have these obnoxious cookie banners are NOT in compliance because don't offer a simple and unambiguous opt-out option. These cookie banners and cookie popups are intentionally made to be maximally annoying. That's not good faith behavior by companies. That's malicious and an attempt to get consumers to blame regulators for breaking their browsing experience. The worst thing is that some people totally fall for it!
- mrguyorama 3y agoIf these are the two options your lawyers give you, fire them, because they are lazy shit bags. All you need to do is not store cookies. That's it. It's not difficult at all. If you do want to cover your ass and use a consent dialog, there's a million options that are non-disruptive to your users and allow them to one click opt out.
- 3y ago
- oefnak 3y agoThe ads are a lot worse than the consent banners, though.
- OptionX 3y agoIt may be annoying, but just the possibility of opting out of some of them is already something against the rising tide of taking control away from the user. Is it the perfect system? No. Is it better than no system at all. I think so.
- throwbadubadu 3y agoAnd it is not like companies could have chosen a better approach.. like default opt-out, or remember that one thing, or respect a DNT. There would have been some options to comply with the law, but there was only one that still allows companies to grab most of the data and at the same time get people annoyed about the attempt to reasonable legislation (which certainly could be improved, like just go a DNT approach, but companies went immediately rampant on that for the same reasons..) But big corps know what they wanted and do and lead the rest of the pack..
- nequo 3y agoPeople with anti-GDPR views appear to assume that like them, everybody else also just wants to accept every cookie. But that is not true. And the interface affects how users respond, too. For example: Given a binary choice, more users are willing to accept tracking compared to mechanisms that require them to allow cookie use for each category or company individually https://dl.acm.org/doi/abs/10.1145/3319535.3354212 https://dl.acm.org/doi/abs/10.1145/3319535.3354212
- menus 3y ago> you're going to consent to anyway Speak for yourself. I never consent to marketing or analytical cookies. I appreciate the option to turn them off.
- brookst 3y agoAnd it’s so easy, with the choice of one button to make things work like they always did, or a quick sixteen-part questionnaire and identity verification process if you want to submit a request to be considered for an alternative cookie delivery experience.
- drcongo 3y agoGuns don't kill people etc.
- telmo 3y agoIn my personal experience, people who hate the GDPR are typically not EU citizens. I am an EU citizen and I strongly approve of GDPR. Is it perfect? No. Is it a step in the right direction? Yes.
- 0xfedbee 3y agoDo you also approve of surveillance states that a lot of EU countries are? Do you approve of push to end encrypted messaging? Do you approve of impossibility of getting an anonymous SIM card?
- nottorp 3y agoThe UK is not in the EU any more? Also, I got handed an anonymous sim card for free at the post office last week.
- wussboy 3y ago"This legislation is not perfect, therefore all legislation is useless."
- mrweasel 3y agoAnd the EU is the only thing that consistently fights countries that try to spy on their citizens. I'm in Denmark and the government flat out refuse to stop tracking people via the cell phone network. The EU is pretty much the only organization that cares and tries to stop it (hard to actually stop it when the local government just ignores every ruling from the EU on the subject).
- Deestan 3y agoWhataboutism is detrimental to discussion.
- babypuncher 3y agoI don't consent to them. If websites are making it hard not to consent, then they are in violation of the GDPR. Stop blaming the government for something private companies are doing to you. All the government did was require them to be honest about it. Maybe the EU should be more aggressive with GDPR, and start fining these companies out of existence for not being 100% compliant. That would put a stop to the maze of dark patterns pretty quickly. Either every shitty company would go bankrupt overnight, or they would learn how to make very simple "yes cookies" and "no cookies" buttons.
- maaarghk 3y agoi liked how the reddit popup had nothing to do with cookie consent and the second site didnt have any popups at all - author could have cherry picked a bad example but for some reason gave us this?
- s_dev 3y agoNo mention of the dramatic difference between certain news websites not having intrusive pop ups due to GDPR. Which should be mentioned any time this debate pops up.
- whimsicalism 3y agoIf not for EU law the result would have been displayed inline immediately.
- judge2020 3y agoThe Reddit one is just because of Reddit, not cookie consent.
- whimsicalism 3y agoYou would never have to see that with American Google because the answer is displayed inline
- danhau 3y agoWell, it‘s fairer than cherry picking the most outrageous examples. Though I wonder if he didn‘t get any Reddit cookie banners because he had already accepted them at some point in the past.
- mmazzarolo 3y agoI mean... I just recorded a browsing experience? It's the entire experience in general that sucks imho, regardless of cookie consent popups or not.
- 3y ago
- iamacyborg 3y agoAnd think, if website operators chose to actually use the DoNotTrack signal from your browser, you wouldn't have such a terrible experience on their websites.
- itake 3y agoJust a guess, but even people that don't want to be tracked choose the easy "accept everything" button than spending the time to customize the tracking. If companies DoNotTrack, they will have fewer people opting-in for tracking.
- sshine 3y ago> even people that don't want to be tracked choose the easy "accept everything" button The design of these consent forms is often so obscure I end up in some menu system with too much information I didn't want, and no hotkeys to go back except leave the website.
- mrguyorama 3y agoNearly every single cookie pop up I have seen is provided by the exact same third party company. That cookie dialog has an option where you can have a simple "Reject all" button that you can click to reject all "not necessary" cookies and use the website. It is the website owners fault when they choose not to turn that feature on.
- JoshTriplett 3y agoThat shouldn't be a "feature" that you can turn on and off; according to the EU regulations, the option must be equally prominent so there should always be a "reject all" button, and it can't be buried or made harder to see than the "accept all" button. (Leaving aside that sites should just not have these banners, which provides the best user experience. Just delete all the tracking and the banners along with it.)
- yomlica8 3y ago
- whimsicalism 3y agoIn my view, most of these laws have a protectionist aim and this has been admitted in the legislative debates around them. We might have tried similar things if Europe was as dominant in American tech markets.
- delecti 3y agoI feel like a reasonable tweak to GDPR is to require that if a site has an "accept all" button, it needs an equally (or more) prominent "reject non-essential" button.
- seba_dos1 3y agoIt's pretty much a requirement already. The website can't make it hard to reject or make it seem like accepting is the only way ahead. Many popular sites had made rejection easier after GDPR complaints (smaller ones often still didn't because nobody cared enough to complain, I guess).
- pasc1878 3y agoThat is already the law - note the cookie consent law is not GDPR. Many websites seem to break this law.
- handelaar 3y agoGDPR regs in fact already require exactly this, and all "consent" acquired without one has no legal basis. One or two national regulators have belatedly started to pursue it.
- ktosobcy 3y agoBut you know that the problem are we operators - right? There could be browser configuration for the cookie consent popup (accept, essential, reject all) that websites could follow but now - they prefer to be obnoxious about it hoping that everyone will click "allow" pit of boredom (not to mention that at the beginning it was only visible option and reject was hidden, which was illegal)...
- danhau 3y agoThis. It boggles the mind that browser vendors (and standards committee) haven‘t come up with a preferences page for cookie consent. Expose that through JS and/or send it to the server via a HTTP header.
- jonas-w 3y agoI don't know if you are being sarcastic, but the DNT header exists, just no one respects it. https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/DNT https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/DN...
- ilyt 3y agoNothing to boggle. Google is ad company. They will do everything in their power to not give users easy option to opt out of tracking.
- danudey 3y agoThe companies who actually use these cookies don't want that, because everyone would just turn everything off forever. It would probably just kill off tons of analytics companies overnight. (I wouldn't lament the loss of invasive analytics, but the job losses would be saddening)
- ktosobcy 3y agoIt's not the browser vendors (well, save for morons from google) because there is DoNotTrack header but it's not used/enforced. EU could amend the law to include that and it would be AWESOME.
- Kovah 3y agoInstead of hating the EU, how about directing your hate towards the bad players of the web? Cookie banners are not the fault of the EU, but the fault of companies disrespecting privacy rights and pushing data collection, ads and all possible shady growth hacking strategies towards the user. I am glad that a government body actually made this possible and made visible how horrible the internet is.
- whalesalad 3y agoA bad bandaid is still a bad thing, regardless of what it is covering up. Cookies are table stakes on the internet. This is the wrong solution to a completely different problem.
- nottorp 3y agoAll they have to do is stop tracking us and only use login cookies if i log in. Simple enough. Any other cookies are not "table stakes".
- danudey 3y agoWebsite analytics can be incredibly useful for designers and developers; giving those up would be a huge hit to a lot of companies, large and small, so it's understandable that they're not going to do so. Random example from more than a decade ago: I worked at an online retailer, and we did a nice redesign of our cart page. Looked great, much more readable, but we started losing sales. Did people hate the redesign? It was certainly easier to use and navigate. Our marketing guy looked at our analytics and saw that there was a massive drop in checkouts from users whose displays were set to 1024x768. He changed his resolution and, sure enough, the 'Checkout' button was something like four pixels below the bottom of the screen, if you were using Internet Explorer or Chrome and you had your browser maximized. I get that analytics can seem creepy and gross, and stuff like that is 'none of [retailers'] business' to a lot of people, but without those analytics we would have had no idea why we lost those sales, and would have had to simply revert the redesign with no real opportunity to change it.
- deafpolygon 3y agoThis isn't actually EU specific.
- greybox 3y agoA reminder that websites wouldn't need to do this if their intention wasn't to track you all over the internet. It's google, facebook etc that are trying to shove these things down your throat, not the EU.
- whalesalad 3y agoThat ship has sailed. It is now on the end user to protect themselves. These banners are just plain noise. No one is reading them. People will click whatever they need to click to dismiss the dialog. The general computing population does not give a shit, and the ones who do will use privacy-oriented browsers and platforms.
- loa_in_ 3y agoNothing is written in stone or in stars. Nd there used not to be legislation. And now there's legislation that fights towards user consent, so I don't see how anything has sailed anywhere. It's just a bunch of company code that needs to change, with a quick solution of a multiple-deletion commit as an option in most instances.
- Heliosmaster 3y agoI think most of the comments here right now are missing the point of OP's post. It's not about one thing in particular (cookie consent), just that the whole ordeal is full of ads and popups (one of which is the cookie consent popup). Most of this crap is the same everywhere, not just in the EU.
- mmazzarolo 3y agoThanks, that was my intention (back when I posted it). I added "from EU" just to make it clear—since people would have otherwise said "that's not how it works in the US :p"
- saiya-jin 3y agoYeah hat EU remark unleashed some emotions a bit, people are (incorrectly) bashing EU for consent popup due to companies tracking (and monetizing) the hell out of their browsing habits
- indymike 3y agoLately, I've been having developers and designers on my team install each of the three major browsers without plugins and visit five of the "top 10 media sites" (https://www.similarweb.com/top-websites/news-and-media/ https://www.similarweb.com/top-websites/news-and-media/), plus twitter, facebook and linkedin for a total of two hours so they see what the web looks like for regular users. It doesn't take long for people to realize just how terrible 25 years of accumulated surveillance, advertising and front-end cruft has made the web.
- jacquesm 3y agoI'm quite literally shocked whenever I have to use a relative's computer for a bit.
- BHSPitMonkey 3y agoYou may want to check that the outlet is grounded.
- skydhash 3y agoI traveled and I wonder why someone would use Youtube's free tier, There's like an ads every 3 minutes, plus the ones when the video starts (Youtube don't show ads in my country). My Twitch usage has gone down a lot because of 7-8 ads in a row. I would subscribe to the few creators I follow if not for the friction when I want to quickly check another creator's page (give me like at least 15 minutes without ads).
- deleted 3y ago[deleted]
- fleventynine 3y agoTo align incentives, maybe it's time we start paying for the web content we consume with money.
- nottorp 3y agoSure. When they charge a reasonable price for occasional visitors, not the "just the price of a Starbucks coffee per month" subscription that's the SaaS wet dream. Edit: also, non targeted NON INTRUSIVE ads will do too. Or would have done. If the ad industry wouldn't have burned any shred of credibility they ever had.
- usrnm 3y agoYou assume that corporations won't just take your money and continue to track you anyway.
- fleventynine 3y agoMaybe, but by being a paying customer with lots of options (including collective negotiation), you have a lot more leverage to get them to do what you want.
- mrweasel 3y agoThat's a pretty good point. If you want to be critical of the cookie/GDPR popup that's really the route to take. HN, Wikipedia and Github doesn't have any of this non-sense, because they have no incentive to track their users. I do question the incentive of a number of sites. Reddit technically don't need to track you, they know all they need to based on which subreddit you're currently on. It's mainly sites that have no context to your activities that really need the tracking to attempt to provide ads that makes sense. Maybe having these sites should be financed differently?
- jacquesm 3y agoThat's what the companies make browsing the web in the EU look like nowadays. It's their decision to abuse us - and the law - and it is on them to fix it. If you check the enforcement tracker you can get an idea of what the tip of the iceberg looks like, the data that's lost/sold/leaked. Then take into account that just like with a real iceberg the bulk of the leaks and breaches goes unreported (and probably a large fraction of them goes undetected until the data shows up on some marketplace). Until the GDPR a lot of this went on anyway, but totally invisible, now at least we have some idea of the magnitude of the problem and companies have an incentive to at least try to get it right. Not that many of them do. People that are categorically against government regulation tend to point at this and say 'see: that's what you get'. But they forget that in the relationship between companies and individuals it is the companies that on balance have the most power and there is ample evidence that this power then gets abused. Hence regulation. I'm all for tightening the rules another notch or two and adding a zero to the average fine. Because there is still a lot of room for improvement.
- PrimeMcFly 3y ago> That's what the companies make browsing the web in the EU look like nowadays. It's their decision to abuse us - and the law - and it is on them to fix it. No, it's the EU that mandated those popups - an asinine solution to the tracking problem. The EU gets the blame.
- jacquesm 3y agoThe EU does not mandate popups. The EU mandates consent to be tracked. You could simply not track and then you wouldn't need consent. Or you could do it without a popup.
- PrimeMcFly 3y ago> The EU does not mandate popups. The EU mandates consent to be tracked. Same difference. Semantics. > You could simply not track and then you wouldn't need consent. Not all tracking is malicious. It's not going to disappear, hence the popups. As I said, it's an asinine solution. It's as useless as the default browser nonsense. The EU seems to make one of these annoying blunders every decade or so, next one should be coming up.
- thuridas 3y agothis is the first time only
- senttoschool 3y agoI don’t live in the EU and I have the same experience. This is my beef with the EU exporting their legislations.
- barbazoo 3y agoI'd blame the poor implementation of legislation by the website operators, not the legislation.
- taneliv 3y agoYour beef is misplaced, madam/sir. EU does not mandate any website to store on your computer cookies that require consent. The companies (and individuals, hah) that choose to track you, do so of their own volition. As an EU citizen, I am actually somewhat delighted that our legislation that attempts to improve privacy is being successfully exported. But similarly to how I find the US exporting their legislation quite loathsome---at least at times---I understand your beef.
- senttoschool 3y agoIt isn't misplaced. It's hard to dynamically figure out if you're an EU citizen or not via the browser. Hence, websites play it "safe" by showing it to pretty much the whole world.
- PrimeMcFly 3y agoThey can't really export it, it's just most big companies have a presence in the EU and don't want to risk it. Plenty of other websites just blacklisted EU IP address space.
- probably_wrong 3y agoDisclaimer: I actually click through the "do not consent" procedure, which tells a lot about what I'm about to say. When the EU regulation came up, I was shocked that a single article was being shared with 100+ "partners". I knew it was bad, but I didn't know it was that bad. At least now I get the choice to opt-out. Sidenote: Google got fined for that pop-up because it should have a "do not accept" option [1]. Companies know they don't need those pop-ups. They are putting them there to anger you and demand for things to go back. Do you want to blame the EU for not anticipating that companies would act maliciously? Sounds fair to me. But don't let the companies off the hook for acting maliciously! [1] https://www.taylorwessing.com/en/insights-and-events/insights/2022/01/google-and-facebook-fined-by-cnil-over-cookie-consent https://www.taylorwessing.com/en/insights-and-events/insight...
- antonf 3y agoI would like an option for those of us who don’t care and click whatever button have brighter color. Like a default consent to sharing all data. This don’t have to be on by default. This would improve my browsing experience tremendously.
- julesallen 3y agoYou're going to love this: https://duckduckgo.com/?q=i+still+don%27t+care+about+cookies https://duckduckgo.com/?q=i+still+don%27t+care+about+cookies
- zeroonetwothree 3y agoNo, they are putting them there because it’s easier and they don’t want to be fined.
- mrweasel 3y agoWhen the first cookie law came into action companies sprung up claiming to provide a solution. Rather than actually doing anything useful they'd give you a JavaScript snippet to just dump onto your page and then they'd deal with everything. They'd scan your site and compile a list of cookies and their purpose and present that to your users. It sort of worked, expect the service would frequently fail to recognize certain cookies or part of you site might be behind a login. But it was something you could easily implement and push the responsibility to a third-party for a small fee. Then came GDPR and these retarded cookie banner companies decided to offer that as a service as well... Basically the same thing right? Well for many of the sites it is, because their goal is find a way to do nothing, or as little as possible, they don't want things to change and here's someone offering them just that. I hate that it when people are blaming the EU for the nightmare that is consent popups. They aren't required, unless you doing stupid shit. Companies love presenting this as: The EU is making us do this. NO, you want to track people online and the EU is simply asking for you to declare that. It's truly amazing that companies don't see to problem telling people that they care about their privacy, yet presents them with a list of 600 "partners" whom which they share our data. So yes, it's laziness, these sites don't want to chance the way they deal with advertisers, because that would be slightly harder. It's also partly incompetence, there's an entire generation of ad people who don't know the first thing about advertising, they know Google Adwords and Facebook Ads.
- 101008 3y agoThis is one of the reasons why Social Networks are eating websites. Most people get a bad experience browsing the internet. Yeah, I get it, we know Hacker News, and other good websites. But my dad just want to read news about sports and politics, it's much easier to do it through Facebook posts than to open a browser and get annoyed by ads, popups, etc. Same for young people: I can get fun with TikTok and YouTube, why should I go into that maze of websites that do not provide anything worth it?
- switch007 3y agoWow what a totally unintended consequence :D
- naravara 3y agoEven despite the fact that Amazon is a pile of crappy knock-offs and astroturfed reviews, it still manages to be better than the UX nightmare of actually trying to go through the companies' own websites directly to figure out what they're selling and how much they cost.
- m00dy 3y agoyes, it is a terrible experience...I personally think GDPR and thinking about user data is a great thing to have. But, the actual implementation is terribe. Like consent banner etc... I can tell 100% that whoever made this law is not a techie person. They wanted to solve a technical problem, like sharing user data without consent, through the law system that we used to...It would be a lot better if they forced this as a part of http protocol...So that we could have our pre-defined consent answers...I mean right now, we have no standart way to say no to any consent banner. You have to understand the consent banner, understand the options, evaluate them, and then process the outcome...You have to do this for all websites that you are visiting... Yes, please fork http...EU, you can do that...I know it...
- pasc1878 3y agoThe consent banners you complain about are not due to GDPR it is a different law plus a compliant website makes it as easy to reject cookies as it does to accept them.
- m00dy 3y agoI can feel that you are from EU. Just because the way you defend your arguments sounds so european. But, let me whisper it to your ears, this thing is shit bro. Literally, I'm spending hours looking at screen and this consent banner pops out almost every minute...I keep my right to take this to the court if I'm diagnosed with schizophrenia or whatever.
- pasc1878 3y agoI am not in Europe - I am British and we left. The popu repeating is definitely not due to EU legislation. You should only get it once and it shjould offer you the choice to accept all or reject all or optionally the complex choosing. If it pops up every minute it is the website that is doing it wrong sue them.
- esharte 3y agoAnother thread where all the libertarians that US tech culture attracts come out and have a go at the EU
- bloopernova 3y agoYep, this is just poor quality anti-EU blogspam.
- nathanaldensr 3y agoYou will feed corporate overlords your data and habits in order to increase their profits.
- JacobSeated 3y agoWell, at least consent dialog blockers can get rid of some of it.
- mnd999 3y agoThese banners are all basically illegal (tracking is not a legitimate interest). It’s a shame nobody bothers to enforce the GDPR.
- 0xfedbee 3y agoEU politicians are dumbest beings on Earth. Dumbness of US politicians pales in comparison. They pretend like they care for citizens privacy, while simultaneously pushing for an end to encryption. States like Germany, which is at the helm of these policies, has fucking SCHUFA. It’s so hypocritical.
- danudey 3y agoI recently started using Artifact on iOS as a news aggregator, and... wow. It uses a standard customized WebView and not a SafariViewController or whatever, meaning that it doesn't support any of the system-wide content blockers that I'm used to. It's truly amazing that websites are so insanely difficult to just... read, these days. Ads that pop up covering the screen, videos (irrelevant to the article) which I scroll past, and which then suddenly decide to pin themselves to cover the top 1/3 of the screen and autoplay, along with ads covering the bottom 1/4 of the screen, while cookie reminders pop up and the page keeps jumping around because ads take so long to load... It's truly astonishing how bad of an experience I was missing out on. Artifact is a pretty nice app, all in all, but the browsing experience without content blockers is so terrible that I just can't bring myself to use it anymore.
- traveler01 3y agoBad design, not the EUs fault.
- scrollinondubs 3y agoYet another factor that's driving people to bypass Googling and just ask LLM's for answers...
- zelphirkalt 3y agoThe "consent" popup is not GDPR conform. Rejection should not take more effort than accepting. That said, of course you should never trust Google, simply clicking "accept". Especially when they make it take more effort to reject, you need to reject.
- johnnyworker 3y agoThat's only for websites that insist on tracking users first thing before hello. Nothing stops 99% of the sites from having an opt-in link somewhere in the footer, and minimal defaults, other than that they insist on convoluted metrics for their little brochure thingy. It's only really necessary to sell impressions or worse, not to make functional or even beautiful sites. Sure, I know there's counter-examples, there are sites that do interesting things with personal data, even. But I know the vast, vast majority of sites that have these banners are not those sites, and I don't accept these corner cases as a fig leaf for this elephant (whose name is incompetence and greed) sitting on the couch, moaning about this law, since day one. "this is what someone who considers themselves a webmaster, or even a web developer, writes nowadays (2021)"
- pjc50 3y agoIt's a deeply stupid local minimum that the EU has ended up in because they were afraid to mandate details, and also afraid to just ban tracking for advertising purposes altogether. So you end up with a situation where: - most people are tracked on almost all websites by a small number of US megacorps (e.g. google analytics could probably reproduce complete browser histories for most Europeans, and most likely does for some intelligence agency) - AND most people have their time wasted by consent banners - AND small companies worry about compliance costs (my least favourite aspect of EU law is it doesn't understand the need to exclude small companies from complex requirements) It's non-confrontational to a fault and therefore ineffective.
- 127 3y agoI'm using auto-accept all cookies, and after I leave auto-delete all cookies. Then white-list only the cookies I actually need. That and use Firefox containers.
- bob1029 3y agoWe have been able to happily side-step this entire conversation in our new web properties. We literally use zero cookies (local storage, et. al.) in our latest products. The user's state is entirely managed on the server, and we pass their session identifier forward through hidden form fields or URL query parameter as appropriate. The only way this works is to go all-in on SSR-style web applications. 100% of user interactions must be satisfied with boring-ass form get/post. The microsecond you start thinking about SPA or holding onto even the merest of boolean facts between page loads, the whole magic experience vanishes in an instant. That isn't to say you can't use javascript, but you certainly don't start with it. Our initial reasoning for going to this extent was due to weird behavior around cookie lifetime we were seeing on iOS/safari devices as of iOS13. If you don't use any client-side state, other than what is loaded into the current window/document/URL, who could ever ruin your day? They'd literally have to cripple 100% of the internet to start causing trouble for our newest approach. Over time, it became obvious this style also provides a better user & development experience. For instance, I no longer have to put the Apple WWDC event on my work calendar in anticipation of a refactoring effort. Pending legislation is also something I do not worry about anymore. I find it interesting that the most compliant web experience is also the easiest (aka most boring) to develop and also usually provides the best end user experience. To me, cookie banners ultimately seem to be a higher order consequence of splitting the product into front-end/back-end and farming out every possible consideration to a 3rd party.
- pessimizer 3y agoPeople are fucking babies. They're lobbying for deceptive marketing tactics to avoid the fraction of a second that it takes once in order to agree to be subjected to deceptive marketing tactics (although they have to disable their plugins and ad blockers to complain about it.) I couldn't even understand what I was supposed to see; people in the US also get cookie popups the first time they go to a site that is gathering a dossier about them. Oh, the suffering of having to click "OK."
- bilekas 3y agoThis is not an EU problem. This is a web problem. Companies have assumed they have a right to all of your personal information and so they build their sites and services around that. The EU does it's best to at least let you know what's happening. What I would like is for browsers out of the box to auto reject cookies and tracking behavior. But that is probably the reason all the prompts are not standardized. I like it, and Everytime I will go through and reject all of them. If the extension doesn't catch them already.
- legitster 3y ago2016 was a weird time. When this legislation came down we literally had no idea what to do. We were a US company and didn't run any ads or broker data, so we thought at first that we were exempt. After consulting with a legal team they made it clear this was not the case. And for the next 2 years there was a lot of pain. We had too many cookies that were important to UX and analytics. If you don't understand why, imagine trying to run a store but not be allowed to look at your customers. We were fine not chasing them into the parking lot with a Polaroid camera, but GDPR didn't make a distinction really invasive tracking and "normal" un-creepy QOL cookies. Before tools like OneTrust or Trustarc were available, it was also not even clear how you actually handle consent. TL:DR; you basically have to set a semi-anonymous cookie that tells you it's okay to load other cookies. But at the time it was not even clear if this was legal (since there are somewhat conflicting advice as to what could constitute PII in this situation). To this day, we still deal with a lot of GDPR edge cases. Specifically what constitutes PII at a technical level when you are talking about session IDs, users IDs, or client addresses. It's still really tricky and we're always afraid the rug will be pulled out from under us. And even the most expensive lawyers will be experts in the law but need constant hand-holding through even the most basic technology. (Data removal requests are another story - if people only knew, man) The lesson I have learned: - Anyone who says GDPR is simple has no real experience - Do exactly what other companies are doing - do not try to stand out - The only real winners were the lawyers
- PrimeMcFly 3y agoThose cookie consent banners have to be one of the most obnoxious things to affect the web in recent history, only outmeasured by how useless and pointless they are. Consent-O-Matic helps a lot with not having to see this nonsense though.
- appplication 3y agoIs there a web extension to automatically opt out of all these? It should be some global browser config, not per site. I don’t even use an adblocker normally, but the cookie banners are insanely annoying.
- rsynnott 3y agoRemember the horse meat scandal, when horse meat showed up unexpectedly in food in Europe? The ceo of one British supermarket chain blamed the Irish food safety authority, who’d detected the contamination due to routine DNA testing (the British FSA had at the time recently ended such testing due to Tories, iirc). His logic was more or less that the FSAI, by detecting the problem, had created the problem; if no-one had known there would be no problem. Pretty much everyone at the time thought this was a bizarre take. I find it interesting that, in the cookie case, people blame the EU for making the problem visible, rather than blaming the people who created the problem. The cookies are the horseburger, in this instance.
- chankstein38 3y agoIt just ended up feeling like a half measure that did nothing but make the internet more tedious for something most people who know anything about the web already knew was a problem. Now it just adds this group of people who have no idea what the popup means who likely just click on the "Accept All" without having any idea what it means. If they really wanted to do something successful they should've been more strict on the situation. "Accept or Decline front and center" "No tracking cookies without specific UNFORCED opt in" "No annoying popups" Like I don't know what they added to my experience. I already knew cookies existed and what they were used for. I guess now I can at least opt out in some cases. But who knows what is classified as a "strictly necessary cookie" which is the lowest amount of cookie tracking you can get on most of those sites.
- pseudalopex 3y agoCompanies were fined because they had accept all without reject all. Report any violations you see. Strictly necessary means necessary to provide the service the user requested or comply with other laws. It is stricter than your suggested no tracking standard.
- crnkofe 3y agoI no longer stay on websites that require consent, show overlays, demand subscriptions and signups or do any other funky anti-user maneuvers. Just let this part of the web die. Web is already hostile enough nowadays with all the tracking, scams, abuses of consent and bad ux designed to sell shit nobody needs.