5 ms·
Don't fall for the "we are just stupid" propaganda, which is used constantly by governments acting in bad faith. Browsers already had settings for deleting coo
by mike_hock 2mo ago
Don't fall for the "we are just stupid" propaganda, which is used constantly by governments acting in bad faith.
Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.
This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.
- aspbee555 2mo agochanging IP is not really enough for privacy, there is many ways to fingerprint your machine/browser and uniquely identify you across networks https://creepjs.org/checker https://creepjs.org/checker
- deleted 2mo ago[deleted]
- mike_hock 2mo agoNo, but it's the obvious starting point. You can then put additional laws on top banning fingerprinting out of band (if you care about window dressing), fund development of anti-fingerprinting technologies, fund Tor, run exit nodes in a transparent and publicly auditable fashion, etc. It's not hard to make privacy work when you are the government rather than working against a hostile one.
- IanCal 2mo agoWe have those laws. You need consent regardless of how you get the data. That’s they say “we value your data” (a phrase you can read in two ways) and ask if 1368 partners can have it for various uses.
- inigyou 2mo agoI think it's because every single website breaks if you don't allow cookies at the browser level. Some knowledge of what the specific cookie does was necessary.
- Jtarii 2mo agoIs there any reason to believe that the current laws being passed by the UK, EU are against the will of the people? Everything I have seen makes the "anti-porn" laws or whatever seem extremely popular.
- morsch 2mo agoBut I don't want to delete cookies? I want websites to use cookies that are technically necessary e.g. for keeping me logged in. I just don't want them to use it to track my behavior especially inter-website.
- mike_hock 2mo agoInterwebsite is solved by partitioning and login cookies are solved by explicit whitelisting.
- inigyou 2mo agoYou think the average user is going to explicitly whitelist? The law requires sites to whitelist their own cookies under penalty of law, instead.
- mike_hock 2mo ago> You think the average user is going to explicitly whitelist When prompted by the browser on first login/signup, yes, the same way the password manager works. With stored passwords, keeping the login cookie doesn't even add much value.
- inigyou 2mo agoWhat about the other 200 unskippable prompts you get just by opening the website? Well, there is a skip button. It's labelled "accept all"
- bhaak 2mo agoThe EU law already allowed technically necessary cookies without any banner. Every time you get a cookie banner with options, the website wants to know more about you than the law permits by default.
- toxik 2mo ago... or cargo culted a site that did. I think this is far more common. It's almost like you're not a serious web site if you don't have a cookie popup of some kind.
- croes 2mo agoYou mean we had the DNT flag in the browser.
- IanCal 2mo agoIt’s not about cookies. It’s about what the site is allowed to do with your data. Cookies are an implementation detail. It’s baffling we’re having this misunderstanding on this site in 2026 still.
- TurdF3rguson 2mo agoIs there any other way to get that data? It's clearly about cookies but it's specifically about tracking cookies.
- dredmorbius 2mo agoSupercookies: <https://www.comparitech.com/identity-theft-protection/supercookie/ https://www.comparitech.com/identity-theft-protection/superc...> <https://www.eff.org/deeplinks/2009/09/new-cookie-technologies-harder-see-and-remove-wide https://www.eff.org/deeplinks/2009/09/new-cookie-technologie...> <https://www.eff.org/deeplinks/2014/11/verizon-x-uidh https://www.eff.org/deeplinks/2014/11/verizon-x-uidh> Browser fingerprinting / Panopticlick: <https://ssd.eff.org/module/what-fingerprinting https://ssd.eff.org/module/what-fingerprinting> <https://panopticlick.org/ https://panopticlick.org/> On-device identifiers --- Google AdID (GAID), Apple IDFA, etc.: <https://developer.transmitsecurity.com/guides/risk/secure_device_identity https://developer.transmitsecurity.com/guides/risk/secure_de...> <https://geraguard.com/blog/how-device-fingerprinting-works-mobile https://geraguard.com/blog/how-device-fingerprinting-works-m...> <https://alejandrocordon.com/blog/2025/01/18/unique-identifiers-android-ios/ https://alejandrocordon.com/blog/2025/01/18/unique-identifie...>.
- TurdF3rguson 2mo agoSure but these are all the same thing as cookies. And BYW, browser headers can even be a violation if it's determined that you are using them for tracking users in a way that violates ePrivacy demands. It's still a cookies thing.
- IanCal 2mo ago
- AlienRobot 2mo agoExactly. Nobody wants to go to a news website/entertainment website/informational website that relies on ad revenue because they will get bombarded by banners and then by a huge number of ads that were increased because those banners slashed their ad revenue. So instead everyone stays on Facebook, Instagram, Reddit, and Twitter, which ALSO operate on ads and have far more information on their users than any third-party ad tracker could ever have. None of this has gotten rid of the privacy problems. It just consolidated them into the worst offenders while jeopardizing the plurality of the web. Now instead of people being tracked by Facebook on a website with a third-party cookie in a like button, they are tracked by Facebook on Facebook in a Facebook page because they never leave Facebook.
- rtpg 2mo agoThis framing of the banners as cookie banners is a dodge. It's not about cookies. The cookie banner isn't about the usage of cookies, it's about _the underlying tracking_. You're allowed to "just" use cookies for normal shit! You can make a website where you use cookies to store login state for a user, without a single banner. The thing is that every company in the world feels the need to add 1000 tracking cookies to anonymous users to track them through conversion funnels (on top of the ad stuff). That's what you have to inform people about You can use cookies normally without a banner! You can't track without consent! Every cookie banner is actually a "we want to track you" banner. Calling it a cookie banner is playing into the confusion about what those banners actually are meant to communicate