17 ms·
Cookie Consent Speed Running Game
- minitech 6y agoSmall typo spotted: big data and *its impact
- bigdatagirl 6y agoYour the best
- HenryBemis 6y agohttps://i.imgflip.com/52c9jt.jpg https://i.imgflip.com/52c9jt.jpg
- zeepzeep 6y agogood one
- _trampeltier 6y agoThat was fun :-)
- aequitas 6y agoI'm missing the inexplainable 30-60 seconds it takes to "save" your cookie preferences, whether you denied all cookies or just clicked "allow all".
- DelightOne 6y agoDon't forget the redirect away from the initial content with no way to go back.
- aequitas 6y agoOr going back, just to be presented with the same questions again and then hitting the paywall after that.
- Crosseye_Jack 6y agohttps://github.com/iamadamdev/bypass-paywalls-chrome https://github.com/iamadamdev/bypass-paywalls-chrome is what I use and most of the time I never see a paywall. (If you are a FF user (as I am), ignore the word chrome in the url as it also supports FireFox. I think the chrome version got removed from the chrome extenstion store, so you might want to look for something else if you want auto updates and the "you are using dev mode" message on chrome start annoys you.
- 1f60c 6y agoThis annoys me to no end. And opt-ins are instantaneous? Get outta here.
- aequitas 6y agoThats the weird thing. I haven't had this case where the opt-in was quicker, only that both options where slow. Maybe some websites just add a ad-blocker penalty whether you opt in or out.
- dylan604 6y agoMy browser is set to not accept cookies. I then use the Dev Tools to highlight the GDPR/cookie banner to add a Display:none to the css. I'm trusting uBO/no-script/etc to protect me the rest of the way
- Macha 6y agoIt's easy to explain: "We can't be bothered to not load trackers without consent so we're going to make calls to all their endpoints and trust they'll respect that and not use the calls themselves to track you" with a mix of: "Hey, if we put a sleep(1) every 5 entries it's going to be slow and annoying and less people opt out" The people doing it just know you won't like the explanation so they're not going to.
- aequitas 6y agoBut the problem is that they have the same delay, whether you opt in or out.
- rapnie 6y agoYes, this was on Oracle site when downloading Java (don't know it its there still). The thing had a progress bar when 'processing' cookies. Always made me wonder.
- avian 6y agoI always thought the intention was to make people angry at lawmakers for coming up with GDPR. “Look what your government made us do to you” kind of thing.
- Macha 6y agoCertainly has succeeded on this site, though I'm not sure that's entirely sincere on the behalf of every commenter.
- Crosseye_Jack 6y agoThat annoying "TRUSTe" modal. The one you see on java.com for example? While I have seen less of the "30 seconds to save" issue recently (I dunno if it was a ublock origin update or the ad companies actually fix their scripts). The issue causing it was ublock origin. Looking at the network activity when it was happening (it pissed me off too), the script was sending a request to each of the partners with your prefence and the script had to wait for the timeout on the request (as ublock was blocking the request) before moving onto the next batch. this scaled over all the partners listed in their ad/tracking partners added up for a piss take of a long time. But as I said for me personally when I see that particular opt in/out modal these days it saves almost instantly, so someone somewhere fixed it :-) EDIT: thinking about it, it might of even been the addition of FireFox's built in tracker protection that "fixed" the issue for me. I can't recall extactly when I stopped seeing the TRUSTe modal take forever to save my prefs.
- mhils 6y agoI don't know if uBlock Origin increases this further, but even without it it's ridiculous. We measured this just for fun in a paper last year [1]: > Compared to accepting cookies, opting out causes an additional 279 HTTP(S) requests to 25 domains, which amounts to an additional 1.2 MB / 5.8 MB of data transfer (compressed / uncompressed). [1] https://informationsecurity.uibk.ac.at/pdfs/HWB2020_Consent_Management_IMC.pdf https://informationsecurity.uibk.ac.at/pdfs/HWB2020_Consent_...
- Crosseye_Jack 6y agoIts been an age since I looked into it. But I remember if you disabled uBlock on the page before you hit save, it updated the settings a lot faster then if it was enabled. Same thing for the Ad Choice mass optout tool (Though that would say it failed to opt out for all the companies as it couldn't send the request).
- runawaybottle 6y agoWish cookie consent could be saved at the browser level and websites can just check against my settings instead of asking me every time. I guess that makes too much sense.
- bigdatagirl 6y agoI think there is a browser extension for this. I forgot what it's called but it partners with the cookie banner companies, so that it automatically sets your preferences on most websites.
- deleted 6y ago[deleted]
- littlecranky67 6y agoCookies are not the problem here. They don't need consent for cookies, but for tracking. And if you were to block cookies, they can still track you with a lot of other fingerprinting technologies - and would again ask you for consent for that. I recommend enabling the EasyList Cookie blocking list in the adblocker of choice (i.e. uBlock Origin). Its not enabled by default, so check your settings (Edit: This will block the consent popups, not the cookies).
- mortehu 6y agoIf there was a browser setting to accept (or reject) all cookies regardless of intended use, that would actually solve the problem for many. Just because many people want to make case by case decisions, we shouldn't have to burden everyone with this task. I personally would prefer to accept all cookies, and take responsibility for keeping separate cookie jars as needed.
- AnssiH 6y agoYeah, I'd like a Please-Track-Me option that auto-accepts everything.
- 6y ago
- dalbasal 6y agoCookie/privacy consent stuff is really just an instance of the "terms and conditions" problem, canonically described in South Park's HumancentiPad. In modern times, we hang a lot of hats on explicit contracts. If contracts don't work well, we're stuck for ideas. The reductio ad absurdum is that contracts are supposed to be a flexible solution. Meanwhile, almost every implementation is a rote ruleset.
- ludamad 6y agoContract interning - when you make several immutable contracts the same to save only processing one in court
- fallat 6y agoWow this is an excellent experiment. I quit on level 2!
- abledon 6y agoyeah got to 1:33 and level 2, 1 unit left hiding somewhere... ragequit haha
- isthisnametaken 6y agoThing I keep seeing and don't understand is "Legitimate interest" as a separate thing to consent. "You opted out of our cookies, but we're going to say we need them anyway, but you can still opt out of that". It's somewhere between underhand and downright disturbing ("our interests override your lack of consent"? Eww)
- Nextgrid 6y agoIf legitimate interest is actually legitimate then there is no reason to allow an opt-out. They allow it because the truth is that it wouldn’t actually fall under legitimate interests.
- m_eiman 6y agoIt’s about time someone fined them a handsome amount for their deviousness.
- skinkestek 6y agoSomebody told me about this the other day and it brightened my day a bit: https://www.enforcementtracker.com https://www.enforcementtracker.com Hint: columns are sortable.
- dylan604 6y agoThis site has a 3 item slider at the very top of the page promoting recent? decisions. 2 of the 3 have the same number of lines of text. The third one has an additional line of text. Every time the 3rd one comes/goes, the entire page is shifted up/down to accommodate causing the page to have a very slow bounce. tsk tsk tsk
- alpaca128 6y agoI am not impressed. I clicked on my country and the four most recent fines are: 600(private indiv.), 150 (private indiv.), 100 (Bank), 0 (Post office). I'm not opposed to GDPR. I just think it's ridiculous how they boasted about fines up to 20 million or 4% of annual worldwide revenue, and then we get an interpretation of "up to" that we otherwise only know from ISPs. I mean, a "fine" of 0 Euro, and 100 Euro for a bank? That is not how you make organisations respect user privacy. At this rate we're going to have three different any% categories of this speedrun before we can hope for an announcement of a plan to tighten restrictions in an unspecified amount.
- Xophmeister 6y agoThe "Cookie Law" and the GDPR aren't the same thing. I've noticed people make this mistake a few times recently. The Cookie Law is circa 10 years ago, I think, and is widely considered to be poorly implemented. The GDPR is newer (implemented in 2018) and is widely considered to be a good idea. AFAIK, the GDPR didn't subsume the Cookie Law, but I may be wrong about that.
- the8472 6y agoThe law isn't poorly implemented. The way websites deal with it is. Just don't set any cookies for a read-only visitor and you don't need to add any popups.
- Xophmeister 6y agoYes, fair enough -- point taken :)
- lmkg 6y agoIt's both. The law itself is poorly thought-out and overly restrictive. And then websites also don't understand it and do stupid things in the name of compliance, which are neither compliant nor beneficial to the user.
- jimmaswell 6y ago"Make a fraction of the ad money you'd have had with targeting and you don't need any popups" doesn't help people running non-hobby websites put food on the table.
- lmkg 6y ago> AFAIK, the GDPR didn't subsume the Cookie Law, but I may be wrong about that You are correct. GDPR repealed and replaced the Data Protection Directive (DPD) from 1995. The "cookie law" (ePrivacy Directive, ePD) was an extension of the DPD, and made heavy reference to it. As part of replacing the DPD, GDPR includes a provision that any law referring to the DPD now refers to GDPR instead, which affects the ePD. So ePD is still in effect, and by reference uses GDPR's new stricter definition of consent. This is a problem. The ePD was dumb but mostly ignorable. The "upgrade" has made its dumb-ness actually impactful.
- Toutouxc 6y agoGood job, I hate it.
- akalsz 6y agoAnd this is exactly why I enabled the global "Disable JavaScript" option in uBlock Origin. The frustration these popups constantly cause far outweighs the slight annoyance of having to re-enable JS for some websites (and you can ask uBO to remember those anyways).
- rapnie 6y agoYeah, the only problem is that sometimes it is not clear that a site is broken, when just some parts are omitted, like a search bar.
- SquareWheel 6y agouBlock Origin actually has a blocklist for cookie warnings. It would still allow sites to function normally without the constant interruptions. See "EasyList Cookie". https://easylist.to/ https://easylist.to/ Or if you prefer to block social media junk too (as I do), Fanboy's Annoyance list includes both cookies and social blocking.
- jsmith99 6y agoThat's a bit broken for me now. I don't see the popups but I still sometimes get the overlays that stop me scrolling and I have to turn off ublock for the site, click accept, and turn ublock back on.
- jabroni_salad 6y agoGrab the Remove Sticky bookmarklet to take care of that (not my website): https://alisdair.mcdiarmid.org/kill-sticky-headers/ https://alisdair.mcdiarmid.org/kill-sticky-headers/
- mfontani 6y agoAnd this is why the consent information/opt-in/out boxes ought to be able to run with JS disabled, too. It's easy enough to do that... but that easy if it's something that gets put on the site via JS.
- SiempreViernes 6y agoSlightly disappointed this wasn't just a list of iframes to actual opt-out screens. What would be there harder end level, the google or the facebook out out screens?
- bigdatagirl 6y agoDefiantly open to making a Hardcore mode
- fogihujy 6y agoI know this might just be me, but I miss the good old days where the browser would simply allow you to accept or reject cookies from a specific domain and then remember the choice. It made things like this much easier, although I suspect it would be something of a nightmare in todays cookie-infested third-party hell.
- simion314 6y agoI turn off JS globally in Vivaldi, then the browser has a super easy way to enable JS for each website. Then when I hit something that I really want to view and it needs JS I open it in a private window.
- tomaszs 6y agoPersonally I think all efforts to protect online privacy and stop tracking are wrong. But not in an obvious way. It sees right at first. But the truth it is impossible in the long run to keep privacy and not be tracked on the internet. But the effort is to fight tracking and protect privacy at all cost. Even if this destroys foundations of the internet. Moreover it gives the false belief that clicking NO will protect you from tracking, that companies protect your data. But it is not a true belief. People should be aware that every password and everything transmitted through the internet can be tracked and may become public one day. And act accordingly. It is just like data protection. You can have firewalls, antivirus and so on. But what you always really want to have is a backup. The same goes for privacy and tracking. You can use some measures to protect, but you should act as you are tracked and everything can become public one day. But such laws ensure people they don't need to act in such a way, what makes them less safe in the end run, rendering these laws to making people surprisingly less safe contrary to the intention of law makers.
- linkdd 6y agoCookie banners have been so badly designed everywhere I see them. This being mandatory makes me work the extra mile to ensure I don't require/use ANY cookie on the webapps/websites I make.
- dbetteridge 6y agoThanks, I hate it. Such a shame do not track got ignored so hard.
- ibdf 6y agoThis cookie consent functionality should be something the browser reads and gives it to you on a standard format - like the https lock and other privacy info.
- elmomle 6y agoBingo. I'm horrified at the tax on everybody's time to that this has come to be.
- NullPrefix 6y agoLet me broken window fallacy a bit and tell you about the jobs these consent dialogs created. Think of the GDP.
- IgorPartola 6y agoThis is the correct goddamn answer. Or, better yet, get rid of cookies as a thing. The one and only legitimate use for them is session tracking, so why not provide a session storage mechanism instead? Every website gets a standard login/logout button with pluggable functionality for how you authenticate. And maybe, just maybe, we can then also have Persona-type identities that are stored and synced across all your devices so you just choose from a drop down of which identity you want to use to log in rather than typing usernames and passwords.
- scubbo 6y agoWhat makes you think that those sessions wouldn't get (ab)used in exactly the same way that cookies now are?
- IgorPartola 6y agoBecause when I hit the logout button, the local session ID is deleted from my browser session storage (because that action would be performed by the browser and not by the website’s code under this system), so I would look like a brand new user to the site (setting aside other identifying stuff like IP address, etc.). All the session store should hold is an opaque ID for the session and it’s expiration info and it would be sent to the web server as a header (Session: djsisnxidnskxjf). The server would store all the info about you but if you don’t send that header, the server has no idea who you are.
- barbazoo 6y agoWhy did I just spend 2 minutes on that?!
- yur3i__ 6y agoI spent more time than i'd like to admit getting my time down to 11 seconds
- beyondcompute 6y agoI like that they didn’t go all out on those dark patterns and created a rather user-friendly and straightforward version of how that experience feels in real life.
- iujjkfjdkkdkf 6y agoSomewhat related, I got a new computer this week, and had to boot into windows so I could partition the HD to install linux. This was the first time in 15 years I have booted into a brand new "consumer" windows install (it was windows 10 pro). The "setup" was basically just 10 minutes of them asking in different ways if they could collect my personal data, track my location, send back telemetry etc. Office 365 is the same. I find some new thing every day that I have to opt out of to prevent them stealing my and my business data. Its like they have given up on trying to improve their products (which are basically stable) and shifted into finding more ways to steal data. As much as I dislike google for this, I realize I'm the product there, with Microsoft I thought I was paying to get business tools, not to be spied on. (To be fair, I then installed ubuntu which also wanted to send my data back to canonical) Another example, I bought a car recently that defaults to stealing my personal information and sending it to the manufacturer. I had to call, and provide more information to them, to opt out (and I can only assume they are still stealing information they have deemed critical in some way) Anyway, I'm reminded of all of this because I think the obfuscated cookie consents are just one facet of how hostile consumer tech has become to users. Aided by complex and ambiguous regulations, companies are able to stay within the letter of the law while making it impossible to just be left alone with your purchase and not be tracked and marketed to. If there is a regulatory solution, it has to focus on clarity and spirit, not on just more rules. I'm not aware of an example of something like this working elsewhere. One idea is a heavy tax on advertising. I've argued before that there is a lot in common between environmental pollution and the effects of advertising on the public value of the internet, and I would say this extends to tech generally. Charge a 25-40% tax on ad revenue, and make it less economic for companies to pollute.
- tester34 6y ago>The "setup" was basically just 10 minutes of them asking in different 10minutes for something like 5 questions? >and shifted into finding more ways to steal data if they wanted to steal your data, then they'd ask you about it?
- dylan604 6y agoIt easily could take 10 minutes to actually read/decipher the word games being played to confuse the reader into accepting the preferred option the vendor wants. Just like it only takes seconds to accept the ToS/EULA because nobody reads them. If people did actually read them, it would take hours/days to do a "simple" install.
- azalemeth 6y agoIf anyone wants to report a site's bad practices to the UK regulator, this is the relevant link (they are only doing it en mass): https://wh.snapsurveys.com/s.asp?k=150296439091 https://wh.snapsurveys.com/s.asp?k=150296439091 I'd love to know similar sites for other EU countries. One thing that I particularly dislike (and seems to be a uniquely US take on the EU GDPR rules) is "you must consent to access our site" banner. Not give _or refuse_ consent, but actively agree to the marketing crap or be redirected to a "bugger off commie" wall. An example would be healthline.com I think this explicitly violates article 7, paragraph four of the regulations that states: > When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. But then -- I am not a lawyer. But if any HN readers are lawyers, I'd love to hear your take on it...
- djhworld 6y agoThis is amusing and on point, kudos to the creator! The biggest takeaway from this is the dark patterns sites aggressively use to trick you into accepting all their cookies, by making use of creative language that might take a while to parse for the impatient reader or setting buttons to common colours that might confuse someone into clicking. I really wish there was just a setting in the browser that just says - Accept 'functional/mandatory' cookies (with exclusion support for sites that abuse this...) - Reject advertising cookies - Reject personalisation cookies - Reject analytics cookies - Reject tracking cookies etc. and this config is available for these GDPR banners to query and apply the appropriate settings.
- xd 6y agoA DNT header should really be all that's needed .. but never seemed to gain traction.
- Shank 6y agoThe DNT header got abused and sent by default, which gave companies the excuse that it wasn’t actually conveying a user selection, thus wasn’t reflective of their actual choice to avoid tracking. So it goes.
- mnw21cam 6y agoIt got sent by default, but I think calling that an abuse is stretching it. Do not track by default is what is meant to happen. That's what opt-in means.
- aasasd 6y agoI'm just using uBlockO as such a solution—with the hope that vast majority of problematic ‘third parties’ are already in the blocklists, at a given time.
- ksdnjweusdnkl21 6y agoLet's not create more bits for fingerprinting.
- manjana 6y agoPriceless lol. It captures the sleazy maneuvers perfectly. Let's hope it reaches out to many people. Humor is a great messenger.
- andrewla 6y agoAs long as I can block third-party cookies by default, I'm content to let the website I'm on set whatever it wants. Firefox is moving in the right direction with total isolation, including caches, to prevent Spectre-style timing attacks, and I only hope that Chrome will follow suit. "Clear cookies on departure" feels like it goes too far -- I do want the ability of the site to remember my login, etc., as a default thing, and once you open that door, they can link any browser identification to whatever they want on the backend; cookies just give an easy way for them to not talk to their own backend, but introduce no new security or privacy issues as far as I'm concerned.
- 2Gkashmiri 6y agoif there was a web that didnt have any "tracking" cookies, JS, server side analytics, other bs, what would it be like?
- waspight 6y agoI would love to see the cookie concent being part of the javascript api, so that the browser could show a standard dialog instead.
- monotypical 6y agoI made a tool-assisted speedrun to complete this in 00:00.00 which has been confirmed by the dev as the TAS world record, paste this into your browser console after clicking on "let's do this" https://pastebin.com/NZQGSxhL https://pastebin.com/NZQGSxhL
- frothy-dashcam 6y agoOn a sidenote: the game ist (fun) advertisment for a website selling a book. When I visit this site (me sitting in Europe) they immediately set the _ga cookie (tested on vanilla Chrome on purpose). There is no privacy banner at all, they just set the cookie. They probably left out the banner to save my time, no? EDIT: gumroad sets the cookie, not bigdatagirl. Does that make it better?
- bigdatagirl 6y agoHey, It's me the guy who made both those things. We spent along time removing all non essential cookies from the site, so i'm not sure what your getting. I just panicked and tried on vanilla chrome, and couldn't find that cookie? We have no GA but use fathom instead. But if it's there I want to remove it asap. Let me know if you have any more info
- bigdatagirl 6y agop.s. We have gumroad's trackers off. They seem to be one of the only payment system that allows that. https://gumroad.com/gumroad/p/turn-off-trackers-enhance-your-customers-privacy https://gumroad.com/gumroad/p/turn-off-trackers-enhance-your... I may be completely off, but would love to get this resolved.
- kderbyma 6y agowow.... exactly 2:30 to solve.....damn
- rexpop 6y agoConsent should not be an obstacle course.
- jcun4128 6y agoI saw something recently said "by scrolling this page you are agreeing to cookies"
- fermienrico 6y agoThis is the part that they didn't legislate.
- moneywoes 6y agoAre these dark patterns all legal?
- bromuro 6y agoThe “I am happy” that I have to click when I open The Guardian is horrible - especially when after reading the news. How mean.