4 ms·
Honestly, I think it is our job as the creators/hackers to come up with a better solution. The problem is very real, and needs to be fixed. But no good solution
by polocode 6y ago
Honestly, I think it is our job as the creators/hackers to come up with a better solution. The problem is very real, and needs to be fixed. But no good solution has ever been created by lawyers. Ever. So here we are, left with a forest of cookie warnings that perfectly break the internet.
So here is a proposal:
What if a user could declare her/his consent settings _before_ opening the website? There would no longer be a need for consent dialogues, right?
One way to achieve that would be to take an example from the UTM parameters. A browser/User could just use ?utm_consent=all, ?utm_consent=minimal, and ?utm_consent=deny to indicate the level of consent. Browsers could offer it as a standard setting and automatically amend it to any URL. Websites could just drop the consent dialogue whenever that UTM is set.
- nyanpasu64 6y agoAnd the do-not-track header was created, and promptly ignored and used as a form of fingerprinting, due to an absence of legal backing.
- Arch-TK 6y agoSurely there's an easier way: Standardize an extension to the Set-Cookie header for a "Purpose" field. This field if unset means the cookie is essential (local laws now still apply so if a website misrepresents a non-essential cookie as essential then that's illegal just the same way as implementing a fake cookie banner or not implementing one (if you need it) is illegal). Now in my browser I can set my cookie preferences to only store and send essential cookies. For other tracking methods that don't use cookies there's already DNT and all that's needed is for a local law update to clarify what it means and to enforce its use. These things would actually make sense as opposed to the current situation where the EU makes it sound like cookies are something a website forcibly stores on your computer and uses.
- polocode 6y agoBeautiful technical solution. Wouldn’t it depend on all website creators and all browser makers to pretty much commit to changes in their code at the same time, before the first consent banner would actually go away? How do you get them to do that?
- Thorrez 6y agoYou could do user agent sniffing and skip showing the banner if you know the browser supports cookie purposes. Of course user agent sniffing tends to cause a lot of problems, so this probably isn't a good idea.
- Arch-TK 6y agoOr just have the browser advertise its support for the extension (e.g. yet another header).
- Arch-TK 6y agoYes it would require everyone to make changes, but like the other person who responded to your comment it probably wouldn't need to happen at the same time. The point being is that it's probably a bit late now but if this was the original solution proposed by the EU the end result would be a lot cleaner while still taking about the same amount of effort (at the end of the day web developers still had to look at all the cookies they set, categorise them, implement warning banners and then correctly handle responses.
- alexwennerberg 6y ago> Honestly, I think it is our job as the creators/hackers to come up with a better solution. The problem is very real, and needs to be fixed. But no good solution has ever been created by lawyers. Ever. We could stop using tracking cookies.
- tomjen3 6y agoA much better way: you must ask for consent through something like navigator.cookieconsent, which will trigger the browser specific resolver (that may, or may not, show a prompt for the user depending on her choices). If you set a cookie before this, it will be silently ignored. To work with js free sites, you can feed the same information through in a tag for the HTML. We don't need an exemption for necessary cookies, since the only reason a site would need to set a necessary cookie is to remember the users choice, and the browser can do that better. If the user logs in, by filling out a username and password field, a single cookie should automatically be saved. I imagine Firefox is the best browser to get this started in. Anybody has any pointers to how to get the ball moving?
- ratww 6y ago> Anybody has any pointers to how to get the ball moving? Maybe writing an extension as a proof-of-concept, then finding someone who's a member of W3C to propose it as a standard.
- TeMPOraL 6y ago> I think it is our job as the creators/hackers to come up with a better solution. Here's a radical idea for a solution: pressure EU member state data protection agencies to start seriously enforcing GDPR violations. Internet is so good at amplifying messages, so why not amplify that? GDPR is already a good solution to this problem. The only reason it works so poorly is because it's not being enforced - so most websites feel safe choosing to break the law. If there was an uptick in fines being issued against all players, big and small, the situation would change very quickly.
- b0afc375b5 6y agoI'm sure there's a Consent As A Service (CaaS) somewhere. If not then that's potential revenue right there.