19 ms·
New browser signal could make cookie banners obsolete
- deleted 5y ago[deleted]
- gmueckl 5y agoI don't see how this will be adopted without backing by legal threats. Even if this gets implemented on a voluntary basis, you need a fallback for browsers that don't support it. And if you need to have a version of the prompt with a user experience that isn't controlled by the browser, you might just as well use it to keep pushing the same dark patterns to everyone. Am I missing something?
- mkreis 5y agoI agree. Why would anyone who wants to track users implement this standard and abandon their dark patterns?
- amelius 5y agoBecause governments will slap them on the wrist real hard if they don't.
- JCWasmx86 5y agoIt would have to be enforced by legislation (As opposed to the dark patterns with cookie banners). If any company doesn't implement this fully compliant with the spec, fine them every year with 2-25% of the yearly revenue.
- young_unixer 5y agoWe've sunk so low that even the "hackers" want the government to force people to use specific protocols on the Internet.
- vbezhenar 5y agoCookie banners works because they're everywhere and user has been trained to dismiss them as soon as possible. If this technology would get traction from major players, cookie banners will become an exception rather than norm. It means that users will be scared of those banners and might prefer to leave the website which will hurt the conversion. If this movement is not backed by major web players, probably nothing will happen.
- switch007 5y ago> Cookie banners works because they're everywhere and user has been trained to dismiss them as soon as possible. All my friends and family just click the CTA, "accept", "I'm OK with that", "Mmm cookies yummy!"
- thepangolino 5y agoDon’t browsers already have a feature to block cookies?
- PeterisP 5y agoThe "cookie banners" are not really about cookies but about all kinds of tracking and consent issues that are not eliminated by blocking cookies.
- ratww 5y agoThe idea here is not blocking cookies, which are very useful, but rather to bypass the annoying "cookie banners". Just as with Consent Banners, the website is still responsible for honouring your choices and not tracking you, either via Cookies or any other method.
- pornel 5y agoReminder that we've already had a spec for it. In the 90s! And it even has been implemented in the Internet Explorer: https://www.w3.org/P3P/ https://www.w3.org/P3P/ It did absolutely nothing for privacy. Google has been sending bogus P3P headers that broke IE's implementation and allowed all cookies. Adtech companies don't want users to have an easy opt-out. They didn't want P3P. They didn't want DNT. They will not want this new spec, unless the spec is so bad that most users will agree by accident. The annoying and confusing cookie banners are a feature. Besides making people agree through confusion or attrition, the banners are malicious compliance. Adtech companies putting them up want you to be pissed off at the banners. They want you to associate them with privacy, and conclude that privacy laws are pointless and should be repealed.
- worldsayshi 5y agoUnless regulators force companies to respect automated protocols.
- sascha_sl 5y agoThis. You can see the impact of this on the new iOS tracking permissions. Most people want to opt out, but can't. Regulators stepping in would spell the end of large sections of the online advertising industry, so I doubt it'll happen.
- dividedbyzero 5y ago> Most people want to opt out, but can't. Not following this too closely, I thought that's possible now, or at least as soon as the last few holdout apps get updated?
- Macha 5y agoThat's the point, by Apple taking control of the interface and preventing dark pattern bullshit, opt in rates are way lower on iOS than on websites.
- 5y ago
- juloo 5y agoWhy do they still think we want tracking cookies ? The ad industry should prepare for a future with no tracking instead of trying to survive with ever shadier tricks, IMO. This won't work: - browsers other than Chrome will say "no tracking" by default, tracking companies won't like that - websites will ignore this, this will be known and people will be upset even more - more javascript when we want less
- yoavm 5y agoThe proposal includes no JS at all, and will probably reduce the amount of JS because it replaces current cookie consent modals and banners.
- yakubin 5y agoIt includes JS. See section "8. JavaScript-based interaction". I guess the idea is that just as you can control cookies both via HTTP headers and JS, you will be able to request consent both via HTTP headers and JS.
- yoavm 5y agoMy mistake. It does have an option to use JS, though it's not a requirement and it's no-JS by default.
- enriquto 5y ago> more javascript when we want less notice that if you disable javascript by default most cookie banners disappear and everything becomes better. Then you can enable it per-site if you need something in particular.
- MarcellusDrum 5y agoI tried that for a month, but most sites I encountered on search engines will just break or even refuse to render unless I enable JS. At first, I tried to leave the site and find an alternative, but after a while I found myself enabling JS on every site I visit that requires it, which negates the whole point.
- deepstack 5y agoInstead of blocking cookies, work on more stuff that will block finger printing such as stuff that is mentioned in https://www.nothingprivate.ml https://www.nothingprivate.ml One spec could be split up the JS api into stuff that manipulate the dom and stuff that access GPU and other hardwares that may identify the browser or machine. Safari seems to be the only one that is doing anything in that area.
- SahAssar 5y agoThat site loads third party JS from cloudflare and sentry. Seems like the privacy message would be clearer if they didn't.
- mrweasel 5y agoCookies are used for things other than tracking, so maybe not obsolete, just irrelevant for tracking usage. I didn’t read the entire spec, maybe there’s stuff that replaced cookies in there.
- roblabla 5y agoCookie banners are only necessary for tracking. The idea here isn't to obsolete cookies, just the banners, as the spec proposes a way to gather user consent through the user agent instead of a cookie banner.
- qwerty456127 5y ago> The mechanism serves as an automated means for users to give or refuse consent There already is the do-not-track flag, why not just force everybody to respect it?
- M2Ys4U 5y agoThere are a couple of reasons. DNT is primarily about tracking, this new spec is more general and covers much more processing of personal data, and allows one to opt-in (or out) of specific instances of processing of specific (categories) of data.
- sandstrom 5y agoThe thing with ideas like this is that it'll all boil down to one thing: opt-in or opt-out. If it's opt-in, hidden inside browsers settings, effectively no-one will use it (e.g. current cookie blocking settings). If it's opt-out everyone will use it (see e.g. Apple's recent "This app is asking to track you across the internet, do you want to allow it?". Question is, why make it complicated with a spec like this. Better to just agree to block all cookies, or to allow cookies.
- ketzu 5y ago> Better to just agree to block all cookies, or to allow cookies. But I want some cookies and some I do not. Also I don't want non-cookie based tracking either. Having a binary choice for a subcategory is not very helpful to me.
- 1_player 5y agoIf it's opt-in, it's another bit of information to uniquely identify you (like Do-Not-Track is today.) If it's opt-out and everyone will use it, ad companies will completely ignore this spec and keep tracking you. The Internet is entirely in the hands of an advertising company. 90% of Internet users use Chrome and/or Android? Add Google Search and it's probably like 98%. Good luck with changing the status quo.
- dariosalvi78 5y agonow that's something sensible!
- lizardmancan 5y agoconmunication with the mothership should be clearly defined
- hnarn 5y agoThe most frustrating thing about these cookie banners (more like cookie lightboxes) is that almost none of them are compliant with the rules. Unfortunately I don't have time to find the source right now, but I'm pretty sure I've read official EU guidance docs clearly stating that many "dark patterns" are simply illegal. For example making the "Accept all cookies" button require less effort than only accepting necessary cookies, which almost every page does. I feel like the current state of cookie consent is completely broken, partly due to the complete lack of enforcement, and having a browser-specific setting that propagates to all pages would be great -- but again you have to think about incentives. If pages are not required to accept these settings, their incentive is to ignore them and to claim that since it's unfortunately not supported "yet" (read "ever"), you still have to wade through the cookie form.
- lrem 5y agoMax Schrems now has a foundation you can donate to: https://noyb.eu/en https://noyb.eu/en
- GrayShade 5y ago> For example making the "Accept all cookies" button require less effort than only accepting necessary cookies, which almost every page does. Like those that make you uncheck 10 or 20 entries one by one.
- StavrosK 5y agoOr like those that make the "Accept all cookies" button green and the "accept necessary" white/colorless/default.
- squiggleblaz 5y agoI recently came across a website that makes the "Accept all cookies" button secondary and the the "accept necessary" primary. It's such an effort to actually press the primary button — I have been so trained by the completely disdainful behavior of the majority of websites.
- hibernator149 5y agoI wonder if this fight over cookies is just a diversion. If we ever get an effective law or tech for cookies, won't the advertisers just shrug and switch to browser fingerprinting? I feel like the only solution is to educate users about AdBlockers and stuff like NoScript.
- ratww 5y agoGDPR actually applies to any kind of tracking, it's not just cookies. You also need consent do fingerprinting that can identify individual users, for example.
- maxwellito 5y agoDo you remember 'doNotTrack' ?
- vincentmarle 5y agoAll this does is move the cookie banner from the website to the browser which still means I have to click approve every time I visit a new website. What I really would like to do is to get rid of these annoying cookie banners entirely and have something auto opt-in for me so I can get back to a decent web browsing experience a la pre-2017…
- presentation 5y agoWould be cool if you can set a default policy in the browser.
- diogominhava 5y agoThis is exactly what we're trying to do at Super Agent - check it out https://www.super-agent.com https://www.super-agent.com. Choose your preferences once and our extension will automate opt-in/opt-out where possible :)
- bennyp101 5y agoOff Topic: Your logo is blurred unless I allow scripts from static.parastorage.com ... that seems a weird thing.
- diogominhava 5y agoThanks for letting me know! Looking into it - we've used Wix to build our landing page, I believe this URL may be from a CDN they use to speed up content delivery.
- Macha 5y agoI think the only "safe" auto complete it could provide with this spec is reject all. Otherwise it could just save a list of consents with unique IDs and look at your rejection list for another fingerprinting avenue.
- durnygbur 5y agoTinder, Google, Amazon, Twitter, Facebook and other plaftorms can reliably ban an account without knowing the name, surname, birthdate. Just from the broad fingerprint of the device, email, phone number, Wifi SSIDs, location, and other data they collect. Yet they are showing the cookie and "privacy" splashscreens and popups on every visit. Every. Freaking. Time. Google with Youtube in particular. Isn't it malicious compliance?
- rosmax_1337 5y agoI've done some basic reading on GDPR but can't honestly say I have it completely figured out. Can someone help me out with a use case that I come across frequently? Selling tracking data to third parties is the kind of thing noone wants to actually opt in to, and what I imagine GDPR partially tries to combat. (among other things) What about site statistics keeping? If say a newspaper collects statistics about visitors to their articles, and does browser/user tracking by implementing cookies, for __internal__ use, rather than selling data to third parties. Is a cookie banner still neccesary for that kind of consent? Personally, I don't care if my IP appears on any website log that I have visited, or if a unique cookie ID becomes present on the site until I clear my cookies. If i cared about my IP being tracked, or cookie IDs like that, I would browse using a VPN and "Private mode" in browser. What I do care about is the complex browser fingerprinting that keeps track of (essentially) my entire browser history, externally, with everything from my google searches, youtube videos, online purchases and website visits being visible in some kind of giant aggregate form. Basically compare it to being videotaped when entering a store. Yeah sure, I might be a bit irked by the camera but I don't care too much. Comparing that to putting a camera on every street corner, and using facial recognition to generate a day by day pattern of all my visits to all stores the last 30 years, and I'm not a happy camper any more. I would even go as far as cookie banners for the above tracking scenario, where you are tracked completely, should be illegal. That kind of "consent" can't even be gained by just clicking a <button> on a website, it would require a valid ID and signature at least. And on the other hand, the "internal store videocamera" taping customers as they enter, perhaps even applying face recognition software to count unique visitors per year to the store, is hardly worth the hassle of a clicking a cookie banner personally. I'm certainly not averse to a position of not wanting to be tracked when entering a store or a webpage though, and if someone has a personal need to not be tracked like that, they should be able to apply basic non consent based tools to avoid being tracked. Like wearing sunglasses and a cap when entering the store, or browsing using a VPN.
- nicbou 5y agoGather as little as you need, share it as little as you need, and keep it as long as you need to fulfil your customer's request. For anything else, get consent. Any kind of private information you store or share needs consent. This is why plausible.io doesn't require consent, but Google Analytics does.
- mrfusion 5y agoNow they need one for all the newsletter sign up boxes.
- sam345 5y agoRegulations tend to become pretty stale pretty fast while tech moves on . Maybe users just need to pushback by picking browsers that respect privacy. We would do better by funding better privacy tech and educating consumers then chasing regulations that almost never get it right, bog down the user experience, and generally become a hassle to everyone involved.
- zeepzeep 5y agoI use uBlock Origin with "Easy List Cookies" which blocks most cookie banners
- peterhil 5y agoThank you! The cookie consent banners are especially pointless when you are not keeping the cookies anyway.
- butz 5y agoA bit too late, but still great for users and for developers. Not so much for cookie banner services, but that's their own fault for providing cookie banners that cover half or more of screen, have confusing selections or none at all and uses dark patterns to push visitor to "Accept All" cookies. And browsers should ask user for default preference only once, to prevent bothering with useless notifications from each website.
- timvisee 5y agoData collection is the problem. It is insane to me that we're now resorting to these kinds of 'solutions'.
- mgkimsal 5y agoin the 90s, we had a 'big cookie' scare. and laws were threatened (or passed?). And... MUCH of this came down to ... managing cookies (or other browser state) was (and is) largely so damn hidden behind layers of configs, menus and options. We have a home button. We have forward and back. We have 'bookmark' buttons, which many people understand. A big 'COOKIE' button, on the main browser UI, that clearly show cookie info, with a big "GET RID OF ALL COOKIES" trashcan button right there.... that would have prevented 90+% of the scare and legislation efforts from the start. I looked for "clear my cookies" - in 2021, it's still click '3 dots' or something else, then click something, then click something, then confirm. https://its.uiowa.edu/support/article/719 https://its.uiowa.edu/support/article/719 "But there's so much nuance - I want to keep some, and not others, etc". We didn't have this many choices in 1998. My point is giving a big honking "get rid of it all" back then would have changed the trajectory of the entire discussion. It still might. I've lived through 2 decades of having to deal with support people trying to help users "clear your cache" or "reset your cookies". "Private mode" does help to a degree, assuming you're dealing with somewhat tech-savvy folks.
- ezoe 5y agoThe problem is, most people don't understand what cookie really is. If it's understood, you don't need to support so much clueless people and no sane politician in EU would made a cookie law. The button you suggests cause more harm than good. Because people don't understand the cookie and think "is this button delete unnecessary data from my computer? Why not" and click it. Now all the legitimate data that were saved on their local storage is gone and they complains.
- mgkimsal 5y ago"Now all the legitimate data that were saved on their local storage is gone and they complains." Not necessarily. Cookie !== localStorage (although... localStorage didn't exist at the time, IIRC). My point was "we" (it/tech folks, but mainly browser makers) got ourselves in to this mess in the first place, and rather than making things more obvious and easier to deal with at that time, we seemed to double down on more obscure UIs. I swear, pretty much every Netscape release, and later, for years, every other Firefox release, changed where/what/how cookie mgt was located in their UI. "most people don't understand what cookie really is" And that's... whose fault? Putting a big-ass 'COOKIE' button, with transparency in to what data is there, with quick options to remove it all, would have gone a LONG way to normalizing understanding. See some unknown shit in there? Delete it. If enough important things start breaking after deletion, people would have adapted (either users, or developers). "delete unnecessary data" - there's pretty much nothing people put in cookies that is truly 'necessary' for most folks. We didn't give people usable tools to manage this stuff, so eventually people turned to legislative means.
- Aeolun 5y agoI read a lot of negative things here, but I like this spec. We (as a profession) shpuld try to eliminate cookie banners, while still allowing users to opt out.
- peterhil 5y agoFinally! Why on earth this was not implemented in the first place on web browsers?
- kissgyorgy 5y agoI understand that standards like these take years to make, but this should have been in the browsers for a loooong time at this point instead of every website implementing them differently.
- qwertox 5y agoI would rather have a cookie-based approach where the opt-in dialog is clearly laid out via regulation. At the top of the dialog a "decline"-button and to the right of it an "accept"-button. These buttons toggle all the toggles of the providers listed below those two buttons. You can then manually override each of the listed providers, which may be also grouped by purpose in order to ease selection. No nested dialogs are allowed. Upon declination, one single cookie must get set, with a specific name, ie 'consent-acknowledge-status', with an expiry date of at least one week, where the consent selection is stored, so that it can be respected in future visits.
- technicalya 5y agoNo a comment its a question. Do you use ad-blockers?
- gorgoiler 5y agoThis week I told iOS safari to block all cookies. It’s really not that awful. In fact, it’s kind of fantastic. I use a second browser (Google Chrome) for “signed-in stuff”. Try it. (Although the fact that I just posted this from safari reminds me I’m not 100% up to speed on which-browser-for-what-activity discipline.)
- benhurmarcel 5y agoI wish it could accept the cookies and delete them when you leave. It would break fewer websites.
- aembleton 5y agoHow were you able to post that on Safari without cookies? HN needs to set a cookie called 'user' to know that you're logged in.
- _boffin_ 5y agoBeen thinking of making a chrome/firefox extension that will detect those cookie notifications and automatically nope out of them all for you and submit, but been too lazy to implement.
- slownews45 5y agoI just want ONE option - ACCEPT ALL COOKIES. Seriuosly, I reserve the right to expire, delete, manage and otherwise deal with cookies on my device myself. Can anyone create a different standard with ONE flag - ACCEPT ALL COOKIES - SHOW NO BANNERS* *User reserves right to delete, purge, modify, expire etc cookies on their device. That's what I want.
- pacman2 5y agoI use the I don't care about cookies Plug-in. My browser forgets all the cookies when closed. Besides several privacy plug-ins, I the the temporary container plug-in. Problem solved.
- aembleton 5y agoI don't care about cookies also provides a filter list that you can add to uBO - https://www.i-dont-care-about-cookies.eu/abp/ https://www.i-dont-care-about-cookies.eu/abp/
- axismundi 5y agoUse /etc/hosts based blocking, e.g. https://github.com/StevenBlack/hosts https://github.com/StevenBlack/hosts This way you become mostly invisible to the ad and malware industry, no matter which browser you use. Have JavaScript toggle next to address bar and keep JavaScript off by default. Most cookie banners will disappear. Use Reader mode for daily news browsing. Most things will disappear except for main content. And it makes Internet less addictive. The difference between swimming and drowning is subtle - flailing your limbs frantically vs relaxed movement. To many complex solutions will make us drown. Consider swimming instead :)