7 ms·
Here's an idea for the EU: mandate that all major browsers ship with third-party cookies disabled by default and drop the whole cookie-banner nonsense.
by kkdaemas 5y ago
Here's an idea for the EU: mandate that all major browsers ship with third-party cookies disabled by default and drop the whole cookie-banner nonsense.
- tpush 5y agoThat wouldn't accomplish anything, as cookie banners have to do with tracking and not inherently with third-party cookies. Tracking via first-party cookies is still illegal and would require consent.
- perihelions 5y agoThat kind of technical countermeasure only works when you're a statistical minority and adtech doesn't care enough to chase after you. If everyone were to block 3p cookies, the adversary would create new ways to share data on the backend, without clientside involvement, and we'd be right back where we started (other a small increase in friction).
- zeepzeep 5y agoOther idea: make browsers have a proper cookie banner and not one that tricks me into selling my soul, I never got why pages would need individual banners.
- IMTDb 5y agoPlease don't force browsers (clients) to fix what's fundamentally a server side (website doing shit with your data) issue. Browser can choose to respect the cookies (first, or third parties), but ultimately don't force them to do or not do anything.
- zeepzeep 5y agoForcing 3 companies to change their browsers is a lot easier than forcing millions of shady US businesses to do anything
- visarga 5y agoIt would be nice to have browser support for cookie popup that is uniform and not worded differently everywhere. Maybe even a default setting and ability to auto-reject. The popups have ruined the experience.
- detaro 5y ago> Maybe even a default setting and ability to auto-reject. We sort of have auto-reject, with the Do Not Track header. Which pretty much everyone has decided to ignore, because then people just say no and that's not the result they want. > The popups have ruined the experience. And behind every popup is a company that decided that ruining your experience was the correct thing to do.
- zeepzeep 5y ago> And behind every popup is a company that decided that ruining your experience was the correct thing to do. Yes, of course, they want you to think "uugh privacy just means lots of work and popups I'll just click accept"
- grumbel 5y agoThe problem is that both the client and the server is controlled in large part by Google and they like to optimize the user experience into whatever allows them to sell ads. Lynx is about the only browser that still notifies you and has you accept each cookie manually.
- josefx 5y agoAs long as the most widely used browser is owned by Google? No way that could possibly end up being intentionally broken and misleading. The law would have to specify the exact shape of the cookie dialogue down to the pixel and I still would expect Google to find a way to fuck it up.
- zeepzeep 5y ago> The law would have to specify the exact shape of the cookie dialogue down to the pixel Sounds good to me. > I still would expect Google to find a way to fuck it up. Sure, then we change the law again and/or sue Google.
- josefx 5y ago> Sure, then we change the law again and/or sue Google. Which generally seems to have an almost 10 year delay for every iteration since Google will appeal on every instance and do its best to slow down every curt issued request heading its way to the fullest amount possible. The result: Not happening in the next century or two.
- Griffinsauce 5y ago> I still would expect Google to find a way to fuck it up. Playing cat and mouse with only a few large entities vs. literally every website on the web seems like progress. And let's be realistic, "intentionally broken" can be prevented by having a serious deterrent and removing the incentive.
- piva00 5y ago> The law would have to specify the exact shape of the cookie dialogue down to the pixel and I still would expect Google to find a way to fuck it up. In the EU it's more usual for judges to take the "spirit of the law" into account for rulings rather than the "letter of the law" that is more common in Common Law systems. I don't know enough and IANAL to state that with sureness about the whole legal system of all EU countries but it's a rule-of-thumb, the law doesn't need to be absurdly specific to avoid loopholes, it just needs to be good enough to cover ground for judges to judge if the accused is following its spirit.
- simion314 5y agoEvil sites will use localStorage or some third party API and continue tracking you. I am sure people here will find at least 20 solutions on the problem on "how can a group of evil websites track a user across if cookies do not work but JS is On", the solution would involve something like drop this lines in your html page and the js code there will connect to some server and store some fingerprint there, Google might decide to give your browser a fingerprint to help with their ad business.
- bryanrasmussen 5y agothat's the point of webbugs, https://webbug.eu/ https://webbug.eu/ no cookies needed - actually JS not needed but it sure is useful.
- arlcode 5y agoI wouldn't approach this problem from a technical direction. If there is a browser based vendor agnostic opt-in popup for user tracking (not only cookies) you can outlaw and severely punish attempts to circumvent that. Given the time and resources courts really dislike the "welllll technically..." Argument.
- ratww 5y agoFor GDPR both localStorage, fingerprinting and other methods are all equal to cookies. Even IP tracking is the same as a cookie. "Cookie Banner" is just tech-jargon for these banners, but an incorrect one.
- simion314 5y agoI know, I tried(and probably failed) to explain to OP why his simple idea to "just make the browsers disable third pary cookies" or other technical solutions are not going to work, you need GDPR like laws to focus on the actual problem and not some technical implementation because developers will find workarounds for technical only stuff. Browsers could help by implementing a standard GDPR popup for this shitty websites to share , at least it will not be same dark pattern UX, broken implementation shit this sites use today. Browsers could do a lot of good things if they would focus on the actual users needs and not on what some developer feels cool to work on or what soem giant company ants to implement next.
- xxs 5y agomost sites would not need a 'cookie banner'... unless they wish to track you/mine your data/etc.
- najqh 5y agoThat is... doubling down on a bad idea. Moving the stupid cookie banners to the browser itself so we can not block them. It's so idiotic, the EU bureaucrats will probably consider it.
- cuu508 5y agoI think it's the other way around, if the cookie banners were implemented at the browser level, there would be "auto-reject" extensions on day 0. Or, worst case, auto-rejecting forks of Chromium and Firefox.
- kulikalov 5y agoSounds simple. Could you elaborate? Among all of the problems that this legislation aims to solve, what problems can be solved by simply blocking third-party cookies? And what can not?
- zeepzeep 5y agoTracking can not be solved by this, today many ad companies get subdomains on the websites they track on, so they are technically not "third-party"
- selfhoster11 5y agoIt's a terrible idea. It will break a lot of sites in a way that's not predictable.
- jefftk 5y agoNow that Safari blocks third-party cookies by default, most sites have adapted.
- 1_player 5y agoWhat's an example of a site that needs third-party cookies to work? If it breaks because it can't load Google Analytics, that's a website bug.
- gostsamo 5y agosso, I think. you cannot authenticate with a Google, FB, or Apple account.
- algesten 5y agoThat's not how that works. One common way here is OAuth2 which includes a callback URL such as: https://internal.yourcompany.com/oauth2/callback?token… https://internal.yourcompany.com/oauth2/callback?token… That token in the callback does not require any kind of cookie to use for subsequent authenticated calls.
- IMTDb 5y ago"Sign In with Google" works with third party cookies disabled.
- 9dev 5y agoAuthentication on www.example.com from auth.example.net, would be a common issue, for one. Edit: fixed the domain to actually make the point I was trying to make.
- IMTDb 5y ago
- mrtksn 5y agoThe cookie-banner simply means that there's no enough competitive advantage in improved UX over tracking the user. We don't see many websites who opt out out of the "track the users all across the web" scheme in order to remove the cookie banners altogether. On the other hand, thanks to the banner everyone has become aware that the are being tracked. This is good because it brings people into the discussion, so that when EU says "stop tracking" people are not puzzled about what tracking those Eurocrats are talking about. How people are supposed to know if they should support the actions of their government if they don't know what's happening behind the scenes?
- dijit 5y agoWould be better to implement it in the browser; similar dialogs to the "X site wants to access the webcam", right? Cookies are entirely on the client side anyway: trusting every website to do the right thing is obviously not going to work.
- ratww 5y agoFunny thing is that Internet Explorer used to have these banners. But users started disabling them and accepting the cookies when they got too annoying.
- jeroenhd 5y agoBrowsers do, it's the do-not-track header. It's on by default, as it should be. Websites just refuse to honour the header. Not all, websites, though; I believe medium, of all websites, will actually not embed some content if you sent it a DNT header. Not sure if they still do that, though, because their UX for readers has become absolute trash.
- zeepzeep 5y agoThe do-not-track header is just another bit for fingerprinting you, I don't believe any ad-company actually honors it. Also, why trust that they do, when there's a solution that doesn't need trust?
- alkonaut 5y agoI want the browser to not let any other party get more bits of entropy than I agree to. My ip is a few bits of entropy. Now I want my browser to give not-that-many-more bits of entropy to any remote server. If it allows a remote server to list my system fonts, render something on a canvas and read back the bytes,or do some audio mixing on my machine and read back low level results, then my browser has failed me. I want it to say "I'm not showing this webpage at all because it tried to read back a canvas".
- jefftk 5y ago> it's the do-not-track header. It's on by default The DNT header isn't on by default in any major browser. (Additionally, the spec was abandoned for a bunch of reasons including not being able to agree what constitutes tracking)
- fooyc 5y agoThis would work if cookies was the only way to track people. There is also localStorage, ETag (and other cache-oriendted methods), fingerprinting, owning a browser, etc. What we need is a low that forces websites to obey the "do not track" header.
- jefftk 5y agoCookies, including first-party ones, that are not "strictly necessary in order to provide an information society service explicitly requested by the subscriber or user" still require banners under the ePrivacy Directive [1]. Ex: if you're counting unique visitors with a first-party cookie, you need to gather consent. [1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058&from=EN https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (Not a lawyer)