21 ms·
Automating cookie consent and GDPR violation detection
- systemvoltage 5y agoI wonder what is the GDP cost of millions if not billions of people dismissing a cookie pop-up every day, often multiple times a day.
- oneplane 5y agoI wonder what is the GDP cost of millions if not billions of people flushing the toilet every day, often multiple times a day. We can all make silly arguments, just because something requires you to take action, and it might cost money, doesn't mean we therefore have to just let late stage capitalism run wild.
- systemvoltage 5y agoIf we didn't flush toilets but all of a sudden because of some law (directly or indirectly), we started flushing toilets; we should be concerned about it. But that's clearly not the case here and your analogy doesn't hold up.
- throwaway_sb666 5y agoA better analogy was if you were forced to use the toilet every time you entered a store you haven't been to previously... Just why in the world would I need to take part in such a wasteful charade.
- shadowgovt 5y agoI'd have a lot more patience with this law if it had come with an implementable w3c do-not-track-like signal sites could transparently operate on so it didn't wreck the UX for people who didn't care (or for that matter, people who did!). (... which, unfortunately, I guess wasn't "do no track" since that pretty much failed, right?)
- martin_a 5y agoDismissing cookie notices is just a sign of companies outsourcing the cost of being privacy friendly. They could just run their own analytics tool and you wouldn't need any notice at all for basic visitor counting. But everybody is craving for that shiny numbers from Google Analytics (for mysterious reasons _perfectly_ integrated into all other Google tools), easy ad money and whatever metric marketing wants to see this month.
- lbriner 5y agoPlease don't make glib statements about what people do and don't want. If you don't want the metrics that you get from something like Google then that's fine but a lot of companies, ourselves included, find the insight massively valuable when we are trying to work out which parts of our product are or aren't working properly. Sure, we could roll our own but that creates its own problems and doesn't exempt you from cookies notices at all.
- martin_a 5y ago> doesn't exempt you from cookies notices at all. Sorry to tell you, but it actually does. Cookie notices are only necessary when you are transferring data to third-parties and there's no technical reason for that. Selling my personal data to some analytics company, and you have chosen to do exactly that, is not technically neccessary but a very deliberately made decision by someone.
- Nextgrid 5y ago> If you don't want the metrics that you get from something like Google then that's fine but a lot of companies, ourselves included, find the insight massively valuable when we are trying to work out which parts of our product are or aren't working properly. As a user, I don't want to be spied on so that you can "improve" your product aka make it more addictive or refine your dark patterns. I definitely don't want Google spying on me to help you achieve that goal either. The GDPR making it harder for you to do this means it's working as intended and I'm very glad to have it as a user.
- jaywalk 5y agoThat's what browser extensions like Super Agent are good for. And the fact that we need a browser extension to deal with such incredibly annoying and intrusive "functionality" that is required by law is just insane.
- taeric 5y agoMy guess is that it is not a cost. It is a small annoyance, and I would be delighted for it to be gone. But... I really can't support any argument that inflates the cost of it.
- goodpoint 5y agoThat cost should be paid by the companies forcing pop-ups onto users. Popups in no way GDPR's fault. The law does not mandates them. Instead, it's a form of malicious compliance. Companies pester visitors with popup banners that are almost always unnecessary. E.g. GDPR allows essential cookies e.g. a login cookie containing an encrypted token without any popup. If you want to notify users about it for extra safety you can show a little privacy notice on the login form. No need for popups.
- lbriner 5y agoI'm not sure it's malicious compliance. When you are threatened with massive fines for non-compliance but you aren't told explicitly about how to solve it other than, "A cookie notice would be a way of complying", everyone will use a cookie notice.
- Nextgrid 5y agoBad news: those notices will do nothing to mitigate the fines, and might in fact even increase them if those notices pressure or trick users. Good news (for the companies): GDPR enforcement has and continues being laughable, so you don't have to worry either way.
- ratww 5y agoModern cookie banners definitely are malicious compliance and most certainly are also violations of the GDPR. All those companies could use less invasive methods of asking for consent, such as optional checkboxes in signup forms. Or a non-intrusive "click here to opt-in to tracking". The reason they don't do it like this is because they prefer forcing users to click "Accept All" using dark patterns. Anyone complaining about shitty cookie banners is actually complaining about companies breaking GDPR.
- Loeffelmann 5y agoIsn't there insane money to make just suing everybody in breach of gdpr? I always thought there were laywers scouring the internet in search of a quick buck.
- fsflover 5y agohttps://www.enforcementtracker.com/ https://www.enforcementtracker.com/
- Pungsnigel 5y agoWouldn't that just end up in the hands of whatever government is relevant? I believe the fines you pay for GDPR violations are paid to governments, not users or suers.
- M2Ys4U 5y agoAdministrative penalties (those levelled by the supervisory authorities) do go to the state, but one can receive compensation for damages caused by infringement of rights under the Regulation.
- delusional 5y agoI don't think you really "sue" anyone for breaching GDPR. I think you report it to the local authorities, and then they pursue a case. Basically I don't think there's any money for the lawyers to pick up here.
- M2Ys4U 5y ago> I don't think you really "sue" anyone for breaching GDPR. I think you report it to the local authorities, and then they pursue a case. You can. Article 79 explicitly states that data subjects have a "right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation. Article 82 also states that "any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered."
- jjoonathan 5y agoRight, as with the cookie laws companies seem to have collectively come to the idea that "they can't catch us all!" So far they seem to be correct. I would really like to see the courts deal a few black eyes over this, I hope this tool can help.
- shadowgovt 5y agoI'm not sure what lessons the rest of the world should have taken from the US's "war on drugs" (or, for that matter, the US's prohibition before it). ... but "If you pass the law that outlaws a wildly-popular behavior, most people will stop that behavior" probably wasn't it. Law can bend behavior on the margins. It just encourages rule-breaking when you try to drive it like a spike through the middle.
- jjoonathan 5y agoWait, they criminalized it? I thought it was just fines for shitty behavior. Fines for shitty behavior I can get behind. "We were used to getting away with it" is a poor excuse that gets poorer every day. But yeah, making it criminal is too far too fast. Assuming they've actually done that. EDIT: they haven't, "shadowgovt" just overstated the comparison. No, I do not believe that getting away scot-free with shitty behavior today entitles anyone to get away scot-free with shitty behavior tomorrow.
- vanviegen 5y agoEnslaving people used to be wildly popular behavior as well... So do you propose we stop trying to bend society into something less bad?
- shadowgovt 5y agoIn my country, we didn't end that practice without a civil war. I think that story is an excellent example of the limits of the coersive power of law. Even though the goal is righteous, the law may be the wrong tool to achieve it. What alternative tools can be deployed on this topic?
- tschellenbach 5y agoGovernment regulation that outsources/hides the cost on consumers and businesses needs additional scrutiny. Did anyone analyze the full cost of these regulations? It must be insanely high.
- zelphirkalt 5y agoIf those businesses had thought of actual consent to their practices before and had acted accordingly, they would not sit on a mountain of tech debt now and their costs of becoming conform with GDPR would be minimal.
- karaterobot 5y agoHandy guide to GDPR for web developers: * You can't set all your cookies first, then ask permission. * You can't set all your cookies whether the user accepts them or not. * You can't tell users to stop using the website if they don't want cookies. * You can't convince any business owner to follow the above rules.
- PragmaticPulp 5y agoGDPR is about far more than just cookies. Once you get into it, the GDPR is extraordinarily vague. It obviously wasn't written by engineers or even people with domain experience. You can easily interpret common server-side logging operations as GDPR violations if you're not careful.
- lbriner 5y agoSeems a very patronising response. Personally, I have found the GDPR clear and well thought-out. Of course, there are some things that are annoying that you have to comply with like "IP addresses are personal data" but that is a problem with the web, not with the intention and implementation of GDPR.
- kmeisthax 5y agoAs it should be. The G stands for "General", after all. If engineers wrote the law, it would have no effect, because it would specify the means by which tracking happens (e.g. cookies, HTML5 localstorage) but not the act of tracking itself; and it would be easy to circumvent. Legal documents cannot be precisely specified bundles of English-language-shaped computer code; they need flexibility so that the judge can actually rule things that make sense. For example... why shouldn't server-side logging be treated as in GDPR scope? It does not matter if cookies weren't used to collect it; an IP address and time pair is already enough information to identify an ISP account and that's usually enough for lawyers to sue you with.
- M2Ys4U 5y agoThe clue's in the name, it's the General Data Protection Regulation. The idea is to provide a high level of data protection in general. It's not just an internet/engineering law. It applies exactly the same in an offline setting as it does on the web.
- akersten 5y agoOh the irony of this site itself having a "we use cookies, got it?" banner while lamenting this exact perceived lack of choice. I always laugh a little when I see those anyway, knowing that my browser's settings and privacy extensions are blocking the cookies and tracking connections either way. Did we consider that if everyone is breaking the law, the law itself might need a rework?
- rsstack 5y agohttps://en.wikipedia.org/wiki/Desuetude https://en.wikipedia.org/wiki/Desuetude Three years later, randomly enforced and generally ignored: should GDPR-for-anonymous-browsing be regarded as obsolete by the EU's courts?
- throwaway_sb666 5y ago> Did we consider that if everyone is breaking the law, the law itself might need a rework? Agreed - IMO, make cookie banners illegal and make 'minimum cookies' the default. Done?
- whatshisface 5y agoWhat's the definition of minimum cookies?
- robin_reala 5y agoObviously there’s no definition, but I’d say a reasonable baseline is when a user expects a stateful interaction on the stateless medium that is the web. So for example, a multistage checkout process.
- throwaway_sb666 5y agoThose that don't require opt-out according to the law. Too lazy to look up the legal definition right now. Edit: by law I mean the GDPR. Edit2: Get rid of the "cookie banner law" entirely, actually make it illegal, but require easily found links to privacy statement
- 5y ago
- tomatowurst 5y agowhat is the legal liability to websites that do not do business in EU? There has been zero enforcement on non-EU businesses
- mariusor 5y agoI doubt that very much. A lot of the indieweb sites don't bother collecting information about their users so they don't need to show information pop-ups nor worry about GDPR. I know I don't.
- shadowgovt 5y agoif your site is running on apache with default logging, or a shared host like DreamHost, you are probably not fully in compliance with the letter of the GDPR since you're logging IP addresses and aren't using them for necessary site operations. ... especially if the log just grows and grows and never rotates. The GDPR is a very wide-reaching law. Of course, there's no real need to worry since, practically speaking, it was intended as a cudgel to beat FAANG with and not a dagger to stab indies with. If you're comfortable with the safety of your operations being "The folks with legal power to enforce won't wield it on you", you have nothing to worry about.
- UnpossibleJim 5y agoThe problem is, they can enforce it on you at any time of their choosing should you do something deemed unpopular or troublesome. While the cudgel was intended for FAANG, the dagger still hangs to stab any indie that gets out of line. Why would I rely on the kindness of government not to enforce a poorly written law?
- shadowgovt 5y agoYour position is mine, which is why I'm surprised at how broad the support for GDPR seems to be around here. "Broad government power is okay as long as they're clubbing the right people" is certainly a mood.
- mariusor 5y agoI don't think "enforce" means what you think it means. If you are contacted about a GDPR matter usually you have time to fix it before it's "a violation" that incurs penalties.
- bjt2n3904 5y agoThat's the end result of extremely complicated legislation. Everyone breaks it, but you only get caught if you stick out enough. Uncharitably, it's a way for the government to arbitrarily prosecute anyone they please.
- throwaway_sb666 5y agoMore charitably and historically accurate, it's the result of hardcore political negotiations with the originally proposed legislation watered down due to pressure from politicians and governments influenced by lobbyists. But yeah, the result is too complicated to be effectively enforced, sadly. So further reform is needed.
- deugtniet 5y agoIt's pretty well known that cookie-walls are rife with anti-consumer patterns. Going to something like formula1.com requires me to click more than a 100 times to object to the 'legitimate interests' of as many companies. Which is a pretty terrible anti-pattern when I don't want to be tracked at all... After reading the abstract, it seems the authors try to classify cookies using a special browser extension called "CookieBlock" [1]. I hope they are successful, because I hate being tracked on the internet. [1]https://github.com/dibollinger/CookieBlock https://github.com/dibollinger/CookieBlock
- zeruch 5y agoI use UMatrix for this (and NoScript) for the granularity
- andai 5y agoTrustArc's consent popup disappears instantly on Accept All but shows a loading spinner for "up to several minutes" if you reject cookies. I emailed them about this (because in my experience it's only their software that implements such a dark pattern), they replied "customer misconfigured our software, not our fault" lol.
- Nextgrid 5y agoI wonder if it's a really lazy and terrible attempt at accounting for how long the opt-out request would take. Let's imagine it has no way to know (because of cross-domain restrictions?) whether an opt-out request to a third-party succeeds - in which case it simply waits a reasonable amount of time for the request to complete. Of course, a reasonable time should be a handful of seconds, but I guess at least it makes sense that this is configurable and could explain the problem. That's about the only non-malicious reason I can think of.
- andai 5y agoIt's entirely possible that it is the result of incompetence rather than malice. Either way, it strongly discourages users from rejecting cookies by wasting their time for 20-30 seconds every time. Whatever it's doing can simply be done in the background, it doesn't even require UI.
- spiderfarmer 5y agoIsn't every webserver that uses the standard access.log format (thus including IP address) already non-compliant?
- layer8 5y agoNo. You are allowed to keep such logs for a limited time in order to be able to analyze attacks on your web server.
- gyulai 5y agoIt's not true that you don't need to worry about GDPR if you're only going to use this information for a limited time to analyze attacks. It's a lot more complicated than that.
- Nextgrid 5y agoCould you explain? Keeping the information for a reasonable amount of time for security or fraud-detection purposes would definitely fall under legitimate interest. I really don't see any bad outcome happening from doing the reasonable thing. Enforcement is near non-existent (Google and Facebook are still around after all), and when it does happen it still very much skews towards assuming good faith (even when it shouldn't) so you'll definitely be fine even if you get it wrong in which case you'll just be given guidance on how to do better.
- layer8 5y agoI didn’t say you don’t need to worry about GDPR, I said that GDPR doesn’t prohibit keeping such logs.
- gyulai 5y agoI just jumped in with a clarification to make sure others who read this don't think that.
- gyulai 5y ago
- M2Ys4U 5y agoThe GDPR does not require websites to inform users that a website sets cookies. There is nothing in the GDPR about cookies. It's the ePrivacy Directive[0] that deals with cookies (or, rather, "[storing] information or to gain[ing] access to information stored in the terminal equipment of a subscriber or user"). This is a law that pre-dates the GDPR. If you can't get that right, frankly I question whether anything you write on the subject is correct. [0] Directive 2002/58/processing of personal data and the protection of privacy in the electronic communications sector - https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32002L0058 https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A...
- atoav 5y ago(25) However, such devices, for instance so-called "cookies", can be a legitimate and useful tool, for example, in analysing the effectiveness of website design and advertising, and in verifying the identity of users engaged in on-line transactions. Where such devices, for instance cookies, are intended for a legitimate purpose, such as to facilitate the provision of information society services, their use should be allowed on condition that users are provided with clear and precise information in accordance with Directive 95/46/EC about the purposes of cookies or similar devices so as to ensure that users are made aware of information being placed on the terminal equipment they are using. Users should have the opportunity to refuse to have a cookie or similar device stored on their terminal equipment. This is particularly important where users other than the original user have access to the terminal equipment and thereby to any data containing privacy-sensitive information stored on such equipment. Information and the right to refuse may be offered once for the use of various devices to be installed on the user's terminal equipment during the same connection and also covering any further use that may be made of those devices during subsequent connections. The methods for giving information, offering a right to refuse or requesting consent should be made as user-friendly as possible. Access to specific website content may still be made conditional on the well-informed acceptance of a cookie or similar device, if it is used for a legitimate purpose. The rest of the GDPR makes it extremely clear that the goal of the whole thing is not to mandate some specific solution but to force people who run services to allow tracking only with informed consent and to offer options that do not track. If you are not storing data on your users machines or just do so for legitimate purposes, you should not have a need to ask for a users consent and thus don't have any need a cookie banner. The issue here is, that many people running websites just don't know what they are storing and how. Just slapping a cookie banner on that bad boy and calling it a day won't work either, because you have to list the purposes of these cookies. If you don't know why your weird wordpress template loads a cookie, maybe it is time to change it (or alternatively: change your profession).
- endisneigh 5y agoFine them all! Europe will collect billions.
- ars 5y agoAnd people will just stop providing service to Europe. It's already started, there are tons of sites that refuse service to Europe.
- FreeHugs 5y agoI run a website with a few hundred thousand monthly active users. I get tons of mails from users telling me how much they love it. One unintrusive, smallish Adsense banner pays for everything. For years now, everyone was happy. Now Google sent me an email that they want me to gather user consent before showing Adsense. They offer an automatic consent modal. But the problem with that one is that it not only displays the consent modal but also injects a smaller widget into the site. It looks like the widget only pops up when the user scrolls down to the bottom of the page. Unfortunately, that also makes it pop up when the page is not longer than the screen. So pages where the content fits on the screen behave really really shitty. Maybe that is the reason why I have never seen it used anywhere. And of course loading the consent script from Google before getting consent is not in line with GDPR in the first place. Other consent solutions I see around the web are heavy third party widgets that do a lot of complicated stuff. And because they are third party scripts, they are also not in line with the GDPR. I have not found any indie developers who have implemented their own consent solution. And as far as I understand it, Google has no communication channel. They just threaten to kick you off Adsense. So all I can do is implement my own solution and wait if it happens or not. I started to implement my own consent banner now. Not sure if I will get it right so that it pleases Google. I fear that this whole GDPR thing might be the end of my website.
- olalonde 5y agoGiven the amount of confusion and conflicting interpretations of GDPR we get on HN, I'm not really surprised. Then there's always the vocal minority that is fully convinced that GDPR is very simple and clear.
- Nextgrid 5y agoThere's a huge amount of misinformation spread around it, and not to mention existing online information about the earlier and completely stupid "cookie law" is sometimes mistaken for the GDPR. It doesn't help that the GDPR is only really simple if you don't abuse personal data. It will obviously become very complex when you're hoping to find loopholes do something that the GDPR was fundamentally designed to outlaw, and it just so happens that a large chunk of this site makes their money from this.
- systemvoltage 5y ago> completely stupid "cookie law" It doesn't take a genius to figure out: Before GDPR: No cookie banners After GDPR: Cookie banners Who's to blame is irrelevant. Users don't care and the effects are real whether it is put on directly by companies as an indirect result of GDPR.
- Nextgrid 5y agoCookie banners were a thing before the GDPR - the stupid "cookie law" aka ePrivacy Directive was a thing much earlier on. The main problem however is the lack of enforcement though. None of these "cookie banners" comply with the GDPR, yet are allowed to proliferate because nobody is cracking down on them, so they're a form of pseudo-compliance that is very effective at swaying public opinion against the GDPR.
- systemvoltage 5y agoGood point. If this is not an indictment of the failure of GDPR, I don’t know what is.
- 5y ago
- globalise83 5y agoWhat about a wiki system + workflow tool for documenting all GDPR infringements on every website of interest with auto-submission of a complaint to the regulatory agencies?
- elygre 5y agoWhenever people go "it's been four years, this law is too complicated", I am reminded that every now and again the US Supreme Court has to deal with issues that relate to the constitution.
- ffhhj 5y agoIs the PHPSESSION cookie valid for GDPR? Or should we replace it with a token?
- M2Ys4U 5y agoIs it strictly necessary for the provision of your service? Then the ePrivacy Directive says that it's okay. Otherwise, you need consent.
- ratww 5y agoIf you're using it only to make your website work, then you don't need a cookie banner. However, if it's doing double-duty and is also being used to track users (or to speak technically: if it can be considered PII by GDPR), then you need consent before using it for the tracking part. GDPR doesn't apply for cookies, btw, it applies for any personal data. Someone above used "information stored using fridge magnets" as an example.
- skaul 5y agoBrave has an option to block cookie notices - you need to enable the "Filter obtrusive cookie notices" list in brave://adblock. https://twitter.com/shivan_kaul/status/1488989740690853888 https://twitter.com/shivan_kaul/status/1488989740690853888 We're experimenting with blocking cookie notices by default in Nightly. There's webcompat risk - some websites just break if you block the cookie notice. "Works on 90% of websites" is just not good enough when deploying to 50 million Web users.
- legitster 5y agoPart of my job is to maintain GDPR compliance for corporate websites. Even for companies that legitimately want to exceed compliance, you would not believe how much of a pain in the ass it is. The first company wanted to do it "right". So we enabled opt-out by default for all cookies. Which requires setting an anonymized master cookie to check everytime we load a webpage to see if we are allowed to set other cookies. And since IP-detection was not allowed, we did it for all website visitors. And because we have to remember your settings, we had to create a seperate anonymized database outside of our normal website. And the website broke ALL THE TIME. Product configurators, shopping carts, forms, downtime detection - all this stuff relied on cookies. And for several months the web team had a constant nightmare of customer complaints about broken stuff. In the first year we ended up spending close to $250k on legal advice from European lawyers, and most of the advice boiled down to "you're not going to get in trouble if you just do what everyone else is doing". Seriously. Since then it's gotten better - most third party vendors have done a better job of offering anonymized cookie versions of their products. Or there is just more industry guidance available on what kind of cookies can be considered sufficiently anonymous. For people who claim GDPR compliance is clear and straightforward - I can't believe they actually have much experience working in Privacy. Actual implementation gets... very opaque. Especially when the law says it's illegal to deny service based on their cookie preference, but some services are literally impossible to provide without a cookie of some form.
- oblio 5y agoGrowing pains. Like Neo being unplugged out of the Matrix. It takes a while to learn to respect privacy when all you knew was information = ads = $$$.
- tacone 5y agoI really think we should reject the law and make another one that requires the browser vendors to provide the appropriate notices (think of what currently happens with non-https connections) and (browser enforced) choices. No added work for website developers, no lawyers required, no dark patterns. Common icons and warnings the user can recognize easily because they would be the same for every website.
- tobr 5y agoThat makes no sense. How is the browser supposed to inform the user what they are consenting to? The point of the law is, among other things, that you need to have informed consent when you process personal information. That’s not a technical problem that you can solve with a new API. It requires organizations to work differently. Unfortunately it seems that very few orgs have been willing to put the necessary thought and care into this, instead they just slap these cargo cult consent dialogs across everything.
- timando 5y agoPut a cookies.txt (or json or xml or whatever) at the root of the website (or use a <link> element) with the name of the cookie and what it does. If the cookie isn't listed, the browser rejects it.
- MauranKilom 5y agoThe GDPR is not inherently about cookies, and it also does not stand in the way of the solution you describe. What is standing in the way is corporations considering it more profitable to hassle their users with antipattern-laden popups than to follow the spirit (and, ostensibly, letter) of the law.
- dmitriid 5y ago> I really think we should reject the law and make another one that requires the browser vendors 1. GDPR isn't just about browsers 2. Those "consent" popups are mostly illegal under GDPR. They are often provided by companies whose entire business is dark patterns. Thankfully, the EU is going after them, too: https://techcrunch.com/2021/11/05/iab-europe-tcf-gdpr-breach-belgium/ https://techcrunch.com/2021/11/05/iab-europe-tcf-gdpr-breach...
- trh0awayman 5y agoThe cookie consent stuff has always seemed straight forward to me, but maybe I've had it wrong this whole time. It does really say a lot that 95% of websites had a violation. I wish that we could make the GDPR entirely client-side. Semi-related: my understanding is that it's impossible for American hosting companies to comply with GDPR (due to the CLOUD act). If that's the case, and you're American/using an American host, is there any point in even trying to comply?
- notRobot 5y ago> If that's the case, and you're American/using an American host, is there any point in even trying to comply? It's the user-friendly option. Respect your users. Get consent for tracking.
- ElDomingo 5y agoHonestly why can't browsers just implement a option in there settings? Let the users decide in one place if the want to consent to extra none essential cookies. And add a extra field to exclude certain sites in case you have a domain that you want to grant permission.
- antattack 5y agoI use StarDust[0] extension in FireFox that clicks on cookie banners for you. Seems to be working but it's not a 'recommended' extension. [0]https://addons.mozilla.org/en-US/firefox/addon/stardust-cookie-cutter/ https://addons.mozilla.org/en-US/firefox/addon/stardust-cook...
- ______-_-______ 5y agoYou mean the "do not track" header? Advertisers won't respect any setting that makes it that easy to opt out.
- sytelus 5y agoWe need a movement where top websites refuses to put up cookie consent or pay any fines as part of the civil disobedience.