6 ms·
It's pretty well known that cookie-walls are rife with anti-consumer patterns. Going to something like formula1.com requires me to click more than a 100 times t
by deugtniet 5y ago
It's pretty well known that cookie-walls are rife with anti-consumer patterns. Going to something like formula1.com requires me to click more than a 100 times to object to the 'legitimate interests' of as many companies. Which is a pretty terrible anti-pattern when I don't want to be tracked at all...
After reading the abstract, it seems the authors try to classify cookies using a special browser extension called "CookieBlock" [1]. I hope they are successful, because I hate being tracked on the internet.
[1]https://github.com/dibollinger/CookieBlock https://github.com/dibollinger/CookieBlock
- zeruch 5y agoI use UMatrix for this (and NoScript) for the granularity
- andai 5y agoTrustArc's consent popup disappears instantly on Accept All but shows a loading spinner for "up to several minutes" if you reject cookies. I emailed them about this (because in my experience it's only their software that implements such a dark pattern), they replied "customer misconfigured our software, not our fault" lol.
- Nextgrid 5y agoI wonder if it's a really lazy and terrible attempt at accounting for how long the opt-out request would take. Let's imagine it has no way to know (because of cross-domain restrictions?) whether an opt-out request to a third-party succeeds - in which case it simply waits a reasonable amount of time for the request to complete. Of course, a reasonable time should be a handful of seconds, but I guess at least it makes sense that this is configurable and could explain the problem. That's about the only non-malicious reason I can think of.
- andai 5y agoIt's entirely possible that it is the result of incompetence rather than malice. Either way, it strongly discourages users from rejecting cookies by wasting their time for 20-30 seconds every time. Whatever it's doing can simply be done in the background, it doesn't even require UI.
- iso1631 5y agoVery few people actively want to be tracked by 500 different companies. Some don't mind, some consider it the price they have to pay The whole point of the charade of "asking" is to get people to 1) Just say yes 2) Complain to their government about it
- cge 5y agoMy understanding is that the preferences should not be an opt-out of a default setting per the GPDR, they should be preferences that requested and then saved. So surely the opt-in setting would take just as long as the opt-out setting, wouldn't it?
- ratww 5y agoThe opt-in should technically take more time, since you shouldn't be sending PII data before the consent. In the case of opt-out the only single thing that has to happen is setting a local cookie and closing the modal window, which are things that also happen when you accept.
- the_gipsy 5y agoYou are right that technically opt-in should always take longer. No cookies should have been set until the user accepts. But opt-out should not set anything. I don't know what you mean by "local cookie", a cookie is always sent over the wire by HTTP. If you mean saving to LocalStorage, then I don't think that's allowed either.
- ratww 5y ago> But opt-out should not set anything. I don't know what you mean by "local cookie", a cookie is always sent over the wire by HTTP. If you mean saving to LocalStorage, then I don't think that's allowed either. It is allowed for this case. You must save a cookie (or a localStorage value) with the user preferences to avoid showing the cookie banner again. Simplifying: cookies are fine under GDPR as long as they don't carry PII (Personal Identifiable Information). You don't have to ask for consent to store those. They're called "Strictly necessary cookies" in GDPR lingo. (And, of course you can't use any of those to track, though. Intent matters.) And you can save cookies using a Javascript API. That doesn't involve HTTP requests. The cookie will be sent to the server in future requests, though.
- the_gipsy 5y ago
- throwaway_sb666 5y agoHonestly I think the GDPR/cookie consent providers should be held equally liable as the website owner for the collective violations facilitated by their product. I think being able to go after the enablers and profiteers would make enforcement much easier. An officially maintained list of legal/illegal libraries and services could help website owners to chose a known legal solution. Right now it's hard to expect website owners 'do the right thing' when there's so much contradictory information out there.
- Matticus_Rex 5y agoIf you did that, no one would be in that business lol
- Nextgrid 5y agoIs that a big loss? I can't picture anyone, outside of their employees and shareholders who would be negatively affected by TrustArc disappearing overnight. I just checked their website and it seems like their entire business is GDPR pseudo-compliance targeted at businesses who can't legitimately comply with the GDPR.
- dmitriid 5y ago> Honestly I think the GDPR/cookie consent providers should be held equally liable as the website owner for the collective violations facilitated by their product. The EU is finally going after them: https://techcrunch.com/2021/11/05/iab-europe-tcf-gdpr-breach-belgium/ https://techcrunch.com/2021/11/05/iab-europe-tcf-gdpr-breach... I do hope they get sued out of existence
- mpweiher 5y ago> It's pretty well known that cookie-walls are rife with anti-consumer patterns. Which are all illegal. The wheels of justice turn slowly, but grind exceedingly fine. And you can help: if you find an annoying pop up, file a complaint with your local data protection agency.
- judge2020 5y ago> Going to something like formula1.com r Not sure if this is because i'm in the states, but 'manage settings' has a 'reject all' button for me[0] and it seems to work. 0: https://i.judge.sh/0vCJB/q_nQ34wtjO.png https://i.judge.sh/0vCJB/q_nQ34wtjO.png
- Thiez 5y agoBut does that button also reject "legitimate" interests?
- judge2020 5y agoMost likely everything with a toggle except 'Required Cookies', which are required to make the site work between pages (if you want to turn those off you can disable cookies for the domain in your browser, at risk of the site breaking).
- Thiez 5y agoI'm asking because many of these "consent" dialogs allow you to "reject all" for cookies, but require an "object to all" for "legitimate interest" purposes. It wouldn't surprise me if these dialogs considered the "reject all" to apply only to cookies.
- guitarbill 5y agoSeems like perverting the meaning of "legitimate interest" is the ad industry's next move, now that the obviously illegal popups were officially decried as illegal.