11 ms·
Ask HN: What is the least obnoxious way to ask for cookie permissions?
Recently our legal department is asking to add a cookie disclaimer thing to our marketing website. I hate those and want to put in the least intrusive version. How do people here deal with this? Thanks!!
- deleted 3y ago[deleted]
- warrenm 3y agoPersonally ... I think the best option (if you have to have cookies (and there are plenty of reasons you may want/need them)) is to have screen-wide, contrasting-color, short-top-to-bottom bar with a single OK or Accept button for dismissal Do not give people options about cookies - either they accept (and dismiss the notice), or they leave When I am presented with cookie options, I start to wonder why there are "unnecessary" cookies present: why are you letting me accept "necessary" cookies or "all" cookies? Why would you have ones that are not needed? Seems hyper sketch ... and I'll go elsewhere (or reject all)
- pocketarc 3y agoIf you're adding a cookie banner for legal reasons, that means you're covering against GDPR, which says that you're -not- allowed to refuse service based on someone not wanting cookies that are not necessary for providing the service (e.g. all the analytics/tracking crap). You're obligated to give them a way to opt out while continuing to use your service, and it should be as easy to decline as it is to accept[0]. The funny part, of course, is that countless services have put up banners that don't make it easy at all to reject, which means they're still not compliant, they just make the legal team feel warm and fuzzy. That's why you see necessary vs all, because it's "can we track you or not". If you're just doing absolutely required cookies (e.g. session cookie), you don't even need a banner. [0]: https://gdpr-info.eu/issues/consent https://gdpr-info.eu/issues/consent
- snmx999 3y agoSome of Germany's largest online newspapers, like Bild (https://www.bild.de/ https://www.bild.de/) demand either that you subscribe to their online paper or consent to all cookies. As far as I see there is no way to reject the cookies.
- mnw21cam 3y agoThat's only because Schrems hasn't got round to suing them yet.
- diffeomorphism 3y agoRuled illegal already for other websites: https://noyb.eu/de/pay-or-okay-tech-news-site-heisede-illegal-decides-german-dpa https://noyb.eu/de/pay-or-okay-tech-news-site-heisede-illega...
- markus92 3y agoEnglish link: https://noyb.eu/en/pay-or-okay-tech-news-site-heisede-illegal-decides-german-dpa https://noyb.eu/en/pay-or-okay-tech-news-site-heisede-illega...
- warrenm 3y agoIf that is true, why would any sane company/website stay based in the EU (if they want to use cookies)?
- diffeomorphism 3y agoUnrelated to where you are based. Also there is no restriction on cookies as such, just on spying. So defaulting to spying seems much less sane now, agreed.
- deleted 3y ago[deleted]
- IanCal 3y ago> When I am presented with cookie options, I start to wonder why there are "unnecessary" cookies present: why are you letting me accept "necessary" cookies or "all" cookies? Why would you have ones that are not needed? Seems hyper sketch ... and I'll go elsewhere (or reject all) Because some are required for the functioning of the site. They can justify dealing with those without you approving it. Some are there for advertising, that's not required for you to use the site but they'd definitely like to. So they need you to actively consent.
- warrenm 3y agoI know why the others are there - but the fact that you have unnecessary cookies makes you look sketchy
- mnw21cam 3y ago> Do not give people options about cookies - either they accept (and dismiss the notice), or they leave That's outright and explicitly illegal. (I just thought I'd make that point in a quicker and simpler way than the otherwise great sister post.)
- starbugs 3y agoThe best thing one can do is not use cookies -> no need for a consent banner. If that's not an option, the next best thing is to have an overlay that is as honest as possible and most importantly provides not only an "Accept all", but also a "Reject all" button. Don't use dark patterns, basically. That is, use the same color, style and size for each of those buttons. My experience is that most users are so used to these overlays by now, they just look for the button which gets rid of them most quickly. Marketing will typically push to tinker with the appearance of the buttons to increase the conversion rate in favor of the "Accept all" option.
- bglazer 3y agoYes, if you put the “reject all”, button behind a “customize cookie settings” click, you’re a bad, anti-social person.
- diffeomorphism 3y agoAlso probably illegal. That part of the law is not yet enforced very much, but there have been a few rulings.
- starbugs 3y agoThe question always is whether there's a negative consequence outweighing the "positive" incentive of trying to increase favorable consent decisions by using dark patterns. I had the pleasure to learn a lot about this while working in the higher levels of some german company with a somewhat questionable track record. Here's what you can do (only applies to Germany, but might be similar elsewhere): Complain to the data protection authority of your local state in writing. These complaints will be followed up by the authority and if enough of them accumulate, the company will have a bad time and the aforementioned incentive equation will be bent towards the end that favors user privacy. Don't write angry emails. Nobody cares and you waste time.
- dcminter 3y ago> Also probably illegal. Pretty clearly so. It seems weird to me that so many companies put up a cookie banner in order to avoid breaking the law, and then break the law in order to make it less effective. I suppose the win here is that if the (fairly toothless) regulators notice you can say "oh we thought this was enough" and then tweak it. But in that case why not just have no banner at all, and wait until they notice in the first place? Just as daft as the extra-US sites that choose to show no content to EU geolocated origins instead of complying with the law. Which is... also illegal under the letter of the law, so why not just ignore the law. Presumably you're probably out of the jurisdiction anyway if you're bothering to do this.
- kolinko 3y agoI would ask them what is the absolute minimum required by law and to provide citations and the penalties for not applying it correctly. The last time I checked (a few years ago) most websites were doing a serious overkill with the banners, where the law didn't require it. Also, for certain companies the possible penalty for not having a banner was so low that it didn't make sense to have such banners at all.
- cm2012 3y agoYou can see in this thread that 20 different HNers who are passionate about the subject and done implementation before have 20 different opinions on what the law actually does. So how can we expect random businesses to all be on the same page? And this is not years after GDPR started.
- sdflhasjd 3y agoI think the effort would be best spent avoiding cookies and trackers in the first place. What do you plan on using cookies for? There might be some ways of doing similar things without cookies or trackers (server-side analytics for example) that are more respective of users and also eliminiate the need for any banners at all. I know my company's website has a pointless cookie modal - the necessary cookies are just for session affinity on a gateway (which I don't believe you'd need a modal for anyway), and the unecessary cookies are from one analytics integration that's been used just once since it was set up, and another that is used for the most basic reports that you could get from just the access logs.
- jacobsimon 3y agoCan you explain how server side analytics works without cookies?
- giladvdn 3y agoYou can use IP based tracking or something like a query parameter to track within that session
- remram 3y agoYou're describing a session cookie. Changing the technique slightly doesn't allow you to bypass the law.
- simonw 3y agoYou log the IP address, referrer, user agent and the requested page URL but you don't set a unique cookie to identify the user. This still gets you plenty of actionable analytics information: where geographically people are located (via GeoIP), what pages are most popular, what platforms (including desktop vs mobile) people are using. I've been using https://plausible.io https://plausible.io for analytics on a bunch of my sites for a couple of years now and I honestly don't miss the extra level of detail I got from cookie-based analytics I've used in the past.
- foft 3y agoCookie permissions and EU advertising options should absolutely be built into the browser, it makes no sense for the user to have permissions on each site individually like this with a different system on each one. Then the user can centrally review what permissions they gave, revoke them etc. So no sites should have these kind of approval banners.
- sigwinch28 3y agoPerhaps some sort of Do-Not-Track HTTP header sent by the user’s browser
- nenaoki 3y agoIt'd be especially great for a hip and cool corporation with a burgeoning browser to automatically set that header all the time, helping ensure nobody actually listens to it.
- yjftsjthsd-h 3y agoIf the DNT header is absent by default, websites were happy to assume that it was okay to track users. If the DNT header were set to "no" by default, websites would be happy to track users. If the DNT header were set to "yes" by default, websites screamed bloody murder and pretended that it didn't represent user choice.
- LinAGKar 3y agoThus, it needs to be backed by regulation in order to actually work
- giladvdn 3y agoHuh, I think I agree. Not only are the banners slow, obnoxious, have a tendency to being manipulative and are different for every website, a web developer can easily ignore the user's choice and track them anyway. Apple made a big leap with the “ask app not to track” and I think browsers should have this as well. If only to get rid of those infernal banners.
- rogerian 3y agoCookie banners have ruined the internet! I you have to have one I'd suggest it have a Reject All button which makes the banner go away without any further clicks. Nothing is more soul destroying than having to click several times to make the nonsense go away.
- giladvdn 3y agoYes I think I’ll post the design here when it’s done.
- abcd_f 3y agoI don't like them as any other tech person, but lets give a credit where the credit is due. Ads and SEO ruined it way more thoroughly than cookie prompts.
- giladvdn 3y agoThis would make for a great blog post: top 10 things that ruined the internet. I nominate generative AI for the version of this post two years from now.
- deleted 3y ago[deleted]
- jesuslop 3y agoTry to let user browser anti-nagging extensions do their job
- LordHeini 3y agoApart from the others suggestions. Make sure that it does work with extensions like I don't care about cookies. That one is usually easy but make sure it works with the uBlock script too. Do not have that the banner force any site reloads. Analytics for example can be loaded into a page wihtout reloading. If that is done the ad blocker users will never notice the banner.
- quickthrower2 3y agoMakes me wonder, if the only thing needed is authenticated sessions then just ask for opt in during sign up? Is that possible.
- bigger_inside 3y agothe frustration part sets in when I start reading the page, and then a whole-page popup interruts that experience and makes me disable cookies. Second frsutration is when I have to go dg for the "no". At this point, I reevaluate whether I really want to read this page or not, and if it's not essential, I close the entire page at this point mouthing a silent "fy". SO, as others have already said, definitely a "reject all" and be done with it right in the beginning, without the need for any forther clicks. Better yet if the banner is just a sliver on the side that doesn't interrupt my reading experience (clearly, as long as I didn't click "yes" on cookies, it can't set any; so it would be default-no, allows me to read, and if I want to click in the corner for something else, I can. Even better if it has an "X" to close that unintrusive side window, and of course the X gets treated as "reject all".
- Yizahi 3y agoThe GDPR law is quite clear - it is MANDATORY to have an equal way to reject consent as to grant it. So basically you must have equally designed button "accept" and "reject" on the same banner frame. See, the problem is solved even before it appeared - if your company will comply with the law then the banner would not be obnoxious by design.
- mnw21cam 3y agoMake sure that if someone visits your web site with Javascript turned off, and that means that the cookies won't be used anyway, then they can still read the content without a non-functional cookie banner covering all the content up.
- gljiva 3y agoFrom user's POV: if you do have to ask for cookies, please make the "reject all" button object to all "legitimate interests", so I don't have to manually expand each "purpose" to object. I won't use the site unless I object to all. If it's too big of a hassle at that moment , I'll just leave and not come back
- red_admiral 3y agoIf you have a one-click "no to all" for people like me, and a one-click "yes to all" for people who just want to get on with their lives, and both buttons are the same shape/size/color and easily clickable, then you're already waaaaay ahead of the curve.
- deleted 3y ago[deleted]
- lapsis_beeftech 3y agoThe answer is always no, please don't ask!
- sshine 3y agoLeast intrusive: Make it take up so little space that you don’t even need to close it, make the accept button green and the deny button red, and let there be no consequence if neither is clicked. Don’t make anyone aware of the ambiguity that not clicking it is neither consent or denial. Pointing out this stuff forces you into the path of requiring that people click on it before being able to navigate the website, which is extremely intrusive, and makes all the marketing people insist that you apply dark patterns.
- eviks 3y agoThe noise shouldn't have any bright red/green colors not to attract attention
- aragonite 3y agoThere should be a big "X"-shaped button for simply dismissing the banner, deferring the answer to a later time. After all, if someone is visiting your website for the first time, they likely don't know your site well enough to know whether they want to accept or reject.
- mrgreenfur 3y agoMight as well press decline the , same behavior
- aragonite 3y agoHaving to make a decision on the spot induces analysis paralysis in me :)
- speedgoose 3y agoApple.com does not ask consent to track you for marketing purposes. GitHub used to not have cookies for tracking purposes either but it looks like some people couldn’t live without tracking users so it’s back after 2 years on some subdomains: https://github.blog/2020-12-17-no-cookie-for-you/ https://github.blog/2020-12-17-no-cookie-for-you/
- reportgunner 3y agoThere isn't one.
- eviks 3y agoMake it as tiny as legaldepartmentally possible, it doesn't need to take the full width of the page, nor does it need to have any colored background. Also doesn't need several sentences or text