14 ms·
Show HN: A Chrome extension that will auto-reject non-essential cookies
A FOSS chrome extension that attempts to remove the annoyance of cookie pop ups and banners.
There are some extensions out there that auto-accept cookies, but I didn't find one that auto rejected cookies without either chaining some extensions together or setting up custom rules in tools like uBlock origin. So with this extension, you just need to add it for non-essential cookies to be rejected.
Github: https://github.com/mitch292/reject-cookies https://github.com/mitch292/reject-cookies
Extension Link: https://chromewebstore.google.com/detail/bnbodofigkfjljnopfggfoecokhmhamc?utm_source=item-share-cb https://chromewebstore.google.com/detail/bnbodofigkfjljnopfg...
It's still very early days for the extension. I want it to keep improving and working on more and more sites. Feedback welcome. Thanks!
- mrweasel 1y agoConsent-O-Matic can easily be configured to reject cookies. I suppose that technically you could also just remove the pop-ups, that means that you never agreed to anything and the site have no permission to place cookies on your computer.
- shmoogy 1y agoThis is only true in Europe - it is not required by the US privacy laws and the default most companies deal with will be set to implicit allow
- mrweasel 1y agoI sort of assumed that companies wouldn't even show the cookie/tracking consent in areas where they are not legally required, but that's a good point.
- queenkjuul 1y agoMy company puts the cookie banner everywhere and follows the "hiding the banner is not consent" pattern. Not because we're required, but because that's how the off the shelf cookie banner thing we use works, and better safe than sorry should a European access our US marketing site, i suppose. I always figured most of the popups would reject cookies if hidden, if for no other reason that everyone is too lazy to modify the default behavior (and the default behavior is designed for EU regulations)
- Orygin 1y agoThe law for cookie and privacy consent is (afaik) applicable to any EU citizen or resident, even if they are not currently located in the EU. That means if you do business in the EU, you have to show the banner for everybody because you cannot know if they are an EU citizen/resident from their IP alone.
- GavCo 1y agoWas an interesting experience travelling to Italy and suddenly starting to get cookie banners on sites I visit daily that normally don't have
- bberenberg 1y agoThe common one I use in the space is https://consentomatic.au.dk/ https://consentomatic.au.dk/ but good on you for making an alternative. More options is great.
- agos 1y ago+1 for Consent-O-Matic, it's great
- elashri 1y ago> So the omission of an acceptance should be on par with an explicit rejection I know that is says "should" but how common that practice is followed by the websites? And in that case, wouldn't blocking the entire popups like ublock origin does becomes better option than installing a new plugin?
- queenkjuul 1y agoMy understanding (as was explained by my compliance department at work) is that per EU law, omission of acceptance is on par with rejection. Many off the shelf cookie consent plugins used by websites will default to this behavior (including the one my work uses, despite being a US company). Ublock does actually have an option to enable just hiding the popups. In theory though, there's nothing requiring websites to actually treat a hidden pop-up as a rejection in the US, so i guess it doesn't hurt to explicitly reject instead.
- rizs12 1y agoCan you release it for firefox too please?
- coldpie 1y agouBlock Origin already has this. Enable the "Cookie notices" and "Annoyances" filters in uBlock Origin's settings. Bonus pro-tip: Firefox for Android supports uBlock Origin, which means you can get rid of these godawful banners on mobile, too. Only iOS users are stuck having to put up with them.
- replax 1y agofor iOS users, you can just install eg AdGuard as iOS safari extension/blocker extension and enable the uBlock filter lists :) Fully working ad blocker for mobile safari.
- hammock 1y agoHow do I keep chrome from uninstalling ublock these days every time I restart?
- rkagerer 1y agoHow it’s implemented: Vibe coding is the answer Sorry, you want me to give browser privileges to code written by AI?
- Imustaskforhelp 1y agoWhere is it shown that it was written by vibe coding?
- angryGhost 1y ago[flagged]
- rkagerer 1y agoClick the Show HN link and scroll down to the second heading.
- Imustaskforhelp 1y agoThanks
- Gracana 1y agoYou should stick with extensions that have lots of stars, that way you know they're trustworthy and secure.
- DaiPlusPlus 1y agoI assume you're being facetious; because popular (and good, trustworthy) extensions written by initially passionate people often end-up being bought-out by dodgy orgs - with very-hard-to-refuse offers - and the Chrome Extension Store has no way of knowing about that. I had a Chrome extension with about 20,000 users and I received unsolicited buyout offers a few times a year, and some offers were very hard to refuse - but it's not hard to imagine anyone else capitulating.
- 1y ago
- leoxiong 1y agoI never understood why the HTTP Do Not Track header wasn’t used to signal cookie preferences. It seemed like the perfect solution.
- moebrowne 1y agoMaybe GPC will do a better job https://en.wikipedia.org/wiki/Global_Privacy_Control https://en.wikipedia.org/wiki/Global_Privacy_Control
- charcircuit 1y agoThe issue is with how browsers implemented it. Instead of implementing it with a per domain granularity it was implemented as a global option. People may enable the option to block tracking from malicous parties, but may unknowingly block tracking from good companies. So now good companies would need to ask the user if they actually want tracking since they may accidently be blocking it.
- coldpie 1y ago> tracking from good companies Say what?
- berkes 1y agoThere's proper and good tracking possible just fine. Tracking to discover latency, errors, weird behaviour, malicious actors and so on. Tracking to see what content does well and what not. Tracking to see what rough demographics (mobile, desktop, country, region, time-of-day etc) visit your premises. E.g. plausible-analytics or even Matomo do a good job at i) keeping the data rough and broad and without any PII, and ii) storing the data on-premise rather than at commercial aggregators who will either re-sell or use it for own services.
- sceptic123 1y agoIf it's not tracking the user then I don't understand what the problem is with DNT here
- INTPenis 1y agoI want a Firefox extension that will auto-accept all cookies. Because I already use Cookie Auto-Delete and I'm just sick of the question popping up. Stop nagging and give me all the cookies so I can delete them 5s after I close your tab.
- Spare_account 1y agothat is covered off in the article, for what it's worth
- INTPenis 1y agoThank you! I just installed "I still don't care about cookies" in FF and this has improved my browser experience a lot!
- hedora 1y agoYou could use ublock origin’s annoyance list for the same effect. Even better, you could use one of the ones that send “deny” listed elsewhere in this thread. Note that most tracking is possible without cookies these days, so deleting the cookies on exit (or even always running in a private tab) doesn’t do as much as it used to.
- cj 1y agoI noticed you deleted the privacy policy in Github, and link to this one instead https://privacy.reject-cookies.bymitch.com/ https://privacy.reject-cookies.bymitch.com/ The one you link to doesn't really make sense: > Data is collected on specific sites that the product is not working on. This data is sent explicitly by users and when it is collected we do not collect any information that could be tied to a specific user. Only the name of the site is collected and any additional information you include in the text of the report. The original one that was deleted from the Github repo [0] is much simpler and to the point. [0] https://github.com/mitch292/reject-cookies/commit/18a87b2beed1d05732f106c108f59441aa97a055 https://github.com/mitch292/reject-cookies/commit/18a87b2bee...
- mitch292 1y agoAgree! Unfortunately, that one was rejected by chrome.
- Xunjin 1y agoCould you provide more details?
- mitch292 1y agoAdded some additional details under another reply in the same thread!
- GavCo 1y agoInteresting. Did they explain why?
- mitch292 1y agoThey had this in the reply > How to rectify: Ensure your privacy policy contains details about user data collection, handling, storage and sharing. Omission of any section is not allowed. So I added a section for each. I could make the "Information We Collect" section less verbose for sure.
- m00dy 1y agoA rule based approach alone is insufficient and lacks maturity. The solution must be capable of understanding the context of a given webpage and taking actions based on that understanding.
- HypnoticOcelot 1y agoWhat's the difference between this and "I still don't care about cookies"[0]? [0] https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies
- jauntywundrkind 1y agoIt rejects cookies & reduces how much you are tracked, rather than accepting all tracking & cookies.
- graemep 1y agoI don't care about cookies plus an extension that deletes frequently plus firefox container tabs will make tracking quite misleading.
- jauntywundrkind 1y agoMy gut feeling is that this would be somewhat useful yes at shielding privacy. But even if you delete cookies every day, at least for me, that's a day of various advertisers tracking my motions across the web. And it also involves the inconvenience of losing the sign in cookies that are greatly convenient for me to have. For my own sake, I'd prefer not accepting unnecessary cookies. On a macro sense, I also feel like there's a virtue to making it clear to sites that no I don't want their unnecessary cookies. Exercising my right to opt out (actually I'm American I have no such rights in my state) is a clear & direct signal, one that I hope someday perhaps the majority of the world might exercise. At which point there's little value in keeping up this user-hostile practice. Just deleting my cookies does reduce their usefulness, but it's not as clear a sign; it could just as well be someone who doesn't have a secure personal device they can rely on. I'd rather make it clear that no, I'm explicitly rejecting the premise of your cookies.
- graemep 1y ago> My gut feeling is that this would be somewhat useful yes at shielding privacy. But even if you delete cookies every day, at least for me, that's a day of various advertisers tracking my motions across the web. Browsers mostly block third part cookies by default or have an option to let you do so, so its only site's own cookies that need to be deleted. > On a macro sense, I also feel like there's a virtue to making it clear to sites that no I don't want their unnecessary cookies. That gives them an incentive to find ways to track you, such as fingerprinting. Limited data might convince them that tracking data is of low value.
- shav123 1y agonice how do you know where to reject is that a closed list?
- pete1302 1y agoIn todays world, having a performant and robust (that can support extension) browser on widely used Platforms (Ios, Android) seems like a dream. Is it too much too ask for?
- mcoliver 1y agoLove the idea. I wish chrome extensions had a more granular permissions structure and/or reminders/security checkups on installed extensions and their permissions. As it is the content scripts manifest permission for https://*/ https://*/* for content.js is always so jarring to see. For those that don’t know this allows the extension to run that script on every site you visit after clicking accept ONCE when you install the extension. That means it can see financial info, health info, legal info, your diary, etc… Now this makes sense from a usability perspective (I never have to see a cookie banner ever again!), but the author could change content.js at any time and the extension would continue to run without prompting the user. This is not an attack on you Mitch! It sure looks like you’re trying to provide value in this world rather than take it. Rather it’s an attack on Google’s extension security model I’m really shocked google has not taken a more careful and nuanced stance to protecting users from a security standpoint. I write this as a fellow chrome extensions dev. I wish I had better more granular permissions structures to protect my users and give them more information about what I am requesting and why along with regular reminders so they can make informed decisions about what they want to share.
- mitch292 1y agoDefinitely agree, not a fan of the permissions. The broad permissions were required from a usability standpoint. Granting permission on every site for this extension would just be a 1 to 1 replacement of clicking reject on the banner or pop up for every site. I would hope that before Chrome approves an extension to be added to the store that they are auditing the content of package.
- deleted 1y ago[deleted]
- shadowgovt 1y agoOne of the reasons Manifest v3 was started is that is impossible for an extension that eval's arbitrary code from the web (or downloads, say, a dynamic list of data and acts on it). For something like this, it's tractable.
- 1y ago
- p_ing 1y agoConsent-O-Matic is an extension that works fairly well and is cross browser. https://github.com/cavi-au/Consent-O-Matic https://github.com/cavi-au/Consent-O-Matic
- nashashmi 1y agoWhat works on iOS mobile? That’s the ultimate limitation on customization.
- tenthirtyam 1y agoHave you seen consent-o-matic? https://github.com/cavi-au/Consent-O-Matic https://github.com/cavi-au/Consent-O-Matic https://addons.mozilla.org/en-GB/firefox/addon/consent-o-matic/ https://addons.mozilla.org/en-GB/firefox/addon/consent-o-mat...
- rendaw 1y agoI tried consent-o-matic. Aside from the name making it sound like it says ok to all forms of tracking, it broke a few websites for me and failed to get rid of the banners on many others, and I quickly had to turn it off. TBH I'm not sure how it could be expected to work either, unless all websites use the same consent banner solution.
- jlpom 1y agoAre you aware of https://addons.mozilla.org/fr/firefox/addon/consent-o-matic/ https://addons.mozilla.org/fr/firefox/addon/consent-o-matic/?
- skeeter2020 1y agoCookie banners are a bad/wrong solution to the underlying problem, but it's the dark patterns within that really piss me off. I shouldn't have to invest deep cognitive attention to "only accept mandatory" but if you're not careful many dialogs will trick you into clicking accept all after you go to the trouble to untoggle all the optional shit. The answer is to use isolation containers, aggressively reset them and not to worry about any of this.
- ta1243 1y agoThe underlying problem that the cookie banner operators have is there are laws preventing them from abusing the data they collect. Annoying banners increase pressure on people to contact their representatives to overturn those laws, allowing the operators to abuse the data
- shadowgovt 1y agoI just always click accept all. Less to think about, and it basically puts the web into the state it was in before we all got bent out of shape about tracking, which was fine. (Now that I type that... I should have made an extension ages a go that just does "identify cookie banner and click on the left-most button automatically").
- nottorp 1y ago> and click on the left-most button automatically Why do you think the left-most button is always accept all? Why do you think the accept all button will be in the same position on all reloads of the same site?
- shadowgovt 1y agoIt's more that, as an end-user, I do not care whether I click accept or reject all; my goal is to get that UX speed-bump out of my face as quickly as possible. Maybe it'd be better to randomize which button is selected so if the plugin becomes popular site admins can't reliably guess where to put the button.
- 1y ago
- shwouchk 1y agoI don’t get it. All browsers have a “do not track” toggle implemented. And still, we get consent banners. Wasn’t I clear when i said don’t track?
- convolvatron 1y agowhen you say 'dont track', it seems like you could really mean 'dont not track', which would make more sense. since thats the safer option, maybe i should assume that. or maybe bring up a dialog that asks 'do you fail to consent to the lack of not tracking'
- shwouchk 1y agoyes, that’s what i thought. but then, what would be the point of rejecting anything, except to actively consent to something else?
- fshafique 1y agoWilfully ignored because i guess it's not mandated by law. You need someone powerful like Google to say they will lower Page Rank for sites that don't comply with the Do Not Track flag.
- johncoltrane 1y agoI --still-- don't care about cookies so I use https://chromewebstore.google.com/detail/i-still-dont-care-about-c/edibdbjcniadpccecjdfdjjppcpchdlm https://chromewebstore.google.com/detail/i-still-dont-care-a....
- darajava 1y agoBrave does this by default and it works flawlessly apart from on fairly obscure websites (a lot of obscure websites don't have cookie notices anyway). I don't know why more people don't use Brave - you can turn all the annoying crypto/ad stuff off and it never bothers you about it again.
- queenkjuul 1y agoI guess because Firefox doesn't make me turn off annoying crypto and ad stuff in the first place (plus I've been using it for like ten years now)
- exabrial 1y agoThe whole cookies law in EU is a prime example of government overreach and complete misunderstanding of how technology works. Imagine instead, if they legislated that a browser can merely be an html client, and not a spy tool for advertising companies.
- dsr_ 1y agoBack in the Matt's Script Archive days I would automatically reject anything written in PHP from serious consideration. Whatever it was, would inevitably be full of bugs, security issues, and either unmaintained or poorly maintained. These days, I apply the same filter to anything written with "vibe coding". If the nominal author didn't bother to write the code, I'm certainly not going to bother running it. I encourage my rivals and enemies (if any exist) to screech about how I will surely fall behind the zeitgeist and immediately fire all their devs in favor of six MBAs and a team of coops to be exploited ruthlessly.
- deleted 1y ago[deleted]
- methuselah_in 1y agoI guess firefox is missing
- mp3geek 1y agoRejecting all consents is just a webcompat disaster waiting to happen, "Why is embedded youtube video not working?", "Why is this social embedded not showing?".
- gitroom 1y agocookie banners make me want to toss my computer out the window tbh - you think we'll ever get to a point where browsers just handle all this and i don't have to babysit buttons or install a million plugins?
- troupo 1y ago> you think we'll ever get to a point where browsers just handle all this 1. The Do Not Track header set by browsers was used by sites to fingerprint and track users. 2. World's largest tracking and advertising company is also making the world's most popular browser. and 3. GDPR was adopted 9 years ago So the answer to your question is: no, they never will. Exhibit A: Google assumes Chrome is just another service to track you: https://x.com/dmitriid/status/1908951546869498085 https://x.com/dmitriid/status/1908951546869498085 Exhibit B: Chrome's "more private web" sells your browsing data and behaviour by default: https://x.com/dmitriid/status/1664682689591377923 https://x.com/dmitriid/status/1664682689591377923
- imcritic 1y agoI think the idea is poor: giving some answer is making a choice. I'd rather keep the site thinking I'm still choosing what to pick and have adblocker hide the crap.
- PeterStuer 1y agoAll of this would not be nescessary if the GDPR closed the "Legitimate Interest" loophole and enforced the one click rejection.
- rpgbr 1y agoFor those who use Safari, there's Hush: https://oblador.github.io/hush/ https://oblador.github.io/hush/
- rozenmd 1y agoI kind of like cookie banners, just to see which of the sites I frequent like to share my data with their 1957 partners.
- sneha_tamal 1y agooh this feels like a must need for a person like me.