12 ms·
Kill The Cookie Banner
- paulddraper 2mo agoDoesn't this lead to an all-or-nothing approach? I don't want randomnewssite to track me. But a favorite online store...I do want help with recommendations.
- dymk 2mo agoThen sign in, thats enough signal for them to track you
- frollogaston 2mo agoLogging in isn't consent for tracking. They can even support login by itself without a tracking banner.
- amelius 2mo agoJust configure your browser to ask for cookies for that store only?
- qurren 2mo agoJust disable cookies on your browser by default, and enable it for the sites that you need to log in to. Ironically, this has the effect of cookie banners reappearing every time because they cannot place a cookie that says that you have rejected them.
- mzajc 2mo agoUnless disabling cookies means treating all cookies as session cookies (meaning you can still be followed within a session), this has the fun side effect of breaking pretty much every CAPTCHA firewall like Anubis, Cloudflare Turnstile, and any other that relies on cookies. Unfortunately this means you have to view a lot of the web through archive.today or web.archive.org - I would know because I have uMatrix configured this way.
- qurren 2mo agoHonestly I've found that it's often the local businesses that shoot themselves in the foot more by this. I disable cookies for Amazon because I need to login; if a local business wants me to buy from them directly they need to: 1. Not give me a CAPTCHA or cloudflare shit 2. Give me free shipping and a lower price than Amazon minus 5% cashback that I would get on Amazon 3. No registration needed to check out and I'll buy from the local website. It's really not a high bar, they need to learn to not shoot themselves in the foot. As for the news websites -- bleh. If they want me to read it, make it easy to read. As in, I click into it, show me the content. If I get a popup, banner, anything that covers up the content, I bounce. I'll get the news from social media anyway. If they'd rather I get it from their news website, they need to learn to not make me bounce. I'm not opposed to advertising if they want to get revenue from that, but it should not track me, not cover up content, and not load megabytes of JavaScript to do it.
- frollogaston 2mo agoSession cookies for non-whitelisted sites is a nice balance between usability and privacy. Session cookies for all sites would be fine if passkeys weren't like "We support passkeys. Do you want to use a passkey? Press ok again to use your passkey. Do you consent to using your passkey? Now please authenticate yourself to use the passkey... √ Thank you for using passkeys. Press ok to continue."
- tcfhgj 2mo agoyou can be tracked without cookies - the cookie dialogs are about tracking and processing of personal data in general. -> not really sensible
- Phemist 2mo agoMalicious compliance. You do not need a cookie to "store" the fact you have rejected them. They can simply assume you have rejected them from the lack of cookies. They can store a cookie once you (have gone out of your way to) accept them.
- frollogaston 2mo agoLack of cookies could mean you never visited the site before.
- Phemist 2mo agoSafe to assume I reject things on my first visit as well
- joeframbach 2mo agoYou would presumably be logged in to your favorite store site, and they would be using your identifying session to make recommendations, not anonymous tracking cookies.
- paulddraper 2mo agoEh, maybe. It's easier to click a single button than hunt for how to create/access an account for the brand.
- hieKVj2ECC 2mo agoYes please!
- troupo 2mo ago> he EU Commission finally proposed a solution to the cookie banner problem: automated signals that would communicate your privacy preferences between your device and websites or apps. It wasn't on EU Commission to "finally propose a solution". The soluton has always been there. Somehow, Google, aka world's largest tracking and advertising company incidentally making the worlds' dominant browser and completely dominating all web standards, couldn't be bothered, and instead was pushing crap like FLoC
- cube00 2mo ago> Somehow, [...] couldn't be bothered Google knows if you can set this once it's game over for their adverting business. At least with the cookie banners, there's a possibly you won't refuse every banner. Especially those banners that only have "Accept" or "More options" with all those checkboxes to clear.
- rpdillon 2mo agoThe insanity around cookie banners is a good target. > Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. Fortunately, if you have uBlock Origin, you can enable Easylist cookie notices under annoyances and avoid most of them. Combine with blocking third-party cookies, and the problem pretty much disappears. The fact that the EU tried to regulate this stuff is a shame, because regulation is not a good remedy. End-users have agency here. The solution is to enable end-users to have control in their browser (which they always did, so it's an issue of education, like so many things). Shame that Google is trying to kill uBO though. Extremely pleased that Brave continues to support it.
- mrkeen 2mo agoIf it's not cookies, it will be something else. IP addresses, tracking pixels, browser fingerprinting. The Do Not Track header is the only technology needed. The rest is compelling companies to obey it.
- cwnyth 2mo agoDidn't know that about Brave, but it's moot for me since Firefox also supports it and these days I find that Firefox is the better experience, not Chrome or even Chromium.
- the__alchemist 2mo agoKeep fighting! For now: browser plugins.
- hborscht 2mo agois there a specific one you would recommend?
- the__alchemist 2mo agoI use "I still don't care about cookies"; it works well, but I don't have a current comparison to other options.
- deleted 2mo ago[deleted]
- tcfhgj 2mo agouBlock Origin -> allows blocking dialogs (legally implies refusal of everything not necessary, because you don't agree to something requiring agreement) Consent-O-Matic -> automated configuration to your preferences using the dialog provided. I still don't care about cookies -> least privacy friendliest option, because it may opt into undesired tracking (its goal is just to remove the annoyance of the dialogs)
- pndy 2mo agoExtensions; plugins are nearly dead nowadays anyway
- tezza 2mo agoEven well meaning bodies like TFL (Transport for London) have cookie warnings that impede the actual access of the website. Need to look up a bus time? Full screen cookie consent with accept buttons drawn OFF THE SCREEN.
- inigyou 2mo agoThey obviously aren't well-meaning if they're endlessly tracking everything you do
- igregoryca 2mo agoSloppy, non-privacy-preserving "analytics" set up by some communications intern ≠ malice. They can mean well and still do a poor job. True privacy on the internet is notoriously hard.
- ehnto 2mo agoI don't think you can handwave responsibility like that, even if your theoretical were true it's still the responsibility of the org.
- 4thguy 2mo agoSorry, no. Code doesn't magically go from the intern's workstation to live. If the chain of incompetence is that long, then the most generous read is that they don't care
- igregoryca 2mo agoCould've been as simple as installing and configuring some off-the-shelf "analytics" and "cookie banner" plugins for their content management system. Unfortunately, the chain of incompetence is that long, because these orgs do not attract talent that understands these things.
- Jtarii 2mo agoMore likely it was designed by some firm that put the cookie banner there because "that is just what you do in current year"
- TechSquidTV 2mo agoThe EU has been on a decade-long crusade to destroy the internet.
- yankfatigue 2mo ago[flagged]
- PaulRobinson 2mo agoI think you'll find that's Google and Meta. Just step back and ask yourself what each side of that debate is trying to achieve and why. What is motivating them? Why are they motivated in that way? Don't just recite what you "know", think, look, research, figure it out. It might sound good to have a one-liner like this in your back pocket, but do you really believe it after looking at the publicly available information that it is their real intention to conduct a "crusade to destroy the internet"?
- tcfhgj 2mo agoAdvertisement has been on a decade-long crusade to destroy the internet.
- amelius 2mo agoYou mean: the planet. (because it drives consumerism)
- jebronie2 2mo agoAdvertising funds large parts of the open internet. Killing ad means killing independent content creators for example. Over-regulation and censorship like "chat-control", that only benefits big players like Amazon, Meta etc. is what kills the internet.
- tcfhgj 2mo agoindependent of what or who?
- 2mo ago
- dfaoidsoi 2mo ago[dead]
- tysilva 2mo agoWow, finally. This would be a major quality of life update for browsing the web. As others have stated, not all sites merit the same preferences. Hopefully they can adapt a middleground of default settings with the ability to customize site by site.
- convolvatron 2mo agounder what circumstances as user would I want to explicitly agree to have my browsing history sent to tens or hundreds of third party tracking aggregators?
- PaulRobinson 2mo agoDevil's advocate argument: if they were giving you something in return, and that could be cash, but it might also be "you can have this content for free". In the UK a few news sites have changed cookie banners to "you can accept and see this stuff for free, or you can sign up for a subscription, which would you prefer?". It's the only time I hit accept (and then clear browser history). If blanket preferences from browser signals became the norm, a segment might open up where you would configure preferences and a data broker would make sure you get something in return for your data. At minimum it might force paywalled publishers to consider that as a "lite" subscription option.
- Phemist 2mo ago> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...
- tgv 2mo agoThe problem there is that parent's won't know how to do it, or won't care. Many can hardly operate the most user-friendly phone, let alone manage accounts. The online safety acts and its EU counterparts are somewhat risky, but nobody wants the mention the only proper alternative: a total ban on "social media." Not just for kids, but for everyone. Or a ban on smart phones, that would work too, at least short term. But: money.
- broken-kebab 2mo agoIt's ok if parents won't care. It's a choice too.
- SoftTalker 2mo agoYes, you can't make parents care, but make it easy for the ones who do, and you'll also pick up some number of those who care but only if it's not too difficult. There's no reason a parent should have to set permissions separately in 10 differents apps on a child's device.
- Kuyawa 2mo agoWhen we buy a new phone, the configuration process should ask if the device will be used by a kid. Easy and simple. When restoring factory defaults, the same question, just in case the phone is sold, gifted, stolen or whatever. If you are going to give a phone to a minor you should set that option right from the start.
- conception 2mo ago
- sandeepkd 2mo agoUsually government mandating something is concerning cause it seems to favor the government for its existence. However with EU commission its actually interesting combination, its representing multiple individual governments at once which somehow works good for the citizens. Overall this is a common sense solution. The challenge is that a significant industry makes money by collecting and selling data. It makes it harder for businesses who depend on it, they are going to get creative and will eventually come up with some dark pattern to circumvent it.
- mmarq 2mo agoAs if the DNT thingy didn’t exist…
- IshKebab 2mo agoDNT tried to do this without any legal backing which was obviously stupid.
- reddalo 2mo agoThe problem of DNT is that Internet Explorer 11 set it to true as default, and then all companies started ignoring it on purpose.
- pndy 2mo agoMozilla removed DNT as of Firefox 135, after 13 years since introducing it in 2011 with Firefox 4 In 2024 Mozilla acquired Anonym from former Meta executives and decided to introduce PPA: https://hn.algolia.com/?q=privacy+preserving+attribution https://hn.algolia.com/?q=privacy+preserving+attribution
- alt227 2mo agoI still don't get why every website has a cookie banner by default. I am data controller for several companies and have lots of exposure to GDPR. All my websites have no cookie banner, as they are not required. I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies? Who knows.
- maccard 2mo agoI’ve made a few sites for work that aren’t our primary focus. The sites used cookies for login and for “required purposes” (storing in progress state). We did all the tracking on the backend, no cookies or client side trackers. On our go-live form there’s a question “do you use cookies” and it’s yes/no. If you say yes legal block the site from going live without the pre approved cookie banner…
- jarofgreen 2mo ago> We did all the tracking on the backend Just checking, you do know that still counts as tracking and may fall under GDPR rules? GDPR was never just about cookies.
- maccard 2mo agoI do but we shouldn’t be talking about cookies in our cookie banner then.
- crote 2mo agoThat's why the usual phrasing is some variation of "Are we allowed to track you? We use cookies for that". It was never about the cookies themselves. That just happened to be the most common form of tracking in use when the GDPR was originally written. Cookie-less tracking still requires a consent prompt, tracking-less cookies never required one.
- 2mo ago
- W3cUYxYwmXb5c 2mo agoThis is conflating different things. They are trying to use people's annoyance with the banner THEY caused to build support for another legislation. Cookies were never a problem. Just get rid of the banner. This other legislation should pass/fail on its own merit.
- drnick1 2mo agouBlock Origin with all "annoyance" filters enabled. I haven't seen a cookie banner in years. Another good one to have the "hide Youtube shorts" filter, featured on HN a while back.
- tete 2mo agoThere is Consent-O-Matic. Also I wanna know when websites don't give a shit about my privacy and therefor have to show a cookie banner. While theoretically not consenting should mean not collecting blocking it altogether and modifying page content might mean "all bets are off". If the website expects you to have made a decision that might wrongly consider it consent. Consent-O-Matic says "I don't consent".
- alex1138 2mo agoThat didn't work for me and so now I've added the specific cookie banner options. it's in the filter lists
- jsrozner 2mo agoDoes this still work on new chrome versions?
- srijanbaniyal 2mo ago[flagged]
- ChadMoran 2mo agoWhat does enforcement of not having these banners look like? Wha tif people just... didn't.
- chrismorgan 2mo agoThe other approach to killing the cookie banner is simply to declare that such a thing cannot constitute “informed consent”. (Perhaps: “ticking a checkbox and/or clicking a button cannot constitute informed consent”; and see what they try next.) From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way. Just as shrink-wrap licenses and even simple contracts have at times in some jurisdictions essentially been neutered, so that only terms that a reasonable person would expect to be there are enforceable, at which point it becomes obvious that the whole thing needs tearing down in favour of standard licenses/contracts. In the Australian state Victoria, for example, there are standard rent and property sale contracts; for renting you must use that contract <https://www.consumer.vic.gov.au/housing/renting/starting-and-changing-rental-agreements/different-rental-agreements/residential-rental-agreements#:~:text=You%20must%20use%20the%20%E2%80%98prescribed%20form%E2%80%99%20when%20entering%20into%20a%20written%20rental%20agreement%2E https://www.consumer.vic.gov.au/housing/renting/starting-and...>, and I got the impression that residential sales practically always use the standard contract. But of course it’s impossible to convince someone of something when their livelihood depends on their not understanding it.
- deleted 2mo ago[deleted]
- otterley 2mo ago> From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened. There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
- deaton 2mo ago
- tete 2mo agoNo, please don't! It's great. The current law forces people that don't give a shit about user privacy to have a banner (or any other way of asking for consent first) while giving everyone that cares and everyone not wanting to spy on their visitor a free pass.
- inigyou 2mo agoPeople click yes too often because it's the easier way to make it go away. This new thing could actually result in a 0% tracking cookie consent rate, effectively making them illegal.
- deleted 2mo ago[deleted]
- SeriousM 2mo agoIt's a "Dick over".
- reddalo 2mo agoThe term "dickover" is now approved by the guy who invented "enshittification"! https://pluralistic.net/2026/07/21/dickovers/ https://pluralistic.net/2026/07/21/dickovers/
- hash872 2mo agoAlso there's a big difference between the sites that easily allow you to simply reject whatever their premade cookie settings are. And, the sites that only allow you to use them after you've accepted (example, politico.eu). Or, the sites that do have a 'reject' option, but you have to click through multiple screens and then manually reject each individual option. Sites that easily allow you to simply reject everything are then a short hop, skip and a jump into browser settings where you auto-reject all cookie/tracking nonsense
- imhoguy 2mo agoAnd guess who makes the most of devices and the most popular browser, I already see post install "Get most of the browsing experience by agreeing to these defaults."
- dspillett 2mo ago> automated signals that would communicate your privacy preferences between your device and websites or apps0 Sounds good, as long as it covers the "legitimate interest" bollocks⁰ that is often hidden in inconvenient UI nests as well as the basic preference. ------- [0] "we see your preference not to be stalked, but we want to anyway, click again for every partner to reconfirm you don't want them following you around"
- rusk 2mo agoThis was tried before but was presumably scuppered by the market intelligence and surveillance communities https://en.wikipedia.org/wiki/P3P https://en.wikipedia.org/wiki/P3P
- jeroenhd 2mo agoThe "legitimate interest" bullshit is already illegal. I don't see why websites would stop doing illegal things because of this change.
- shagie 2mo ago> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful. > ... > You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default. That's an excellent idea... lets see how its implemented on https://european-union.europa.eu/index_en https://european-union.europa.eu/index_en Oh... there's a cookie banner.
- wrqvrwvq 2mo agoor we could glass the continent
- SadErn 2mo ago[dead]
- openquery 2mo agoFinally yes yes yes. I've wanted the option to select your cookie preferences once and forget in a brower for ever. I assume the reason this wasn't done initially was corporate pressure (most people would opt-out of everything by default). 1.2 billion exposed users × 8.17 years×365×3 banners/day×4 seconds÷36 is roughly 10-15 billion human hours lost to dealing with damn cookies since GDPR took effect on May 2018. That's about 17,000 human lives.
- hollowturtle 2mo agoI always wondered though why a website in the eu, for the love of their users, won't just drop cookie usage and instrusive third party scripts. Just do analytics on the backend and don't set any cookie, except for tokens in authenticated areas
- reddalo 2mo agoThat's what I'm doing with a service I made. But I don't have any ads, and ad-supported websites can't easily do that.
- tappio 2mo agoThere are privacy respecting ad brokers that dont require user tracking. Its just that people are too lazy or greedy to use those.
- tempestn 2mo agoYou can't even save user preferences (like language or other settings) without showing a cookie banner. Edit: I was mistaken. You can't save inferred preferences, but can save explicit user-saved options. And for a serious website, front end analytics are kind of a necessity to understand how users interact with pages and improve the experience. Note that it certainly doesn't require tracking the behaviour of individual users, just understanding how controls are used in aggregate. I know it seems like you could work around this with careful design and maybe focus groups and such, but I can tell you we regularly uncover surprising insights from (aggregate) trends in front-end events.
- dgellow 2mo agoThat's not true and is a very common misinformation people repeat online. You can save user preferences in cookies without any consent banner, if the cookie isn't used for tracking. See here[0], page 6: > As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’ 0: https://www.edpb.europa.eu/system/files/documents/2024-10/edpb_guidelines_202302_technical_scope_art_53_eprivacydirective_v2_en_0.pdf https://www.edpb.europa.eu/system/files/documents/2024-10/ed... As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen
- Retr0id 2mo agoI think this would be a net benefit, but I can see an issue. A lot of news sites today do "accept tracking, or pay us, or you can't access the page". The orgs doing this are reputable-ish so I assume it's considered legal, on some level at least. So now they'd have a new popup that says "reconfigure your browser to accept tracking, or pay us, or you can't access the page". Which isn't really an improvement.
- JoshTriplett 2mo ago"accept tracking or pay" has already been ruled against, it just hasn't been universally enforced yet because enforcement takes time.
- richard_chase 2mo agoIt would have been funny to get a cookie banner on this site. They missed a good opportunity.
- tgma 2mo agoI am old enough to remember Do Not Track and its failure and problems associated with it. What's new here? Why wasn't it adopted in the first place for GDPR?
- pmlnr 2mo agoNothing. People not reading back on history is still very much a thing.
- charcircuit 2mo agoEven if you communicated your preferences sites would still want to ask for an exception to them. At least you won't see them ask for consent if you preapprove it.
- doodlebugging 2mo agoNo need to kill the cookie banner. Just change the system so that everyone in every organization who supports cookies and other forms of user tracking and engagement will have every detail of their own existence and their family's existence broadcast in real time globally 24/7/365. Anyone who tries to opt out is jailed under 24 hour surveillance for a minimum of one year. EDIT: It's obvious that people really hate this option. Maybe too many here have their incomes too closely tied to the metrics that cookies are designed to collect. It could also be that it is an unrealistic option for everything except the most extreme societal changes. If you are old enough and look back far enough you may remember the time before all this bullshit like I do. Once marketing and advertising get involved and gain power in an organization, things tend to go to shit fast.
- jsrozner 2mo agoHypocrisy is the name of the game in SillyCon valley. Push YouTube autoplay slop on kids globally, but no ipads for children of the tech elite. Computer-based instruction for public schools, but 2:1 teacher:student ratios in the local private grade schools that cost as much as an Ivy League University. Etcetera.
- ezoe 2mo agoIt's technically stupid in the first place. It's YOUR browser, a locally running software on a physical computer YOU own which memorize the cookie key-value pair a remote host told YOU to memorize and YOU return the same value later. It's YOU who allowed the cookie. If YOU don't want to allow the cookie, YOU simply not allow it. You are technically 100% control on cookie. These JavaScript implemented in-page UI has no guarantee to respect your wish. But you have a power to disable it.
- frollogaston 2mo agoIt's not quite the same thing since the same cookie used for login (doesn't require consent) could be used for tracking (requires consent). But also, basically nobody cares.
- troupo 2mo agoThis has nothing to do with cookies, and everything with pervasive and evasive tracking. E.g. storing your precise geolocation for 12 years: https://x.com/dmitriid/status/1817122117093056541 https://x.com/dmitriid/status/1817122117093056541
- TheCoelacanth 2mo ago"Cookie banner" is a colloquial name; not a technically accurate description of what the banners are for. GDPR is not about cookies; it is about tracking. Whether the tracking is done through cookies or through other means makes absolutely no difference. You can prevent some tracking via your browser, but definitely not all of it.
- ktosobcy 2mo agoUhm… > The solution: automatically communicate your privacy preference Would be lovely and would happen if it weren't for… wait for it… Google and whole effed up ad-busines: https://ppc.land/eu-council-drops-cookie-signal-after-google-lobbying-eur-40-50-bn-at-stake/ https://ppc.land/eu-council-drops-cookie-signal-after-google... F*ck google and other BigTech…
- johndhi 2mo agohow about: -if we really don't like targeted advertising, just outlaw it -then let websites do whatever they want with our cookies so long as they aren't targeted advertising instead of building websites and writing laws over the span of decades that just seem to want to ban targeted advertising but don't actually do it. FFS.
- nektro 2mo agocan we also kill the dark pattern of "accept all" and "choose your preferences" ?
- jebronie2 2mo agothis is already illegal, which goes to show how useless even more legislation is
- himata4113 2mo agoOkay, but you can quite literally just delete the cookie banner. Cookie banner forces websites to ask for consent, no cookie banner = no consent = less tracking since they usually hold off on ALL tracking until you interact with the cookie prompt. I have personally never ever had any problems with the cookie banner since Brave deletes them with 100% accuracy, there's sometimes where a site will refuse to function properly, but it's usually sites I don't care about anyway and if I HAVE to get it working I disable brave shield, turn off all tracking, consent and turn the shields back on. It is unfortunate that most browsers cannot implement this as it goes against what the companies behind the browsers want. Deleting the cookie prompt would stop people from occasionally just accepting all cookies and opting into tracking after getting tired of it.
- righthand 2mo agoThe captchas are worse imo (from an usability standpoint) especially the newer Cloudflare infront of everything to check for bots trend.
- pverheggen 2mo agoHere's the full text of the bill (Articles 88a and 88b): https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52025PC0837#:~:text=articles%C2%A0are%C2%A0added:%C2%A0-,‘Article%2088a,-Processing%20of%20personal https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... As written, this doesn't eliminate cookie banners completely, only if your browser is sending a Do Not Track header or similar. That's unfortunate news if you use fingerprint protection - those send default headers, so you'll still be bombarded with cookie banners. Hopefully existing anti-fingerprinting solutions will offer a "default headers but with Do Not Track" option.
- MetaWhirledPeas 2mo agoThe good news is if you're doing Do Not Track you're probably in a good position to block cookie banners too.
- jsrozner 2mo agoCookie banners are just a kind of ad. If you're at the site, the demand you have for the content on the site is probably close to inelastic (especially on services websites). The site exploits its effective monopoly on the content to raise prices to the user (in this case your time, attention, and experience). There is ZERO cost to abusing the user over, and over, and over again by asking for permission to track them. We shouldn't have the cookie banners at all because NO company should be able to do anything with tracking data. Just ban the use of user data by companies and most of SillyCon Valley's garbage behaviors are fixed. Similarly, I should never get "terms of service updates" from digital companies because there should be no changes that they can make. You can provide the obvious service that you're providing; you can't aggregate my data for any purpose other than directly serving me; you can't aggregate my data with that of other users; if you retain my data for any other purpose, the government should take percentages of your revenue. I shouldn't have to wade through the BS that the mercenary corporate lawyers cook up to extract value from me.
- joelthelion 2mo agoAt this stage, it's easier to block them with uBlock and move on. I don't have a lot of confidence for legislative solutions. Although I admire people who keep trying.
- whatcd 2mo agoEvery time a Cookie banner pops up, I want to kill it forever
- logicallee 2mo agoAll browser providers have been required by international law[1] to send such a cookie popup suppression signal as set by the user, or one substantially like it, since July 18, 2026 and all web sites have been required to obey it or a superseding Internet standard: https://stateofutopia.com/laws/2/law2.html https://stateofutopia.com/laws/2/law2.html This is not a proposal, it is duly ratified international law that applies to "Every Browser Maker making a Browser available anywhere" and "Any site anywhere that receives a valid signal". The EU Commission had until July 18, 2026 to modify its laws: >"The site shall not display a banner, modal, interstitial, or other prompt requesting a choice already expressed by the signal. It may optionally provide a “Cookie Settings” or “Privacy Settings” link. This Law overrides all laws requiring such a display. Where any country or supernational entity has a conflicting law, it must rectify the Law within 30 days not to require such notification." Therefore, insofar as it has not rectified its laws not to require such a notification, the EU Commission is in violation of international law as of 8 days ago. Under section 7.3, "The State of Utopia may order compliance, require corrective updates, suspend non-compliant distribution, and impose civil penalties. Fines may be levied in any amount for continued non-compliance." so we can fine the EU Commission whatever you guys want ($1 billion? $10 billion? whatever four and a half millennia are worth) and just distribute the collected fines among you all as cash payments. [1] Here is the announcement of the law 38 days ago: https://news.ycombinator.com/item?id=48585778 https://news.ycombinator.com/item?id=48585778
- whywhywhywhy 2mo agoWould have gone harder without the Corporate Memphis/Alegria art which is the art always used to try and convince you to hand over your tracking rights.
- tomp 2mo agoOr you could just stop spying on people. No cookie banner is required for functionally necessary cookies.
- deleted 2mo ago[deleted]
- jebronie2 2mo ago[flagged]
- Etheryte 2mo agoNot wrong in the EU, you don't need to ask for consent nor notify about cookies which are required to make the site functional. Tracking and ads don't fall under that though, which is why every site these days does need to ask for your consent.
- jebronie2 2mo agoNo, you need to always ask for consent for cookies if they come from a third party, regardless if they are only required to enable functionality. You also need to ask for consent each time data leaves the website (for example when loading an image from a third party host). You can't even load a font file from a third party server because the users IP reaches that server without consent. Cookie banners don't just handle third party tracking cookies, the are needed to record consent for a huge variety of cases. "Banning tracking cookies" does not remove the need for cookie banners.
- kodebach 2mo agoWell if the cookie comes from a third party it implicitly allows tracking. Also AFAIK the Google Fonts question (is the IP alone already PII, if Google has no way of tying the IP to a person) has not been decided by the ECJ yet. There've only been decisions by lower level German courts that are still in dispute.
- CurbStomper 2mo ago[dead]
- lacoolj 2mo agoThis ones a little tough. Advertising through trackers is a massive portion of how sites get revenue. Going back to the old days would decimate this space, and have widespread effects on the internet (though im not sure it would be noticed by most of us anymore with how dead the internet feels now) I guess what I'm saying is, there is no good solution here. I don't want every site I visit to require a usage fee just to browse. Imagine if slashdot turned into WSJ with a paywall for every article. Kagi already does something like this, and cool - if you use it enough, maybe its worth a subscription. I dont find myself googling (searching) much anymore, so paying to do so just becomes something i need to find a way around. Like API token usage for AI, using it is like making a new recipe in the oven every time. You expect it to work but you have to invest the time and money into the attempt before you can find out the results (whereas you dont have to do this on free chatgpt, google search with ai, etc as comparison). Too much investment without guarantee of results. I'm fine without that guarantee as long as im not wasting my time and money upfront. Anyways, thanks for letting me rant
- websap 2mo agoEvery website that you visit and decide the article is worth reading, means a human spent time working on the content, and people spent time building the website. Reading on the Internet has a cost associated with it, whether its your privacy or your dollars.
- j16sdiz 2mo agoI kinda of agree with you - there is no good solutions if we are only changing one or two things at a time . I am kind of wanting to f around and found out. I missed the old internet were most of the big websites are run by hobbyist. I know some of them may not be able to pay the bill without ad. May we can figure out something once we leveled the playing field
- crote 2mo ago> Advertising through trackers is a massive portion of how sites get revenue Sure, but magazines get a massive portion of their revenue through advertising without trackers. Same with television, or radio, or billboards. And the ad space isn't exactly very healthy either. Take a large Youtube channel like Linus Tech Tips, for example: AdSense only accounts for 10% of their revenue! Youtube has been drowning people in ads and it still barely pays any money. I think we should seriously consider the possibility that targeted ads might be less profitable overall. Ad blockers didn't become a thing solely because ads appeared on the web. Ad blockers became popular when ads became obnoxious and privacy-invading. With the current state of the web ad blockers are a hard requirement for a reasonable browsing experience, so the only people seeing ads are the handful of suckers too ignorant to install them. But if ads aren't as invasive and obnoxious, people would have far fewer reasons to install ad blockers. See for example the Acceptable Ads program of Adblock Plus. If switching to user-respecting ads resulted in a significant portion of people turning off their ad blockers, it could very well result in an increase in ad revenue!
- duxup 2mo agoSo much legislation about privacy that involves "oh those bad companies" that ends up putting the onus on the individual to manage it all. I'm visiting a website, i don't want to make a legal agreement with every website ... Social media bad for kids? Everyone hand over your ID at the door ...
- jeremyjh 2mo agoThe companies want to track everything you do on the web. EU passes a law that says they have to ask for permission first. They all comply maliciously because they still just want to track you. Then you blame the government.
- duxup 2mo agoThe mechanism that I have to make a legal agreement with every site was a government choice, and a poor one.
- jeremyjh 2mo agoNo, its the website's choice. They want to track you. The government said they need permission to do that. They could offer a better experience by just not tracking you.
- buildwrangler 2mo agoThis should just be a browser setting with a per site opt-in when more data collection is needed. Just like you can enable notifications, webcam etc... or set it to always deny. Why the fuck do people have to keep stating the same preference over and over again. This is a hellscape of bad government AND corporate policy colliding.
- haute_cuisine 2mo agoYou don’t need a cookie notice if you don’t track. We also had “do not track” is safari.
- buildwrangler 2mo agoYeah, the "do not track" setting I think was the browser based solution that sadly never took off. Better government policy should have required respecting that setting instead of the cookie banners.
- croes 2mo agoSo DNT back again?
- mullingitover 2mo agoIt's great they're talking about it, but they should just do like California and DO something about it.[1] > When the law takes effect in January 2027, Californians will see new privacy options in web browsers. When enabled, these controls will automatically inform websites of their privacy preferences, helping to protect personal information from being sold to data brokers and other third parties. This means they will be able to protect their data — like their browsing history, location data, purchase history, and personal interests — across the entire internet with a single step. [1] https://cppa.ca.gov/announcements/2025/20251008_2.html https://cppa.ca.gov/announcements/2025/20251008_2.html
- TurdF3rguson 2mo agoAnd it will be largely unnoticed by site operators because who can be expected to edge case that into their logic?
- jebronie2 2mo agoThis initiative is ignorant and idiotic. The authors don't even understand the purpose of cookie banners. 1. Making tracking impossible/illegal would NOT kill cookie banners, since you need them to record consent for other purposes as well, such as embedding a video from a third party like YouTube. 2. The GDPR explicitly prohibits site-owners from making cookie banners misleading. The law is already there, it is just not very well enforced. 3. "This results in up to 90% of people saying “YES” – even though only around 3% actually want to be tracked online" This claim is grabbed out of thin air and can be dismissed as such. 4. "The solution: automatically communicate your privacy preference" This is nonsense because it does not actually solve anything, because you need to record consent for a variety of purposes, not just analytics/tracking. 5. Killing tracking would kill the value of ads (since they are not targeted anymore), resulting in a reduced ability for small businesses to advertise and a hugely increased amount of ad spam everywhere. Few targeted ads > Many untargeted ads Unless you want an internet where advertising is no longer possible, this solves nothing apart from stroking a few activists ego.
- m000 2mo agoThis just doesn't make sense. EU regulations are already making progress in improving online privacy: (a) No cookie banner required for functionally necessary cookies, (b) there needs to be an option to refuse tracking cookies in the cookie banner, (c) the dreaded cookie banner appears only the first time you visit a site. I would say, we are like 80% there. Yes, there are still some dark patterns employed by cookie banners, trying to trick you into accepting tracking. But they are not too hard to make out. And they can be fixed by tuning the regulation a bit: Require the opt-out to be the first choice and the only one with highlighting. Ad tracking is not going away tomorrow. If we ever are going to get rid of it, we first need legislation to defang it so it stops being a cash-cow. "Tracking prohibited by default" is a great end-goal, but we are not there yet. Reading between the lines, it appears that there is some new solution proposed to "automatically communicate your privacy preference". That's nice, but when e.g. the Do Not Track header was tried, it just fell flat. So until this new solution is implemented and adopted, I'll take my websites with a cookie banner, thank you. It is an unfortunate choice that the campaign obsesses over the cookie banner, instead of trying to actually advance the solution that would make it obsolete.
- crote 2mo ago> Yes, there are still some dark patterns employed by cookie banners, trying to trick you into accepting tracking. But they are not too hard to make out. And they can be fixed by tuning the regulation a bit: Require the opt-out to be the first choice and the only one with highlighting. The fact that we are still talking about this literally a decade after the GDPR was adopted shows that this isn't working. It has turned into a cat-and-mouse game, and the regulators just don't have the manpower to effectively rules-lawyer every tiny change. > when e.g. the Do Not Track header was tried, it just fell flat. ... because there was no reason to follow it. There was literally zero consequence for ignoring it. This new proposal makes the Do-Not-Track v2 header legally binding. User sends the header and you still show a consent popup? You're breaking the law, simple as that. No weaseling yourself out of it, a simple screenshot is enough. Any regulator could build a fully-automated scanner in half a day: ask the local TLD registrar for a mapping of websites to companies, have some script request the page and do a regex search for "cookie" (or use AI if you are feeling fancy), take a screenshot, pass it to an intern to double-check, then automatically send out a €100 fine. Double it every X weeks they haven't fixed it yet. Want to fight it in court? They have screenshot, you lose, now pay.
- gitowiec 2mo agoI expanded Polish politics names and what I saw made me vomit. Will never send email to those fuckups.
- PunchyHamster 2mo agoThe solution would be for browser to send do not track header and have that header be respected. But we can't have that, can we ? They will lobby to hell and back for that to not happen
- breck 2mo ago[dead]
- chmorgan_ 2mo ago[dead]
- fhn 2mo agois there an extension that modifies the cookie, changes values randomly? This will pollute their analysis with junk.
- 1vuio0pswjnm7 2mo agoActual title: "Stop the tracking circus. Kill the cookie banner!" ;dr The "cookie banner" is an interactive method used by "adtech" companies to try to get user consent, as required by EU law. The forced interaction makes this method annoying Google and other "adtech" companies are lobbying EU Member States to vote against giving users a means to non-interactively deny consent
- wazdra 2mo agoI'm from France, and when browsing, I often get paywalled when I reject all non-essential cookies. The CNIL (who is in charge of the application of GDPR) ruled that this was compliant with GDPR as long as another website was offering an alternative without cookies[1]. Are there similar rulings in other EU states? 1: https://www.cnil.fr/fr/cookie-walls-la-cnil-publie-des-premiers-criteres-devaluation https://www.cnil.fr/fr/cookie-walls-la-cnil-publie-des-premi... (in french, sorry)
- jchook 2mo agoThe most frustrating thing about the cookie banner is that the solution was always obvious: just use the DNT setting on your browser (Do Not Track). It already existed. However, powerful interest groups like ad companies that profit from your attention (which hysterically virtually powers the Internet today) were able to stop it from happening. It was debated way back in 2009 when the GDPR was being developed. Iirc the argument was that browsers accept cookies by default so users do not get a fair consent moment. This is obviously easily fixed by regulation requiring browsers to ask users once. Seems extremely backwards that we chose to forever darken the entire Web browsing experience just so users can "benefit" from a per-site option to let Google profit from them, with virtually zero payoff for the end user (ad relevance?). P.S. If ad revenue is an essential pillar of Internet survival and fruition, the clear alternative seems to be sharing a fraction of that revenue with the tracked consumer.
- _moof 2mo agoAnd in a truly twisted move, ad tech companies were also using Do Not Track as part of browser fingerprinting. This industry is a paperclip maximizer, and it needs to be dealt with accordingly.
- voxic11 2mo agoDo Not Track cannot satisfy the GDPR, it requires that you obtain informed and specific consent so even if a user had the DNT bit set to consenting you would still need to show the banner.
- jchook 2mo agoObvious move is to modify GDPR to not be so obtuse.
- cure_42 2mo ago+1
- kjgkjhfkjf 2mo agoPerhaps it would be simpler to make all non-essential cookies illegal. I cannot imagine why any reasonable person would want to accept non-essential cookies, other than in the course of following a path of least resistance.
- jeremyjh 2mo agoThis is the only way. They'd also have to make all third-party assets illegal as well though and that may break some legit use cases, and make it a lot harder to use CDNs.
- crusty 2mo agoI've wondered for a while what value is assigned if a user ignores or dismisses (when possible) a cookie banner without actively selecting accept or decline. Anyone know?
- micromacrofoot 2mo agomany of these banners don't actually work, for starters but the proper functionality would be no cookies that require consent until consent is given
- giancarlostoro 2mo agoWhy they didn't just force browsers to implement it the same way browsers ask if you want to share location data or mic access is beyond me.
- unmole 2mo ago> Stop the tracking circus. Kill the cookie banner! Perhaps the EU Commission could start by stopping the circus on its own website and killing its own cookie banner: https://commission.europa.eu/index_en https://commission.europa.eu/index_en
- orangelimetea 2mo agoAnother idea: Use (or vibe code and share) a browser that doesn't use cookies. At all.
- sflicht 2mo agoAny US corporation who displays a cookie banner to US based IP addresses should be taxed $1 million per instance of this occurring.
- leptons 2mo agoGot news for you... California now has its own laws around similar things, and the trolling lawyers are out there sending threatening letters to our clients. I manage a few thousand websites that operate across the US, and things are getting a little crazy with the lawyers lately. It's just like ADA compliance and trolling lawyers all over again.
- vivzkestrel 2mo ago- not from EU here - for the love of god please do this - please get rid of every cookie banner on every website on this planet once and for all - you ll be doing humanity a huge favor
- nihonde 2mo ago"The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner." Browser-based privacy controls were proposed in the late-90s/early-2000's as P3P, and were killed by corporate interests. https://www.w3.org/P3P/ https://www.w3.org/P3P/
- m00dy 2mo ago[dead]
- samiv 2mo agoI find the cookie banner always ironically wrongly labeled. Everyone claims to "respect your privacy" while actually disrespecting the privacy. If they did actually respect the privacy they would not use non functional tracking cookies and there would be no need to display the banner. The answer is simple. Don't use tracking cookies.
- sholladay 2mo agoThe cookie banner is a significant accessibility problem, for blind and low vision users, among others. I would like to see a stronger push to attack it from that angle.
- getfluxly 2mo agoI am a builder in the same space(tracking analytics) and I agree with killing the cookie banner. It is really annoying and most of the time, sites don't even respect the decision, they just track it nonetheless. Setting up a consent stance once per browser is way better, also I think there should be fines for the websites that don't follow the same.
- pcollins123 2mo agoI once interviewed for a senior product position at Google by a VP across many of their Web Products (including the Blink engine). He asked me "So, how would you make the Internet better at Google?". My response, "Setup preferences in Chrome to eliminate all popups including Cookie banners". I never got a call back for the second interview.
- alibarber 2mo ago* "This proposal for privacy signals is part of an EU law reform called the Digital Omnibus. Most other parts of this reform are problematic and would weaken people’s rights. We want to make clear that we do not support these other aspects of the proposed reform." Oh.
- eru 2mo agoHas the EU ever ran an honest (or otherwise) cost benefit analysis on the cookie banner rules?
- nottorp 2mo agoEven if it were automatic, there is no guarantee web sites will respect it. Is there any reason for allowing this tracking browser side besides a little convenience for the web devs?
- grumbelbart2 2mo agoI never understood why visited websites and all their first and third party cookies are not isolated by default in browsers. There are so few sites where I really need cross-site logins to work that an opt-in would be much more preferable. Have all sites set cookies on whichever third party they want, but don't share those cookies over. Add an explicit "Do you really want foo.com to share data with bar.com?" if you really need to see those facebook comments on your news site.
- albuic 2mo agoThat's how it works on Firefox
- mrx8086 2mo ago[dead]
- mFixman 2mo agoI have been successfully using the Consent-O-Matic extension [1] to auto-decline all cookie and GDPR banners. As much as I'm not comfortable giving potential access to every website to some extension developers, this improved my internet experience almost as much as AdBlock. Does anybody here know of a better solution? [1] https://addons.mozilla.org/en-GB/firefox/addon/consent-o-matic/ https://addons.mozilla.org/en-GB/firefox/addon/consent-o-mat...
- XzetaU8 2mo agoI still don't care about cookies https://addons.mozilla.org/en-US/firefox/addon/istilldontcareaboutcookies/ https://addons.mozilla.org/en-US/firefox/addon/istilldontcar...
- melicerte 2mo agoMy request to the owner/promoter of the site: provide an email template that we can send to our representatives. I'm willing to send such email, I've the list of the people I want to reach. But what is too complex is to write the appropriate email... Can you help me with this ?
- inigyou 2mo agoIn general, representatives ignore template emails. Their staff throw them in the trash folder before anyone important reads them.
- pjio 2mo agoMaybe I'm naive, but I just click "Accept all" and rely on Firefox's "Total Cookie Protection" to prevent tracking, without having to trust a website.
- inigyou 2mo agoYou also consented to fingerprinting.
- afishisafish 2mo ago[flagged]
- richrichardsson 2mo agoI'm fed up of Croatia never appearing in lists of EU states. I'd get involved if they were added to this site.
- voidUpdate 2mo ago> "around 3% actually want to be tracked online" 3% of people want to be tracked online? I think it's more likely that 3% of people misunderstood the survey question
- benrutter 2mo agoIt probably depends on how people interpret it right? I doubt anyone is saying "I love being tracked" - but some people might choose personalized ads over anonymous ones. I don't really use youtube natively a lot anymore, but I used to with Google's "personalised ads" turned off. I don't know if you've tried that, but the ads Google serves you if you opt out of personalised adds are sketchy, creepy and mostly not child appropriate (a lot of medical stuff, plus adverts for mail order brides etc). Back then I opted in to personalised ads because being tracked seemed a better option to me than being served inappropriate material without my consent. Anyway, that's a long rant, but my point is, there's edge-cases and weird contexts in which I can imagine people saying something like "of the options I see as likely to happen, I'd most like to be tracked".
- voidUpdate 2mo agoWell if the conclusion is "3% of people want to be tracked online", I'd expect the question to be "do you want to be tracked online" or similar, not "do you want to receive personalised ads"?
- billynomates 2mo agoI dunno, the people I've talked to about it (small sample) have said they don't mind because then they get more relevant ads. It's very hard to reason with that sort of thing!
- jukvalim 2mo agoYeah, 3% is pretty close to Lizardman's Constant - meaning the amount of people who misunderstand or give nonsense answer just because. https://slatestarcodex.com/2013/04/12/noisy-poll-results-and-reptilian-muslim-climatologists-from-mars/ https://slatestarcodex.com/2013/04/12/noisy-poll-results-and...
- PeterStuer 2mo agoCan the proposed consent automation kill the 'legitimate interest' abuse is the most important question. Even getting towards a single click refuse all requirement would eliminate the majority of dark patterns endemic today.
- aucisson_masque 2mo agoIt's absolutely not the right time to contact EU representatives. They are in vacation, and the vote goes on september/october. Put a note in your calendar, write a letter and send it then. btw, the link say it's around 3% of people who want to be tracked when the reports state it's between 3 and 10%. it's misleading.
- ghtbircshotbe 2mo agoI click the close button on the cookie banner if there is one. No idea what it does though.
- luquimarti 2mo agoAre there alternatives that won't use cookies to persist user information and provide reliable tracking?
- onel 2mo agoAs a PSA, there is the Consent-O-Matic family of extensions that makes option available at the browser level. You can choose the level of "tracking" you are comfortable with. They automatically choose the option in the cookie banners. Not a perfect solution, especially with custom made cookie banners but worka really well overall. Haven't clicked on a banner in years
- lofaszvanitt 2mo agoFinally, another idea of mine. Another one nailed. Now do the funding too.
- richartruddie 2mo agoThe banner is needed because I want to toggle settings depending on the website. A one size fits all model does not give agency and choice thats easy to adjust for a website visitor. Thats how I feel but you can call me biased.
- krul_umiaru 2mo agowhat cooke banner?... https://addons.mozilla.org/en-US/firefox/addon/istilldontcareaboutcookies/ https://addons.mozilla.org/en-US/firefox/addon/istilldontcar... also some say it should be browser setting. Thye gonna piss on it, same as google piss on autoplay API setting on youtube (still autoplaying) 'bc their business model would hurt...'