OK Google
Should have been handled on protocol level. Cookies get priority levels, set browser to only accept required cookies and done. Everyone just wanted to do it the easy way… add a banner and ask the user… or dont even make the banner, call a third party library that does it for you… and has its own tracking code… yay!
I need to verify this, but I vaguely remembered you’re supposed to be able to exit these safely in two clicks maximum, though they sometimes obscure it.
Usually, it’s something like “Customize” then “Save” without checking anything, or just “Reject All”.
I’ve seen a few sites set the toggles so that the on position is for options out instead of allowing the use of.
it’s even more straight forward than that; accepting and rejecting has to be the same number of steps.
So basically 90% of sites aren’t GDPR compliant.
correct!
Somebody should in some way pass that information to the companies then.
Correct. But companies seem to not give two fricks about it. There should be harsher punishments in place.
Why oh why didn’t the lawmakers add an obligation to use a standardized cookies selection popup.
I remember day one of it coming into effect and it was already obvious this was a necessity.
Lobbying. One of those laws pretending to do the right thing but sabotaged.
Or maybe its even worse than that. Before you could just have the cookies deleted. But if you do that now you get the awful popup every time, so you just accept them in the end.
I know I do.
This law has made me accept cookies spying.That’s already part of the GDPR, companies just aren’t complying with it.
From the official GDPR site:
To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must:
- Receive users’ consent before you use any cookies except strictly necessary cookies.
- Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received.
- Document and store consent received from users.
- Allow users to access your service even if they refuse to allow the use of certain cookies
- Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place.
“Make it easy”
If you make a vague law that companies can circumvent they will do it.
That’s why you force the use of a standardized menu, because nothing else makes sense, no? The same way you don’t leave it to the tobacco manufacturers to implement the warnings on the box ; you force them all to adopt the same one that’s clearly visible.
It feels like it’s either severe incompetence, or the work of lobbyists. But I don’t know enough about the matter
Not “make it easy”, it’s “make it as easy”, meaning it can’t be easier to accept than to revoke, much clearer bar.
And you dont think that’s really vague though?
Why not mandate a x by x pixel popup with a specific wording?
I remember this French company, I think SFR (phone), which had to show on their website their condemnation. Since there weren’t clear specifications they made it so the message would disappear when you scrolled down one pixel, so almost no one saw it.
Well, that could make the popup unusable depending on screen size. I think the wording is pretty clear, the issue is just that there’s no followup and not clear enough incentives to avoid skirting the rules at the moment.
Because those laws were made with good intentions in mind.
But businesses never have good intentions, especially if it eats into their revenue. So they use malicious compliance to make it seem like it is the law that is bad.
brave browser gives you a lot of options to block that bullshit and delete it before it’s ever able to make a profile on you…I’ve already heard what everyone on here has had to say about it. It works and it also works really well against most fingerprinting techniques used by invasive websites
adguard for windows, mac and linux can also be helpful for that stuff.
nextDNS and ReThinkDNS are also helpful for blocking garbage from advertising companies landing on your computer like the leech it is
You can also just toggle on a blocklist for that in ublock origin
bypass paywalls is in ublock origin now?
is it ever going to be in ublock lite?
- Just leave that website and find somewhere else to do business.
So, probably stupid question.
If a website pops up and asks for permission, and I bypass that pop-up in some way (like killing the pop up with an addon or some you can just ignore it and keep scrolling with it on the bottom of the screen)
Until ive clicked agree, do websites just not start tracking or creating or doing anything with cookies? After all, they’ve acknowledged they need, dont have permission.
Or is this by and large pointless, and unless ive jumped through their hoops, they’ve already started the page with cookies enabled?
If the site is GDPR-compliant, they are not allowed to set any cookies until you click the accept button. But, a ton of sites and ad agencies are not. For example, Russians commonly just put a “we tracking you, deal with it. [OK]” banner, thinking they are funny, when it’s clearly illegal even by Russian law, but they are shielded from it by responsible officials incompetence. Same story in the US, I believe.
depends on the site.
legally you’re assuming the correct way it’s supposed to work in a lot of jurisdictions but in practice who actually litigates these sorts of things?
people get away with it all the time.
there’s also tons of sites hosted in places where it’s totally legal to just have cookies with any user from anywhere with or without consent, those might have a permission banner just as a UX thing to make the site feel more “familiar” or “official”. learning how whole contemporary stack works, at least broadly speaking, is one of the only remaining ways to actually be proactive. knowledge is power.
Many sites have a one click “reject all” now, and it’s getting more common over time.
Which doesn’t reject all.
They need a cookie to remember your choice otherwise it has to ask you every single time. It’s the paradox of cookies!
There’s always a category “necessary”, so the preference cookie just falls in that.
That’s because they have to. If I remember correctly it is supposed to be as easy to reject as to accept, but until it has been judged in a court it is “unknown” what the sites can or should do.
Block. According to the GDPR consent has to be explicit, so never pressing “Accept” is surprisingly a valid tactic.
Enforcement, however, is a different story.
I will on rare occasions accept all if the site gives me the option to reject all but necessary.
Reject all
~ tada! ~
Yeah, it’s also super easy to prove P!=NP. Just do this one step:
prove it
~ tada! ~
Idk why anyone is still struggling with it.
YMMV. Some of the pop ups like to make the “Reject” button difficult to find.
Just use a browser that doesn’t save cookies. Then accept all.
deleted by creator
Are you trying to suggest that I would be better to just deny the cookies? I don’t know what you’re trying to say by linking to that article.
Device fingerprinting as a technique it’s pretty easy to defeat. There are plenty of privacy focused browsers that will also include device fingerprinting protection. In fact pretty much any browser that doesn’t store cookies will also do this device fingerprinting protection as well.
…how does that help?
It’s just that cookies are only one tool for tracking. When you accept all you consent to tracking but it doesn’t necessarily use cookies for that tracking.
Haha yeah, I doubt cookies are even a necessity in many modern stacks
No, they are a necessity for so many things, no doubt about that. They’ve plenty of legitimate uses.
You can hold anything in a session on the server as 1kb here and there is nothing nowadays
I think people really misunderstand cookies and have been lead to get angry at exactly the wrong things which actually give the biggest companies huge advantages so they’re fine with all of this mumbojumbo.
When you cant have local cookies, or there are hoops, companies that need not bother with this because they own your browser (Google) or companies that own major search engines (Google) or companies that most other companies rely on for ads or social media integration etc (Google) are tremendously advantaged.
Now, basically only Google can collect a wholistic profile of a user, while regular websites must now waste extra man power implementing completely useless cookie preferences when in reality this should have been simplified, at worst, to 3 buttons.
All, No Marketting, No Telemetry.
Anything else is just the user wasting their time or destroying the functionality of a website for no reason/requiring busy body work to comply with ill conceived regulations.
With the downfall of third party cookies in most browsers, cookies literally just serve as some temporary storage for websites on your local machine. Cookies existing or not existing arent what control whether you are tracked, especially given all the fancy fingerprinting that goes on nowadays.
https://addons.mozilla.org/de/firefox/addon/consent-o-matic/
Also available for other browsers.
Wow, thank you!
Block all 3rd party cookies by default. Done.











