• PieMePlenty@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    11 months ago

    Should have been handled on protocol level. Cookies get priority levels, set browser to only accept required cookies and done. Everyone just wanted to do it the easy way… add a banner and ask the user… or dont even make the banner, call a third party library that does it for you… and has its own tracking code… yay!

  • Katana314@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 months ago

    I need to verify this, but I vaguely remembered you’re supposed to be able to exit these safely in two clicks maximum, though they sometimes obscure it.

    Usually, it’s something like “Customize” then “Save” without checking anything, or just “Reject All”.

  • Imhotep@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    11 months ago

    Why oh why didn’t the lawmakers add an obligation to use a standardized cookies selection popup.

    I remember day one of it coming into effect and it was already obvious this was a necessity.

    Lobbying. One of those laws pretending to do the right thing but sabotaged.

    Or maybe its even worse than that. Before you could just have the cookies deleted. But if you do that now you get the awful popup every time, so you just accept them in the end.
    I know I do.
    This law has made me accept cookies spying.

    • Pelicanen@sopuli.xyz
      link
      fedilink
      arrow-up
      0
      ·
      11 months ago

      That’s already part of the GDPR, companies just aren’t complying with it.

      From the official GDPR site:

      To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must:

      • Receive users’ consent before you use any cookies except strictly necessary cookies.
      • Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received.
      • Document and store consent received from users.
      • Allow users to access your service even if they refuse to allow the use of certain cookies
      • Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place.
      • Imhotep@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        11 months ago

        “Make it easy”

        If you make a vague law that companies can circumvent they will do it.

        That’s why you force the use of a standardized menu, because nothing else makes sense, no? The same way you don’t leave it to the tobacco manufacturers to implement the warnings on the box ; you force them all to adopt the same one that’s clearly visible.

        It feels like it’s either severe incompetence, or the work of lobbyists. But I don’t know enough about the matter

        • Pelicanen@sopuli.xyz
          link
          fedilink
          arrow-up
          0
          ·
          11 months ago

          Not “make it easy”, it’s “make it as easy”, meaning it can’t be easier to accept than to revoke, much clearer bar.

          • Imhotep@lemmy.world
            link
            fedilink
            arrow-up
            0
            ·
            11 months ago

            And you dont think that’s really vague though?

            Why not mandate a x by x pixel popup with a specific wording?

            I remember this French company, I think SFR (phone), which had to show on their website their condemnation. Since there weren’t clear specifications they made it so the message would disappear when you scrolled down one pixel, so almost no one saw it.

            • Pelicanen@sopuli.xyz
              link
              fedilink
              arrow-up
              0
              ·
              11 months ago

              Well, that could make the popup unusable depending on screen size. I think the wording is pretty clear, the issue is just that there’s no followup and not clear enough incentives to avoid skirting the rules at the moment.

    • Honytawk@feddit.nl
      link
      fedilink
      arrow-up
      0
      ·
      11 months ago

      Because those laws were made with good intentions in mind.

      But businesses never have good intentions, especially if it eats into their revenue. So they use malicious compliance to make it seem like it is the law that is bad.

  • Law Abiding VPN User@feddit.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 months ago

    brave browser gives you a lot of options to block that bullshit and delete it before it’s ever able to make a profile on you…I’ve already heard what everyone on here has had to say about it. It works and it also works really well against most fingerprinting techniques used by invasive websites

    adguard for windows, mac and linux can also be helpful for that stuff.

    nextDNS and ReThinkDNS are also helpful for blocking garbage from advertising companies landing on your computer like the leech it is

  • AxExRx@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    11 months ago

    So, probably stupid question.

    If a website pops up and asks for permission, and I bypass that pop-up in some way (like killing the pop up with an addon or some you can just ignore it and keep scrolling with it on the bottom of the screen)

    Until ive clicked agree, do websites just not start tracking or creating or doing anything with cookies? After all, they’ve acknowledged they need, dont have permission.

    Or is this by and large pointless, and unless ive jumped through their hoops, they’ve already started the page with cookies enabled?

    • drath@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      11 months ago

      If the site is GDPR-compliant, they are not allowed to set any cookies until you click the accept button. But, a ton of sites and ad agencies are not. For example, Russians commonly just put a “we tracking you, deal with it. [OK]” banner, thinking they are funny, when it’s clearly illegal even by Russian law, but they are shielded from it by responsible officials incompetence. Same story in the US, I believe.

    • 𝕛𝕨𝕞-𝕕𝕖𝕧@lemmy.dbzer0.comdeleted by creator
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 months ago

      depends on the site.

      legally you’re assuming the correct way it’s supposed to work in a lot of jurisdictions but in practice who actually litigates these sorts of things?

      people get away with it all the time.

      there’s also tons of sites hosted in places where it’s totally legal to just have cookies with any user from anywhere with or without consent, those might have a permission banner just as a UX thing to make the site feel more “familiar” or “official”. learning how whole contemporary stack works, at least broadly speaking, is one of the only remaining ways to actually be proactive. knowledge is power.

  • Madu@lemmynsfw.com
    link
    fedilink
    arrow-up
    0
    ·
    11 months ago

    Many sites have a one click “reject all” now, and it’s getting more common over time.

    • Kjell@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      11 months ago

      That’s because they have to. If I remember correctly it is supposed to be as easy to reject as to accept, but until it has been judged in a court it is “unknown” what the sites can or should do.

  • Capricorn_Geriatric@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    11 months ago

    Block. According to the GDPR consent has to be explicit, so never pressing “Accept” is surprisingly a valid tactic.

    Enforcement, however, is a different story.

    • Speiser0@feddit.org
      link
      fedilink
      arrow-up
      0
      ·
      11 months ago

      Yeah, it’s also super easy to prove P!=NP. Just do this one step:

      prove it

      ~ tada! ~

      Idk why anyone is still struggling with it.

      • Echo Dot@feddit.uk
        link
        fedilink
        arrow-up
        0
        ·
        11 months ago

        Are you trying to suggest that I would be better to just deny the cookies? I don’t know what you’re trying to say by linking to that article.

        Device fingerprinting as a technique it’s pretty easy to defeat. There are plenty of privacy focused browsers that will also include device fingerprinting protection. In fact pretty much any browser that doesn’t store cookies will also do this device fingerprinting protection as well.

        • ivn@jlai.lu
          link
          fedilink
          arrow-up
          0
          ·
          11 months ago

          It’s just that cookies are only one tool for tracking. When you accept all you consent to tracking but it doesn’t necessarily use cookies for that tracking.

            • ivn@jlai.lu
              link
              fedilink
              arrow-up
              0
              ·
              11 months ago

              No, they are a necessity for so many things, no doubt about that. They’ve plenty of legitimate uses.

              • KeenFlame@feddit.nu
                link
                fedilink
                arrow-up
                0
                ·
                10 months ago

                You can hold anything in a session on the server as 1kb here and there is nothing nowadays

  • Credibly_Human@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    11 months ago

    I think people really misunderstand cookies and have been lead to get angry at exactly the wrong things which actually give the biggest companies huge advantages so they’re fine with all of this mumbojumbo.

    When you cant have local cookies, or there are hoops, companies that need not bother with this because they own your browser (Google) or companies that own major search engines (Google) or companies that most other companies rely on for ads or social media integration etc (Google) are tremendously advantaged.

    Now, basically only Google can collect a wholistic profile of a user, while regular websites must now waste extra man power implementing completely useless cookie preferences when in reality this should have been simplified, at worst, to 3 buttons.

    All, No Marketting, No Telemetry.

    Anything else is just the user wasting their time or destroying the functionality of a website for no reason/requiring busy body work to comply with ill conceived regulations.

    With the downfall of third party cookies in most browsers, cookies literally just serve as some temporary storage for websites on your local machine. Cookies existing or not existing arent what control whether you are tracked, especially given all the fancy fingerprinting that goes on nowadays.