> Back in the 90s we had cookie confirmation things. A browser called konqueror even had it on by default. Every time a server tried to set a cookie you got a chance to say no, etc…
>
> For users it was as awful then as the experience is now.
Yes, I remember. Back in the 90s you could always choose another browser that didn't do that, and we didn't yet have the rampant data collection and exploitation that we have seen since. Back in the 90s it was a novel thing when $known_company got a website at all. In the intervening years a huge amount of our life and identity has moved online.
> The people who made this law seemed to be under the impression that sites would react by removing cookies. This is naive or plain stupid. Instead what we have now is that every single site has a popup saying "Lorem ipsum" (nobody reads this), and you have to click "fuck off" to get to the content.
Where there is no way of opting out of the data collection I leave, and I have taught my family to do the same.
It is possible to run a website that doesn't use cookie popups. Amazon UK sets 3 essential cookies (i18n prefs and two session cookies) on first page load. https://basecamp.com/ doesn't set any.
> ACTUAL security problems now, or ACTUAL choices, now cannot be warned about. Because if users were not good at reading actual meaningful warnings before, they sure as hell don't read them now.
Sorry, which websites were warning users of potential security issues before? What choices were users being asked to make? I am not sure we were browsing the same web.
> So not only is this law (1) not helping, people still have cookies. It's also (2) annoying absolutely everyone every day, with up to four "fuck off" buttons users need to click per page load, and (3) actively hurting via huge externalities, as described above.
Remember that this law isn't about cookies. It's not a cookie law, it's a law about data privacy and control. Cookies are just one part of it. The law also deals with the safe and appropriate handling of user data, and when a website does pop up a huge hard to use banner that uses dark patterns to get you to click it then it's not the EU being annoying and forcing users through this annoying process, it's forcing websites to effectively tell users that they want to do extra things with their data. It's like forcing bank robbers to dress up in stripey shirts and use bags labelled "SWAG".
Any website that is doing that is basically being forced to wave a big red flag "I AM DOING DODGY THINGS WITH YOUR DATA" when you visit. You can at that point blindly click the "Accept" button if you want, I choose to leave.
The web industry, and avertisers in particular, have had over 20 years to pull their shit together to avoid this, but they didn't, so now we have this.
> Oh, and for extra bonus on a weekly basis I run into websites that chose to simply block users from EU IPs, presumably after a ROI calculation. Thanks, EU.
I've hit very few of those, and to be honest it's not been a particularly big deal. It's also their choice. Don't want to stick to the EU speed limit? Don't drive on the EU roads.
> Are you in Europe?
For now.