Live data from Hacker News

Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences

consentomatic.au.dk

101–110 of 147 posts

Re: Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences

#101
Shouldn’t this just be called “no”? Or “I do not consent”?

Anyone who cares enough to automate this will disable all optional cookies.

Also, don’t we all think the law should have simply required websites to respect the browser setting for this instead of requiring it every goddamned time?

Re: Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences

#102
post #78

Earlier quoted context omitted.

The problem isn't lack of a solution, we've had DNT for years. It's that the people who want to track you generally don't want to make it easy for you to opt out.

Yes, this will need legislative backing. We had the GDPR since the DNT. I also just discovered the GPC which seems more interesting: https://globalprivacycontrol.org

Actually, GPC support is required in CPRA. CPRA, if you're not familiar, is the California privacy law.

Re: Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences

#103
post #62

I like this proposal to add a "purpose" field to the cookie header. This could allow consent settings at the browser level, preventing all these pop-ups. https://mailarchive.ietf.org/arch/msg/httpbisa/Mp-DjtBk-sfdQ...

And they will mark all the advertising cookies as "Legitimate interest", as they've already started to do that with the confirmation prompts. The "legitimate interest" of selling you shit you don't want and selling your interests to third parties.

Nothing prevents a company from doing this, but it's definitely not GDPR compliant.

Re: Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences

#104
post #58

Earlier quoted context omitted.

GDPR requires explicit informed consent for data not strictly required for the working of a A user giving consent to A does not translate into consent for . And yes, the default for such consent questions must be "no"

Perhaps I was unclear. IMO someone picking "sure fine everyone track me" when setting up browser (DNT preference) first time should count as explicit consent for every site. And similarly choosing DNT for all should legally count as telling site not to track and not to ever prompt.

In addition to being explicit, consent must also be informed in order to be valid under the GDPR. This is not a blanket understanding of "I may be tracked on the internet." but a specific "X information may be used by Y data processors for Z purposes." If somebody is not informed of X, Y, and Z prior to giving consent, then it doesn't count. A browser-wide preference from years ago is not informed consent.

There is one and only one legal default under the GDPR: Do not track.

Re: Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences

#105
post #2

I’ve been using this for a couple years now, and absolutely love it. Thanks, team! I also love that it’s owned by the University of Aarhus, as I am more willing to trust academia with something that has a disturbing level of (client-side) access to my browsing data. I really wish the browser vendors would develop better permission models to guarantee my data can’t be exfiltrated by a malicious plugin (aka a once-good…

while we're wishing for impossible things i'd also love if the consent dialogs were an actual standard. if sites could describe a list of what they needed consent for and the browser supplied the actual dialog, so i could just configure it to always allow all if i wanted to, that would be fantastic.

> if the consent dialogs were an actual standard. if sites could describe a list of what they needed consent for and the browser supplied the actual dialog

There is a standard for this called P3P, which was implemented by Netscape, Firefox, Internet Explorer and Microsoft Edge before eventually dropping support for it. But there was nothing requiring website owners to use it. Various data protection regulations across the world require them to obtain consent for collecting data, but they are not required to recognise consent or non-consent expressed via P3P settings.

These standards will only get used if the website owners are forced to use them, either by regulators or by monopolistic/oligopolistic market forces.

https://en.wikipedia.org/wiki/P3P

Re: Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences

#106
post #66

With how aggressive websites are in shoving popups down our throats for every little random thing, we need an in-browser AI bot to get rid of them appropriately. It's leaking too. I got a popup on my keyboard on my phone yesterday, and literally thought "this is too much, I wish I was dead" (I'm doing fine, just an intrusive thought :). Time to dial it back in folks. It is unbearable.

The actual problem is not the popups, it's that websites have so much spyware crap on them that you need all those warnings.

> The actual problem is not the popups

Yes, it is. That's the actual problem and so is everything else about the attention-hijacking industry.

Re: Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences

#107
post #83

Earlier quoted context omitted.

And they will mark all the advertising cookies as "Legitimate interest", as they've already started to do that with the confirmation prompts. The "legitimate interest" of selling you shit you don't want and selling your interests to third parties.

Would this get past the GDPR? I get the defeatism, there are powerful actors, but it doesn't mean we shouldn't try to improve the situation.

No, it's not legal. It's clearly not legal, it doesn't need a case. It's well established in the law as it was written.

It's just that the enforcement agencies are large, lazy and won't enforce anything. They don't even enforce when you can prove beyond a shadow of a doubt when and how the corporations have leaked your private information, let alone when their use of cookies is illegal.

Re: Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences

#108

Earlier quoted context omitted.

Perhaps I was unclear. IMO someone picking "sure fine everyone track me" when setting up browser (DNT preference) first time should count as explicit consent for every site. And similarly choosing DNT for all should legally count as telling site not to track and not to ever prompt.

In addition to being explicit, consent must also be informed in order to be valid under the GDPR. This is not a blanket understanding of "I may be tracked on the internet." but a specific "X information may be used by Y data processors for Z purposes." If somebody is not informed of X, Y, and Z prior to giving consent, then it doesn't count. A browser-wide preference from years ago is not informed consent. There is o…

> There is one and only one legal default under the GDPR: Do not track.

This is immediately followed by every head of marketing (at least for US-based companies) asking "Okay, so how do we track those people?"

I'm not saying this is right. But it is reality. We normalized for two decades marketing leadership having the expectation that they can track every interaction, and prying that data away has been painful, especially for folks who really want to do the right thing but are told otherwise by their managers.

Re: Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences

#109

I love the idea but giving "root access" to an extension that's "not monitored for security" is a non-starter. I wish Mozilla would step in and do something good for a change.

Check out this feature from Firefox then: https://bugzilla.mozilla.org/show_bug.cgi?id=1783015 Apparently can be turned on with the following:

cookiebanners.service.mode = 1 cookiebanners.service.mode.privateBrowsing = 1 cookiebanners.ui.desktop.enabled = true

Re: Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences

#110
I wonder how many websites declare the Google Tag Manager a technical necessity (as part of the consent layers). In my world, it is a tool to manage different tracking and ad tools, far from being technically necessary to host a website.
Post reply on HN