Live data from Hacker News

Please stop putting cookie pop-ups on your website (2022)

olivergrimsley.com

31–40 of 211 posts

Re: Please stop putting cookie pop-ups on your website (2022)

#31
> it is not legally required to provide the service if a user declines tracking cookies. The site can simply not provide functionality. So in many cases, its not really a choice – the choice is either not to use the site, or consent to tracking.

to be fair that is the choice. And ideally, the invisible hand would show that this is a horrible idea and cause a huge spike in traffic, but alas.

I think "stop putting popups cookies" on websites is an extreme stance, but I agree we could use fine tuning on the little things to help keep the spirit of the law. It should indeed be opt-in and not "ask for forgiveness". And it should adhere to current compliances.

Re: Please stop putting cookie pop-ups on your website (2022)

#32
post #26

By far, my favorite feature in iOS 18 is Safari’s “hide distracting items” feature. It lets you permanently hide the cookie popups on a per site basis. And the annoying google sign in popups, and the annoying scroll down popups.

and the annoying scroll down popups Wait, is it when you pull the page by moving your finger to the bottom of the screen and the “header” pops up?

Some sites ask you for an email, or login when you scroll down, and you have to hide it to keep reading. I think Medium pioneered this?

Re: Please stop putting cookie pop-ups on your website (2022)

#33
Malicious compliance gets the website two benefits: 1) Annoying the customer enough with the popups might net a permission to track from an user who originally did not want the cookies 2) Making the cookie banners as frustrating as possible increases the political pressure against the EU, hopefully leading to them repelling the anti-tracking legislation

There's no upsides for a website from providing an easy "Never track me" button, or just not using analytics cookies - you don't have to put up cookie consent banners for technical cookies used to save e.g. light/dark mode preference

Re: Please stop putting cookie pop-ups on your website (2022)

#34
post #7

The cookie policy is a stupid value-signalling stunt with only negative real-life effects. The correct way of handling the problem would have been through request headers and browser settings, or simply, use the existing option of either allowing or disallowing cookies, and put this option on a per-site basis and a bit more into the users face..

> only negative real-life effects

Almost. It hardly worked as intended, but at least it increased awareness. The fact that some sites tried to comply and actually provided a full list of all sites that they sell your private data to is somewhat a win. It got to a lot of wider public that realized "they sell it to 97 companies?!".

I personally think local governments or EU wide institutions should have a registry of companies and their sites with ratings, so we could integrate that directly in our browsers, company registries, phone dialer apps. iFixIt style.

- Clarity of EULA: 1/10, impossible to understand without lawyer's interpretation.

- Length of EULA: 1/10, pops up every week with no diff or summary of changes

- Legality: 4/10, historical track record of rules that are not compliant with local laws of xxx

- History: 1/10, no way to track what were the previous versions of the document or when they changed

- ...

EDIT: to give some context and prove it's possible to provide metrics to legal documents, in Poland we have a formal "Registry of Forbidden Clauses" with references to lost court cases:

https://www.rejestr.uokik.gov.pl/

Re: Please stop putting cookie pop-ups on your website (2022)

#35
post #26

By far, my favorite feature in iOS 18 is Safari’s “hide distracting items” feature. It lets you permanently hide the cookie popups on a per site basis. And the annoying google sign in popups, and the annoying scroll down popups.

and the annoying scroll down popups Wait, is it when you pull the page by moving your finger to the bottom of the screen and the “header” pops up?

You mean the vanity flap at the top?

No those are a different sign of design ineptitude.

They mean the popups that appear as you try to read what you followed the link for.

Re: Please stop putting cookie pop-ups on your website (2022)

#36
post #8
post #3

Interesting article. This policy has felt like a complete failure, but I didn't know the depths of how badly it has failed. I would really like to see these die. Regulators should just work with browser vendors to make an API that I can set at the browser level, and websites just read that to know my preferences and leave me alone.

Your preferences should be on the website level though, not global. And you should be asked about it on first visiting the website. Let me explain why with an example: say you're the type of people who doesn't care about "privacy" online ("I've got nothing to hide"), or you do; and you want to "support " certain ad-supported websites you're a fan of; but not that new clickbait toilet paper your aunt sends you. I can'…

Your preferences should be on the website level though, not global. And you should be asked about it on first visiting the website.

Preferences should be expressible in any form a user seems fitting their needs. If they want to block-all,enable-per-site or enable-all,block-per-site, or block-mask, or enable-mask, or top-down rule priority list — they should be able to. Designing preferences in any other way is a dark pattern not worth considering as a fully user-controlled mechanism.

I can't think of any way to have a good UX to opt in or out of "tracking" cookies which people would actually use

Virtually any UX is better than cookie popups as they are now, cause they get designed with interests of a site owner in mind. This alone makes it the worst possible UX on average.

Re: Please stop putting cookie pop-ups on your website (2022)

#37

So, the problem with this is: the law. If you use session management: GOOD NEWS GDPR AND CPPA UNDER PENALTY OF THE COURTS DEMAND YOU INFORM USERS and if you know a better way than an intrusive "accept this before you can continue" by all means pipe up but the problem is overbearing laws, not "people following them". The law requires that you disallow access until people tell you their position on your handling of the…

Session management does not require a cookie consent. Implementation-relevant technical cookies are exempt, it's the 337 different analytics services that sites use that require the cookie consent

Re: Please stop putting cookie pop-ups on your website (2022)

#38
post #7

The cookie policy is a stupid value-signalling stunt with only negative real-life effects. The correct way of handling the problem would have been through request headers and browser settings, or simply, use the existing option of either allowing or disallowing cookies, and put this option on a per-site basis and a bit more into the users face..

Besides cookies, there are tracking methods based on fingerprinting, IP and so on. None of them are permitted without explicit consent. This means that a site may not load resources from a third-party server without consent, since the request itself reveals enough information for fingerprinting and tracking.

Tracking is plainly not permitted without consent.

Re: Please stop putting cookie pop-ups on your website (2022)

#39
post #14

uBlock Origin has cookie notice filters. I don't think this is enabled by default; you can enable it in the Filter Lists section, along with "annoyances".

And it works really well. Until it does not, and then you need to figure why the page isn't working for you but your neighbour has no problems. I still use it all the time though but there is some pages I won't bother with much. Probably better that way anyway :-)

Re: Please stop putting cookie pop-ups on your website (2022)

#40
post #6

The larger lesson here is this is what happens when governments try to regulate things they don't understand. Cookie popups just add friction, and it's not clear consumers see any real privacy benefit. What's even worse is people seem to not care that the policy isn't working, but they aren't telling lawmakers to fix it.

I'm not sure why you're being downvoted. I believe the way you stated this is accurate. The regulation and its outcome was clearly not understood or intended by those who mandated it. Absolutely everyone is suffering from this. As for the "not care", I think the primary issue is that most people don't make much effort to understand the things they use. If they understood what was going on, they would be more upset an…

I think it's a bit weird (but the author did the same thing) that the blame is put on regulators here for not being precise enough with language, and not companies are are happily exploiting the loophole for as long as they can. And if it does get repealed: great! companies win, tracking is back.

There seems to be a nuance missing here in most of this discussion.

Post reply on HN