Live data from Hacker News

Kill The Cookie Banner

killthecookiebanner.eu

321–330 of 621 posts

Re: Kill The Cookie Banner

#321
post #288

Earlier quoted context omitted.

> it’s well-understood that very few people actually read those things, they just want to get them out of the way. This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data…

It literally does not matter what you pick on these things - most of them don't work anyway. Think about it: Of course they don't. All the third-party javascript is already on the page. Anything you do inside the sandbox with UI provided by, usually, some other third-party, can't just magically force all that other code to behave in a specific way, unless someone has done a great deal of work to integrate the cookie…

> Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you

Exactly. I use the "I don't care about cookies" extension, which rejects most cookies automatically without me having to see the popups. But even accepting cookies is fine - I'll be closing my browser soon anyway and they'll be gone.

Re: Kill The Cookie Banner

#322
post #236

Or you could just stop spying on people. No cookie banner is required for functionally necessary cookies.

Apparently the eu official website really needs to track you then. For what’s essentially just static content. I’ll consider dropping cookies banner when their website can work without. Stop the “do as I say not as I do”

EU official website in it’s cookie banner glory: https://european-union.europa.eu/index_fr

Re: Kill The Cookie Banner

#323

At this stage, it's easier to block them with uBlock and move on. I don't have a lot of confidence for legislative solutions. Although I admire people who keep trying.

FWIW, Legislation IS what brought us here in the first place :)

How fortunate the state with none

Re: Kill The Cookie Banner

#324
post #242

Earlier quoted context omitted.

> But in many cases, you could just click "reject" and the banner would also disappear... Oftentimes the reject flow is substantially more annoying than the accept flow. I click reject myself when it's an option, but I can absolutely understand how people might get conditioned to click accept when clicking reject might result in more popups.

A lot of UK sites (Reach local news stuff) now explicitly say take cookies or pay, which tbh I always thought was illegal.

The UK is somewhat famously no longer part of the EU (you may have heard of a thing called "Brexit" a few years back).

However the UK does have its own GDPR regulation (see: https://www.gov.uk/data-protection>), though my understanding is that it may be less strict in requiring equivalence between "accept" and "reject" actions. (I may be wrong on this.)

UK sites accessed from the EU would have to be under EU GDPR compliance.

Re: Kill The Cookie Banner

#325

Earlier quoted context omitted.

Online retailers in the nordics occasionally try to post terms and conditions that contradict consumer protection laws, for instance retailers being on the hook for warrantying product(ion) defects for 5 years after purchases of products that ought to be durable, like electronics. The retailers win out on a substantial amount of the population not contesting it, but if you as a consumer go through the process the fin…

Right. But those are substantively unconscionable terms, not about the agreement process itself.

sorry I did not phrase that very well, when I said as a general rule I believe I meant that if put to the test it could be often won on length alone in conjunction with the activity being done, but almost always these contracts are substantively unconsionable and of course people contest that, because most people don't get angry and want to fight for no reason, they do it because it is violating their rights.

As an example I have an email account with site A. I go to site A and log in, they suddenly spring a large new contract for me to read, I cannot get through to do what I came to do, it will take me 5 minutes to read so I click OK because I am on my way to check my email with site A. Procedurally this is not reasonable behavior.

What would be reasonable?

"Hi, we are changing our terms of service, you can see it at this link and agree. If you don't have the time right now you can do it later, but in three days you will lose access to the service unless you agree to terms."

There are however lots of other laws in the EU which may in fact make this behavior substantively unconscionable anyway. I certainly believe there would also be substantive arguments to be made in this case.

Re: Kill The Cookie Banner

#326
post #120

Earlier quoted context omitted.

Cookie control always should have been a browser control. The legal route always should have been to force it to be built into browsers that provide sane defaults, and make it illegal to circumvent what the browser declares as far as fingerprinting etc. any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.

Just enforce the GPC header... https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/...

Or the "Do Not Track" header: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/...

Re: Kill The Cookie Banner

#327

Earlier quoted context omitted.

[flagged]

Not wrong in the EU, you don't need to ask for consent nor notify about cookies which are required to make the site functional. Tracking and ads don't fall under that though, which is why every site these days does need to ask for your consent.

No, you need to always ask for consent for cookies if they come from a third party, regardless if they are only required to enable functionality. You also need to ask for consent each time data leaves the website (for example when loading an image from a third party host). You can't even load a font file from a third party server because the users IP reaches that server without consent. Cookie banners don't just handle third party tracking cookies, the are needed to record consent for a huge variety of cases. "Banning tracking cookies" does not remove the need for cookie banners.

Re: Kill The Cookie Banner

#328

Earlier quoted context omitted.

> it’s well-understood that very few people actually read those things, they just want to get them out of the way. This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data…

> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning. There is one. It's a DNT header. Knucklehead websites ignore it.

Because it doesn't mean anything specific and breaks entire business models (merely logging that you landed from an ad click and seeing if you check out counts as 'tracking,' doesn't it?) if interpreted purely literally. So, the only way to treat it is to either ignore it or to just send back an error code and message that says "Sorry, having some tracking is the condition to get this free content. Accept or don't."

Like it or not, the Web is a two-way street, meaning that the server end of the transaction doesn't owe the client end anything in particular unless there's some relationship in place (like a payment). It appears the "just ignore it" matches the intent of most web users, though, since an overwhelming majority of web visitors accept a bunch of spammy ads + free 'content,' and a slim minority pay for ad-free alternatives.

Re: Kill The Cookie Banner

#329

Earlier quoted context omitted.

You think the average user is going to explicitly whitelist? The law requires sites to whitelist their own cookies under penalty of law, instead.

> You think the average user is going to explicitly whitelist When prompted by the browser on first login/signup, yes, the same way the password manager works. With stored passwords, keeping the login cookie doesn't even add much value.

What about the other 200 unskippable prompts you get just by opening the website?

Well, there is a skip button. It's labelled "accept all"

Re: Kill The Cookie Banner

#330
I'm from France, and when browsing, I often get paywalled when I reject all non-essential cookies. The CNIL (who is in charge of the application of GDPR) ruled that this was compliant with GDPR as long as another website was offering an alternative without cookies[1]. Are there similar rulings in other EU states?

1: https://www.cnil.fr/fr/cookie-walls-la-cnil-publie-des-premi... (in french, sorry)

Post reply on HN