Live data from Hacker News

Kill The Cookie Banner

killthecookiebanner.eu

571–580 of 621 posts

Re: Kill The Cookie Banner

#571

Earlier quoted context omitted.

I think you're right that many (most?) CMPs are broken, though usually not deliberately. Most try to gate analytics and ad tracking on consent, just often misconfigured. The common exception is companies that deliberately hide Reject All, which is not complaint My company scanned 209 European regulated sites in June, and roughly 7 in 10 had tracking that wasn't correctly gated by consent. It's rarely indifference, th…

I don't buy it. 70% of the CMPs being "misconfigured" tells us that even if these panels were broken by design, the companies using them must all conveniently not notice this. Strange, given that even a small risk of large fines or prolonged legal process with public entities would warrant someone paying at least a moment of attention to this. I suspect they are, and the choice of leaving things misconfigured is deli…

> I suspect they are, and the choice of leaving things misconfigured is deliberate.

That honestly doesn't fit our data or my experience. In our scanning, about 60% of the misconfigured sites had a CMP with blocking active but one or two tags bypassing consent controls

Generally those misconfigurations aren't valuable to the business. We don't see for example lots of ad targeting and conversion tracking firing without consent on an otherwise compliant site.

What we do see is things like sites with CMPs generally working, but one or two analytics events tags firing because consent wasn't properly added to a trigger, or embedded Youtube cookies set without consent, or unexpected data from a URL or query param being accidentally ingested by tracking, or devs adding performance monitoring or observability tools to applications without realising the compliance implications

There's not much business logic in paying for a CMP, blocking your own ad stack, but then letting three analytics events pass through

> FWIW, this was a problem long before LLMs were a thing, and it didn't get worse with LLMs.

This isn't supported by our experience. In the last 18 months, we've seen a big increase in ungated tracking that we catch in CI (albeit with overall much higher velocity in general). LLMs will happily add non-compliant tracking to sites, often following defaults that might be acceptable in the US but not EU. If you push back, they'll also happily implement compliant tracking, but it's definitely not the natural default you can rely on

But your comment left me curious, so I just ran an experiment via Codex -p (gpt-5.6-sol) and Opus 5 via Bedrock

Codex returned the vendor quickstart on 5 of 5 neutral prompts. It gated properly when told the company is Irish, with full Consent Mode v2 defaults denied, GA4 only mounting after consent, with a reject button

So models can produce compliant/non-compliant code based on the context you give them, which reflects what we've seen in industry

Our business is giving devs and increasingly LLMs efficient tests to check the tracking they add is as expected for the EU and then providing signed evidence packs that prove that behaviour at a given time

Re: Kill The Cookie Banner

#572

Earlier quoted context omitted.

> that solution has already failed. Yes, granted, a globally enforced whitelist probably wouldn't work. I'm referring to bespoke lists that parents control. I know plenty of parents that use this. e.g. here's Apple's feature: https://support.apple.com/en-us/105121#:~:text=Prevent%20ina... > It works for websites because they can cleanly identify a child and filter content if appropriate. This still doesn't solve the…

You are confusing a lot of different lines of argument, and in the end I'm not even sure what you are arguing against. I think you are mostly agreeing with the proposed solution by echelon? You mentioned AB1856 which seems waaaaay broader than emitting an age bracket header based on user settings. It puts the onus on the website operator to not only prevent presenting content to wrong age bracket users, but also to d…

> I'm not even sure what you are arguing against.

I am against legally requiring devices to transmit a signal that the user is a child to websites. What I want instead is to handle any content blocks client-side. Instead of legally requiring adult sites to verify the age of users, I'd prefer requiring that these sites self-label (or move to an obvious TLD like .xxx), which makes it easy for the device to block it. This accomplishes the same thing without the tracking infrastructure and privacy concerns. I don't want my kid's device blasting that they're under 13 to every sketchy website that asks.

> It puts the onus on the website operator to not only prevent presenting content to wrong age bracket users, but also to determine the age bracket of the user.

I believe AB 1856 does not do that any more. As of July 1st, they amended it to remove all requirements on website operators, except one. What it does now is make the app's age signal apply "across all platforms of an application, including an internet website [owned by the same developer]." e.g. the Facebook app gets the age signal, now facebook.com knows the same signal.

Also AB1856 (and the DAAA which it amends) has no content policing requirements. All it does it force apps and websites to know the age of their users, which then triggers liability under other laws like the up-and-coming social media ban AB 1709 (which I'm against). Or CA's Age Appropriate Design Code act (which I believe is getting tossed around in the courts for First Amendment concerns).

As far as presenting a filtered view of a website, e.g. Reddit blocking some subreddits for kids, I'm open to debating this. I personally think it doesn't work and platforms will just over-regulate or wholesale ban minors (Claude, character.ai) rather than comply with the patchwork of laws in different jurisdictions. Or they'll spin off a heavily locked-down version for kids only, like YouTube Kids.

Steam is an illustrative example of how hard it is to get the filtering right. They're trying to comply with OSA but there's still a lot of information leakage between the kid-safe portion and the rest of the platform: https://youtu.be/hOaGUfy6NTw

Re: Kill The Cookie Banner

#573
post #563

Earlier quoted context omitted.

No, I'm just saying that it's okay to burden humans with the responsibility to learn a few basic ideas about how to operate their own computers if they want to control their data privacy. Simple, easy tools are already there, such as the Clear Browsing Data menu item in Chrome, Edge, and Safari. For more complicated intents, the browser settings are no more complicated to navigate than the actual customization UI in…

Then I don't understand the driver analogy. Drivers are forced to take lessons and get licensed for the precise reason that we know people can't take the responsibility on their own. Clearing browser data is anything but easy for people who aren't certain what is "browser data". Is this going to delete all my google sheets? Those are in the browser. And it's not a bad question, some apps actually use IndexedDB or wha…

> some apps actually use IndexedDB or whatever to store user data.

Not any notable apps used by noobs though. Unsophisticated users don't include Local Storage in their mental model - they simply believe that "When I log into Gmail, Google Docs, or Slack on a fresh computer, my stuff will be as I left it on my other computer." Webapps which subvert this by not persisting things outside of Local Storage would be taking wild and unnecessary data-loss risks with user data.

> people who aren't certain what is "browser data".

This I agree with you on. Everyone including EU legislators are trying to regulate something that none of them actually know or agree on what it even is.

The common person has basically only one single concern that relates to cookies: They don't like retargeting ads. That's it, that's the whole beef. They feel offended that by some mysterious (to them) means, they see ads 'around the Web' for things they've browsed before. Of course, those ads exist because they're incredibly effective. But they are annoyed that it, in their opinion, manipulates them into spending money. These ads are "too good."

This is a technical problem with a technical solution, and if the EU (and US) regulators weren't technically illiterate they would recognize this and issue clear requirements aimed at browsers[1] instead of the stupid ones we have today which are basically just rely on the honor system, meaning compliance will be patchy at best, and it relies on costly enforcement actions and complaints, is subject to litigation, and has so many gray areas - "If the CMP didn't work right and cookies were stored, is MY company liable? We tried!").

There is a second concern, but it has little to do with cookies, it's just that we ideally want to stop companies from keeping and exchanging dossiers on our behavior and preferences (and a dispute on whether anonymized data is ok, or whether it's unethical because if detailed enough it can be deanonymized). That is bigger than cookies, and applies just as much to offline companies.

[1] Here's an imaginary scheme, just for example:

1. Segment cookies storage by the domain in the address bar - the same way the memory/disk cache works today. This is really functionally the same as turning off third-party cookies, but if anything "needs" them, this sandboxing would nerf it so that a Facebook Like Button on a webpage can't be aware of a facebook session you created on a different domain.

2. Big switch in the browser's UI that defaults to "Temporary" - if you leave it alone, all cookies and storage are evicted 2 hours after last tab is closed, or you switch it to "Permanent" (preference stored per top domain) to have the current behavior where expiry can be longer.

Regardless of the specifics, a browser-side solution would solve the problems of "compliance" as it pertains to cookies and other client-side tracking (they can't abuse data the browser simply won't persist for them), and level the playing field between the tech giants and upstart competitors.

Re: Kill The Cookie Banner

#574
post #563

Earlier quoted context omitted.

No, I'm just saying that it's okay to burden humans with the responsibility to learn a few basic ideas about how to operate their own computers if they want to control their data privacy. Simple, easy tools are already there, such as the Clear Browsing Data menu item in Chrome, Edge, and Safari. For more complicated intents, the browser settings are no more complicated to navigate than the actual customization UI in…

Then I don't understand the driver analogy. Drivers are forced to take lessons and get licensed for the precise reason that we know people can't take the responsibility on their own. Clearing browser data is anything but easy for people who aren't certain what is "browser data". Is this going to delete all my google sheets? Those are in the browser. And it's not a bad question, some apps actually use IndexedDB or wha…

One more thing re: my potentially distracting analogy.

> Drivers are forced to take lessons and get licensed for the precise reason that we know people can't take the responsibility on their own.

Ok, I see what you mean here, but I'd argue that the licensing requirement is only acceptable because the risk is both grave and impossible to limit to just yourself.

We don't require a license or training to use a table saw at home even though table saws are also dangerous unless used very wisely. That's because the risk is mainly limited to the user and at worst, someone who chooses to be nearby that table saw.

To bring it back to my point, I'm not discussing the licensing part, I'm saying rather that we don't make excuses for people who refuse to learn the rules of the road, or how to safely use a table saw, and we don't say that it's the job of wood manufacturers to somehow secure the table saws of ignorant DIYers. The responsibility is on the user of the car, the table saw, or the browser. If the user chooses to never learn the basic operation of their tool, they might get hurt. And if we do have to regulate something, we should regulate the saw, and give it clearly-labeled safety features. Not regulate all pieces of wood.

And in my opinion, the 'danger' from cookies is so trivial compared to any real dangers (mainly the danger of seeing ads that are "too good"), that I am not convinced anyone needs to be protected from it by a third party.

Re: Kill The Cookie Banner

#575

Earlier quoted context omitted.

No, you don't need consent for that. It falls under the legitimate interest exception. You need to disclose it in your privacy policy, you need to delete it after a reasonable retention period and you can't use those logs for other purposes like ad targeting, but you don't need a consent banner to track things that you are legitimately using for security purposes.

>It falls under the legitimate interest exception. What makes that a legitimate interest and not advertising?

Because preventing crime is drastically more important to having a functioning society than being able to target advertising slightly more accurately.

Re: Kill The Cookie Banner

#576
post #505
post #331

Earlier quoted context omitted.

It's wild to me that anyone thinks that would be a reasonable law (whether or not it is law, I have no clue, I don't live in UK or EU). If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to le…

> If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway." More: "To view the private content on my website, you have to either pay me, or let more busines…

I'm in agreement with you that most computer users haven't bothered to learn anything about how to use their browser or computer.

But still, let's say I agree that there's even an important problem to be solved.

We can (A) regulate the browser to dumb this down for these ignorant people, and have the problem guaranteed solved, or (B) we can burden every single company that operates a website, and rely on enforcement since otherwise it's all honor-system.

The EU and so far multiple US states, have chosen the stupid option B.

Re: Kill The Cookie Banner

#577
post #504
post #393

Earlier quoted context omitted.

Let me be clear, I can't stand the social-media industrial complex and the advertising universe. I've seen the bottom that we've raced to, with absolute bullshit popping up everywhere and entire sites full of slop with clickbait "headlines" just rigged to get ad impressions. And I'd gladly trade today's BS for any version of "The Internet" pre-2007. But the "Before" Internet wasn't some natural sustainable state. Bef…

> achieved great success with ad-based business models because of the ability to target ads better There's an old saying in advertising, "Half the money I spend on advertising is wasted, and the trouble is I don’t know which half." - https://quoteinvestigator.com/2022/04/11/advertising/ The supposed benefit of the current model is to find and eliminate that wasted half. Facebook has shown me ads for dick pills and bo…

There are lots of ads that don't work, but I can tell you from experience that there are a lot that do. A company I worked for a couple jobs ago basically just added a new pretty color of a clothing item, then ran ads with models wearing it on Instagram (targeted to female, right age range and income level) and the resulting cost per conversion was way below our margin. It was incredibly easy. What made it work though was how the Meta algorithm understood which of the users in that broad filter was into stuff like we were selling, based on all their on-platform activity.

I suspect hackers are far tougher to target - it's kind of a special case.

Re: Kill The Cookie Banner

#578
post #504

Earlier quoted context omitted.

> achieved great success with ad-based business models because of the ability to target ads better There's an old saying in advertising, "Half the money I spend on advertising is wasted, and the trouble is I don’t know which half." - https://quoteinvestigator.com/2022/04/11/advertising/ The supposed benefit of the current model is to find and eliminate that wasted half. Facebook has shown me ads for dick pills and bo…

Megagiantcorp Proctor & Gamble cancelled all internet advertising, with no loss in sales.

That proves little though. Their ads would be brand advertising anyway, notoriously hard to measure. Just "Don't forget Coca-Cola exists!" and you can accomplish the same with billboards or in-store advertising.

The ads that perform online are the direct response type.

Re: Kill The Cookie Banner

#579
post #576
post #505

Earlier quoted context omitted.

> If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway." More: "To view the private content on my website, you have to either pay me, or let more busines…

I'm in agreement with you that most computer users haven't bothered to learn anything about how to use their browser or computer. But still, let's say I agree that there's even an important problem to be solved. We can (A) regulate the browser to dumb this down for these ignorant people, and have the problem guaranteed solved, or (B) we can burden every single company that operates a website, and rely on enforcement…

Option A is insufficient, as cookies are a mere implementation detail about how tracking is done, and the tracking is the concern.

Re: Kill The Cookie Banner

#580
post #473

Earlier quoted context omitted.

> "Sorry, having some tracking is the condition to get this free content. Accept or don't." The law that caused the cookie banners also says companies cannot block access to the site if the cookies are not required for the functioning of the site. Some German news sites have broken this and have "accept or pay" and I think this leaked to news sites in other countries. Facebook even tried it. So, sure, if DNT is true,…

The most annoying thing about that is not even the "accept or pay" banners. There are more: - even if you accept the tracking, you might still not be able to read the article, because while the site may be free in principle if you accept ads, that specific article is not. - and the most annoying thing is that such paywalled articles show up on Google News. Not sure if they're tricking Google into showing them (by sho…

Speaking of the news-type sites you bring up:

I hate all these patterns too, but interestingly it feels like I hate it more because the whole Internet has been designed around the "free to read with ads" paradigm -- we've been taught that if you can see something, get the URL and share it, so that others can reference the thing you're trying to either comment on or raise awareness about.

With paper newspapers or magazines it wasn't ever a problem, because if I subscribed to the Dallas Morning News, I automatically got all their articles, and even stories that weren't local to Dallas were covered by them too. I didn't need a subscription to the San Francisco Chronicle and didn't miss it.

Today, if someone is reading an article in the Chronicle, or even the Verge, it's a huge problem for them to share it with someone else even if the other person actually pays for subscriptions to say, NY Times and Bloomberg. Even if all four of those publications each have articles just summarizing the same 5 bullet points.

I'd blame the "news" industry as a whole for not implementing some kinds of reciprocal agreements. Even giant news conglomerates like Media News Group[1] who publish dozens of major US papers don't give you a simple subscription that at least covers all their own properties. I'd argue that they should try harder to stand up some shared subscription services with heavy reciprocal benefits and revenue sharing, so that most people would be able to read most paywalled articles with one monthly subscription. That industry has no one to blame but themselves for not figuring this one out.

[1] https://www.medianewsgroup.com/about-us/

Post reply on HN