ES version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
55% Positive
Analyzed from 6729 words in the discussion.
Trending Topics
#cookie#cookies#banner#don#tracking#browser#privacy#consent#user#need

Discussion (204 Comments)Read Original on HackerNews
But of course it’s impossible to convince someone of something when their livelihood depends on their not understanding it.
This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data mining, profiling, and other privacy-related aspects. But in many cases, you could just click "reject" and the banner would also disappear...
To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
Some variant on "reject" takes more effort like 70% of the time. Which is on purpose, of course. The ones that aren't maliciously-complying have a "necessary only" button that insta-closes it, but tons pretend that you might want to allow some spying but not all of it and make you go through another screen if you don't just "accept all".
> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
Then it'd be possible to default it to "nope" (Firefox, and perhaps Safari, might do this) or to allow a "never, anywhere" setting the first time the question is asked, and malware and spyware vendors know that'd mean a much larger proportion of denials.
It is known that warnings and pop-ups that show up almost all the time yield diminishing returns. I think it was named "normalization of deviation" by some folks in a blog a while ago, and I believe that name fits. If you get warned about missing https all the time, or that something might be dangerous (even though it does precisely what you want it to do), it will loose its effect by the time you actually need it.
You can argue this is malicious compliance, but if you want it to go away it would probably be easier to go for banning tracking and personalized ads altogether. Eliminate the reason for this behavior, so to speak.
What harm are you worried about?
Lack of privacy harms journalism and activism, making the government too powerful and not accountable. If only activists and journalists will try to have the privacy, it will be much easier to target them. Everyone should have privacy to protect them. It’s sort of like freedom of speech is necessary not just for journalists, but for everyone, even if you have nothing to say.
There is one. It's a DNT header. Knucklehead websites ignore it.
Oftentimes the reject flow is substantially more annoying than the accept flow. I click reject myself when it's an option, but I can absolutely understand how people might get conditioned to click accept when clicking reject might result in more popups.
There's a mismatch between the velocity at which people visit sites and the time it takes to navigate the cookie particulars of each site.
And, we can dismiss this as people being uninformed or lazy but the reality it is that's actually not so unreasonable. Cookies are in some ways near the bottom of the list where privacy is concerned, given everything else from breaches to search dossiers to device finger-printing to mobile device location-tracking to the ubiquity of cameras in the real world, and on and on.
The idea that we're clawing back privacy in any meaningful sense by blocking a few cookies here and there is kind of quaint.
any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.
How often do you get prompted for, say, secure DNS or HTTP? Almost never, because your browser has sane defaults and controls that. So, there you go.
P.S.: No true Scotsman spotted
If people really cared, they’d chose reputable suppliers that sell non toxic food. If they are eating food with lead, they don’t care.
Don’t force your wordview on people through regulation
There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened.
There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
It can to an important extent: https://en.wikipedia.org/wiki/End-user_license_agreement#Eur.... Note that the point about “reasonable consumer expectations” is exactly because users shouldn’t have to read the full EULA to find out whether it meets reasonable expectations or not.
Only engineers have trouble understanding this. It can be a reasonable defense, and it has successfully been used in courts of law many times. The law is not a machine that compiles text like code literally. Imagine someone who coerces a dying or sick person to sign an agreement they couldn’t possibly be in a reasonable state of mind to understand what they were doing -- the law can and does invalidate such “contracts”. That is the same principle behind age of consent laws. The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
> The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
I haven’t heard of a single case where an agreement was voided because “no one could reasonably be expected to understand it.” Unless the language was so impenetrable or vague that the agreement itself could not be discerned. Lawyers tend not to write such agreements.
Also, striking an unconscionable term typically does not void the whole contract. Just the term in question.
https://www.nbcnews.com/news/us-news/disney-says-man-cant-su...
"Disney is trying to have a widower's wrongful death lawsuit dismissed and sent to arbitration because the man had signed up for a Disney+ account several years ago."
Now what happened was that Disney quit fighting over really bad PR. But the court challenge would have liteky succeeded.
The value is derived from the people consuming the product. Placing the "incentive to produce value" above the people who presumably are the source of this value seems...misaligned.
So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...
Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.
This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.
https://creepjs.org/checker
THIS
Holy shit. This is such an obvious fix. And it shuts up those surveillance state goons immediately.
My God, why have we tried to summon up the ghost of 1984 when such a simple fix as this will do.
Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.
The blast radius is zero.
Good God, we need to fast track this into browsers right now. If we hurry we might be able to point to this as the technical fix.
Once some of the infrastructure exists, OS vendors can hook into it.
Firefox devs - please do this right now. Please spearhead this.
I might have to vibe code an advocacy site for the spec and set up a GitHub / RFC process.
CA tried this with AB 1856. I wasn't a fan of this (neither was EFF) because of the privacy and tracking concerns of blasting the fact that the user is a child to all websites.
https://www.eff.org/deeplinks/2026/05/one-step-forward-two-s...
It would better for the block to happen at the device level. That is, the browser knows it's on a child's device and has a whitelist of allowed sites.
There is already an RTA (Restriced to Adults) header where the website self-labels that it's for adults only and the browser can block it while protecting the user's privacy. I'd prefer expanding the use of RTA.
I've long since considered that the efforts for online child safety should be pointed at educating parents and spearheading some kind of certification of compliance for child safety of software and websites.
[this product is certified to adhere to EU:CSA]
Then you can block everything not certified, and the software that does the blocking would also be certified, the two major prongs you need (endpoints and sites working together: else they're blocked). The rest of the money goes to education for parents about this fact, and the dangers of not doing it, and how to do it.
This is super "easy" (when comparing to the effort it would take for putting backdoors in everything).
Which is why I think that the reason is definitely not child safety, and more about crime control.
Me talking about UK blocking people unless they ID themselves in 2013: https://news.ycombinator.com/item?id=6979295
Me talking about how its disingenuous because we have superior technical solutions to this particular issue last year: https://news.ycombinator.com/item?id=45010902
The online safety acts and its EU counterparts are somewhat risky, but nobody wants the mention the only proper alternative: a total ban on "social media." Not just for kids, but for everyone. Or a ban on smart phones, that would work too, at least short term. But: money.
This is unfortunately the reality.
The other day a friend asked me to help her make her phone safer for her kids to use. I started by asking if she set permissions on the apps she downloaded. She looked at me blankly, "What permissions?". I proceeded to show her how you can granularly control what you allow each app to do on your phone and what access it is allowed. Her head blew up, she had no idea any of this existed and after gong through a few menus, she didn't care any more. It was all too complicated and too much to think about for a busy mum.
This is why governments unfortunately are having to try to protect people from themselves. As tech competent people it all seems so simple to us, but we need to remember the majority of the population just click 'Allow All' and blow past all permission and security questions as they have no idea what any of it means.
I haven't set up an Android in a while, but, I doubt it's massively different.
When restoring factory defaults, the same question, just in case the phone is sold, gifted, stolen or whatever.
If you are going to give a phone to a minor you should set that option right from the start.
Options between "we don't have tech in the house" and "wide-open tech, we have it all" are all some amount of painful, usually for no good reason.
(I remember once investigating how to do some pretty basic stuff for this in Linux, hoping to find something nicer than manually setting some executable permissions and firewall rules and then having to go back and change them all the time, and the closest thing to a guide I found was an old article from Red Hat that basically lead with "LOL, good luck you poor sap, Linux sucks at this" before going on to explain the various bad ways available to sort-of, but not entirely, accomplish it with a lot of work, and significant ongoing time-burden)
Exactly. The problem is its from the parents side.
There is ZERO cost to abusing the user over, and over, and over again by asking for permission to track them.
We shouldn't have the cookie banners at all because NO company should be able to do anything with tracking data. Just ban the use of user data by companies and most of SillyCon Valley's garbage behaviors are fixed.
Similarly, I should never get "terms of service updates" from digital companies because there should be no changes that they can make. You can provide the obvious service that you're providing; you can't aggregate my data for any purpose other than directly serving me; you can't aggregate my data with that of other users; if you retain my data for any other purpose, the government should take percentages of your revenue. I shouldn't have to wade through the BS that the mercenary corporate lawyers cook up to extract value from me.
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
As written, this doesn't eliminate cookie banners completely, only if your browser is sending a Do Not Track header or similar. That's unfortunate news if you use fingerprint protection - those send default headers, so you'll still be bombarded with cookie banners. Hopefully existing anti-fingerprinting solutions will offer a "default headers but with Do Not Track" option.
Need to look up a bus time? Full screen cookie consent with accept buttons drawn OFF THE SCREEN.
I have personally never ever had any problems with the cookie banner since Brave deletes them with 100% accuracy, there's sometimes where a site will refuse to function properly, but it's usually sites I don't care about anyway and if I HAVE to get it working I disable brave shield, turn off all tracking, consent and turn the shields back on.
It is unfortunate that most browsers cannot implement this as it goes against what the companies behind the browsers want. Deleting the cookie prompt would stop people from occasionally just accepting all cookies and opting into tracking after getting tired of it.
Sounds good, as long as it covers the "legitimate interest" bollocks⁰ that is often hidden in inconvenient UI nests as well as the basic preference.
-------
[0] "we see your preference not to be stalked, but we want to anyway, click again for every partner to reconfirm you don't want them following you around"
https://en.wikipedia.org/wiki/P3P
> ...
> You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default.
That's an excellent idea... lets see how its implemented on https://european-union.europa.eu/index_en
Oh... there's a cookie banner.
In the UK a few news sites have changed cookie banners to "you can accept and see this stuff for free, or you can sign up for a subscription, which would you prefer?". It's the only time I hit accept (and then clear browser history).
If blanket preferences from browser signals became the norm, a segment might open up where you would configure preferences and a data broker would make sure you get something in return for your data. At minimum it might force paywalled publishers to consider that as a "lite" subscription option.
ads don't require invasve and pervasive tracking
They did not read the text to agree.
It was the fastest way to get the banner to go away. Sometimes they force you to confirm multiple times if you click ”none” or ”minimal”.
It's YOUR browser, a locally running software on a physical computer YOU own which memorize the cookie key-value pair a remote host told YOU to memorize and YOU return the same value later. It's YOU who allowed the cookie. If YOU don't want to allow the cookie, YOU simply not allow it.
You are technically 100% control on cookie. These JavaScript implemented in-page UI has no guarantee to respect your wish. But you have a power to disable it.
E.g. storing your precise geolocation for 12 years: https://x.com/dmitriid/status/1817122117093056541
And for a serious website, front end analytics are kind of a necessity to understand how users interact with pages and improve the experience. Note that it certainly doesn't require tracking the behaviour of individual users, just understanding how controls are used in aggregate.
I know it seems like you could work around this with careful design and maybe focus groups and such, but I can tell you we regularly uncover surprising insights from (aggregate) trends in front-end events.
See here[0], page 6:
> As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’
0: https://www.edpb.europa.eu/system/files/documents/2024-10/ed...
As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen
So now they'd have a new popup that says "reconfigure your browser to accept tracking, or pay us, or you can't access the page". Which isn't really an improvement.
Sites that easily allow you to simply reject everything are then a short hop, skip and a jump into browser settings where you auto-reject all cookie/tracking nonsense
I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies? Who knows.
I think most companies just don't give a fuck about user privacy and therefor have to show one. There are of course exceptions. But I don't know how many of them have been actual (for-profit) companies.
50% that, and 50% that way more companies than you expect are harvesting and profiting from your data.
On our go-live form there’s a question “do you use cookies” and it’s yes/no. If you say yes legal block the site from going live without the pre approved cookie banner…
I mean that both in the sense of "you, plural" (your company should fix that) and "you, personally" (because diffusion of responsibility is a real issue, and someone needs to actually do it).
Just checking, you do know that still counts as tracking and may fall under GDPR rules? GDPR was never just about cookies.
That has been my guess as well. If you run npm install half-the-internet you have no idea what's in there, so just slap on that cookie banner for good measure. Of course the real problem is not knowing what's inside your application, but the thought process is "eh, if a blanket cookie banner does the job then that's good enough for me".
> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.
Fortunately, if you have uBlock Origin, you can enable Easylist cookie notices under annoyances and avoid most of them. Combine with blocking third-party cookies, and the problem pretty much disappears.
The fact that the EU tried to regulate this stuff is a shame, because regulation is not a good remedy. End-users have agency here. The solution is to enable end-users to have control in their browser (which they always did, so it's an issue of education, like so many things).
Shame that Google is trying to kill uBO though. Extremely pleased that Brave continues to support it.
The Do Not Track header is the only technology needed. The rest is compelling companies to obey it.
It wasn't on EU Commission to "finally propose a solution". The soluton has always been there.
Somehow, Google, aka world's largest tracking and advertising company incidentally making the worlds' dominant browser and completely dominating all web standards, couldn't be bothered, and instead was pushing crap like FLoC
Google knows if you can set this once it's game over for their adverting business. At least with the cookie banners, there's a possibly you won't refuse every banner.
Especially those banners that only have "Accept" or "More options" with all those checkboxes to clear.
Overall this is a common sense solution. The challenge is that a significant industry makes money by collecting and selling data. It makes it harder for businesses who depend on it, they are going to get creative and will eventually come up with some dark pattern to circumvent it.
> The solution: automatically communicate your privacy preference
Would be lovely and would happen if it weren't for… wait for it… Google and whole effed up ad-busines:
https://ppc.land/eu-council-drops-cookie-signal-after-google...
F*ck google and other BigTech…
People not reading back on history is still very much a thing.
In 2024 Mozilla acquired Anonym from former Meta executives and decided to introduce PPA: https://hn.algolia.com/?q=privacy+preserving+attribution
Another good one to have the "hide Youtube shorts" filter, featured on HN a while back.
Also I wanna know when websites don't give a shit about my privacy and therefor have to show a cookie banner. While theoretically not consenting should mean not collecting blocking it altogether and modifying page content might mean "all bets are off". If the website expects you to have made a decision that might wrongly consider it consent.
Consent-O-Matic says "I don't consent".
instead of building websites and writing laws over the span of decades that just seem to want to ban targeted advertising but don't actually do it. FFS.
Consent-O-Matic -> automated configuration to your preferences using the dialog provided.
I still don't care about cookies -> least privacy friendliest option, because it may opt into undesired tracking (its goal is just to remove the annoyance of the dialogs)
I don't want randomnewssite to track me. But a favorite online store...I do want help with recommendations.
It's easier to click a single button than hunt for how to create/access an account for the brand.
Ironically, this has the effect of cookie banners reappearing every time because they cannot place a cookie that says that you have rejected them.
Unfortunately this means you have to view a lot of the web through archive.today or web.archive.org - I would know because I have uMatrix configured this way.
Session cookies for all sites would be fine if passkeys weren't like "We support passkeys. Do you want to use a passkey? Press ok again to use your passkey. Do you consent to using your passkey? Now please authenticate yourself to use the passkey... √ Thank you for using passkeys. Press ok to continue."
I disable cookies for Amazon because I need to login; if a local business wants me to buy from them directly they need to:
1. Not give me a CAPTCHA or cloudflare shit
2. Give me free shipping and a lower price than Amazon minus 5% cashback that I would get on Amazon
3. No registration needed to check out
and I'll buy from the local website. It's really not a high bar, they need to learn to not shoot themselves in the foot.
As for the news websites -- bleh. If they want me to read it, make it easy to read. As in, I click into it, show me the content. If I get a popup, banner, anything that covers up the content, I bounce. I'll get the news from social media anyway. If they'd rather I get it from their news website, they need to learn to not make me bounce.
I'm not opposed to advertising if they want to get revenue from that, but it should not track me, not cover up content, and not load megabytes of JavaScript to do it.
-> not really sensible
I've wanted the option to select your cookie preferences once and forget in a brower for ever.
I assume the reason this wasn't done initially was corporate pressure (most people would opt-out of everything by default).
1.2 billion exposed users × 8.17 years×365×3 banners/day×4 seconds÷36 is roughly 10-15 billion human hours lost to dealing with damn cookies since GDPR took effect on May 2018.
That's about 17,000 human lives.
EDIT: It's obvious that people really hate this option. Maybe too many here have their incomes too closely tied to the metrics that cookies are designed to collect. It could also be that it is an unrealistic option for everything except the most extreme societal changes.
If you are old enough and look back far enough you may remember the time before all this bullshit like I do. Once marketing and advertising get involved and gain power in an organization, things tend to go to shit fast.
It's great. The current law forces people that don't give a shit about user privacy to have a banner (or any other way of asking for consent first) while giving everyone that cares and everyone not wanting to spy on their visitor a free pass.
Just step back and ask yourself what each side of that debate is trying to achieve and why. What is motivating them? Why are they motivated in that way?
Don't just recite what you "know", think, look, research, figure it out. It might sound good to have a one-liner like this in your back pocket, but do you really believe it after looking at the publicly available information that it is their real intention to conduct a "crusade to destroy the internet"?
(because it drives consumerism)
Cookies were never a problem. Just get rid of the banner.
This other legislation should pass/fail on its own merit.