Prebake: Block EU Cookie Notices with Adblock
prebake.eu
prebake.eu
Since internet law will only get worse, maybe it's time for a "real" technical solution to this. For example, if we had a standardized HTML element attribute to mark these widgets, browser/adblock makers could enable people to opt out of displaying them. It might look something like this:
<div legal-notice="cookies">...</div>
<div legal-notice="DMCA">...</div>
<div legal-notice="terms-of-service">...</div>
And ideally, there would be a JavaScript API to query this as well, maybe piggy-backed on the Permissions API: navigator.permissions.query({ name : 'skip-notice', topic : 'cookies' })It seems to me there would also be an active push against any such implementation because it would make current solutions for getting around this type of cruft more effective than it already is.
Although if we were going to go this route I'd like to see it be a server-side rather than included in the markup. The browser could detect that you are visiting a new domain and request relevant information upon connection.
Not every country. This is EU legislation after all; any website hosted in one of the 28 member countries has to abide.
It is however inconvenient for the websites. They could always stop using privacy-invading ad networks and external services which track users and then they wouldn't have to show any message.
"if these companies would just invent and build a new infrastructure to pay the bills, they wouldn't need to present a nag."
There are many business models which do not come with moral dilemmas and that do not fall under the incidence of this law. Data mining and tracking might be trendy, but it's not a free for all, there need to be rules and the privacy of users must be respected. If some companies are unable to do fulfill these basic and fair requirements, that is strictly their problem.
Because I have better things to do with my time than click to close the message on every single website I visit.
If you actually read them then good luck to you. I think most people either a) don't care or b) install a global blocker to suit their particular privacy requirements.
Because the web becomes unusable with those "helpful" cookie notices when I actually do block cookies browser-side.
Those "TRUSTe" JavaScript solutions are the worst. They fade the whole page to black, then take whole seconds to load and make the browser sluggish.
Because as I am already using an AdBlocker that blocks the tracking cookies, this message is irrelevant.
The last thing we need is more cruft sent across the wire.
You can search for more sanctions here: http://www.agpd.es/portalwebAGPD/resoluciones/procedimientos... Search for "Articulo 22.2 LSSI" or similar
This accounts for the seeming uptick in cookie notices. To my knowledge, Google has not enforced this in the past.
My solution was to use CloudFlare to get geotags and PHP to serve the warning to only to those who live in the EU, but to each his own.
And as far as there isn't any "cookie law" on the books, it's about compliance with data protection and privacy regulation. So the EU isn't standing in the way of the industry to do that in another way.
why? Then ads will use that "new" thing as well. Cookies are enough for authentication.
DNT: 1 (Do Not Track; don't show cookie notice)
DNT: 0 (Allow tracking; don't show cookie notice)
No DNT header (Ask before tracking)https://boingboing.net/2012/06/13/error-code-451-an-http-err...
Then these notices popped up everywhere. So where do the sites store the information that you've already seen the notifications? In the cookies of course! So if you're actually serious about your privacy and delete cookies you will the the notices every time...
I visited a conference during that time which had a panel where those lawyers was discussing this and even brought up a question if a person really could agree to 20 pagers of policy document from the mere fact of just continuing using the website, and their collective answer was yes (through one agreed that 30 pages would be too much). To my knowledge no legal case has ever tested this, and thus we got this ridiculous cookie notice system where things has gone from bad to worse after the 2002 directive.
I recently started out to implement the cookie header on my site, and discovered things are rather unclear. For example, couldn't Google somehow get global consent for all Google Ads?
There also doesn't seem to be a way to ask for consent and only trigger Google Ads if consent is given.
Maybe there are some things that Google could improve to alleviate the situation. But advertising probably also depends on at least a little bit of tracking.
If they (the politicians) want to outlaw online advertising, maybe they should just say so directly?
If anyone can spare 5-10 minutes a week to help me and a couple of others maintain this list (testing and merging pull requests, closing issues, etc.), I'd be very appreciative!
You can contact me here or send an email to cookies[at]prebake[dot]eu
Problem is the abuse of technology to track users.
I don't know how aggressively they [google] will have to enforce this but the possibility of losing adsense revenue will be a hugely motivating factor.
So the number of sites the need such warnings is about to increase massively.
I somehow have a feeling that large corporations intentionally are trying to make this law ridiculous. E.g. why blogspot pages would need such warnings? Please Google just stop tracking.
Seems quite straightforward and fair.
And there is plenty of legitimate usages that are not whitelisted. The most notorious is non-shared traffic analysis. Meaning what basic google-analytics offers and half of the internet uses. There is absolutely nothing wrong with knowing how many unique visitors you got today, and everyone with a website wants to know that.
Maybe people running those websites want to know that, but as a visitor, I might not want that. Being ablet o tell "how many unique visitors you got today" implies that you can group actions by unique visitors, and thus tell e.g. exactly what I was doing on your website over the course of days. If I'm not logged in, I might not want that.
And don't get me wrong - I'm not really a strong privacy advocate or something. Most of the time I don't care much about tracking. But while in theory there's nothing wrong in tracking unique visits, we all know that the primary use of this is to manipulate users and shit ads on them, nowadays mostly cross-site. It's entirely reasonable people get fed up of being on the receiving end of someone else's malice.
That's like asking the guy behind the counter in a shop to not look at you because as long as you are not buying anything you don't want him to know you are there. You are entitled to your feelings but if you don't want to be seen don't go there, or care enough to open an incognito window.
> But while in theory there's nothing wrong in tracking unique visits, we all know that the primary use of this is to manipulate users and shit ads on them, nowadays mostly cross-site.
No, primary use is regular analytics. 99.9% of websites on the internet are not amazon. And if the law was for cross-site information sharing cookies then this would be a totally different debate, but it is not.
I acknowledge some benefits of this law, but I vehemently oppose it from the perspective of freedom of speech. I know it's an american innovation, but I think other countries should adopt the same principle that code (and algorithms/protocols) should be considered protected speech. I don't like this law because it interferes with http protocol by dictating how the protocol should be used. EU should not curtail the speech of W3C and of any users of their protocol. If you created a popular protocol then other entities shouldn't suddenly and arbitrarily start dictating how users of your protocol should now use it.
EU should either create their own version of http or create their own client for http, which would be relatively cheap as they would only have to fork firefox or chromium and add sandboxing bound to domanins. Some infrastructure is already there with sandboxing in the form of incognito/private window, it only needs to be extended so that each domain is automatically in its own sandbox instead of just websites you open in incognito window.
The real problem here is probably Google Analytics.
[1]: https://github.com/r4vi/block-the-eu-cookie-shit-list
[2]: https://addons.mozilla.org/en-GB/firefox/addon/self-destruct...
True, but also not True (unfortunately), because the websites can identify you anyway by your fingerprint: https://panopticlick.eff.org
this works: https://raw.githubusercontent.com/r4vi/block-the-eu-cookie-s...
this doesn't work: https://raw.githubusercontent.com/liamja/Prebake/master/obtr...
Personally, I'm annoyed by the cookie messages, but the law is supposed to help people.
Blocking (or auto-accepting) them is basically saying we don't give a shit about this law :-)
There are far larger security related concerns on the web. The cookie warnings are on par with if you had to agree with Javascript running on any page you visit in the EU. So, yes, I want to auto-accept.
As a developer I feel like I'm not going to make special considerations that ensure you can use forms on my website without cookies enabled. And I'm not going to find another way to detect and re-instate your login state.
The law is half baked and passed only to appease people who worry about their privacy. And it really doesn't do much...
And there are a lot of ways to track users even without cookies.
If they include services like Google analytics they should absolutely display the message.
Don't use GA and you don't need to show it. Your login cookies etc and anything "essential to the operation of the website" are all explicitly excluded.
The law is absurd, but it's not braindead.
Am I to understand companies are loading their own domain in hidden iframes that phone home when I visit a website? Like it checks the iframe's top window location and tracks what pages I'm on? Now you have me feeling paranoid.
What can be done about that. Google analytics arguably is a very useful service.
You can look at how GA tracks users with a bit of googling:
https://developers.google.com/analytics/resources/concepts/g...
It warns users who don't accept cookies that the website uses cookies, at every connexion. It doesn't warn users who accept them that they're used, putting aside the first connexion.
It should be the other way around. The website should warn the user that a cookie is used when the website just accepted a cookie from the browser. The privacy concern happen at this very moment, when you phone back to the website, not when the website phones you information.