This would also open the door to extensions that just default consent to 'no'. This can't be the default though, to avoid another failure like Do Not Track.
This would also open the door to extensions that just default consent to 'no'. This can't be the default though, to avoid another failure like Do Not Track.
https://ec.europa.eu/digital-single-market/en/proposal-epriv...
What you want is the ePrivacy Directive which "introduced" the cookie banners many years ago and its updated version which is (still) not ready.
Since the browser itself stores the cookies, it has the absolute authority to stop them.
https://en.wikipedia.org/wiki/GDPR_fines_and_notices
Google, $50M; Marriott International, £99M; British Airways, £183M; 1&1 €9.5M; etc.
I contacted my MEP at the time about this, and please do the same if you can voice your support for simpler, genuinely user-friendly and consent-respecting settings.
That could lead us back to the current situation where consent dialogs are designed by advertising networks, and result in user consent fatigue.
2. Because website builders need to write custom things for consent
Encoding the usage of a particular (probably otherwise short-lived) technology in law is generally a pretty bad idea. Sure, have the EU write laws about cookies - the two outcomes are A) this becomes useless when people switch to a different tech stack that doesn’t use cookies B) we’re stuck using 30-year-old technology to try to get things done, at least for regulated industries like banking or government services. Like the IE regulatory situation in Korea but worse.
Quoting recital 30 of gdpr
"NATURAL PERSONS MAY BE ASSOCIATED WITH ONLINE IDENTIFIERS…SUCH AS INTERNET PROTOCOL ADDRESSES, COOKIE IDENTIFIERS OR OTHER IDENTIFIERS…. THIS MAY LEAVE TRACES WHICH, IN PARTICULAR WHEN COMBINED WITH UNIQUE IDENTIFIERS AND OTHER INFORMATION RECEIVED BY THE SERVERS, MAY BE USED TO CREATE PROFILES OF THE NATURAL PERSONS AND IDENTIFY THEM."
I found this from 2013:
https://www.zdnet.com/article/south-koreans-use-internet-exp...
Anyone have an update to that story? I know in Korea they use a ton of apps to order things all the time now. Maybe this law was phased out, or just didn't apply to phones?
Not to take away from your broader point. Laws are just such a terrible development model. Everything's tested live and you can't easily revert anything.
> Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.
From: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL....
Otoh, we already have cookie-consent in browsers. Just don't accept cookies if you don't consent!
P3P could be a hint for the the user-agent, but the user-agent would have to tell the server what level of tracking etc is acceptable to the user.
The solution is just proper enforcement and education. Opt-out by law must be the default while opt-in requires extra actions. Just teach people to always click No and eventually the dialogues will go away.
You can disable all cookies altogether in at least Firefox and Chrome. You can make them only last for the current session.
Power users, upon request, should be presented with and asked to accept/reject/blacklist/whitelist cookies.
Interestingly the only browser I know of that does this is Lynx, which is text-only and does not support Javascript.
What is your workflow when visiting a new site and figuring out what cookies to allow?
With browsers you can of course default to blacklisting all cookies and add exceptions as you go. I did this privately in Firefox until I was sent to work from home during the pandemic, after which figuring out what cookies I needed to enable to get Teams to work proved too much of a hassle.
The political is in trying to limit the options to either party like the Computer Fraud Abuse Act charging someone for entering in every possible phone number into a phone directory. The extreme unlimited (il)logical extreme is "If the user is capable of exploiting several 0 day escalation of priveledge attacks to download all of the credit card information and then delete the website that is on the designers for making a shoddy website" being legal. That would be a pure "no politics" UX system with many obvious and inobvious side effects.
Blocking cookies should be done by users via software.
This is only going to make the barrier to entry higher and more expensive.
I have no idea what many small non tech businesses would do? Pay a few thousand every year when standards change?
That's the point. We want the barrier to entry in widespread tracking to be high.
For what it's worth, you don't need cookie consent warnings if you use them only for functionality integral to the product you offer your user. For example, if you need to use a cookie to facilitate a logged-in user session, you don't need to warn them.
The only ones paying the high price is the people who use it to collect user information not essential to the service they provide to the user, for god knows what.
That’s what is done.
The government doesn’t block cookies for you, they set the rules with user data, and the actors (service providers and users) act accordingly.
That’s how things should be.
I don’t want the governments to build or design software, I want them to set the rules and let browser developers and other actors react accordingly. If the reaction isn’t judged well intended or good enough, they are sanctioned accordingly.
I'm an old dude, so I never understood why you would require websites to ask for cookie consent, when you can handle that more safely in your web browser.
That's like putting a sticker on your car saying "Don't come into my car" instead of just locking it. Why do you need regulation when you can just let technology solve it? No idea.
So NO! NO fucking cookie consent API! Just let the browser ask you when a cookie needs to get set... DAMNIT!
In my day, website used to be websites where you could read stuff. Anyone who wasn't able to predict these annoying popups after HTML5 and GDPR, is seriously blind.
(Sorry for the rant ;))
I'm stuck in Europe. I was fine without the GDPR. Now, I waste my time clicking "accept" because I don't have time to deal with this crap. Meanwhile, my university has hired what my stepfather would have called a "tweety little person" to police GDPR regulations. God knows what she does (she doesn't). God knows in what single way she has improved a single person's life. But she has a job now, and by God, she'll fight for it.
I care about privacy, but there were options to manage this already - like browser extensions. You could download them if you cared, and if you didn't want to, you didn't have to. Government regulation, demanded by zealots, has added one hundred tiny frustrations per day to millions of ordinary people, caused an expensive pain to thousands of small websites, and created a new, wholly useless compliance industry.
And is Facebook tracking me any less? Ha ha ha. Facebook can afford lawyers.
The argument I always hear is "Ordinary people don't know about cookies so it's the websites responsibility". As if ordinary people now understand cookies.
It's all a big fiasco, supported by people who think theory works in practice.
Have you read the GDPR, though? Because in no way does it require "cookie consent", incidentally, neither did the previous "cookie law". The consent forms I've seen so far are all willfull misinterpretation, dark patterns, or both.
95% (if not more) of non-shady uses of cookies do not require consent, and thus don't need a consent popup. If you do implement one on your website it means one of several things:
1) You did not actually read or understand when/why you need consent
2) You did read it/don't understand, but are unable to figure out where all the stuff on your site is actually coming from and are thus unsure about the implications
3) You actually need consent (in case you are hosed anyway, you can't predicate usage on consent, so there's 0 motivation for users to ever consent)
4) Your purposely trying to annoy EU residents in hopes they will lobby against GDPR back in the EU
5) You're blindly copying what other people are doing, because thinking is hard.
1. Is there risk?
2. Does adding a consent screen reduce or remove risk?
3. Is the risk reduction from 2 less than the cost?
Congrats, now every website in the world gets a cookie consent screen even if not technically required.
Not "subtly getting a minor detail wrong", but "doing something that is explicitly mentioned as not allowed" levels of wrong.
But 99% of businesses owners went to full panic mode and went straight to your point 5. "Our website needs such a popup".
Do you think the general public now understand cookies? Of course they don't.
Seemed all pretty obvious to me.