What Do You Agree to When You Accept All Cookies
conradakunga.com
conradakunga.com
For example, for cookies, legally force, with the cookie (with a standard protocol), transmit of "intent", like cross-site tracking, whether it is used for advertisement or something else, whether it may be shared with third parties, etc. Then the browser would simply not accept cookies with intent the surfer disagrees with.
Another possibility is, that the browser could, in a standard header, with a bunch of standardized flags, tell what the site may or may not do with the data they gather about the surfer.
There was a W3C standard called P3P which is similar to what you describe. It was implemented by Internet Explorer, but fell into disuse long before cookie notices became common. Bringing back something like that would be an improvement over having to deal with cookie banners per site.
Realistically, if the EU were to impose such a rule, then any ad company doing business in the EU would have to follow it. Thus, any web site deriving any significant revenue from EU advertisers would have to follow it. I'd strongly assume that it's not possible to effectively monetize EU eyeballs without EU advertisers. Of course, anything operated by a EU company or hosted in the EU would also be subject to these rules.
While some local US news would certainly take the "we block all traffic from the EU" approach to avoid dealing with it, the advertising and tracking landscape would quickly and drastically improve.
If now, for example, California would also decide to copy these rules, this would very quickly be the worldwide standard.
[1] https://github.com/w3c/dnt/commit/5d85d6c3d116b5eb29fddc6935...
I understand that you’re suggesting pairing it with legal force, but I also highly doubt that would or could be effective in any kind of consistent way.
The industry-led-initiatives are all basically bad, for the obvious reasons. So many of them amount to telling ad networks whether or not the massive amount of data they have collected about you should be part of the consideration for what ads to show (for now) — many offer no possible way to opt out of recording and storing such data in the first place.
This is a situation where legislation is probably the only answer.
A standard written for advertisers by advertisers. This is the problem. There are technical solutions, but the biggest advertiser (Google) makes the browser. This is the same as "the revolution will not be televised." The adversary controls the medium.
Needs more work,, but the concept is that it needs to incentivize developers to develop track-the-tracker technologies that will catch violators, which then leads fairly directly to a profitable private suit (instead of relying on the overworked govt bureaus to do it).
And then you get Facebook spending millions of dollars taking out full-page ads in newspapers telling people that you are an evil demon who kicks puppies and hates small businesses.
(Ever notice that when Facebook wants to reach the most people, and the most important people, it uses newspapers, rather than its own platform?)
They do this when they want to get the attention of legislators, or the gatekeepers/editors of legacy corporate media outlets.
If they wanted to, Facebook could target directly 1:1 to decision makers on their platforms with their own data. It would probably be creepy though instead of just doing a blanket all of DC type promoted post.
The New York Times, Wall Street Journal, and Washington Post
https://www.google.com/amp/s/www.macobserver.com/news/facebo...
[0] uBlock Origin
https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...
[1] Firefox Multi-Account Containers
https://addons.mozilla.org/en-US/firefox/addon/multi-account...
It's still a bit wonky because some sites do redirections, and it's not properly caught (unless there's some option I missed)
The next step is to disable _all_ cookies, even first-party, by default (unless I have a special relationship with the domain of course). It's working surprisingly well and I believe this should be the default.
I suppose you never login to websites?
A good extension for the cookie part is https://github.com/Cookie-AutoDelete/Cookie-AutoDelete - it deletes all cookies from a site after you close the tab.
They are required to have a button to let you manage preferences, and are required to allow you to disable all cookies that aren't necessary for the site to function.
So, on any GDPR cookie banner I always click the smaller "manage" link instead of the "accept all" button. On the manage page, disable every option provided, then close the modal. I've never had a site that offered this kind of banner break in any way because of the disabled cookies.
And I haven't paid close attention, as I'm an American citizen and couldn't pursue sites over such a blatant violation of the law.
Were I a European citizen, however, I would watch extremely closely and absolutely be bringing complaints against sites that did that.
If I just clicked a link to a random article from search or social media, I'm not spending a full minute getting past the prompt on a website I'll probably never visit again. I'll click accept, and make sure my browser is loaded with all possible privacy extensions so none of it works.
You know what is necessary for a site to function? Revenue. Therefore advertising cookies are necessary for the site to function and we shouldn't need these banners.
However:
Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects [1]
Section 3.3, Paragraphs 51-53:
> 51. Online behavioural advertising, and associated tracking and profiling of data subjects, is often used to finance online services. WP29 has previously stated its view on such processing, stating
> > [contractual necessity] is not a suitable legal ground for building a profile of the user’s tastes and lifestyle choices based on his clickstream on a website and the items purchased. This is because the data controller has not been contracted to carry out profiling, but rather to deliver particular goods and services, for example
> 52. As a general rule, processing of personal data for behavioural advertising is not necessary for the performance of a contract for online services. Normally, it would be hard to argue that the contract had not been performed because there were no behavioural ads.This is all the more supported by the fact that data subjects have the absolute right under Article 21 to object to processing of their data for direct marketing purposes
> 53. Further to this, Article 6(1)(b) cannot provide a lawful basis for online behavioural advertising simply because such advertising indirectly funds the provision of the service. Although such processing may support the delivery of a service, this in itself is not sufficient to establish that it is necessary for the performance of the contract at issue.
[1]: https://edpb.europa.eu/our-work-tools/our-documents/guidelin...
I'm an American citizen, so I have no real recourse with that, but their European citizens can bring the case to a regulator and they could very well be fined.
That interpretation goes against the spirit, and the very plain letter of the GDPR regulations.
That dog don't hunt.
I happen to agree with the European values more than I agree with your values.
My data privacy should be a more important and more fundamental right than your ad revenue.
> x-ccpa I do not consent to the sale or disclosure of my personal data and demand the deletion of my personal data per Californa CIV 1798.120, 1798.121, and 1798.105
Secondly, this is another thing that would be used to fingerprint the web browser.
We sometimes like to pretend that if a law is in force somewhere, it's in force everywhere, but that isn't the case. Otherwise, I'd be in serious trouble for saying I support Hong Kong independence. So you're creating these massively granular permissions and then passing some law, somewhere, saying they can't be used to fingerprint, but that's precisely what they will be used for everywhere the law isn't in force, which will likely be most of the world.
It's really really hard to come up with a machine readable code that encapsulates what each cookie means and does.
Also obviously true bad actors would just lie.
in effect our browsers will need a db type tech to manage cookies and only serve them back when appropriate. a lot of what sites want to preserve for us; log in and such; can easily be done without cookies
The saying not to attribute to malice what could be explained by incompetance only works if the actor isn't generally malicious. AdTech definitely is.
Why? That sounds illegal.
Why doesn't it simply not load the trackers?
Well, it could have been really easier to implement the opt out it later by this design, but it is more likely, that the dataflow is intended.
> Weather.com - an IBM business
felt like it explained this design pattern perfectly
No, it wasn't. It was at one time partially owned by NBC. Perhaps that's what you remember.
It's beyond a dark pattern - it's plain fucking disgusting behaviour.
As I mentioned in my other comment, I suspect it's actually forbidden by the GDPR, but that doesn't stop anyone.
I realise it's comically unenforced, but doesn't the GDPR forbid websites from doing that?
Obvious ugly workaround: use a Private Browsing session for that website.
Choose not to accept / options.
You'll be faced with 330+ individual agree/disagree toggles. THERE IS NO REJECT ALL BUTTON. If you're not technically inclined, you have to manually click them all.
You also have to choose block/remove consent (or whatever it is called) for similar crap hidden under the "Legitimate uses" category moniker. Same shit.
For this, and similar idiotic dark patters, there's a Firefox addon called "Unchecker".
https://addons.mozilla.org/en-US/firefox/addon/unchecker/
That, is, of course, until they start using buttons (some already do), double negatives in the wording or some such crap.
In this case I would always reach for typing a JavaScript oneliner into the dev console, using a couple of tricks:
1. Right click the element in the Inspector and choose "Copy" -> "CSS Selector".
2. Start typing the oneliner in the web dev console: Use [].slice.call(document.querySelectorAll("PASTED CSS SELECTOR")) to turn the elements into a JS array.
3. Use (...).map((o, i) => {...}).join("") to turn the JS array into a long formatted text string.
The result is the following, which took me a minute to type up and debug - from my perspective, a thousand times faster than firing up an IDE and setting up a new "project" to simply run a regex against some HTML.
{const rows = [].slice.call(document.querySelectorAll("li.vendor-item")).map((o, i) => {const idx = 1 + i; const name = o.querySelector(".vendor-title").textContent.trim(); const url = o.querySelector(".vendor-privacy-notice").href; return `|${idx}|${name}|[${url}](${url})|\n`}).join(""); `Listing As At 30 December 2020 08:10 GMT\n\n|-|Vendor| URL |\n|---|---|---|\n${rows}`}Perhaps the header should be made to be easy to apply per domain, so websites can request tracking permissions, but in my opinion the necessity of the header is exactly the point of enabling it by default.
The header is simple: I do not want to be tracked. Do not track me. If you want to track me, ask me to disable the header so I can leave your website.
Honestly, I don't understand why this header wasn't mentioned in the ePrivacy directive the EU passed recently. There's a perfectly good way to communicate intent about tracking options to websites, and it's being blatantly ignored.
Which is what it should have been to begin with: a “do track” header that no sane person would opt in for.
The whole “people consent to everything unless they go out of their way to say otherwise” thing is a farce.
Instead, the appropriate framework is that advertisers do not have a moral right to track users unless the user has consented to it. By having the DoNotTrack header be on by default, it means that a user removing it shows consent to be tracked, where previously its absence could also have indicated that the user was unaware of the header.
But that's not what DoNotTrack was. It was supposed to show specific intent. It wasn't there to change the default.
So by removing the intent, the fragile agreement broke entirely.
If you want to change the default, you need something that can be enforced.
It pretty clearly isn't. It should be but isn't.
> DNT was just reflecting the reality of the situation: user not making a choice indicates they don't want you to steal their data.
Advertisers don't need a header telling them what they should do by default. They can get that information from elsewhere. DNT was going to be a way to opt-out, and some advertisers promised to listen to that. Setting DNT without user action removes the "opt".
By honoring it they would loose an advantage over all the other ones who don't.
[1]: https://spreadprivacy.com/global-privacy-control-enabled-by-...
I'm not good at reading legalese and there seems to be no commentary for the current version[1] yet. What I understand is that they "encourage" browsers to implement "whitelists" (their choice of word, not mine) as a solution to "end-users [..] overloaded with requests to provide consent". I'm not sure there is an update regarding first-party analytics cookies which some hoped will be there.
[1] https://data.consilium.europa.eu/doc/document/ST-6087-2021-I...
I am one of the few that (most of the time) actually takes the time to click "Reject all" whenever possible. Some websites are EXTREMELY shady when it comes to this though and hides their targeted advertisement and user-profile building into their "legitimate interests" section that IS NOT automatically turned off even if you "reject all". You have to manually go trough them and "object" to each and every one of them. Often no "object to all" button.
Imagine if sex used the same notion of "consent": "Ok so you rejected having intercourse with me, but I have a 'legitimate interest' in fellatio that you didn't specifically say no to, so now you have to!". It is just terrible..
"Legitimate interest" is a broken term in those cookie forms. Legitimate to whom? Of course any company has a legitimate interest in making buckets of money.
Every browser should have a mandatory "cookie preferences" section where you can set your preferences for each of the typical use-cases for cookies. Strictly functional cookies? OK. Targeted advertisement? NO. Tracking between websites? NO. Measure site performance? OK. etc.etc.
Whatever role the current cookie panes now fill, the browser should take over using some standard. The preferences could get sent directly over HTTP with the initial page-load and the server/site would have to comply or face extreme fines.
With the browser approach you could maintain your own allow/blocklist for site-specific settings. All this could be synchronized across your various devices.
Only then would we not be annoyed by those popups again.
All the concerns you raise here are covered by the law. It's illegal for it to take longer to reject tracking than to allow it, which should ban all these web site that try to get you to scroll through several hundred options turning them all off. "Legitimate interest" means that the whatever data they want to process is a necessary step in order to do what the user has asked for - for instance, the web site has to be able to set a login token cookie when you log in, and that's allowed because you literally just asked to log in, and that's the only way the web site can do what you asked.
All these web site are illegally making the cookie experience dire. They are doing it so that they can:
1. Collect data from people who get fed up and click accept, people who accidentally click accept, etc.
2. Annoy everyone and make people think that the laws are broken, which increases the chances that the laws will be changed in the future.
Enforcement would help with this, but there's little sign of it happening.
No one ever used it, and over time it got more and more hidden. It's still there if you look for it.
So cookies aren't the only thing that requires consent - things like browser fingerprinting and even collecting IP addresses for non-essential purposes (aka you can probably claim legitimate interest if you collect them for technical or fraud prevention reasons, but using that data for analytics or marketing would require consent).
This is also why I think clicking "accept all" on the cookie prompts with cookies disabled at the browser level isn't a good idea. You're still giving them permission to stalk you using other means than cookies, and they very well know that. At least use an ad-blocker which blocks the consent prompts completely - technically you never provided permission, so while they might still stalk you at least they don't have a legal basis for doing so.
The GDPR is less about the technical aspect of data collection and more about the intent behind said collection and the planned use for the collected data, something the browser can't really tell.
And in the end, people still just Accept All because it's the fastest way to content.
It kind of seems like a second attempt to the do-not-track switch which was a failure. There must be strong backing in the laws for such feature to be meaningful otherwise nobody will respect it
The cookie debacle has been going on for so long now, and is obviously not going away any time soon - surely there must have been draft RFCs or even W3C proposals along these lines at some point?
Let's be honest most of the websites that won't work without JavaScript aren't even really worth it. The content is usually garbage anyway.
If I still see a popup, I just leave. I refuse to interact with popups. That was true in the 90's, and it's true today.
Maybe lockdown is making me cranky, but I'm getting really, really tired of the popups.
One thing I would like to see (and it shouldn't be too hard to code, using the example) would be a mirror of the entirety of text of all the privacy policies and everything else pasted back to back.
The screenshots and implication of having 647 privacy policies is bad enough, but I really want to see my scroll bar shrivel up and die.
I thought cookie popups were annoying, but I didn't realize how much more ubiquitous they are when you have an EU origin ip address. If you haven't tried it before, it's worth doing it just to see what those poor people put up with.
The neighbouring town publishes data on water quality, and you pity the poor souls because the data shoes their water quality is horrible. Thing is, you are using the same water source. If anything, your water is likely worse because there is no transparency and some of the pipes might be leaded and you wouldn't even know it.
Same with cookies. The internet is polluted with aggressive tracking everywhere. In the EU you see how horrible it is - in the rest of the world people aren't even half as aware.
That said, people either start using browser plugins or just click yes and sacrifice their soul to the gods of dark patterns. In either case you don't see those banners as frequently unless you use private browsing.
Btw, some of my message was lost in your attempted analogy: If we both are drinking toxic water, then I feel bad that you have to additionally click through a legislator's theater of concern and sign through various permission-granted-to-poison-me slips while you drink from the same tap.
But this is a prime example for a "dark pattern"
And also, if I can't reject most of the stuff I just close the site
Presenting the user with the full list of advertisers is indeed silly and not compliant IMHO. We also offer an open-source privacy & security tool for websites (Klaro! - https://github.com/kiprotect/klaro) and we have decided against implementing the IAB framework as it's clear that it does not conform to the intent of the GDPR. We also opted against using dark-patterns and making declining more difficult than accepting. Overall this results in slightly less opt-ins (around 50-70 % for most websites) but in any case those dark patterns will have to go sooner or later.
I don't recall receiving any comments or complaints about this.
The article would be much improved with an opening paragraph that summarises the findings.
It would also be improved with formatting that clearly differentiates the article text from the extensive site text it quotes. That site text is designed to numb users and put them off reading. It worked for me.
1. First go to cookies and reject all cookies except the strictly necessary ones
2. Then go to “Legitimate interest” and then simply click “Object all”.
At my primary browser level -
3. In Firefox settings, choose “Block all cookies” (Hasn’t messed with my browsing experience, yet)
4. Periodically keep on deleting your browser cache and cookies. Don’t delete browsing history and saved logins.
I am currently looking for ways to minimize JavaScript usage. If anyone has any ideas, kindly proffer.
Caveat :- I am fully conscious that despite the painstaking activity of rejecting all cookies and objecting to all legitimate interest, I cannot rest easy that all websites I visit are scrupulous, cognizant and conscientious of my choice.
Also, I don’t get to option to reject and object on all websites, in which case I first check if there’s an archived snapshot on the Wayback Machine[1], or I simply forego reading the article altogether. For ex - www.BBC.co.uk, and even Reuters as mentioned in the OP’s post.
Ref.
[1] www.archive.is
trying "reject all third party cookies" instead
Many subscription news sites might consider the "how many free articles has this visitor viewed this month" to be a strictly necessary cookie, but that's just speculation on my part.
Does anyone know what that entails? I couldn't find it in the policy itself.
That said, the actual example summaries given seem to IMHO make a case for mandating specific and explicit language, akin the "Surgeon General's" warning text on cigarette packs, to accompany whatever euphemistic language companies continue to use. We're far enough into the Internet age to be pretty confident that the vast majority of people just do not and cannot comprehend that "We use cookies to improve the site, measure performance, understand our audience, enhance our experience and provide you with advertising based on your browsing activities" means actual tracking.
[0] http://www.conradakunga.com/blog/images/2020/12/Banner1.png
[1] http://www.conradakunga.com/blog/images/2020/12/Reuters5.png
It would be good to define some phrases in the law that then have unambiguous legal meaning so that privacy policies don't have to spend time defining things in full.
But really, most of the time the cookie deal is "do you agree to have all kinds of information gathered about you and sold at will to other companies, our future management, and mysterious government entities in perpetuity, in exchange for seeing a few cat pictures? oh, and also we can make this even more unfair at any time without your agreement." They really should just be illegal, period.
Not as explicit as 140 characters, but it's already covered the GDPR
From the preamble, paragraph 32:
> If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.
From article 7, paragraph 2:
> 2. If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding.
(emphasis mine)
If we walk outside of our house then we're likely on camera, potentially with facial recognition. Cameras will track our cars' license plates. Cellular networks know where our phone is at all times. Our payment card networks and the stores we shop at gather data on what we buy. This is effectively public information because normal everyday citizens can just look around and see us and recognize us and what we're doing. I assume every action I take is probably observed and logged by someone. Those folks share the information with their business partners.
This has been going on since at least the 1980s to various extents; there isn't a way to opt out of participating in public spaces unless one is particularly wealthy, and then the risk is becoming a celebrity and losing even more privacy.
If anything, the web is slightly less intrusive despite occurring in public (I argue that the Internet is just as public as any real public space; we rely on third-parties to forward all our traffic. We use TLS if we want to hide the details of what we're doing). It's not technically us being tracked but our devices and we can wipe them, block javascript or cookies or network requests, etc. Maybe tracking is more effective for being fully automated and granular, but I'm not sure if that's worse from a privacy point of view.
I think collectively we need to decide whether we want more privacy or anonymity. Full anonymity is nearly impossible to achieve but would mean that no matter where we went or bought or did no one else would be the wiser. Presumably we'd only see shadowy hooded figures in public so that even we had no idea who they were. It sounds draconian in the other direction. Privacy, to me, is a polite fiction that we won't individually bother each other by using all the information we know about each other. For the most part this is already done in real life and the web. Companies don't wholesale dump/sell every piece of data they collect about us; they aggregate and categorize it. This is the middle ground of privacy where people mostly mind their own business but don't blind themselves to trends and patterns of behavior occurring in public.
The problem is that it doesn't seem like the regulation gives the right to a wronged party to sue for those sums of money. You can sue (I guess technically you can sue for anything anyway) but this would involve proving some damages.
The only parties that can enforce the regulation (and levy the promised fines) are privacy regulators (such as the ICO in the UK, or the CNIL in France). Sadly, they've all demonstrated their incompetence and unwillingness to improve multiple times.
There's a non-profit in the UK that wants to take the ICO to court over its incompetence/unwillingness to enforce the regulation - feel free to vote with your wallet: https://action.openrightsgroup.org/help-us-protect-your-data...
Between cookie banners and GDPR forcing newspapers to ban European visitors, I have to go through more hoops in order to see what I want.
Just because you care about a website tracking you, that doesn't mean someone else cares.
Legislation shaping the internet in this way and forcing everyone to think in a certain way is an authoritarian behaviour that I don't tolerate.
it's highly disappointing.
Or fund someone to write better anti-cookie-banner extensions. Ublock works incredibly well for ads, after all.
Always use u block, right click and choose "block element".
In practice, the real defense is a good ad blocker which would block both the consent prompt and the associated trackers.
I’m guessing a simple GDPR complaint supported by this request would be very exciting.