That’s so stupid, why not just take your OWN cookie and use it in the backend to send to all these resources, proxying through your own server or having a CNAME for theirs under your domain?
The CNAME practice is becoming more and more common. See https://blog.apnic.net/2020/08/04/characterizing-cname-cloak... or https://medium.com/nextdns/cname-cloaking-the-dangerous-disg... or https://www.laquadrature.net/2020/10/05/le-deguisement-des-t...
I think proxying or doing it server side only will be implemented later when these people will be forced to hide to save their shitty business model.
It is similar to a CNAME record but instead of storing the domain name you want to map to it pulls the A record and puts that IP as your A record.
I’m not saying this is a perfect system. It’s not. But it’s an attempt the problem you describe.
No, thank you, I don't want to go through audits and deal with bureaucracy when I just want to publish my side-project blog on the web. If you want to discourage people from building and publishing their personal projects and making them easily accessible to the public, that's how you do it.
However, I am absolutely ok with EU doing this, given they seem to be hellbent on running their local tech industry into the ground. Truly great founders from EU will either manage to make their companies succeed despite EU or eventually end up creating their companies in the US, and both of those scenarios sound like a win-win to me (from the perspective of the US; from the perspective of the EU, I guess they are doing all of this knowingly, so they get what they wanted, which would count as a win in a way too).
If all you did was publish an HTML+CSS page, your innocence is self-evident. Anyone can look at your page's source and confirm it. If you link to Google's javascripts though, that should put you into a completely different category of suspicion.
Things change. Back in the day, HTML+CSS page was all it took. These days, wanting to know how people discover your page or how many new readers come to your blog is basics. Reliability and performance tracking is something that wasn't really a commonplace thing back then. For all of those things, you kinda do have to use JS.
The question is, do you necessarily need those features? No. Would it be nice to have? Yes. When I publish a side project, I want to make it nice and great, since I am not getting paid to do it, I am doing it out of pure enthusiasm and motivation for creating the best I can. Forcing anyone in this situation to go through audits and deal with bureaucracy just to be able to publish their personal side-project is a certain way of discouraging people from ever doing so. All you end up with is a bunch of people who are willing to jump through all these hoops because they have something monetary to gain from it or those who know how to jump around those hoops really well.
Your accusation would be very troublesome if made against individuals but for corporate lawyers its just another day at the office.
Inverting the burden of proof is listed as a logical fallacy for a reason. It is never appropriate.
The income accounting in the UK and Pakistan are the closest thing to legitimate and even then self evidently regarded as extreme by their limited adoption.