On HN it's like - go ahead and let me cable company and cell phone company track / sell and target me on my browsing history (wildly intrusive), but random website doing pet necklaces, try to stay on top of all the popups you need to shove at your users (who will all say OK) so you can show your page.
If you can't share the data you buy up the other companies into groups and then are just using it "yourself" etc.
What is gained, SERIOUSLY, by these stupid pop-ups? I'm serious, has anyone analyzed this? It really shows how the heavy hand of govt has ZERO cost/benefit constraint or analysis. Browsing on phones is particularly painful.
I wish we could just set an accept all cookies header in our browser and govt would let these websites then stop displaying these damn notices, banners and consent boxes.
The GPDR ones (if you use euro websites) are getting even crazier.
Disclosure
I appreciate the ability to allow "required" cookies, but reject all other cookies.
I agree that I would absolutely prefer an HTTP header for cookie preferences instead of pop-ups. But the new cookie popups add some value to me, in letting me allow session authentication cookies, and reject all others.
An outright block on all local cookies tends to break authentication for many sites.
- reject all cookies
- allow only required cookies
- allow all cookies
And never to have to fall into 100s of different dark patterns by people who have spent dozens of hours coming up with solutions that would basically trick people in clicking whichever button is highlighted (usually the "accept all cookies" one) just so they can browse some content?I absolutely would prefer that to the world we have now. I'm all on board, you don't have to convince me it's a good idea.
But, that doesn't exist today. I do prefer having the stupid annoying popup that gives me the option to allow only required cookies to having no choice at all.
The new GDPR compliant cookie popups give me that option. It's a step up above not having the option at all.
Analogy would be like:
Law: you can't store someone's picture or personal data without their consent, unless it's necessary for the transaction.
Most companies: <nag you for consent to store your picture>
GitHub: We authenticate you by your face, so it's necessary to collect that, so we don't need to get your consent for it. Then, once we have it, we do whatever the fudge we want with it.
This is all posturing. If you want to reduce tracking, use a browser that reduces the tracking. Seriously, just use total cookie protection or something on firefox.
By a corollary, some users DO care about tracking and click "no" to these popups.
I guess it's for the courts to decide if requiring the same number of clicks but letting you wait for an eternity is equally easy, but I doubt it.
And why call an opt-out endpoint at all, after all there has to be a mechanism that prevents setting the cookie before the user sees the cookie banner. Just continue using that mechanism (e.g. gtag's consent default denied).