I am sure people here will find at least 20 solutions on the problem on "how can a group of evil websites track a user across if cookies do not work but JS is On", the solution would involve something like drop this lines in your html page and the js code there will connect to some server and store some fingerprint there, Google might decide to give your browser a fingerprint to help with their ad business.
If there is a browser based vendor agnostic opt-in popup for user tracking (not only cookies) you can outlaw and severely punish attempts to circumvent that.
Given the time and resources courts really dislike the "welllll technically..." Argument.
"Cookie Banner" is just tech-jargon for these banners, but an incorrect one.
Browsers could help by implementing a standard GDPR popup for this shitty websites to share , at least it will not be same dark pattern UX, broken implementation shit this sites use today.
Browsers could do a lot of good things if they would focus on the actual users needs and not on what some developer feels cool to work on or what soem giant company ants to implement next.
Ah, sorry ,I messed up. I am trying to force myself to always quote the text I am replying, sometimes I do not do it and is causing issues, I will try to do better.
Browser can choose to respect the cookies (first, or third parties), but ultimately don't force them to do or not do anything.
We sort of have auto-reject, with the Do Not Track header. Which pretty much everyone has decided to ignore, because then people just say no and that's not the result they want.
> The popups have ruined the experience.
And behind every popup is a company that decided that ruining your experience was the correct thing to do.
Yes, of course, they want you to think "uugh privacy just means lots of work and popups I'll just click accept"
Lynx is about the only browser that still notifies you and has you accept each cookie manually.
Playing cat and mouse with only a few large entities vs. literally every website on the web seems like progress.
And let's be realistic, "intentionally broken" can be prevented by having a serious deterrent and removing the incentive.
In the EU it's more usual for judges to take the "spirit of the law" into account for rulings rather than the "letter of the law" that is more common in Common Law systems.
I don't know enough and IANAL to state that with sureness about the whole legal system of all EU countries but it's a rule-of-thumb, the law doesn't need to be absurdly specific to avoid loopholes, it just needs to be good enough to cover ground for judges to judge if the accused is following its spirit.
Sounds good to me.
> I still would expect Google to find a way to fuck it up.
Sure, then we change the law again and/or sue Google.
Which generally seems to have an almost 10 year delay for every iteration since Google will appeal on every instance and do its best to slow down every curt issued request heading its way to the fullest amount possible. The result: Not happening in the next century or two.
[1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
(Not a lawyer)
Not all, websites, though; I believe medium, of all websites, will actually not embed some content if you sent it a DNT header. Not sure if they still do that, though, because their UX for readers has become absolute trash.
The DNT header isn't on by default in any major browser.
(Additionally, the spec was abandoned for a bunch of reasons including not being able to agree what constitutes tracking)
We don't see many websites who opt out out of the "track the users all across the web" scheme in order to remove the cookie banners altogether.
On the other hand, thanks to the banner everyone has become aware that the are being tracked. This is good because it brings people into the discussion, so that when EU says "stop tracking" people are not puzzled about what tracking those Eurocrats are talking about. How people are supposed to know if they should support the actions of their government if they don't know what's happening behind the scenes?
Cookies are entirely on the client side anyway: trusting every website to do the right thing is obviously not going to work.
What we need is a low that forces websites to obey the "do not track" header.
Edit: fixed the domain to actually make the point I was trying to make.
In 2020 my friend couldn't add a new credit card to his account because browsers updated their same-site cookie behavior.
They were setting their JSESSIONID cookie wrong when doing oauth behind-the-scenes which caused a nice 302 redirect loop. For whatever reason the API calls required both *.battle.net and account.blizzard.com.
You have to activate them for the login but you can deactivate afterwards.
They finally fixed it this year. Made it impossible for me to login on my Firefox browser.
Sony Playstation website also broke until like three years ago with third-party cookies disabled.
https://internal.yourcompany.com/oauth2/callback?token…
That token in the callback does not require any kind of cookie to use for subsequent authenticated calls.