It’s time we fix the unethical design of cookie consent windows
uxdesign.cc
uxdesign.cc
This should be handled at the browser level. There's no reason for most users to ever be burdened with even a fantastically designed cookie consent window.
Browsers would hold cookies for a session, but not between them.
This is no longer a viable option as:
- There are those who keep browser sessions alive for long periods of time (days, weeks, months, ...)
- Cross-site cookies. (Thanks, Doubleclick, and by Doubleclick, I of course mean Google which produces the most widely-used browser in the world.)
Make the Web Stateless Again.
The main motivator there is actually Google Chrome's abysmal tab management and navigation, as it is all but impossible to clear out tabs in a reasonable manner.
On Firefox, with Tree-Style Tabs, the problem still exists, though it is less severe.
There's still ample opportunity for tracking, unfortunately. I consider both Chrome and Android to be actively user-hostile and privacy-hostile, for what I hope are evident and well-founded reasons. Google's advertising motiviation is powerful.
If the website conforms to the standard, then the browser could use its own UI to ask the user for their preference. Importantly, the user would be able to state global preferences like: "only required and login cookies, don't ask about others", and then they wouldn't need to be prompted by every new site. If the website doesn't conform, then they'd need custom UI to comply with existing cookie laws, same a today.
So, the website could lie and say that their tracking cookies are in the required category, but they can do that already by not using a cookie banner, or miscategorizing the cookie in the banner.
I think the users who hate cookie banners and the sites that don't want custom cookie banner UI would like this approach. Sites desperate to trick users into allowing tracking cookies: they'll still find a dark pattern and we'll hate them for it.
A browser never creates a cookie or of thin air. A browser stores a cookie only when it's sent by the server, or set by JavaScript code sent by the server.
- some cookies are essential for the website to work,
- some others are not, and
- the browser can't ever tell the difference,
then it doesn't really matter what config is set in the browser.
I think the original point still stands (that this is fundamentally different from "do not track"), and moreover I disagree with the contents of that moved goalpost:
As a compromise solution, the vast majority of sites work fine if you delete their cookies when you're done with a session. If the browser did that by default we'd have a significant improvement in privacy and a negligible amount of breakage.
The most obvious counterpoint is login flows. That's not antithetical to the idea for a couple reasons. First, we'd all be a bit more secure if we logged out more frequently. Second, if you do want persistent sessions you've already given up exactly the same amount of privacy as if all cookies were blindly allowed since you're manually tying your visits together with that login information. With that in mind, there's no harm in having a setting somewhere for allowing cookies from the few sites you actually login to frequently. For convenience that could be tied to the existing password box detection, and otherwise it'd be something you have to dive into a menu and fiddle with to keep it from turning into the same kind of annoyance as browsers asking for notification privileges.
That would break a few things, but browsers have had a trend lately of breaking a few things for privacy gains. I don't think it's obvious that we couldn't meaningfully reduce cookie setting.
If it's gonna happen at all, there will be a law enforcing that, because it's not in the interest of website owners (which also leads to the dark patterns in the dialogues).
If there is law, people can sue, which usually is enough for companies to (usually) follow it
This isn't the case for do not track afaik
But this is not the case. The biggest browser maker is also the biggest cookie tracker.
In theory this would be a point of differentiation for say Firefox, but then again the biggest funder of Firefox is also.... Da dum.... That's right, the biggest beneficiary of cookie tracking...
I imagine there are browsers out there that offer what you want, but you'd have to go looking for them.
Disagree about Firefox. They'd do a good job.
Likewise Firefox. They _could_ implement tracking protection. But they (so far) clearly choose not to. You say they'd do a good job, and I agree, but it's not like they haven't thought of it, or they're waiting for approval from the HN forums before implementing it. Given they have chosen not to do it, it makes you think maybe there's a reason for that. And maybe that has to do with the wishes of their biggest benefactor...
Of course I might be wrong. Perhaps they're just thinking that tracking everyone is good for the end user, and so they want to provide a browser which offers users the best possible experience. That's obviously a possibility as well.
Google avoids losing money by having a large Chrome user base. It's the same as making money. They have to write checks to Firefox and Apple to maintain access to those users, but not with Chrome.
> Likewise Firefox. They _could_ implement tracking protection.
Curious what you want Firefox to do? https://support.mozilla.org/en-US/kb/enhanced-tracking-prote...
Reading Firefox, Google gets money from chrome by a second order effect - from users using Google as their search engine. They also get money when you browse the web from adverts. The value of those adverts goes up the note they can track you.
Google avoids losing money by keeping tracking in the browser high.
To solve this problem in the browser you'd need to discard all locally stored information when the user closes it.
Thia comes with two prpblems
- first, users rarely close their browsers. They may close a tab, or a window, but the app is still running. I'm pretty sure Chrome has been running on my Macbook for months.
- second, this mechanism would break every app that actually respects user privacy. Apps that don't upload data or track people need the users content and prefs to be held locally between sessions. By wiping it you'd force app developers to implement mechanisms to put that data in the cloud, which is the opposite of your intent.
Intents:
- REQUIRED_FOR_SITE_FUNCTIONALITY (translation "Required For Site Functionality")
- FIRST_PARTY_ANALYTICS (translation "First Party Analytics")
- THIRD_PARTY_ANALYTICS (translation "Third Party Analytics")
- FIRST_PARTY_MARKETING (translation "First Party Marketing")
- THIRD_PARTY_MARKETING (translation "Third Party Marketing")
Let the browsers themselves provide UI for accepting or denying these (maybe the users should be able to choose their own defaults per intent): Message:
https://some.site would like to use your browser to store data for these intents:
Required For Site Functionality [X] Yes [ ] No
First Party Analytics [X] Yes [ ] No
Third Party Analytics [ ] Yes [X] No
Unspecified [ ] Yes [X] No
[ Submit ]
Which could then correspond to how everything is stored in the browser: Storage:
https://some.site
REQUIRED_FOR_SITE_FUNCTIONALITY (accepted)
Cookies - ...
LocalStorage - ...
IndexDB - ...
FIRST_PARTY_ANALYTICS (accepted)
Cookies - ...
LocalStorage - ...
THIRD_PARTY_ANALYTICS (rejected)
FIRST_PARTY_MARKETING (rejected)
THIRD_PARTY_MARKETING (rejected)
UNSPECIFIED (rejected automatically after 01.01.2030)
And extend the JavaScript API for cookies (and also all other mechanisms for storage, this is an example): document.cookie = "user_id=1234"; // this would go under Unspecified
document.cookie = "intent=REQUIRED_FOR_SITE_FUNCTIONALITY; user_id=1234"; // this would go in the proper group
document.cookie = "intent=THIRD_PARTY_MARKETING; uid=1234"; // this would throw something like an IntentViolationError
And ideally something for checking these intents as well: let canUseRequired = document.intents["REQUIRED_FOR_SITE_FUNCTIONALITY"].accepted; // true
let canUseTPAnalytics = document.intents["THIRD_PARTY_ANALYTICS"].accepted; // false
Who would define these types? Well, i think that there are two ways: - have some international body decide on these types
- allow custom types per site, maybe with different UI for that
And then just prosecute those who don't follow the convention and abuse the mechanisms.Of course, that will never be done.
Oh... Right.
Can't charge people for things running on their own hardware! Gotta shovel some cloud BS in there!
Good, there could have been a standardized way to ask for that consent — but to me the way a site tries to trick you into consenting is yet another data point whether I want to be on this site.
What we need is better isolation at the browser and web protocol level. This is a technical problem, not a regulatory problem. You cannot regulate actors who don’t obey the law in the first place.
The goal of the law is partly to make people who run websites aware of what they do with the data of their visitors. And that means for one part that they need to know what happens with things they embed in thwir site like google analytics and google fonts (for which someone has been sued already). But it also means that once website owners are informed they can decide wheter they want to ask people for their consent or whether they just remove those third party options.
In reality many don't inform themselves at all and just slap a cookie thing onto their page, because that's what all the others are doing — just like they did with google analytics et al.
Not knowing the law is not an excuse which will help you once someone sues you tho.
This is evidenced by the fact that the GDPR already made these actions illegal with huge penalties and it has had scarcely any effect. Most websites just ignore it completely as a "strange foreign law", including this one.
You’re being tracked in incognito mode, too.
It was complicated and never caught on. I'd say the basic problem (visible also in the DNT fiasco) is that if you ask a user in a global and easy to understand way if he wants to accept tracking cookies, he'll say "no" once and for all, and that's it: you just disabled all tracking cookies everywhere. The only way it can work from the point of view of the tracking companies is to use these obnoxious dialogs everywhere: that way, at least some people will accept the cookies from lazyness.
Frustratingly it seems to have worked. Recently I had to explain cookies vs tracking to a data protection analyst at work.
I get really annoyed at having to care. The economics for content sites are so poor I feel bad for a lot of them.
> This is not about storing cookies or not alone, it is about consent to do so.
Yes, and regulators misjudged the incentives. Relying on each website to create the consent UI leads to a bad outcome for users.
For everything else, just say no.
First, every shady website that despite the UX detriments decide that they want to sell their users must publicly state that. That is a feature. I want to know that, I want to see how far in dark patterns they are willing to go to absolutely ruin any trust they imagine they could exploit.
Second, while (most of) these popups are illegal it is so abundantly clear what and how they are trying to get away with it. If the "browser" did this for me I wouldn't know what absolute illegal nonsense they would try to sneak in via "legitimate interest".
Third, normal decently behaved sites/operators obviously don't have cookie-banners at all. That is also a feature, it is an edge. If you see two sites for X one with a cookie-banner and one without it is clear as day which one you'd close and forget.
The times I've backed out of sites because of cookie banners is uncountable. And it is liberating.
Software engineering: the last bastion of legitimacy for people who still seem to have a fundamental issue with the idea of consent.
And if it goes via browser you can deliberately choose advertisers you trust, centrally in one place.
Of course I want this in the browser.
To have it set in the browser is quite detrimental to online privacy. Legitimate interest is an attempt to circumvent the law. It is not like your browser is sentient and could recognize that.
In that case, starting to go after big corps that abuse legitimate interest with GDPR fines should sort the problem out pretty quickly
Youtube was drastically improved recently (due to fines), for example.
> If the "browser" did this for me I wouldn't know what absolute illegal nonsense they would try to sneak in via "legitimate interest".
Of course you would, if it's done properly. The browser would be able to list the cookies too, but in this case in one consistent UI that wasn't built with malicious intent.
Which is also a huge cost. As you say, users want a "no and never ask me again". Well, you can have that today. Just don't do anything that requires anyone to say no.
And again, if a site chooses that path then the banner is a feature. It is disrespectful and although it is a royal pain it is very good for users to know up front what kind of entity they are dealing with. Remove that and people will become apathetic to it.
Also I said this in the context of GPs statement in that legitimate interest couldn't be handled. So it without saying it goes alongside a general advertisement cookie rejection.
The fact that almost all websites use cookie banners kinda disproves your theory.
Website operators need analytics and advertising to do their job and generate revenue. Most media runs at razor thin profits, so building those tools in-house or not using interest-based advertising would make those websites economically not viable.
I understand that your argument will be "so close down those websites". But how about you do not visit them instead?
Really not true. And it gets better for every year.
Analytics and advertising does not need tracking.
> I understand that your argument will be "so close down those websites". But how about you do not visit them instead?
I try to avoid. I'm not perfect, sometimes I can't be bothered. Cookie-banners helps me decide which sites not to visit and is a constant reminder of what crappy companies still rely on them.
It is a feature. And it is pretty damning to see which developers ruins their UX for this.
Here is the thing, this has run unchecked for far too long and it takes time to change. Just look in this thread (or any other cookie-related thread on this site or on any site on the internet). People that are supposed to know still are confused and have absolute no idea that cookie-banners is an active choice for site operators. They have/had no incentive to care. Now they do, but they are so deep in denial that it will take years and years for them to even realize that the "cookie-law" was never about cookies or that these banners are an active choice.
The default is tracking, for no real reason. Sites that earn on the order of cents absolutely wreak havoc on the internet just because developers are clueless.
But the best part is that it gets better for every year. Really, it is so slow so you barely notice but if you you'd take a snapshot today and one from a year ago the difference is stark.
Only last month google of all places (because of fines, obviously) changed the youtube banner so that rejecting is the same number of clicks as acceptance. Previously rejecting took five clicks (or was it six?) and some scrolling to be able to perform all those clicks.
I want to know if people who consumed X bit of the website also consumed Y. If those are correlated, it's a good idea to give Y-like content to people who like X-like content. If they aren't correlated, it's a huge waste of everyone's time and money.
How do you do that without tracking?
If my employer pushed out garbage there's gonna be a real hit to our reputation (we work in a deeply technical sector - the backlash would really hurt the long term profitability).
The website itself is well organized. There's good reason to believe that people who want some X info will also be interested into Y info (due to legislation or standards set by the industry or simply because there are domain specific trends).
There really is a mutual interest in knowing these correlations. That way some segments won't be pushed useless stuff that they aren't likely to be interested in.
They said we wouldn't need tracking. How would we get those info without tracking?
No, we are not selling that data to anyone and it could be anonymous for all we care (IMO this is more an issue with the http protocol than anything else, but good luck changing that)
Interest-based advertising is a huge con, and in my opinion an egregious waste of energy doing all the data processing, an affront to people’s privacy, and has spent decades now distracting people who could be working on things with actual value.
Sure, you can track my every move on the internet and burn vast amounts of energy analysing that data to say “this is someone with disposable income who likes technology”, or you could just… advertise directly on the sites I frequent, and on YouTube channels I watch. The “targeted” ads I’m exposed to are invariably utterly irrelevant to me anyway. I had a recent spate of adverts for head of department teaching jobs in Dubai… I’ve never taught in my life, and I’ve got no idea what got interpreted as wanting to move to the Middle East.
I doubt it will happen, but I’d love nothing more than advertisers to stop drinking the kool-aid on targeted ads.
^ This, absolutely.
Ah yes, "the leave my money printer alone" defense. Nevermind the exploitive underpinnings and utility through which surveillance capitalism is made possible! Just go over in your corner, and let me exploit the rest of the ignorant rubes.
No. Sorry. Absolutely not. Sometimes a foot has to be put down in the name of common decency, and clearing out a behavior that creates even greater problems. This is one of those times.
This is nonsense, there are plenty of legitimate reasons why a site operator may want to use digital analytics, advertising, etc.
And if it's not your own web application, why should you be allowed to track it?
You need consent to set cookies that are not relevant to the (user-side) functioning of your app/website—and since that's the only way for you to track users outside your own site (an oversimplification, but close enough), naturally you need it to track them beyond there.
You would require consent for this as far as I understand.
I get the idea, but is this really what you want, all the time? Maybe you do, but if I'd ask myself the same question - I think I'd disagree.
If I want to satisfy my interest in how scummy some website is, I sure can do my research. But typically I just don't care, it's an one-click stay. Some random article or some random website happens to pique my interest, I check it out, and all those banners and stuff are misfeatures because I don't care who runs this website and what they're willing to do to earn some money - not for a split second. All I want is to have what I came for, with the best possible signal-to-noise ratio. So read (or maybe I click the "reader view" if the site is too bad), see if the content that I came for is what I wanted, and close the tab. Maybe the content suggests that the site is really good (happens if I notice I've already seen that site more than once or twice) so I'm enticed to stay - then I'd do my research whenever it's worth to bookmark it or subscribe to something, etc.. But that's rare.
This is why I have an ad-blocker - because life is too short to be constantly distracted with all those ads. Even though some can argue they're an indicator of website scumminess. Let me judge that from the actual content, not the paraphernalia around it.
And this is the logic why I want to see that utopic world where browsers are back to being user agents, acting on my behalf and my instructions for my personal benefit. Sadly, I doubt this is ever going to be the case.
But I do want my browser to automatically act based on the decisions I've informed it about. And I don't particularly mind if it would explicitly ask me to pick "yes or no" on a few questions the very first time I start it, if that's what's needed for the consensus. I think all the noise about DNT from the ad industry was about it having some default setting - okay, if it would ask me "do you want to be tracked? yes/no" (or even "yes/no/it's complicated, show me some advanced settings...") one single time I start the browser - I guess I can live with that, if this would get those banners out and my choice will be properly respected everywhere.
Something browser-based that would show icon in address bar similar to http:// protocl would be far more effective in letting me prefer banner-less websites.
https://en.wikipedia.org/wiki/Do_Not_Track
https://www.eff.org/nb/issues/do-not-track
The problem is not of UX. It's of law as Apreche has already commented (https://news.ycombinator.com/item?id=31291960).
DNT was a warning.
The answer is now tools such as cookie blockers and Tor.
But DNT and a legal mandate that both browser vendors and sites must comply with it, is the only way out of this.
Otherwise ... so long, World Wide Web. We had a good thirty years. Been nice knowing you.
Gemini, Tor, and the like, are the path out.
Like
DNT: 1 == no cookies, except technical required cookies, like sessions
DNT: 0 == accept all cookies
If you don't like repurposing the DNT header you could also imagine introducing a new header for this purpose.
What would happen?
[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/DN...
1. DNT’s already failed as a opt out since less scrupulous actors either ignored it, or used it an an extra tracking signal (!)
2. More scrupulous actors would likely take the view that DNT can’t express adequate consent for tracking (no granularity or evidence of informed consent to privacy policies).
in the browser's settings:
[] only allow login cookies (and maybe some other standard essential)
[] ask every time
[] gimme all the cookies...
How would this work? Maybe a w3m-standard for various cookie types? An
API for the common things that are done with cookies?The browsers need to provide a method to persist those essential data such that it can only be used for that intended purpose. Then all 'un-standard' cookies can be blocked per User's preference. Sites that really do need extra cookie features must convince the user.
First, set a default of either accepting all cookies, accepting cookies but deleting them after you close all the tabs from that site, or accepting no cookies. Then, per site, you can change that site default to a different setting than your global default. Then, you can temporarily override the site default, but that override will revert after you close the browser session (or you can manually clear the override so it goes back to the site default.)
These settings are separate for first-party and third-party cookies. It didn't handle localStorage because that wasn't a thing when it was written. IIRC you could also delete all cookies from the current site manually, or open up a window to view all of them (and delete them individually from that window.) All of these functions were a click and a drag away, and none deeper than a secondary menu.
What I'm saying is if the bizarre restrictions that both Firefox and Chrome have put on browser extensions keep this from being packaged as an addon any more, build a browser that has it built in.
edit: add to that a global toggle for popups when sites make cookie/localStorage requests that you've set to be denied, and that's a pretty complete featureset for me.
Still not ready to enable the scheduled deletion but I clear it once a week to find new things I need to whitelist. It can handle all storage types and even has some limited support for tab containers. Setting up the rules is time consuming though.
The first step might be creating a shared JS library for generic remote list management (periodically checking for updates, downloading lists, managing local list versioning) that extension developers can use in their extensions.
>We examined a UI component that we see every day, but that the designers did not design correctly.
What’s the point of this article? The cookie consent UIs do exactly what the designer intended: Trick users into clicking “accept all”.
The article talks about dark patterns as if they are engineering mistakes. I doubt anyone in control of those sites would agree.
As a user, i honestly don't care how the site funds their internal expenses, as long as it's lawful.
If they want to charge me money for it, the just have to ask.
I for one am very thankful for the cookies and tracking that brought us the modern web. It's made a humongous impact on my life.
That's very funny... Do you work in ads or something?
No one should get to erode my privacy and have me shut up about it.
And not that they try to get away with the darkest possible patterns until the law is enforced enough and they reluctantly switch to a legal design?
Cookie approve, eula it could be have been anyone who clicked the approve link. So it does not bind the approve action to the person.
It could be your spouse, kid, cat, dog who clicked approve.
Even worse, often the banner is outsourced to parties like onetrust or quantcast. In that case, the site will only ask if the supplier claims to be compliant, and how successful they are in coercing visitors to comply.
However, on their own website, they get it right.
So they do know the rules, they just don't actually follow them in their products.
These companies are not getting around the law, they are simply breaking the law. If a consent popup allows you to accept all tracking immediately, but requires an additional step to opt out of tracking, then it is illegal under GDPR.
We don't need to plead to UX designers, but immediately report companies that don't have a "Reject all" button next to "Accept all", and only show a "More options" button that leads to a maze of settings for opting out of tracking.
https://www.theverge.com/2022/4/21/23035289/google-reject-al...
I am using a browser extension called "I don't care about cookies" which is kinda a popup blocker for these messages. But I wish there was something better, like a setting in browser. Right now the internet is broken with these consent popups.
Cookie consent is dumb.
Cookies are not bad, and in fact are required for basically any website. What is the point of agreeing to them over and over again, when your only alternative is to not use the internet, or at least not to use that site?
Some companies might do bad things with cookies, but how does it help to condition us to agree to cookies on every website we visit.
The fix is to repeal this dumb law.
One should take care when writing a law aimed at advertisers, because they will find ways to make the greatest laws look stupid; no matter how sane they were on paper. (and this law was very sane indeed, but sadly still far too nice)
I don't want to outright force them out of business, since we do still need advertisers occasionally. But laws will definitely need to be yet even more strict.
What does require consent is advertising/tracking/metrics cookies.
Transactions (for data) require consent.
TV, Radio, Magazines, Newspapers etc have worked for years just fine with generic, non-personalised ads. Or in the case of cable/sat, non-personalised ads + subscription fees.
If cookie consent forms reduce privacy violations, lower ad revenue and push these “content creators” off the web, that seems like a win-win to me.
Yeah, and you'll be damned if you ever have to adjust how your business works in order to satisfy the desires of customers not to be tracked and monitored.
I, and most people, have UNIVERSALLY found that we can just skip paying by skipping reading and lose out on nothing. And now we're not being tracked! Hooray! What's not to love? We can't read as much poorly-written op-eds? I think we'll be fine.
The fact that the law basically says you can’t cookie wall it (I.e accept or leave) just means that you either convince enough people that the price is acceptable, or you get off the internet. It’s not complicated.
So you show the service, with untracked ads. That’s it.
And if that doesn’t pay the bills, then you change business model or shut down shop. It’s not complicated.
tl:dr; making the user click "I agree" would work more for you in a court setting
The fix is to have the law recognize that data is extremely valuable personal property, that stealing it is a criminal act and that the predatory "buying" of it (such as offering a $ service in exchange for $$$$$$ worth of data) should be highly regulated.
Secondly, not all data can be treated as equally valuable, let alone "extremely" valuable. That depends on factors such as what the data is, who is using it, and how. A dump of user activity on a cosmetics site might be useless to a layman, moderately valuable to an academic researcher, and highly valuable to a fashion marketer.
Finally, if all data is extremely valuable, then anyone entering bogus data should be persecuted for fraud.
The solution is to educate the population on how these technologies work so that they understand the risks involved with surfing the web. These consent boxes are beyond useless because consent should be implicit when simply using the Internet. Ad block technology takes care of a lot of this already
Browsers do not "willingly provide" anything. Code is written to trigger functionality. You're ascribing motivation where there is none. Developers willingly write that code.
>If this is considered "theft", then copying anything without removing the original would be theft, which would be a huge problem for anyone advocating for free file sharing or "piracy".
Non-sequitur. Just because the API is there, does not mandate it's use. Free file sharing or even "piracy" can still happen without cognitive dissonance. It isn't the copying that is the problem, but rather the storing, caching, processing and monetization that taken together create a surveillance apparatus that is the problem. The connection to piracy, while undoubtedly seductive, fails to pass muster, because ultimately, entertainment wants to reach audience, and reap value, even if only in brand recognition.
Everyone else does not. Advertising fails to realize, the world is not full of brands looking to be recognized.
Actually, it does. That is how cookies work. This is where my sentiment of increased education around browsers and cookies would help.
> Non-sequitur. Just because the API is there, does not mandate it's use. Free file sharing or even "piracy" can still happen without cognitive dissonance.
You should have labeled this paragraph as a tangent rather than a non-sequitur. Copying the data keeps the original in place, but makes a new one for someone else. Thus, that is now their data and they can use it how they please
> Cookie consent is dumb. - Yes!
> Cookies are not bad - Correct!
> Some companies might do bad things with cookies, but how does it help to condition us to agree to cookies on every website we visit.
What? Every site that has a cookie-banner does bad things with cookies. That is the very reason that they have to show it.
Also, it is extremely hard to imagine any beneficial outcomes that tracking would enable to outweigh the UX improvement of removing the consent-banner.
QA departments suffer through this crap all the time.
Both the size, rate and amount of the fines needs to increase by orders of magnitude. The problem (and the internet in general) is simply much bigger than the current enforcement agencies can ever hope to keep up with.
The problem is, where I worked, my boss forced us to add a cookie banner even though we do not actually have any tracking cookies at all, and have no plans to add them, because that’s not our business model. It is just a legal CYA, because the business we’re in is highly regulated.
It’s the problem with government solutions. Everybody’s so paranoid that they wind up overcorrecting.
Seriously, no one’s life has been harmed by tracking cookies. The fears are overblown. Plus we can find alternative ways to track people. Aside from that, most people just consent to cookies anyway, and they’re fine.
The objective is to reduce the need for advertising, whenever possible (most of the time, it's not).
Advertising (static banners, in-house analytics by different companies) is fine but tracking the entire human population across the entire web and aggregating the data is not. Things might seem stable right now, but do you really trust corporations and governments to keep that data safe in perpetuity and to never use it for nefarious purposes?
To give you an example, right now you have the US on backwards path of banning abortions, how would you feel about the government using browsing history and analytics collected by Google and other corporations to track down women who are seeking or thinking about an abortion? Regimes and laws change, data stays forever.
> Thankfully these out of touch, delusional opinions are a minority.
Considering the progress we're making with EU regulations such as GDPR, you're certainly wrong. People are starting to become more informed with every passing year and are starting to pay more attention. Industry practices are also slowly changing to make it easier to opt-out of intrusive tracking, which is a net win even for those who don't pay much attention to their privacy posture.
We're going in the right direction.
I would argue that privacy is a basic human right and tracking (stalking) should be taken seriously.
Would you say the same thing about stalkers following you on the street, watching you from a distance and browsing through your trash? As long as they don't do anything to you, is it all okay?
No, it's not and you would get a restraining order (i.e. GDPR)
> The fears are overblown. Plus we can find alternative ways to track people.
Yeah that's not creepy at all.
If you can guarantee they will not do anything and are just collecting information for some other purpose, then no it doesn’t matter.
https://www.annefrank.org/en/timeline/70/the-amsterdam-munic...
In particular these annoying walls would get you fined.
Lots of downsides to that of course, but it would deal with all of this crap.
All cookie-banners are an active choice by site operators.
Cookie banners on page load are not necessary for consent. The user can provide consent at the point of enabling the feature or setting. Of course, non-exempt cookies can not be stored until consent has been obtained.
Irrespective, here's the fundamental problem – the whole thing is about a technical detail – cookie – rather than meaningful outcome for the user.
A modern online app has to keep shared inter-related state on client-side and server-side and persists for several months and use that state for doing various things like security, abuse prevention, personal preferences (and other types of automated personalisation), monetary incentives optimisations (free-trial, limited offers, conditional offers etc.). Then there is commercial product ads cost optimisation based on expressed and inferred interests of the users. IMO, all this should be okay.
But then what is not okay? –
The line between personalisation vs discrimination is a thin one. In ecommerce, insurance etc – there are regulations restricting price personalisation to protect consumer interests. In other domains, different users can get different experiences and those decisions are opaque to the consumer.
Then there is targeted psychological manipulation at scale.
People have instinctual fear/discomfort about companies amassing longitudinal demographic/behavioural data associated with their PII data. There is a real risk of companies using that data against users interests in both direct material and indirect non-material ways. Companies have a motive to increase their profits and without guardrails they will go to extremes in seeking profits that will hurt the users. There are a lot of examples of insidious behaviour – they may want to cover up flaws that could be harmful to humans/animals directly or harm environment and hence harm humans/animals indirectly, flaws that render the product useless and hence cost them support costs or be forced to recall the product etc. Recently, I was shocked to learn about how lead being mixed into petrol/diesel in US was marketed effectively for decades. With the power of big data, how much more effective such a campaign would have been. (It is easier to look at an example from decades ago more objectively than an example from our current time).
There have been information wars in all ages – in the age of verbally narrated stories, then stage drama with touring companies, then printing press, then telegraph, then broadcast radio, then distributed cinema, then broadcast tv, then broadcast cable tv, and now Internet. The different between all the previous ones and Internet today is the speed, intensity and effectiveness of it at scale. That's what makes it much more scarier than all those previous attempts.
In this context, fighting cookies is a very nice strawman distraction.
https://uxdesign.cc/unethical-design-of-cookie-consent-windo...
An online store keeping track of what products you looked at before a purchase on their own website is similar to a physical store watching for shopper patterns, and is completely different than a Facebook shadow profile correlated all over the web.
Cookie consent is like putting a list of all pesticides on vegetables: it's nice to know, but honestly why put the burden on the population to be experts in chemistry? And all pure-tech solutions always fail when the company you want to stop makes the browser.
The fix is to simply to not track any users in any way, shape, or form. Don't have to worry about opting in or out if there is nothing to opt in to in the first place.
edit: It’s not, just the page! Hush is meant to reduce the hassle associated with cookie requests, so I am assuming that there must be some example of offending code in the blog post. I’ll check it out later.
[1]: https://www.i-dont-care-about-cookies.eu/
* I know, this is not what the author meant. But it just fits here and in case if there is still somewone who not use it.
(blanket denial instead of blanket consent)
I am a former web developer and back-in-the-day I wrote the cookies / session handling logic for an agency's homebrew framework. I understand the DOM, the data layer, tag management, local storage objects etc.
Giving people more control about how their data is used is laudable. In Europe, privacy is considered a human (cf. citizen or consumer) right. Clickstream data can be highly revealing of a person's interests and behaviours. The “invisible processing” of huge datasets of such personal data has the potential to surreptitiously erode privacy and impact on people’s lives.
Nevertheless, ‘cookies law’ is bad law:
1. It regulates the technology not the activity. It applies whether the use of cookies is for basic webstats, or to hive data off to data aggregators for profiling for remarketing, fraud prevention etc. Having to explain and control all cookie-based activities from the benign to the potentially intrusive, through the same UX, is difficult. It impedes one’s ability to have a proper discussion with the user about fair value exchange for their data.
2. It is written in out-of-date terminology (“terminal equipment”) and confuses the concept of “cookies” (storing AND retrieving information) with the actual regulated activity (storing OR retrieving information from a device). I recently saw a proposal from a BigTech which fundamentally misunderstood the scope of the regulation – perhaps deliberately – and I see this confusion arise time and time again in practice.
3. Its exemptions and exclusions are narrow and ambiguous. Consent is needed unless the information collection is “strictly necessary in order to provide an information society service explicitly requested by the subscriber or user”. GDPR’s legitimate and public interest grounds are not therefore available for the collection of data, even if they later become available for the use of that data (even that is controversial and lacking in clarity: bifurcating approach to e-PD and GDPR may not find favour with regulators).
Then there’s a whole other debate about browser vendors, APIs and the various misaligned interests which conspire to prevent industry-led solutions to this problem. And vendors and consultants who go around recommending widgets, seemingly armed with only an elementary understanding of the underlying law. The result is to push the problem onto individuals through ugly, jarring UX which is often ineffective, both in communicating and delivering its intent. I often still see data collection notwithstanding which buttons I click.
Basically, everyone could do better. (I am sure us lawyers are not blameless either!)