I've actually started to reject nonessential cookies most of the time now. Doubt it matters at all.
What makes you say they don't need them?
There are a bunch of different kinds of payment gateway integrations, with various tradeoffs.
However a common pattern, at least at the time, was to use an iframe with the payment form in it.
Our form was multi page, and used cookie based sessions to track state between pages, so when they started being blocked, the payment form stopped working for safari users. The solution we chose at the time was to put the session id into the URL, but that has it's own security issues. There are other ways to address that particular issue that don't involve cookies, but would have required a significant rewrite of the system.
Some potentially legitimate ongoing use cases for 3rd party cookies, would be remembering payment details, and one click checkout across various sites that use the same payment gateway.
It should also be noted that these popups are likely not legal (or rather, they probably don't constitute informed consent under the the GDPR), but that's a completely different discussion to be had.
Who does "you" refer to in this sentence? A random business that doesn't like the warnings? How can that random business force everyone to do it for everything?
If a site is asking for consent, they're either idiots who don't understand what the law requires of them or they intend on tracking their users.
Not to mention teaching users who are not tech-savvy to blindly click "I Accept" and "I Agree" without thinking about it which is an absolute disaster since such users cannot distinguish between a marketing cookie prompt and an OS elevation prompt coming from a piece of malware they just downloaded.
Since untracked ads pay 80-90% less than tracked ones, they are borderline required by every site that requires advertising to survive (most websites).
In a way I'm sure it's added to vendor lock in, any random Google result you click is guaranteed to hit you with the banner, which on mobile is especially annoying when since they're also required to be prominent (ie take up half the screen because everything in that law is incredibly vague).
There's a browser extension that automatically rejects cookies on these popups - https://consentomatic.au.dk/. I've found it works for most websites.
The problem with browser extensions is... you have to trust them.
I feel like EU regulators should have worked with web standards committees to add a technical means and requirement to classify cookies. Then browser vendors could allow users to choose which types of cookies they are willing to accept from which websites.
A link to a page where visitors can opt-in would work just fine and not be obnoxious. The banners are obnoxious not because it's impossible, but because the very idea of consent goes against the business' goals. Or their just lazy: You don't need PII to track marketing performance, and if you aren't unnecessarily collecting PII, you don't need to ask.
> I feel like EU regulators should have worked with web standards committees to add a technical means and requirement to classify cookies.
Hardly anyone would use it, because most companies aren't seriously interested in getting consent. They are interested in data, and consent is merely a hoop to jump through.
If it were to see widespread adoption then all you would have to do is change a setting in your browser.
- Needing writing a documentation (which is viewable even if cookies, CSS, and JavaScripts are disabled) about what each cookies means. (This includes both necessary and unnecessary cookies.)
- Writing a better web browser(s) with more user controls, and can more easily modify it and recompile, etc. (This way, you can more easily adjust individual cookies more finely, including which cookies are enabled, duration overrides, values, etc.)
Do you mean “Consent is only needed...”, because while the existing word order is grammatically viable, it doesn't communicate anything that makes sense with the rest of the post.
Understand that cookie banners are malicious compliance and they make a lot more sense.
If the vague proposal I’m suggesting sounds outlandish, that’s more or less how every major browser implements other requests for intrusive APIs as a matter of protecting users. Even when they do it half-heartedly they do it by developing a standard with their more invested peers which is far less prone to universal abuse.
> Understand that cookie banners are malicious compliance and they make a lot more sense.
How are they malicious compliance? The laws are poorly-reasoned and poorly-written. I'll continue to be mad about that.
*Edit: Sorry if this came off as rude but it was a legitimate question. I honestly cannot think of another plausible reason that would explain the proliferation of the banners.
> “The legislative department is everywhere extending the sphere of its activity, and drawing all power into its impetuous vortex.” -Madison, Federalist No. 48
HN is still in a love affair with GDPR.
Nice things need to be thoroughly thought out.