“I don’t care about cookies“ web extension acquired by Avast
i-dont-care-about-cookies.eu
i-dont-care-about-cookies.eu
Judging by the size of the user base the author was paid at least 100k USD, all for an open source project that is free to fork. Avast has acquired you, the user, and the original maintainer continuing to work on the project is just a ruse, the new owners prefer to do it this way to reduce user loss until the business end of a future extension update is pushed out to your devices.
```
javascript:(function()%7B%20let%20i%2C%20elements%20%3D%20document.querySelectorAll('body%20*')%3B%20for%20(i%20%3D%200%3B%20i%20%3C%20elements.length%3B%20i%2B%2B)%20%7B%20if(getComputedStyle(elements%5Bi%5D).position%20%3D%3D%3D%20'fixed'%20%7C%7C%20getComputedStyle(elements%5Bi%5D).position%20%3D%3D%3D%20'sticky')%7B%20elements%5Bi%5D.parentNode.removeChild(elements%5Bi%5D)%3B%20%7D%20%7D%20%7D)()
```
javascript:(function(){window.location.href = "https://hn.algolia.com/?q=" + window.location.href;})();For example, video embeds rarely work because they need to know if you accept cookies before deciding which preroll ad to play.
The same works for vimeo, dailymotion, etc. Even if the video embed doesn't even get created in the first place because I didn't run that page's javascript (I only run javacript on a whitelist basis), I can usually watch a video that would have been embedded in it by simply directing mpv to the hosting page itself. This even works for most local news websites (which seem to be the trashiest sort of pages on the web.)
That's a super neat feature - where does it come from? uMatrix?
From a quick Google on how to open URLs with mpv.
Seems like a neat hobbyist / handy tool space that quickly turned into a sorta predatory space.
These developers are then offered funds for perhaps a new home, and they can hardly be faulted for taking the deal. This issue can only be solved by finding better ways to fund the development of popular software projects that serve the public good.
https://armin.dev/blog/2019/08/supporting-browser-extension-...
Linux distros manage fine without such sales - and this kind of behaviour would get a maintainer kicked and probably marked for life. Too bad that Browsers have chosen a free for all store model instead a maintained distro model. Meanwhile Mozilla keeps locking down installing extensions outside their store for "security".
For trying to cash out and retiring for maintenance they'd be excluded from ongoing development? This is precisely what I meant by not shaming people for selling off their product.
There are a lot of assholes out there that are far more worthy recipients of your ire - I'm sure this extension wasn't acquired for 1.2 billion.
And yes, there are always bigger assholes - that's never an excuse.
Rando popular freeware suddenly has an installer from hell and so on.
For those looking for the list, here it is: https://www.i-dont-care-about-cookies.eu/abp/
I think the IDCAC extension would probably not even exist if it was just a simple filter...
This might have been their best/only option. The only other approach would be to notify them post-update.
I've never understood why operating systems allow focus switching.
It's always been a pox on Windows, but macOS does this more and more these days. Just this morning, I plugged in a USB hard drive, then returned to my other work while it mounted. Suddenly, I'm typing a memo into Finder's password field to unlock the drive. Just. Stop. It.
If you need my attention, there is no shortage of methods to do that — Beep. Bounce the icon in the dock. Notifications messages. Your stupid program is not more important than whatever I'm doing at that moment in time.
Normally I would lol at your misfortune but I actually got bitten by this too.
I restarted after a macOS update (remember when they used to update in the background and now every one requires a restart like Windows?) and 1Password needed my master password to unlock in the browser but apparently Messages app took a few seconds to load and when I saw the notification to enter my 1Pass master password I started typing and at that moment Messages took focus and I typed my master password into a message and hit enter to send.
Thankfully it was to my girlfriend, but still wtf.
KDE calls this "Focus stealing" and has a setting to disable it.
Students: have 4 hours of homework per day
The latest app that needs their notifications disabled on my phone is Amazon. Shame really, knowing about packages was useful. But I really don't need spam about "Hey this thing you glanced at is on sale now" every 2 days.
Every new app I installed gets every permission I can disable disabled including notifications and if it continues to function well enough for my needs why let it do anything more? Why even give new apps opportunity to be obnoxious?
These days I no longer give notification permissions to apps. But I used to. So I go back and remove when someone’s being a problem.
Is there a general name for this sort of bias? It's not just phone apps and notifications; I notice this center of the universe attitude in developers of all kinds of auxiliary programs. Chat app programmers who think that quip "unused ram is wasted ram", which they learned in the context of the OS caching files in ram, gives their chat app license to use as much ram as the user may have. It ignores all the other programs the user is probably running that are much more important than their chat app. To the chat app developer, the chat app is the center of the universe and the user has no use for any of their ram besides running the chat app.
selfishness?
Why much I jump through countless hoops just to make it so a third party doesn't have the ability to take over the full screen and audio of the device I was actively using?
Ideally an incoming call would only vibrate the device briefly and put an icon in the status bar. That's it. Instead, I don't remember what I did anymore but it's completely suppressed on my device now. It's actually worked out OK because I don't give my number to anyone new and anyone who does know it also knows by now that I don't pick up and to contact me some other way. Means that ~100% of incoming calls are spam and my device is correctly filtering them all to /dev/null
It's a pretty safe bet you can throw any mail that has "IMPORTANT" printed on the envelope in the trash.
Every online store, software vendor and web site wishes they could get my attention for an "IMPORTANT" message at least 100x more often than I wish they did.
The kind of company that would abuse an extension API like this for marketing is just the kind of company I wouldn't trust for extensions, so even spammy marketing messages would still be a useful signal (to uninstall).
What I don't particularly care about is "performance optimizations and bug fixes". If that's all you have to say about your latest release, just don't bother telling me. I suspect that's where some of the fatigue from release notes comes from.
Sure enough, a week later I received an email saying it was safe to upgrade to iOS 16, provided I updated the app in the App Store first.
And as frustrated as I was that a company that large with a product so safety critical had waited literally months after the iOS betas before testing iOS16, I was more frustrated when I read the release notes for this incredibly important update:
“Bug fixes and performance optimizations”
I'd prefer a less intrusive way of notifying me of the change, but in this case the extension in question is one that works passively in the background, and doesn't have a UI that users regularly interact with. I can't really think of a better way to inform people, except maybe via the notification API?
In order to detect those keyboard short cuts, they need to listen for them.
You are free to not give them permission.
Posting about asking permission under a comment talking about "abusive" behavior is a bit odd.
Analogously, i am sure that discord would have preferred to have finer control over the permissions it requests, but Apple's mission is security theater. If apple exposed a set of "application specific out of focus keybinds". The security breach would not be necessary.
As it stands lots of software in the apple ecosystem has identical permissions to discord, but those don't get scary warnings associated to them. This constitutes a (clearly illegal) competitive advantage for Apple and they have no interest in removing this advantage by offering finer permissions controls, even in the case where they do not offer competing software.
Many people complain about OSes and apps for that matter, stealing focus inappropriately.
Edit: Maybe it is just a talent acquisition?
[1]: https://www.vice.com/en/article/qjdkq7/avast-antivirus-sells...
[2]: https://palant.info/2019/12/03/mozilla-removes-avast-extensi...
blanket optimism sounds like a nice lifestyle of the young, but with age comes realization the world only takes advantage and wisdom leads to being more pessimistic. question everything including authority is how i was raised.
We will know definitively when the next updates to the extension comes out. Until then we are all just speculating.
That being said, the security consciousness user should probably switch to a pre-acquisition fork such as https://github.com/OhMyGuus/I-Dont-Care-About-Cookies
https://www.vice.com/en/article/qjdkq7/avast-antivirus-sells...
so calling them 'a famous and trustworthy IT company' is quite a thing. infamous perhaps.
Implementing this into a browser would be the biggest QOL improvement any web browser could possibly do at this point.
What I would like to see browsers do is grow a feature that tells web servers what uses of my data I consider acceptable, so that I don't have to waste my time every time I visit nearly every site on the entire damn Internet.
But we've been there before - P3P, Do-Not-Track, and now Global Privacy Control. Until regulators force web sites to obey signals from browsers, we're going to be stuck with these bloody popups.
Opt-out means the website loads, creates all the cookies it wants unless you find some hidden option to disable cookies.
Opt-in means the website loads, it does not create cookies, but because the website wants to create cookies it will show a popup asking permission (opt-in), because it is illegal otherwise. The website does not have to create cookies. The creators of the website could simply choose that cookies are not necessary and in that case they are not required to show any consent request. The EU cookie opt-in legislation works as intended.
We are stuck in this adversarial environment unfortunately.
The people that should be mocked are the EU bureaucrats that thought this was a good idea and the people that defend it.
It's a idiotic legislation that does NOTHING to protect your data. It's feel-good nonsense that EU can occasionally use as a club to extort business corporations that they want something from.
The only thing that it accomplished is to create a false sense of security in the public.
These companies are not trustworthy and neither is the EU government.
The correct solution to this problem is at the browser level and at the human level. Don't disclose information to the internet you don't want to show up on the internet.
Absolute nonsense. Tracking has to be disclosed, and is only permitted after obtaining informed consent from users. Without the law I'd have no idea what thousands of companies are doing with my data, without my consent.
This means that before getting your consent, each website has to show you the text. And they cannot get your consent from a setting that does not correspond to them, specifically.
So if you tell your browser: « I accept that website track me on what I do on them, but do not allow marketing related stuff », website are not allowed to recognise that level of consent, skip the banner and act accordingly.
Websites only have to ask consent to track you if they track you in the first place. Sucks to suck.
Any website showing a cookie banner already prioritizes their ad revenue over your convenience of not seeing a banner. So why would they implement any extra work to spare you that banner, if you're one of those customers that won't drive ad revenue?
So, please read those pages - on every website - then systematically click on "Reject all". That's what the law asks you to do, and it is indeed absolutely nuts.
A decently-designed website would just tell you it's about to set a cookie with a “more info” link. If you choose to go ahead, that's informed specific consent.
Besides, under the GDPR companies can collect and store personal data without needing consent if it's for one of the listed permitted purposes. They only need consent at all if they have no good reason to collect the data — consent is really supposed to be the excuse of last resort.
cookies are local storage. cookie prompts are you telling the server how you'd like it to instruct your client to behave. it's so weirdly roundabout: if EU wanted this regulated why didn't they just tell browser vendors that they need to implement cookie control as a 1st-party feature?
In other words: browsers are perfectly allowed and capable of implementing the setting, but websites are forbidden to use it.
Yep, it’s that crazy. The legislator really likes blocking banners.
The desire of developers to get around distro maintainers and grab full control of update distribution is strong...
I cannot trust either Mozilla or Google's extension repositories, they are 'managed' in a substandard manner relative to Debian or android's F-Droid. Both of these extension repositories are managed so poorly it seems farcical to say they're managed at all.
I'd like such a repository too, but the "extensions going bad" dynamic usually happens with the full cooperation of the extension's developer, so I could imagine many extension developers would be actively opposed to such a repo. Therefore, the browser would have to possibly act against the wishes of the developers here and e.g. keep an earlier version of an extension available even if the developer would like to remove it.
If this extension were a program packaged by Debian or F-Droid, this wouldn't happen. The upstream can sell out and start publishing malicious updates but they can't push those updates to Debian or F-Droid, because they don't have the necessary permissions to do so. They would need to buy out or trick the Debian or F-Droid package maintainers, which I generally trust to not happen (and I haven't been burned by this trust before.)
This scheme works fine for the majority of software I give a shit about. Some developers don't like this scheme and that's fine, for the most part I simply choose to not use their software. I don't want this scheme forced on either users or developers, it's entirely voluntary on both ends. It could exist for browsers just as it does for linux and android, but as far as I know it presently doesn't.
there's loads of UX improvements to be made. i update the plugins with `nix flake update` and `nixos-rebuild switch` and that process tells me which repos have new commits, but getting to a changelog for the relevant plugins is manual enough that i skip it. but it very much seems like a good direction to me.
https://github.com/elgrove/idcac-3.4.2
I am not well versed in open source licensing but I believe the GPL3 gives me permission to do this. Please could someone more knowledgeable confirm this for me.
I am not a web developer, I'm hosting the code in the hope that someone else will take it and fork it. It's one of my favourite extensions and a day 1 install on any new machine, along with UBO
The problem with consent pop-ups isn't the European law; it's the failure to properly enforce it.
These days for privacy with Firefox you really don't need anything else. There are a few others that may have something to offer https://github.com/arkenfox/user.js/wiki/4.1-Extensions for specific purposes.
In fact, that already happened, and that’s why it’s called uBlock Origin: https://en.wikipedia.org/wiki/uBlock_Origin
> The uBlock project official repository was transferred to Chris Aljoudi by original developer Raymond Hill in April 2015, due to frustration of dealing with requests. However, Hill immediately self-forked it and continued the effort there. This version was later renamed uBlock Origin and it has been completely divorced from Aljoudi's uBlock. Aljoudi created ublock.org to host and promote uBlock and to request donations. In response, uBlock's founder Raymond Hill stated that "the donations sought by ublock.org are not benefiting any of those who contributed most to create uBlock Origin.” The development of uBlock stopped in August 2015 and it has been sporadically updated since January 2017. In July 2018, ublock.org was acquired by AdBlock, and since February 2019, uBlock began allowing "Acceptable Ads", a program run by Adblock Plus that allows some ads which are deemed "acceptable", and for which the larger publishers pay a fee. uBlock Origin remains independent and does not allow ads for payment.
I think using uBlock etc is more likely to result in preventing tracking through blocking known urls and code etc compared to hiding consent forms... I know it's far from infallible but currently most trackers don't bother going to extremes if you block them.
Don't do this, it doesn't work the way you think, but in fact makes your browser easier to fingerprint. Very few people use that extension.
This was an extension for people who don’t care about privacy.
So I went for a solution that makes browsing less annoying, whithout storing many cookies:
- Have this add on accept all cookies - Block third party cookies - Delete cookies from websites as soon as I close a tab
I (and you) don't know if many users of this add on do something similar, but it is what's recommended on the website
> Please educate yourself about cookie related privacy issues and ways to protect yourself and your data. For example, you can block 3rd party cookies, install ad blocking extensions and then block tracking tools, delete browsing data regularly, enable Tracking Protection in your browser etc.
And besides that, I think it's really naive to assume you've got any influence on tracking that sites do on their site. With cookies I know I can choose to save them on my machine or not. If a website uses the fingerprint of my computer to identify me, they'll almost certainly keep doing that after I've rejected their cookies.
Consent-o-matic is the extension that people use that do care about tracking (or believe that most companies will mostly follow the law, I guess).
Only checked the bundled version but the code seemed very custom and labor intensive to keep up with website changes. Best of luck to future forks and maintainers.
I didn't spend too much time on it, because a filter based approach seemed more maintainable.
You can call Avast many things, but a "trustworthy IT company." is not one of those things.
1. Can we somehow get Mozilla/Firefox ban/de-list the extension from the extension store so Avast doesn't get the user-base this extension has/had?
2. We should be able to get the author to publish the source code of the latest version licensed under GPLv3, any way to do this, except asking on Twitter/LinkedIn?
https://www.gnu.org/licenses/gpl-faq.html#MustSourceBuildToM...
and
https://www.gnu.org/licenses/gpl-3.0.txt section 6, point d
It's in Chrome extensions folder in Profile, in LICENSE.
I think that means the extension can still be put to github even right now and re-distributed.
Auto Cookie Optout are both pretty good.
They also let you block rather tham accept all cookies. Wild to me that the accept all cookies extension has been the winning one, but they have a cute name. You should care though, caring is cool & good, & you should care about privacy online & reducing the vast capitalist-survelliance machinery. It's easy, just use a non apathetic extension instead of one whose whole premise has been apathy.
(I hear uBlock Origin has an anti-annoyance filter or filters that does something to deal with cookie banners but unsure what.)
Not having to wait for Cookiebot's slow servers to get their act together would be quite refreshing.
I delete cookies every time I close the browser anyway.
2 out of 3 of those things are very easy, but "maintain a more community run alternative" is an enormous undertaking.
I hate that I have to, but I have to.
Anyone know of a good alternative?
(No, UBOs annoyance/cookie filters dont come close sadly...)
If you have uBlock Origin, go to settings, filter lists, scroll to bottom, custom, import, paste this URL. Enable AdGuard annoyances while you're at it. It's not perfect, but this replicates the "don't show me cookie dialogs" feature pretty well.
e.g. https://github.com/AdguardTeam/AdguardFilters/tree/master/An...
What does Brave do about the cookie crap?