Fork of the popular “I don't care about cookies” extension
github.com
github.com
According to this german article: https://www.soeren-hentzschel.at/firefox/firefox-sagt-cookie... , you can already set various values for the cookiebanners.service.mode about:config setting on Firefox nightly. 1 denies all cookies, 2 also accepts if there is no option to deny or if denying didn't work.
If you don't trust, don't install. Maybe don't install anything on your machine just to be safe
Firefox can improve their addons security audit, their addons website to help users make a choice... absorbing addons seems like wasting time
Telling your users about what web technologies are and what certain settings mean is also cool.
Wanting to be helpful to a wider audience rather than have a funny easter egg for tech nerds feels like an okay thing to do, once a project is past a certain stage and aims for larger adoption.
That said, seeing "18 years ago" for the message dates in the discussion feels sobering.
(I'll go back into my bubble now.)
If I sign in / store a password for the website, allow cookies.
The GDPR is not about cookies, the freely-given consent requirement applies just the same if they’re tracking you in other ways (perhaps submitting a fingerprint via XHR, or even server-side—arguably just storing IPs in an access log counts[1]). The recorded data doesn’t have to be actively used to identify you, only usable for that purpose in principle.
The earlier 2002 “ePrivacy Directive”[2], which came to be known as “cookie law”, does mention cookies in the motivational part, though the actual text just refers to storing stuff client-side whatever the means. Storage strictly required for the website to function is specifically exempted. Unlike what the GDPR would say later, the preamble said sites would be able to tell users to GTFO if they refuse the cookies.
[1] https://curia.europa.eu/juris/document/document_print.jsf?mo... (ruling), https://gdprhub.eu/index.php?title=CJEU_-_C%E2%80%91582/14_-... (unofficial explanation)
[2] https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX..., recital 25 and article 5(3).
https://www.ghacks.net/2020/10/01/you-can-now-install-any-ad...
I've been using this on Android for a while now and holy crap, never going back.
This makes no sense. Cookies required for operation of a site are not covered by GDPR, so shouldn't be in a cookie consent form.
If you use cookies for your shopping cart, then you do not need to ask permission to create a shopping cart cookie.
In my opinion, this goes against the spirit and the letter of GDPR, but it seems that they are getting away with it for now. The matter hasn't been discussed by the European Court of Justice yet.
In those cases, as a non-paying user, you essentially have the choice between accepting being tracked, or not viewing the site. IDCAC errs on the side of being able to view the site.
[2] https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...
[3] In the case of online raffles, a German court even explicitly allowed forcing users to agree to their data being used for advertising purposes if they want to participate in the raffle. https://openjur.de/u/2185336.html
And I don't think that option is as good as IDCAC (or Consent-O-Matic [0]) + CookieAutoDelete. With those two add-ons even first party cookies are deleted, while you don't need to close banners all the time.
[1] https://www.ghacks.net/2021/07/15/umatrix-has-an-unfixed-vul...
The different UI of uBO was part of this decision, but not the biggest factor. Over time it had gotten less and less workable even with uMatrix's great UI. I could no longer configure a site once and then expect it to work for any amount of time, as the rate at which new mandatory third-party dependencies were added to sites kept increasing. And I was visiting more websites as part of avoiding big sites like Amazon.
In addition, uBO's CNAME unmasking meant that many resources that were considered first party by uMatrix, are treated as third party by uBO. This added to the burden of whitelisting, but also got me thinking about how fuzzy the first party / third party distinction was and that it was increasingly a poor proxy variable for what I was really trying to block (trackers mostly, and also some annoyances).
I also use the Temporary Container extension in Firefox. In the end I decided that the default block lists of uBO combined with the isolation and discarding of persistent data provided by Temporary Containers was good enough for most browsing. I still use a whitelisting approach for my handful of permanent containers, and uBO's dynamic mode UI is good enough for that.
The vulnerability does not seem that serious to me... isn't it going to be pretty obvious if it gets exploited with this description?
> An attacker may exploit the vulnerability to get the extension to crash or cause memory exhaustion according to the researcher. When the extension crashes, users are left without protection until it is reloaded.
So I'm going to start seeing a bunch of ads as my clue, right?
[Not a drive-by:] > It requires that users become active, e.g. by clicking on a link.
The article you linked has plenty of information in the comments, it's actually a good resource.
This vulnerability has been fixed in uMatrix 1.4.2 [0], released few days after the linked news article.
> and has known vulnerabilities
which is demonstrably false. If you want to talk about other points move on to a related sibling sub-thread.
Yes. Because I don't care about cookies. This is not an anti-tracking extension. I do not care about being tracked. I just want to stop being bombarded with cookie consent dialogs.
Once the GDPR came out, now it was required, even admirable, to distract users. Once that window was broken the car got stripped within 24 hours and now it is not unusual to have to dismiss 3 or more pop ups asking you to subscribe to an email newsletter.
The only issue with DNT is that it wasn't mandated.
That it's inconvenient for the tracking industry and thus was ignored is an enforcement issue, not a technical one.
If my browser tells you not to track me, it should be illegal to ask me again.
That's it. We don't call it a user agent for nothing. Or rather, we shouldn't, but we are.
https://en.wikipedia.org/wiki/P3P https://www.w3.org/P3P/
From Wikipedia:
As an example, a user may store in the browser preferences that information about their browsing habits should not be collected. If the policy of a Website states that a cookie is used for this purpose, the browser automatically rejects the cookie.
Corporations essentially had a presumed right to track users. Now they don't, they need to get informed consent first. A DNT header makes the user's non-consent explicit: not only is the user presumed not to have consented to tracking, the presence of this header signals active and explicit denial of consent from the user.
It's not like the evil bit at all. We're dealing with corporations that operate openly on the market. It's perfectly possible to say "it's illegal to ignore this bit" if it comes with the threat of heavy fines attached.
there’s a good example of 25 seconds of constant bombardment for InfoWorld visitors. I cant count the popups.
If I can't use the site while ignoring them, I close the tab.
What I realized after a while that this sort of user-hostile design correlates strongly with poor quality content, so it's also a great way to save my time.
That's not how zero-tolerance works.
I guess I should clarify that in the rare case I still want to access the content, I still do not engage with the modal dialogs, but instead use a proxy service such as archive.is to present it in an accessible way.
I consider modals to be a gross accessibility issue.
I worked on it pretty seriously for two weeks but got hung up on the problem that my web archiving system was never 100% sure that a page had finished loading (that there would be more significant AJAX calls) so it would set long timeouts and even with a lot of stripping out the junk it was going to be even more awkward than dealing with the junk.
Looking back at it however it looked like an overly ambitious project.
Complete sentences may make it possible to pretend bad wording is consistent, but that doesn't make it good wording.
Still a loss for the rest of us who got suckered into reading the last ten or so stupid comments but oh well...
They are not the same thing.
Let's say there is a scale from 0 to 10.
If you accept 1-2, that's low tolerance.
If you reject anything above 0, except this particular 2 and this particular 5, that's zero-tolerance with exceptions.
By zero tolerance, I mean to say that I do not engage with the dialogs in any way, e.g. clicking agree, cancel, close, or the area around the dialog if it is blocking the page.
By few exceptions, I mean that I look for an alternative method to access the content rather than disengaging from it entirely.
I am imperfect, so if you were to observe me 24/7, you would probably see me slip up eventually. But this is an ideal I strive for and for the most part am satisfied with the results of pursuing.
nit: couldn't
though I completely agree with your sentiment
If the first part were true, the second would be your name.
Also your comment doesn't make sense. They're different things.
I'm fine with being tracked by a service operator, I don't want my name to be public.
It's about principles. We simply don't want corporations knowing anything about us unless absolutely necessary. It's bad enough that governments have to know about us. We really don't need the private sector mass surveilling the entire globe and exploiting our data for god knows what purposes.
Data should be a massive legal liability. It should cost them money to hold onto any piece of data about any person. They should be scrambling to forget all about me the second the transaction is finished.
In practice I'd prefer a world without government and with companies tracking me over a government that steals half of my income and protect me from "evil" trackers.
Same thing with abortion. Of course wasting a human life is a tragedy, but it's hard to imagine economic model where you can guarantee the life of a foetus nobody knows much about, without needing a centralised entity. (you could in theory have protection agencies - as in The Machinery of Freedom - which guarantee your safety have you sign a contract saying you won't do that or else - but that would be hard to enforce).
What does "in practice" mean here?
I get the sense that when people say things like this, they think folks would have the lifestyles they currently have in the US, but much better because they don't have to pay any tax. In reality, a world without government would be run by the type of people who run Russia right now.
Great if you're connected to enough strongmen to be an oligarch I suppose but not that great for anyone else.
Okay. Nice to meet you, throwaway787544. Please reply with your real name and address to proceed.
If you walk in on a store that has security cameras in it and you accept to be filmed while you are in there, does that mean that I should be allowed and able to access you entire private photo and video gallery ?
What an absolutely twisted view.
The simplest way would be for companies to stop tracking individuals then they wouldn't need to seek cookie consent.
I would say that, getting companies to convince the user that they would be better if they are tracked would be a good feature. Currently,tracking helps the company and hurts the customer, so companies should come up with a reason why tracking is actually good for the customer.
They are following the law in a way that makes it as annoying as possible for the people whom the law protects.
I don't care a lot about cookies, but if a website is abusive enough that they need to ask for my permission, I prefer to deny it rather than give them a blanket approval (again: what I really care about is wasteful and overbearing JavaScript code that complements tracking via cookie... If I cannot object to that, at least let me object to cookies used for tracking)
Again: you don't need permission for necessary cookies. The fact that the cookie prompt is annoying/difficult to parse and requires opt-out instead of opt-in is against the spirit (and possibly the letter) of the law. If our automation around the cookie prompt is accidentally giving an implicit consent, we ended up doing exactly what the people that push pervasive tracking wanted. We end up rewarding, instead of punishing, people who implemented dark patterns.
How do you tell the difference?
> Again: you don't need permission for necessary cookies.
Usually it's better to ask forgiveness than permission, but I can understand sites wanting to play it safe and throw up a banner even if they only have "legal" cookies.
They should pair it with a "yes, I am an adult" extension.
Use a moral & good & fit to task (not apathetic & consenting extension) like Consent-o-matic[1] or Auto Cookie Optout[2].
Some people actively dont care. Dont do that. Care. Help. Be a positive influence. (Ed: wow, unpopular opinion, over something that costs people nothing to assist in!! -2 points!
I do not care about cookies. Not one person on the Internet can demonstrate a concrete harm caused by the existence of advertiser cookies on their machine. If you want to spend time twiddling these knobs, more power to you. I've got things to do and I will gladly take the first option that erases the annoyance with a minimum of disruption.
I dont get why this proclaimed unwillingness & lack of deciding leads you to pick the worse less defensive pick though. Why actively choose worse defense? I dont get your argumentation. Why is the worse dumber pick better for you, even if you dont feel convinced of the harm? Presented with a defensive & apathetic option, I don't see why you would still choose worse.
It blows my mind that you'd have such disregard for your own personal data protection by not implementing a similar system. Why not spend half a day setting up something that solves the problem long term without depending on you to consciously make the "right" decision over and over?
You're assuming way too much active thought and choice on the part of the people who don't care about cookies. You're assuming that it was a choice between options at all. In my case, a website I was happening to read mentioned the I Don't Care About Cookies extension, and I thought, "oh, it'd be nice to have something that stops all of those annoying cookie pop-ups" and installed it. That is all. Is such an action really an "anti-progressive and pro-shitty attitude"? Am I really harming you or myself or society by doing that?
'Actively not caring' is insidious and depressing. It normalises data surveillance and says there's no point fighting it.
Comments here seem to ask if cookies are really worth all this fuss. Frankly, I don't think it's much of a fuss at all. Block the pop-ups, auto-delete the cookies. It's so simple I'm bemused there's any pushback.
And thanks for the links to those extensions :)
It's a feature not a flaw. See, I literally don't care about cookies. Deny them, allow them, whatever. Just don't bother me. That's exactly what the extension says and does.
I've never understood the obsession with cookies and tracking. It seems that some people imagine Sundar Pichai sitting in his underground lair, following the browsing session of individual Chrome users, cackling with evil delight.
The CEO? No. A disgruntled ex? Yes.
Again, anyone can use this, I really don’t care, but the original author is essentially doing the work of adtech companies (not really surprising that they sold out their users in that context) by lying about the extension.
“I don’t care about cookies“ web extension acquired by Avast - https://news.ycombinator.com/item?id=32850799 - Sept 2022 (215 comments)
I don't care about cookies - https://news.ycombinator.com/item?id=26519457 - March 2021 (187 comments)
Isn't the correct response to say "I always care about unnecessary cookies, don't set them"?
I know there are much less popular extensions that do just this, but I won't link to any because I'm not sure which are best now (just did a search and realised my choice may be out of date).
If a website wants to track a user and sell that data to a couple of hundred data brokers, having to let people know, is in my opinion a good thing. That they go about making that a shitty experience is on them.
I think we can agree that none of us likes to be taken advantage of, and this law is trying to stop that.
EDIT: P.S. The law actually isn't badly written, and the malicious compliance is _breaking_ it. The law accounts for these kinds of behaviours, it's just that nobody has tested it yet. Though there are people trying to bring the widespread law breaking to the attention of the EU
The disagreement is over whether paying for information services with your personal data is being taken advantage of. Yes, there's an imbalance of size, and of information, but the attention market is also intensely competitive and - even in social media - switching costs for the consumer are low. A market-oriented solution would have been to sponsor independent organizations to score websites on privacy.
Sure, if that was clear then we'd be in agreement. The EU law is aiming to make it clearer that you are indeed "paying" for the use of the website with your privacy.
Personally, I'm happy to pay for services with money, and do so whenever I feel a service is good enough. I'd wager a significant portion of average users would be too, if they knew what was happening with the profiles built up on them.
Putting that aside for a moment: If we paid for services, then it would promote good services. When we pay with our privacy, it promotes more effective data collection that doesn't have anything to do with the service, such as a focus on "engagement" (and everything that entails, that you've already alluded to).
E.g., I like to be able to go to facebook.com and be logged in, but when I click an external link, I kind a like to open a tab where I am not logged in. Same for hacker news and Youtube and my email.
When I'm "outside" those websites, sure, just accept all cookies and delete them when I close the tab
I imagine this can be done with Firefox containers and a bit of smarts, but I don't know how.
You can use the extension "Simple Tab Groups"[1] to automatically open some domains in specific Firefox containers like you described, by assigning a container to a group, and then configuring a domain to always open in that group.
The downside is that not all groups will be visible at a time, and you'll need to first select your previous group before finding the tab you came from. For me, that's an acceptable downside given the advantages it brings.
[1] - https://addons.mozilla.org/en-US/firefox/addon/simple-tab-gr...
1. Install Firefox container management extension 2. Make some containers 3. Visit websites and add them to only open in certain containers 4. Install cookie auto delete extension. 5. Add exceptions for sites you want to be logged into for each container the first time you visit them.
I have some other extension that makes a temp container for each new click that I can’t remember the name of now and I’m not by my PC.
Cookie auto delete may be superfluous.
Con is google is still broken for me (mainly gmail) because of the web of redirects they do and there’s no way in the container extension to add a top level domain to a particular extension (that I’ve found).
You have to turn it to "Automatic mode", and fiddle a bit with the settings, but I have it set up so that every time I open a new tab it is a fresh isolated session, and will be destroyed when the tab is closed.
When I need to be logged in, I use the regular containers in Firefox for each service, or a context like "work", instead of the temporary containers.
> In most cases, it just blocks or hides cookie related pop-ups. When it's needed for the website to work properly, it will automatically accept the cookie policy for you (sometimes it will accept all and sometimes only necessary cookie categories, depending on what's easier to do). It doesn't delete cookies.
At least that is how i implement google analytics for example.
By not showing the button in the first place, nothing happens and no cookies are set (apart from the functional ones which are set regardless).
Other than that it really does not matter that much because if you use a plugin like this you will usually use an add blocker as well which removes the tracking.
Cookie popups are aids, what's someone gonna do? Say no and then quit the site? It doesn't actually change behaviour from the root cause, just passes on the different to the end user.
Yes, "Fanboy's Annoyance" list under the "Annoyance" section, in uBo "Filter Lists" configuration tab. I enabled it recently only, and so far it looks OK with IDCAC removed. And uBo is also supported on Firefox for Android.
https://www.ghacks.net/2020/10/01/you-can-now-install-any-ad...
https://addons.mozilla.org/en-US/firefox/addon/consent-o-mat...
With this you can preconfigure your choices, even accepting them. The default is to reject all.
Its web site feels very… corporate, and I can't find a source code link anyway, so I'm sure it's making money off of me somehow, but I can't figure out how - according to the site's FAQ, it isn't selling any data, so who knows.
Adguard annoyances
Ublock filter - annoyances
I'm almost to the point of trying to do it myself.
Eg https://github.com/brave/brave-browser/issues/20059
> Yes - manifest v2 extensions will be supported by Brave We'll be taking steps as V2 is sunset by Chromium team (https://developer.chrome.com/docs/extensions/mv3/mv2-sunset/)
>During the deprecation period, we can keep this functionality via patch (since it's there for Enterprise). After V2 is pulled from store, we'll need to stand up our own extension store for manifest v2
Browsers should silently accept cookies, and delete them once the tab/window has been closed, and cookies should be stored only on user request (a toggle near the url bar) or after submitting a login form.
BTW for anyone who doesn't know what P3P is:
> The Platform for Privacy Preferences Project (P3P) enables Websites to express their privacy practices in a standard format that can be retrieved automatically and interpreted easily by user agents. P3P user agents will allow users to be informed of site practices (in both machine- and human-readable formats) and to automate decision-making based on these practices when appropriate. Thus users need not read the privacy policies at every site they visit.
How that would become complicated by regional laws requiring specific legal wording is anyone's guess, though - as this standard never became widely used.
https://www.ghacks.net/2020/10/01/you-can-now-install-any-ad...
this specific fork of IDCAC isn't on AMO though.
Any use of that codebase - Brave, etc. - empowers Google. They're the ones pushing it forward, and developer mindshare empowers the player holding the reins.
Firefox or broke.
[0] https://github.com/OhMyGuus/I-Dont-Care-About-Cookies/issues...
But then there’s electron also…
I find really useful extensions on https://addons.mozilla.org ... but they often require permission to look at all of my browsing data, and I haven't found a way to view the canonical source that will be installed.
I'm sure it's available somewhere on the file system, but is there an easier way?
https://addons.mozilla.org/firefox/downloads/file/4003969/ublock_origin-1.44.4.xpi
Right click the "Add to Firefox" button, "Save Link As" and open with something that supports zip files.My take from watching some open source extensions is you are relatively safe from properly nasty things with a popular extension as they receive a higher "weighting" in the review process. Releases tend to get held up when something strange is added. Mozilla also document their process and tools (they have a web UI for it all):
It’s an excuse to take political (economic in this case maybe) pot shots at your rivals.
I recall multiple-browser compatibility support was a challenge quite a few years ago when I worked as a manager for a smallish dev-shop, the problem stopped when IE moved their code to Chromium.
Sorry if this is a dumb question.
While it's indeed great for web developers in the short run. The problem is giving a single company too much power on the web. Google in the end, is also an ad company, which happens to also be starting making it harder for ad blockers to work: https://www.theregister.com/2022/06/08/google_blocking_priva...
The web should be available for all, and not managed by a single company.