Yes. Because I don't care about cookies. This is not an anti-tracking extension. I do not care about being tracked. I just want to stop being bombarded with cookie consent dialogs.
Once the GDPR came out, now it was required, even admirable, to distract users. Once that window was broken the car got stripped within 24 hours and now it is not unusual to have to dismiss 3 or more pop ups asking you to subscribe to an email newsletter.
The only issue with DNT is that it wasn't mandated.
That it's inconvenient for the tracking industry and thus was ignored is an enforcement issue, not a technical one.
If my browser tells you not to track me, it should be illegal to ask me again.
That's it. We don't call it a user agent for nothing. Or rather, we shouldn't, but we are.
https://en.wikipedia.org/wiki/P3P https://www.w3.org/P3P/
From Wikipedia:
As an example, a user may store in the browser preferences that information about their browsing habits should not be collected. If the policy of a Website states that a cookie is used for this purpose, the browser automatically rejects the cookie.
Corporations essentially had a presumed right to track users. Now they don't, they need to get informed consent first. A DNT header makes the user's non-consent explicit: not only is the user presumed not to have consented to tracking, the presence of this header signals active and explicit denial of consent from the user.
It's not like the evil bit at all. We're dealing with corporations that operate openly on the market. It's perfectly possible to say "it's illegal to ignore this bit" if it comes with the threat of heavy fines attached.
there’s a good example of 25 seconds of constant bombardment for InfoWorld visitors. I cant count the popups.
If I can't use the site while ignoring them, I close the tab.
What I realized after a while that this sort of user-hostile design correlates strongly with poor quality content, so it's also a great way to save my time.
That's not how zero-tolerance works.
I guess I should clarify that in the rare case I still want to access the content, I still do not engage with the modal dialogs, but instead use a proxy service such as archive.is to present it in an accessible way.
I consider modals to be a gross accessibility issue.
I worked on it pretty seriously for two weeks but got hung up on the problem that my web archiving system was never 100% sure that a page had finished loading (that there would be more significant AJAX calls) so it would set long timeouts and even with a lot of stripping out the junk it was going to be even more awkward than dealing with the junk.
Looking back at it however it looked like an overly ambitious project.
Complete sentences may make it possible to pretend bad wording is consistent, but that doesn't make it good wording.
Still a loss for the rest of us who got suckered into reading the last ten or so stupid comments but oh well...
They are not the same thing.
Let's say there is a scale from 0 to 10.
If you accept 1-2, that's low tolerance.
If you reject anything above 0, except this particular 2 and this particular 5, that's zero-tolerance with exceptions.
By zero tolerance, I mean to say that I do not engage with the dialogs in any way, e.g. clicking agree, cancel, close, or the area around the dialog if it is blocking the page.
By few exceptions, I mean that I look for an alternative method to access the content rather than disengaging from it entirely.
I am imperfect, so if you were to observe me 24/7, you would probably see me slip up eventually. But this is an ideal I strive for and for the most part am satisfied with the results of pursuing.
nit: couldn't
though I completely agree with your sentiment
If the first part were true, the second would be your name.
Also your comment doesn't make sense. They're different things.
I'm fine with being tracked by a service operator, I don't want my name to be public.
It's about principles. We simply don't want corporations knowing anything about us unless absolutely necessary. It's bad enough that governments have to know about us. We really don't need the private sector mass surveilling the entire globe and exploiting our data for god knows what purposes.
Data should be a massive legal liability. It should cost them money to hold onto any piece of data about any person. They should be scrambling to forget all about me the second the transaction is finished.
In practice I'd prefer a world without government and with companies tracking me over a government that steals half of my income and protect me from "evil" trackers.
Same thing with abortion. Of course wasting a human life is a tragedy, but it's hard to imagine economic model where you can guarantee the life of a foetus nobody knows much about, without needing a centralised entity. (you could in theory have protection agencies - as in The Machinery of Freedom - which guarantee your safety have you sign a contract saying you won't do that or else - but that would be hard to enforce).
What does "in practice" mean here?
I get the sense that when people say things like this, they think folks would have the lifestyles they currently have in the US, but much better because they don't have to pay any tax. In reality, a world without government would be run by the type of people who run Russia right now.
Great if you're connected to enough strongmen to be an oligarch I suppose but not that great for anyone else.
Okay. Nice to meet you, throwaway787544. Please reply with your real name and address to proceed.
If you walk in on a store that has security cameras in it and you accept to be filmed while you are in there, does that mean that I should be allowed and able to access you entire private photo and video gallery ?
What an absolutely twisted view.
The simplest way would be for companies to stop tracking individuals then they wouldn't need to seek cookie consent.
I would say that, getting companies to convince the user that they would be better if they are tracked would be a good feature. Currently,tracking helps the company and hurts the customer, so companies should come up with a reason why tracking is actually good for the customer.
They are following the law in a way that makes it as annoying as possible for the people whom the law protects.
I don't care a lot about cookies, but if a website is abusive enough that they need to ask for my permission, I prefer to deny it rather than give them a blanket approval (again: what I really care about is wasteful and overbearing JavaScript code that complements tracking via cookie... If I cannot object to that, at least let me object to cookies used for tracking)
Again: you don't need permission for necessary cookies. The fact that the cookie prompt is annoying/difficult to parse and requires opt-out instead of opt-in is against the spirit (and possibly the letter) of the law. If our automation around the cookie prompt is accidentally giving an implicit consent, we ended up doing exactly what the people that push pervasive tracking wanted. We end up rewarding, instead of punishing, people who implemented dark patterns.
How do you tell the difference?
> Again: you don't need permission for necessary cookies.
Usually it's better to ask forgiveness than permission, but I can understand sites wanting to play it safe and throw up a banner even if they only have "legal" cookies.
They should pair it with a "yes, I am an adult" extension.
Use a moral & good & fit to task (not apathetic & consenting extension) like Consent-o-matic[1] or Auto Cookie Optout[2].
Some people actively dont care. Dont do that. Care. Help. Be a positive influence. (Ed: wow, unpopular opinion, over something that costs people nothing to assist in!! -2 points!
I do not care about cookies. Not one person on the Internet can demonstrate a concrete harm caused by the existence of advertiser cookies on their machine. If you want to spend time twiddling these knobs, more power to you. I've got things to do and I will gladly take the first option that erases the annoyance with a minimum of disruption.
I dont get why this proclaimed unwillingness & lack of deciding leads you to pick the worse less defensive pick though. Why actively choose worse defense? I dont get your argumentation. Why is the worse dumber pick better for you, even if you dont feel convinced of the harm? Presented with a defensive & apathetic option, I don't see why you would still choose worse.
It blows my mind that you'd have such disregard for your own personal data protection by not implementing a similar system. Why not spend half a day setting up something that solves the problem long term without depending on you to consciously make the "right" decision over and over?
You're assuming way too much active thought and choice on the part of the people who don't care about cookies. You're assuming that it was a choice between options at all. In my case, a website I was happening to read mentioned the I Don't Care About Cookies extension, and I thought, "oh, it'd be nice to have something that stops all of those annoying cookie pop-ups" and installed it. That is all. Is such an action really an "anti-progressive and pro-shitty attitude"? Am I really harming you or myself or society by doing that?
'Actively not caring' is insidious and depressing. It normalises data surveillance and says there's no point fighting it.
Comments here seem to ask if cookies are really worth all this fuss. Frankly, I don't think it's much of a fuss at all. Block the pop-ups, auto-delete the cookies. It's so simple I'm bemused there's any pushback.
And thanks for the links to those extensions :)
It's a feature not a flaw. See, I literally don't care about cookies. Deny them, allow them, whatever. Just don't bother me. That's exactly what the extension says and does.
I've never understood the obsession with cookies and tracking. It seems that some people imagine Sundar Pichai sitting in his underground lair, following the browsing session of individual Chrome users, cackling with evil delight.
The CEO? No. A disgruntled ex? Yes.
Again, anyone can use this, I really don’t care, but the original author is essentially doing the work of adtech companies (not really surprising that they sold out their users in that context) by lying about the extension.
This makes no sense. Cookies required for operation of a site are not covered by GDPR, so shouldn't be in a cookie consent form.
If you use cookies for your shopping cart, then you do not need to ask permission to create a shopping cart cookie.
In my opinion, this goes against the spirit and the letter of GDPR, but it seems that they are getting away with it for now. The matter hasn't been discussed by the European Court of Justice yet.
In those cases, as a non-paying user, you essentially have the choice between accepting being tracked, or not viewing the site. IDCAC errs on the side of being able to view the site.
[2] https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...
[3] In the case of online raffles, a German court even explicitly allowed forcing users to agree to their data being used for advertising purposes if they want to participate in the raffle. https://openjur.de/u/2185336.html
And I don't think that option is as good as IDCAC (or Consent-O-Matic [0]) + CookieAutoDelete. With those two add-ons even first party cookies are deleted, while you don't need to close banners all the time.
[1] https://www.ghacks.net/2021/07/15/umatrix-has-an-unfixed-vul...
The different UI of uBO was part of this decision, but not the biggest factor. Over time it had gotten less and less workable even with uMatrix's great UI. I could no longer configure a site once and then expect it to work for any amount of time, as the rate at which new mandatory third-party dependencies were added to sites kept increasing. And I was visiting more websites as part of avoiding big sites like Amazon.
In addition, uBO's CNAME unmasking meant that many resources that were considered first party by uMatrix, are treated as third party by uBO. This added to the burden of whitelisting, but also got me thinking about how fuzzy the first party / third party distinction was and that it was increasingly a poor proxy variable for what I was really trying to block (trackers mostly, and also some annoyances).
I also use the Temporary Container extension in Firefox. In the end I decided that the default block lists of uBO combined with the isolation and discarding of persistent data provided by Temporary Containers was good enough for most browsing. I still use a whitelisting approach for my handful of permanent containers, and uBO's dynamic mode UI is good enough for that.
The vulnerability does not seem that serious to me... isn't it going to be pretty obvious if it gets exploited with this description?
> An attacker may exploit the vulnerability to get the extension to crash or cause memory exhaustion according to the researcher. When the extension crashes, users are left without protection until it is reloaded.
So I'm going to start seeing a bunch of ads as my clue, right?
[Not a drive-by:] > It requires that users become active, e.g. by clicking on a link.
The article you linked has plenty of information in the comments, it's actually a good resource.
This vulnerability has been fixed in uMatrix 1.4.2 [0], released few days after the linked news article.
> and has known vulnerabilities
which is demonstrably false. If you want to talk about other points move on to a related sibling sub-thread.