Firefox may soon reject Cookie prompts automatically
ghacks.net
ghacks.net
> the absence of any option for refusing/rejecting/not consenting cookies at the same level as the one provided for accepting their storage constitutes a breach of the legislation [0]
GO Europe GO !
[0] https://www.cnil.fr/en/edpb-adopts-final-report-outcome-cook...
How many cumulative wasted hours have been spent tapping through cookie pop ups?
I made a game about it if you feel like wasting even more of your precious life on pop ups.
Maybe not quite as privacy conscious, but a quick workaround: (1) Open in incognito (2) Click big, easy to find "Accept" button
However it's deeper since the popups we see today were never recommended nor required by the original regs. The laborious nonsense we endure was invented by websites as a workaround for the regs. So it wasn't obvious that consent parity would ever need to be clarified like this because it wasn't even obvious that the industry would come up with such an awful popup pattern to begin with (though in retrospect we should've known I guess).
The fact the popups were never even compliant anyway is just a combination of wilful ignorance, dark patterns, consulting companies wanting to sell something and - yes - an added set of people innocently misinterpreting regulation.
Lots of things are subjective judgement calls. They are not all nonsense.
Most of our longest standing torts and crimes have subjectivity right at their core, and I'd argue that's not a coincidence but survivorship bias.
The world just isn't black and white, and attempts to legislatively render it so inevitably cause problems (though, obviously too much subjectivity and something because uselessly vague; it's a tricky balancing act for sure).
> The other legal tradition underlying the EU copyright system which is the continental European tradition of droit d’auteur (or Author's Rights). In this system, the authors of cultural works have certain inalienable rights that they cannot sell to a right holder. And, importantly, the exceptions to copyright, the interests of the public are written into the law. [...] The problem with the continental system is that it is quite inflexible because every time a new technological development comes about, you have to change the law to allow this type of use without a copyright infringement. So every new way of dealing with culture is fobidden by default. - https://www.youtube.com/watch?v=wL_Wxu6x1HU
Whereas other legislative cultures prefer to set a general framework, then leave the details to the Courts and or to Government ministers.
I mean the EU published a guideline on what it calls deceptive design patterns. They are quite clear there with what is unacceptable (link to PDF): https://edpb.europa.eu/system/files/2023-02/edpb_03-2022_gui...
When even Google felt they had to make "reject all" equally big and not hise it in a sub menu, you know that everything else is likely not legal.
¹: whether you use cookies for it or not doesn't matter
I think that the poster was saying that the popups themselves as a concept were never recommended nor required by the regulations.
Yeah I guess the word "require" has a few interpretations. The regulation didn't explicitly require popups, it required user consent IFF a company wants to collect/process/sell data the company doesn't need, but the intent was that companies would not do this, with consent being the exception, and the mechanism of consent was neither prescribed nor a focus: it certainly wasn't annoying popups per reg.
Only when deceptive patterns became clear the EU made clear that allowing one simple "ok" option and a million convoluted ways to say "no" is not resulting in informed consent.
Wheter you us a popup or hide it in a menu with the default of not tracking does not matter.
The frontend content screen component of the whole topic was something that emerged afterward as businesses' attempt to get away with continuing rampant unfettered data collection.
A bigger question is: why didn't they go with the DoNotTrack header.
> P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&a... for more info."
The GDPR requires that consent be informed, explicit, freely-given, and limited to a specific use case. Of these, the "DoNotTrack" header could be at most freely-given. Its design as a binary yes/no that can be configured across all sites prevents it from ever being used as a way to grant permission to track.
While the presence of "DoNotTrack=1" could be used to assume that no permission to track has been granted, this is already the default assumption that the GDPR requires companies to make.
There are at least two solutions for that:
1. Force browsers to support the header.
2. Always send the header "DoNotTrack=boolean", then force websites to take action (show a popup) when there is no header.
when you join a poll you do so with consent, when a market/social/political research entity invites you to a focus group (for example) you get at least a coffee and snack if not real money.
websites just get this for granted? it’s like stealing. it will never stop until the industry gets some understanding of these concepts.
This is the industry that perfected psychological manipulation in the pursuit of profits. It's built on decades of research into the best ways to associate brand names with positive feelings, and plant a desire to make a purchase in the subconscious mind of consumers. They will do anything humanly possible to deliver ads to your senses, and they've corrupted every media technology to do so since the existence of public broadcasting.
The internet has just given them the most profitable delivery mechanism, and in turn has made technology companies insanely rich. These adtech giants rule the internet, and can build the playground they need to make ad delivery more efficient than ever. Now these profits can trickle down to website owners, which will in turn take the path of least legal resistance, and employ every dark pattern imaginable in order to maximize _their_ profits.
And if this corrupt business model wasn't enough, adtech companies can perpetually multi-dip by selling the data they collect on shady data broker markets.
So, no, it's not just stubbornness, or lack of understanding. Deceit is built into this industry, and these cookie consent forms are just the tip of the iceberg.
The solution requires much stronger regulation than the GDPR. Unfortunately, this is very unlikely to pass given the influence advertisers have on governments.
Isnt the user getting free content in return?
Archive for life.
Free content was around before advertising on the web, this whole 'but they get free content' spiel was cooked up by advertisers.
Static we pages are cheap to host. Very rare is the article on [news site] getting mllions of simultaneous hits. But they all want videos embedded everywhere, gifs galore when all I want is to read their 20 min video in 2 minutes. They want their website hosted on the cloud with every new/hot architecture out.
How mant nyt articles are reprints of a reuters article the nyt then turns into 10 pages with aforementioned videos etc.
They did this to themselves.
They aren't a form of malicious compliance at all, because they aren't compliant at all.
As a designer I despise mandatory content blocking modals and each one will still have a new design you have to decipher. Maybe if they clarified some design rules (2 or 3 big buttons with clearly defined text in legible colours/fonts etc) then it would be tolerable.
Regardless making it always have Accept/Reject/Custom is a good step forward, even though fingerprinting and browsers like Firefox blocking 3rd party cookies by default pretty much eliminates their utility.
I've only seen a handful of sites do this. Developers inclined to respect Do Not Track seem less likely to add tracking anyway, in which case you also don't need the banner.
Sure, shady surveillance-based businesses can still pilfer your information and sell it to illegitimate businesses regardless of the legality. But it being illegal will stop the vast majority of wanting-to-be-legitimate businesses from collecting it, and prevent the largest group of threat actors (insurance/credit/etc) from using it.
I was responding to this: "There's also nothing stopping a website from showing a cookie banner, getting a user who clicks on "no cookies" and tracking that user anyway". You seemed to be implying that since a website can technically ignore a user's (lack of) consent regardless, that the popups are unnecessary. But legally, the concept of consent is very significant.
The popup mechanism itself isn't designed for you. I do agree that honest businesses don't need "consent" nag walls, as nobody actually wants their personal information datamined as a feature. But the actual dynamic is that these businesses are trying to preserve the status quo of user surveillance by obtaining fig-leaf consent. And the "best" way to do this (from their perspective) is an obtrusive nag wall that makes it easier to submit rather than reject (whether by accident or through attrition).
So nag walls are just a similar user-hostile solution just like surveillance based advertising itself. And the main way the dynamic of malicious compliance will go away is further enforcement, although I fully support technical solutions that delete nag walls as well.
Depends on what legislation the website is hosted and/or the company is ? Not a layer, just trying to learn.
No banners necessary. Just block 3rd parties.
A lot of users are already blocking third party cookies and that's the default in Safari and Chrome nowadays - but ad companies have moved on.
(Under your analogy maybe the store is putting a beacon in my pocket.)
Physical stores don't do that and therefore your analogy breaks down.
They don't need to sic a minion to sniff after you. The implication of buying condoms and then visiting the hotel only requires to correlate three tables.
https://techgdpr.com/blog/wifi-tracking-retail-analytics-gdp... has some background.
https://www.spring-board.info/differences-between-geo-wifi-f... is from a British company which claims to do compliant tracking in shopping centres etc.
There's a very good reason why I don't have any such client card and will never apply for one.
The store can track your purchases down to the line item if you use one of those. I vehemently disagree with that.
Also, I pay mostly with cash.
Yes, absolutely. I don't have an expectation of having as much privacy as I do when in a private residence with the blinds closed, but I do have an expectation of some forms of privacy.
* The store will not perform a full strip-search of my person upon entering.
* The store will not place a GPS tracker on me as I leave, to determine where I live.
* The store will not have a team of employees with clipboards follow me at all times, making notes of my location within the store.
* The store will not keep a record of my eye movements, correlated against which products are being glanced at.
The problem is that, as technology has advanced, some forms of privacy that used to be protected by impracticality of implementation no longer have that protection. For example:
* The store will keep video record of my visit for a few weeks at the most.
* The store will not analyze video records outside of suspected shoplifting.
* Record of previous purchases is limited to the cashier's memory.
Privacy is not a binary yes/no decision. As technology improves, forms of privacy that were previously protected by limitations of implementation must be protected through other means.
You're agreeing to all — otherwise illegal — tracking they can manage to do, not just some cookies.
Of course the whole issue is that the most popular user agents (i.e. web browsers) did very little to empower users to act responsibly with their cookies. I mean I consider the Cookie Autodelete extension just basic hygiene at this point, just like having a good ad blocker and some kind of firewall/virus scanner.
Nothing else.
In addition, legitimate cookies to provide a service don’t require consent.²
If you’re annoyed at the EU instead of the websites, you’ve played right into the hands of the people wanting your data for illegitimate purposes. Every time you agree to a bad cookie banner you validate their shady practices and make the web worse for everyone, including yourself.
¹ https://noyb.eu/en/where-did-all-reject-buttons-come
² https://wikis.ec.europa.eu/display/WEBGUIDE/04.+Cookies+and+...
"Oh you are against x regulation? Yet you aren't against mandatory seatbelts or warnings in cigarette packages, or child labor laws! Curious!"
Like you realize that it is a pretty self defeating argument, since you are inadvertently saying that any regulation is a slippery slope to another one. Which thankfully isn't the case, and people can actually form an opinion on individual laws (and even disagree with them!) even if they are in favor of other regulations.
People sometimes then have the weird reflex to blame regulators for making explicit what garbage they're being fed, when you should take it up with the company who is actually responsible for vacuuming up your data.
Simply not accurate. The GDPR has other, more important accomplishments. See also: "gdpr unsubscribe", "gdpr do not contact", "gdpr consent". e.g. https://ico.org.uk/for-organisations/guide-to-data-protectio...
There are also other, less visible accomplishments. I've been on the inside of companies doing a GDPR data compliance check, and for some data stores, simply deciding that this one is not the "system of record", that passes beyond usefulness and setting a time-to-live of e.g. a month or a year, so that data about user actions is not retained beyond that.
This _absence_ of retained PII ( https://gdpr.eu/eu-gdpr-personal-data/ ) that has been encouraged by GDPR will inevitably make some breach somewhere less severe, but "what could have happened but did not" is not a visible accomplishment.
Thinking that it's all about your cookie banner is shallow, dismissive and egocentric.
Wow no one opted in? Shocked.
Fundamentally, standards as vague as "legitimate" or "necessary" shouldn't be a part of law because they are so subjective. What do you say to the executive who says that without the advertising the company will go bankrupt, and untargeted ads earn no money? That her company is not necessary? That her business is "wrong" in some way? That customers are wrong for not wanting to pay? It's ludicrous that such a situation can ever arise.
Good law is precise. Bad law isn't, regardless of how convenient it may be for the lawmakers to be vague. The existence of bad law doesn't justify the further propagation of it.
Being able to make more money through ad tracking to stay in business to keep the service running is not one of them.
I imagine the company behind this site is hosted at the US. There are not many places one can still do this.
It is sadly perfectly legal afaik. Nobody is entitled to your content without agreeing to some terms. Luckily, archive.is works very well. Wish there were more alternatives.
You basically cannot enter if you don’t agree or have payed.
Example: https://t3n.de
So for at least that site, it appears that all of the 'protection' is provided by javascript, and if one does not allow the javascript to execute, one receives the article content. There also does not look to be much in the way of ads with the javascript blocked as well.
[1] https://developers.google.com/search/docs/crawling-indexing/...
You can also access any site in the google cache with prepending "https://webcache.googleusercontent.com/search?q=cache:", that will you show you the website like the google bot saw it.
For example github.com would become "https://webcache.googleusercontent.com/search?q=cache:https%..."
It is still worth to try, but many sites already prevent this.
"Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance."
Since GDPR clearly does not consider ad-tracking cookies as "necessary for the performance of service", this should be against the spirit of the law. I guess it's up for the BfDI and relevant state-level commissioners to prosecute this and I don't know what is their stance, but this type of behavior does not seem compliant.
Of course, there are many other types of non-compliant behavior. Most cookie banners out there make rejecting cookies harder than accepting, and there are many cookie walls that block you from accessing the site at all until you dismiss them. These are clearly non-compliant, but prevalent. Even oversized or disruptive banners that goad you to click "I Agree" in order to dismiss them, cannot be considered as "freely-given consent".
Which of course requires an account, which requires a cookie, which is then tied to your payment details, and therefore far less private than ads, but that's GDPR for you. A nonsensical law in which nobody involved thought anything through.
What they can't do is say "no tracking, no service".
If we could turn tracking I to a banned way to earn money from free visitors, I think we’d all be better off. This is not how gdpr works today.
Legitimate interest is things like a legal requirement to maintain PII because of the services offered.
[0]: https://www.garanteprivacy.it/home/docweb/-/docweb-display/d...
No it isn't.
You need the same feature for visiting EU government websites:
https://www.consilium.europa.eu/ (best example)
There's "NoJS", a extension where you can enable all JS through a switch, but it doesn't handle iframes very well at the moment.
You only have to do this once per website, so (unless you've already uninstalled it) you've already done the hard work time investment for the sites you visit most often.
Basic / Premium / Ultra
With you guessed it, Ultra being the most tracking cookies. I was flabbergasted.
But of course, for maximum trap potential, we need to find a wording such that Premium is the option without, while Ultra tracking and Basic tracking should both do roughly the same amount of tracking (modulo not really relevant details). With a sufficiently discouraging wall of text, a bad UX, and a limited time option, no one would spend the time to figure out they need to click the middle option.
(This tweet brought to you by our sponsor, Moloch.)
I don't even care about all the dark patterns of now allowing you to dismiss and ignore with one click.
Thank you Europe
I agree, sites shouldn't be doing the things that require showing one.
> I don't even care about all the dark patterns of now allowing you to dismiss and ignore with one click.
How is this a dark pattern?
> Thank you Europe
Indeed! If such tracking has to be allowed, I'm happy that at least I can opt out of it.
Like what, showing ads? Collecting payment from the user in leiu of ads? I wonder what website you're imagining that doesn't do something that requires a cookie consent popup. GeoCities, maybe?
Any popup or obstruction is cancer, cookie consent or otherwise.
We need the same approach as for ad blocking. Just remove the crap from the DOM tree. Block the tracker cookies, based on curated blacklists or heuristics, or both.
We need to take back control of our devices, not leave it to every single website to hopefully obey some law.
Edit: remove double post of link
X-I-Dont-Give-A-Fuck-About-Cookies: true
...and let the world wide web stop torturing me. I have a nice button that clears cookies and websites can't do anything about it. This whole dance is stupid. DNT: 0It was the tracking advertisers who wouldn't play ball, so are you saying people are unfairly putting barriers in the way of tracking advertisers?
You’re proposing DNT flag. We’ve been there, done that, it failed.
Pragmatically, the opposite flag has a better chance of being adopted, because it aligns incentives - both parties get what they want: the website can track me (and really: some people don’t give a fuck and don’t need lectures on the wrongness of their ways), I get less annoying UI.
The "can I track you?" question does not add value.
localstorage: Clear along with cookies.
entropy: Reduce observable information.
Fuck the law. Defend yourself with technical measures that actually work. You wanna make a law that helps? Give safe-haven protections to Tor exit nodes.
It's easy enough to block cookies with an extension, but I'm sick of wasting time clicking the damn banners.
This should be controlled by the browser not the site. Let the site do whatever it wants to try to track, but let my browser do whatever it wants to prevent that.
DNT: 1For more than ten years I've had all cookies turned off by default in Chrome's site settings, and I click two buttons when visiting a site if I want to allow it to store data on my machine. That allowlist is persistent so I don't have to think about it again.
Cookies for managing login's are explicitly allowed by the GDPR. If you get a cookie choice prompt when visiting a website, it is an indication that the site is placing "advertising/tracking" cookies, for which the GDPR does require consent.
Because this is malicious compliance by websites. They are attempting to annoy people into clicking the easiest button, which is always the "store all my data, spam me at will" button.
And then the second is: browsers don't really know the purpose of any particular cookie, or how much the user actually wants it or not. Due to how cookies work, they really have no way to know. Cookies are not standardized enough.
Without obtaining consent or having a legitimate (i.e. functional, not economic) reason, the website operator cannot collect server-side logs or fingerprints either. Or they might not need consent to collect data (e.g. remember your purchases for refunds) but do need it to disclose that data to third parties (e.g. to feed the purchases into a recommendation engine... or, let’s be real, an advertisement profile).
None of this nuance is enforceable browser-side. It could in theory be communicated in machine-readable form by the browser, such as with a DNT header, but before somebody sues over that I doubt it’s going to be honoured.
(I remember that the SameSite cookie proposal had a follow-up, even more web-breaking same-origin-policy cookie proposal. That’s probably the most meaningful thing you can do client-side. But it had seemingly died when FLoC did, and I can’t find it now.)
For example, load StackOverflow in Chrome incognito. It has buttons for "Accept all cookies", "Necessary cookies only" and a "Customize" menu that gives you checkboxes for "strictly necessary", "performance", "functionality", and "targeting cookies" all with a lot of links and explanations.
It isn't just a matter of turning off third party cookies.
Though they might be hard to enforce.
> the cookie provision, which has resulted in an overload of consent requests for internet users, will be streamlined. The new rule will be more user-friendly as browser settings will provide an easy way to accept or refuse tracking cookies and other identifiers. The proposal also clarifies that no consent is needed for non-privacy intrusive cookies that improve internet experience, such as cookies to remember shopping-cart history or to count the number of website visitors.
https://digital-strategy.ec.europa.eu/en/policies/eprivacy-r...
Given that the EU has now conceded that point, we can finally get rid of this noise and move on. Hurrah!
Now, some of you may disagree with the above analysis, but your analysis is no more valid than anyone else's. EU privacy law is deliberately vague and open to interpretation so you can't complain when someone interprets it the way given above.
The laws themselves are not any more precise. I spent way too long puzzling over the wording in the GDPR.
First, because they don't actually inform you of much.
Second, because they're tricky to understand if you're not a lawyer. Most of them mean "you have no privacy", but worded in a way that leads you to think you do.
Third, because it's a bit ridiculous to expect everyone to read them. You'd spend more of your time reading those damned things than the page you want to read -- and you'd have to read them on every visit because they can change at any time without notice.
Better is if sites would just give basic, truthful warnings at the moments where you are making a privacy-impacting decision.
I suppose we could require users to take a test to prove that they read the privacy policy. That would be interesting.
> I suppose we could require users to take a test to prove that they read the privacy policy
That wouldn't really address the main issue with them, which is that they're written in a deceptive manner. I can tell you right now what 90% of them mean: "you have none". But that's not how they read. How they read is things like "we may share your data with trusted partners in order order to deliver you a great experience".
but none of the ones I've read qualify as "informed consent" because even if they're clearly understandable, they don't fully inform you. They always mention sharing data with partners, for instance, but never say who those partners are, what data is being shared with them, and what those partners are doing with that data.
Unless you know that, informed consent is impossible.
Complaining about them seems to miss the bigger picture.
Benefits:
(1) Don't have to trust the site to honor your consent.
(2) Sites won't try dark UI patterns (because they're not building the UI).
(3) More standardized UI because instead of each site inventing their own, they all use the browser's UI.
(4) Less tedium for the user. Browser can let the user choose defaults for the cookie consent dialog. Or define rules to handle certain choices automatically. And, if you can standardize categories (performance cookies, advertising cookies, etc.), then you can apply defaults and rules to those too.
(5) Web developers' jobs are easier. Just maintain and serve a cookie description data file. And of course be prepared to live without certain cookies.
Yes, this is extra work for the developers of browsers themselves. But it would be worth it. And apparently they're already spending engineering resources on cookie consent anyway.
(https://en.wikipedia.org/wiki/Five_stages_of_grief in case the reference is too niche)
(sorry, I'm in a silly mood)
[1] https://github.com/OhMyGuus/I-Still-Dont-Care-About-Cookies
If security conscious it would be recommended to also use disposable VMs for browser sessions like with Qubes OS. Otherwise, with persistence like you describe, it's crazy to me that one bad click could so easily compromise you forever
A rejected cookie preference could be stored client side in local storage and depending on that value you could decide whether to show the cookie prompt.
Source: https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX...
However, the ICO has suggested that saying "I refuse to allow any cookies on my computer" could be taken as implied consent to allow a cookie stating such.
Many common practices are against some particularly pedantic interpretations of the law. Nobody cares, because following the law to the letter would not be in anyone's interests. If an obnoxious asshole decides to really push the issue, and they are not laughed out of court because the judge is an equally obnoxious asshole, the practice may be found technically illegal. There will likely be no consequences, because it was done in good faith with everyone's best interests in mind.
However, the ruling may force the government to change the letter of the law, wasting a lot of time and money that could have been spent for other purposes. All because of some particularly evil asshole.
You can of course try living your life like that, but you'll likely find that it becomes effectively impossible to do anything.
Some are really bad - Admiral requires me to either accept all (hundreds of cookies) or press one link, open a form, then accept a default selection. Some also present me with a confirmation popup. Some I have to stare at for a moment to see where is the puzzle to solve - where is that button.
Chrome: https://chrome.google.com/webstore/detail/consent-o-matic/md...
Firefox: https://addons.mozilla.org/en-US/firefox/addon/consent-o-mat...
The thing that really grinds my gears is the phrase “We care about your privacy”. Bullshit! If you cared you wouldn’t even need to ask for consent!
That's not bullshit. They really do care about your privacy. They care a lot about relieving you of it.
It's present in the uBlock Origin filter list settings under Annoyances but not enabled by default. HN readers may also find some of the other default disabled filter lists interesting such as the AdGuard URL Tracking Protection list which strips tracking parameters from URLs.
For example, the manner in which Brave blocks Transcend Consent Manager can increase first party tracking due to Transcend Consent Manager being blocked in its entirety.
This never needed a legal solution in this form. Browsers should just not accept cookies, unless the user explicitly wants something stored on their device. That might have been better to legislate. Software on a user's device should not store or enable tracking by remote services, without disclaimer.
If the government wants to get involved they can make public service announcements and try to convince people to care.
Is that the best outcome?
Most (all?) browsers I've ever seen have a setting that makes them reject all cookies.
[X] NO, I do not want to subscribe to your newsletterThere should be more congressional hearings of adtech representatives, with legislators who are technically equipped to grill them on all details of their business, and how it affects the population.
Unfortunately, given how most legislators are technically illiterate at best, and financially corrupt at worst, nothing of value for the people has so far resulted from these hearings.
I'm hoping that in the coming decades, as younger generations get in government, this will improve. We really need much stronger regulation for Big Tech, just like we have for Big Tobacco, Oil, Pharma, et al. Hopefully this will come sooner than the point when the harms from its long-term effects are fully understood.
Well, that is bullshit. GDPR requires that you have some form of legal basis for storing cookies. Consent is the last ditch effort if you were not able to find any other justification. So by nearly by definition, denying that consent is in the user's interest.
I think there is some other EU regulation that requires cookie banners. But don't blame it on the GDPR!
Not even that. It requires a legal basis for storing and processing personal data.
But most sites didn't get the hint of "just don't track" and still want to track you.
The website should ask your browser should ask for permission to store cookies beyond the length of the session as it asks for your location / camera access.
The advertising industry won with their prompts, then.
This is applied for purposes such as "build a personalized profile", "show personalized content" and "show targeted ads" so I have no idea what the cookie dialog is supposed to prevent anymore... clearly the original purpose has been rules lawyered into oblivion by amoral scumbags.
But if they don't handle this, they're just going to blindly opt people into a bunch of stuff you'd expect to be opted out of.
These banners are the most-user-hostile possible response to the law, so it makes sense to automate getting rid of them.
I wouldn't be surprised if they find some way to defeat this in a not quite legal way and break stuff for people who use it.
> Access to specific website content may still be made conditional on the well-informed acceptance of a cookie or similar device, if it is used for a legitimate purpose.
https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX....
Tracking is not a legitimate purpose.
All this cookie banner nonsense could have been solved years ago by implementing a simple standard of setting your privacy preferences right in the browser.
it's since recently also blocking "use our app" nagboxes in mobile
What about localStorage?
I just don't understand how people are supposed to maintain an account with a site, without this stuff. Maybe using WebAuthn? Or what?
There is much more fundamental and core functionality missing which has been requested for years like this for example https://bugzilla.mozilla.org/show_bug.cgi?id=1325692
In general it would be good having such functionality built-in, I guess they're gonna have to maintain it as well.
All and all, I'm glad to see any kind of progress on the browser and in any case wish them the very best.
Also, the mobile version may have limitations on extensions.
I think the solution lies in somewhere in the realm of legally limiting the ability to profit off of the sale of collected data or even collect data without my consent. I don’t care if snazzy.app wants to collect product analytics and marketing data when I’m on their site. I consent to that by navigating to snazzy.app. I do care if snazzy.app embeds cambridge-analytica.js, though. And cookie consent banners simply don't address this nuance. What we need is control over where the data goes and if it crosses property/origin boundaries.
Users should decide themselves what to filter, so the bad actors with aggressive cookie policy gets automatically filtered out over time
I was looking for a recipe last time, I googled what I wanted, clicked the 1st link, bunch of popups for cookie/ad, I immediately hit "previous page" then I checked the next link, I bookmarked the one without fuss
Firefox as a user-agent is mirroring me-the-user's choice.
Admittedly that doesn't hold for every user. Some users might make other choices.