Cloudflare launches easy to set up consent manager that respects users
blog.cloudflare.com
blog.cloudflare.com
Checking to see if that statement is secure.
refreshes
Checking to see if that statement is secure.
refreshes
Checking to see if that statement is secure.
I don’t think that’s a good analogy.
Better to evaluate the merits of each product than to make a blanket judgment about the company and force your opinions of each product to confirm.
I think that the point is that Cloudflare's business model lies largely on its ability to monitor individual end users. So when Cloudflare announces they are providing a service whose primary selling point is that it affects their ability to monitor users then this sounds like a blatant contradiction.
I also think that begging people to blindly trust corporations, specially when it's without any rationale or reason, is to say the least very silly.
Sorry. Can you clarify what the business model is?
Disclaimer: work at cloudflare and this is the first time I’ve heard our business is monitoring users.
Or from the opposite direction, in practice every single time I add more privacy tools to my collection, CF puts more "are you sure you're human?" pages in my way. Motivations they tell themselves they have ultimately matter very little in light of what they're actually doing to the web.
You didn't read that at all. You read a claim that cloudflare depends on its ability to monitor individual end users.
That's not actually a nitpick. Given you work at cloudflare can you point me to the part where clouflare state in some legal doc of consequence they do not monitor individual end users? I'd appreciate that.
If they are not going to let me past, I wish they would at least come out and say it. Are they trying to waste bot time like someone stringing along a scammer? Not everyone on a VPN is a bot or otherwise malicious user.
So yes. I mean cloudflare. But don't pick a fight on the internet about it, set do not track in your browser and watch the web break for yourself.
Cloudflare are pretty terrible and need to be called for it.
https://www.ghacks.net/2022/12/24/configure-firefox-to-rejec...
Rejects/Hides/Accepts depending on the situation. Not ideal, but hides a lot of these messages.
So cookie consent increased the hurdles users face to explore the real web.
So the real winners are the dominant websites and apps.
Btw, if you haven't tried, give Cloudflare pages a shot if you are looking for a no nonsense static website tool. Combine it with Cloudflare workers, you can add dynamic features as needed. I don't work for them but just a happy customer.
If so, how do you manage consent?
I tried to build a simple modal that asks the user if they agree to ads+cookies, with a link to a privacy policy which explains that I use Adsense and a link to their privacy policy. And only loaded Adsense if the user agreeed. But Google never accepted that. They never gave an explanation why.
I load up all the tracking guff bizdev and marketing want with Google Tag Manager. Tag Manager's code isn't output to the page at all until the user has opted in to 3rd party tracking cookies.
I'd do the same with ads (on an advertising toggle rather than tracking) if I were using them.
Edit: to be clear because this gets downvoted - when I'm saying "does the same", I mean both options will be treated as "I do not give consent".
The confusion would probably be quickly resolved when the dialog closed after clicking Reject all, but perhaps changing the wording of "Confirm my choices" to something like "Allow checked" would make it more clear it is a sibling of the other two buttons (and that checked means allowed).
I get it: the intent is that there's always a quick, one-click way to broadly consent/not consent. But with how this is designed, after clicking Accept All or Reject All, I'm left wondering what Confirm My Choices did. (Maybe it persists my consent on subsequent visits? I dunno.)
Perhaps, "Confirm My Choices" (or better put, simply "Submit") stays, but change the "Accept All" and "Reject All" buttons to "Select All" and "Deselect All" buttons, respectively. These buttons should only serve to change the state of the checkboxes without submitting.
I tend to think that the one click flow serves users and respects their time more, even if it comes at the cost of having confusion about the difference between "Confirm my choices" and "Reject all". It's bad when consent managers confuse users between agreeing and disagreeing, but if we're making users confused between two good options, I personally think it's an okay price for a one click and you're done experience.
That's a fair tradeoff. "Reject all" should be one-click imho.
The issue with this and all consent mangers is always ads.
It is impossible to know all the potential ad vendors, ad tech, and what other devices ads will load in advance.
Googled consent framework, the IAB framework, etc, all fail to address this.
The dark pattern you describe is shown in the first screenshot as an example of what not to do: they say it "can at best be frustrating to users and at worst draw enforcement actions from regulators in a number of jurisdictions", which is a nice way to say it's annoying and illegal.
(Disclaimer: I'm on the team behind this feature)
1. It's usually hard to find and to touch on a mobile device
2. Many websites use the dark pattern where clicking "X" is actually a way to give consent (or so they claim, as such "consent" is not valid under the GDPR rules). Due to that, many users are habitually confused about what will happen to their data choices if they press "X".
(Disclaimer: I'm on the team behind this feature)
My rule of thumb is just never to use them as a proxy, CDN through R2, static pages etc are okay. Unfortunately Zaraz requires your website to be behind CF proxy.
> And if you've ever clicked something other than Approve you'll have noticed that the list of choices about which services should or should not be allowed to use cookies can be very, very long.
There should be a reject all button, right?
What's Clourflare's share? I would guess that Akamai delivers a lot more traffic, and they've been around for a whole lot longer and no one really cared.
Zaraz doesn't actually require your website to be behind CF proxy, see this: https://developers.cloudflare.com/zaraz/advanced/domains-not...
> There should be a reject all button, right?
I could be wrong about this, but I _think_ that the definition is that it should be as easy to reject as it is to agree.
It's only because sites are jam-packed with spyware that all these horrendous popups are everywhere.
If you need a complex consent manager, it's a signal that you're doing the wrong thing.
Ads are not strictly necessary, nor visitor tracking, btw.
Obviously you should not keep any other information with the page view events as to not be able to relate other events with the page view but it's definitely doable
Agree btw, all these “basic functionality” cookie consent toggles are FUD by marketers who want to confuse you into giving up.
If Cloudflare is serious about privacy here, they should at least respect GPC and not provide customers with an option to disable it.
We really want to see GPC succeed, but we haven't prioritized supporting it because it doesn't seem like it's going to benefit many users, yet.
(Disclaimer: I helped deliver this feature)
We have never even for a minute considered not providing the "reject all" button. It was a user-respecting project from its conception. We actually consider being user-friendly a competitive advantage rather than something that we'd do out of fear of Noyb.
For some context, I'm a co-founder of https://www.internet-czas-dzialac.pl/, which can be described as a "Polish noyb" ;)
No consumer is going to say "oh, now that you've provided me such a streamlined tracking consent experience, I'll give you consent to track me across sites to show me personalized ads". They'll just click the "reject all" option you're legally compelled to give them.
Also, the example includes a consent option for anonimized pageview counts data, which under GDPR you don't need consent for.
An approach that would really respect user would be to store traffic analytics anonymously (in a way that resists trivial de-anonimization, so with binning and stuff), and throw away the rest. There, no consent popup needed.
Coincidentally, those people are also the most susceptible to advertisement-driven brain washing and least likely to understand what adblockers are.
If sites use this because it's easy to set up, then Cloudflare has done something good for the internet. Compared to the alternative, which is where they choose a product that loads up dark patterns to get users to accept cookies.
Google Analytics is problematic[1], consent or no consent, unless you send anonymized analytics events through your own proxy server.
[1]
Austria: https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-...
France: https://www.cnil.fr/en/google-analytics-and-data-transfers-h...
Denmark: https://www.datatilsynet.dk/english/google-analytics/use-of-...
Finland: https://tietosuoja.fi/-/apulaistietosuojavaltuutettu-antoi-h...
Norway: https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2023/va...
Not really, since embedding YouTube and Twitter should work even if the consent for tracking is refused (under GDPR consent inherently is opt-in, not opt-out; and consent is valid only if it is freely given, i.e. if you don't refuse service to those who refuse consent), and for that you don't necessarily need a popup, because you're free to assume that noone opts in to anything where a choice is provided - if you just treat everyone as if they clicked 'I refuse any optional consent', you don't need to ask that question.
Should it? I mean, GDPR wise you're sending a subrequest by embedding eg. an iframe - which involves user data that might be used for tracking by yt/tt etc.
Shouldn't it be better - to err on the safe side - to just replace eg. the embedded player with a placeholder (maybe featuring a link to youtube) unless user has given consent to the embedded player?
You overestimate how much a regular internet user cares about cookies and had the knowledge to even know what they are.
Second, Cloudflare Zaraz actually offers many options for anonymizing your data, such as masking IP addresses, hiding referrer URLs, user-agent strings and more. See this: https://blog.cloudflare.com/zaraz-privacy-features-in-respon...
Again, don't take this as a legal advice or anything like that - this is just to say we're doing everything we can to help users comply.
and the US is not considered to have adequate data protection laws under the GDPR