Consent-O-Matic – automatically fills ubiquitous pop-ups with your preferences
consentomatic.au.dk
consentomatic.au.dk
I also love that it’s owned by the University of Aarhus, as I am more willing to trust academia with something that has a disturbing level of (client-side) access to my browsing data.
I really wish the browser vendors would develop better permission models to guarantee my data can’t be exfiltrated by a malicious plugin (aka a once-good plugin that got bought out by a bad actor).
For example, I’d love to see the browser impose a policy of “no outbound network requests except to pre-registered endpoints with pre-defined headers and data payloads”, so that plugins could fetch allow lists but could not exhilarate my browsing history.
There is Content Security Policy (csp) which applies to the whole page and sometimes governs scripts injected by extensions but not the extensions themselves.
I would love to see browsers add a chain-of-custody to scripts and DOM nodes, so it is easy to tell which nodes were added/touched by a script, and if a script adds a script tag, that newly loaded script would show up as branches in the custody tree. Then we could say, “no nodes or scripts in this tree may trigger requests to unauthorized domains”. It would be sort of like CSP, but with a runtime-tracked implicit capability/taint for extensions.
There is a standard for this called P3P, which was implemented by Netscape, Firefox, Internet Explorer and Microsoft Edge before eventually dropping support for it. But there was nothing requiring website owners to use it. Various data protection regulations across the world require them to obtain consent for collecting data, but they are not required to recognise consent or non-consent expressed via P3P settings.
These standards will only get used if the website owners are forced to use them, either by regulators or by monopolistic/oligopolistic market forces.
https://oag.ca.gov/privacy/ccpa#collapse8b
> Under law, it must be honored by covered businesses as a valid consumer request to stop the sale or sharing of personal information.
It's leaking too. I got a popup on my keyboard on my phone yesterday, and literally thought "this is too much, I wish I was dead" (I'm doing fine, just an intrusive thought :). Time to dial it back in folks. It is unbearable.
It is.
The idea of pushing more contracts than you can read, all of what you must accept just to survive is a deliberate attack on our agency. You are just more sensitive to it.
There are places with laws about advertising pollution in public spaces. That needs to extend beyond advertising to a more general set of aggressive attention grabbing features, and to our digital lives, where we spend a huge amount of our time. It's not going to self-regulate. Ironically, the ubiquitous GDPR popups sort of broke a dam that have led to popups of all sorts being forced on us all over the place.
Not just popups. We need browsers to die and be reborn as User Agents again.
Currently the best browsers do is some translation and summarization, but there's currently zero automation.
An ability to tell user agent a command, in a natural language, like "go through first 10 pages of those Amazon search results, check every one of them including photos, descriptions and reviews, filter products according to those and those criteria (and not whatever Amazon lets me search and filter on) and give me a nice clean list of images and links with zero extra junk" will be a game changer.
We have all the tools, it's about time we show a middle finger to dark patterns and enshittification. Sure, it'll be a game of cat-and-mouse with websites fighting against robotic agents empowering end users (ad industry is going to hate this so much), but it's a battle worth fighting.
And this status quo needs to change. Too much power and information disparity at the moment, the markets are essentially broken.
What should we call this.. mmh..
"Do Not Track" is a bit long, maybe we just shorten it to DNT?
Nah thats dumb. /s
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/DN...
Yes, it is. That's the actual problem and so is everything else about the attention-hijacking industry.
This is the flimsy excuse made not to respect the Do Not Track header. By making it so that it's a tool for expressing the user's opinion, be it negative or positive, it becomes harder to spin it as being a tool that does not actually embody the user's view.
A user giving consent to <site|app...> A does not translate into consent for <site|app...>.
And yes, the default for such consent questions must be "no"
There is one and only one legal default under the GDPR: Do not track.
This is immediately followed by every head of marketing (at least for US-based companies) asking "Okay, so how do we track those people?"
I'm not saying this is right. But it is reality. We normalized for two decades marketing leadership having the expectation that they can track every interaction, and prying that data away has been painful, especially for folks who really want to do the right thing but are told otherwise by their managers.
Not exactly. The issue was that a specific version of IE enabled that header without giving the user a choice. If a user explicitly chooses to toggle the header, or install an add-on, then that argument would not hold up.
https://mailarchive.ietf.org/arch/msg/httpbisa/Mp-DjtBk-sfdQ...
I also just discovered the GPC which seems more interesting: https://globalprivacycontrol.org
The "legitimate interest" of selling you shit you don't want and selling your interests to third parties.
It's just that the enforcement agencies are large, lazy and won't enforce anything. They don't even enforce when you can prove beyond a shadow of a doubt when and how the corporations have leaked your private information, let alone when their use of cookies is illegal.
Look at the difference between Germany and say Austria, for example. Or if you must compare two large countries Germany and France. There is quite a large gap between different countries.
This extension on the other hand used to work maybe on a third, don't know if it improved but I would suggest the first if you're fed up with the cookie popup.
I don't have a plugin for disabling the banners, but I accept them if that's the easiest thing because I can already see that uBlock Origin blocked all their trackers anyway.
if i recall this just closes the cookie popup
but if you want some functionality you may need to accept some basic cookie like "remember me" for logging in, etc?
this is what the extension is great for
not sure if you can use both
So for now I disabled the blocking of cookie pop-ups and I let C-O-M automatically reject cookies for me.
My solution in these cases is to leave the website in question and do something that doesn't involve getting abused.
It absolutely can't block the more advanced, sometimes multi-stage prompts Google, Youtube, and many newspapers use. Consent-o-Matic actually goes through those prompts and declines the maximum possible amount of tracking, while consenting to the necessary options required to make the site work.
If a website does not respect that, it probably won't respect your choices either, so you might as well block the cookie banner and all tracking scripts.
I sometimes forget how bad the unfiltered internet is.
It is great to see but I'm also happy if we can have even half a solution like this in the meantime.
Did asking honest businesses to restrict how they use cookies protect users from invasive tracking? Nope. Data brokers simply employed other methods or bent the "legitimate interest" exception.
Did all websites provide a single button to reject tracking, with equal prominence and proximity to the accept button? Years on this is still rare, despite being the rule.
Did data brokers find new ways to obtain the same data? Sure did and more.
Was the end result a disproportionate burden on users, including those not even in the EU, while not delivering the intended benefit. Sure is.
Do entire websites, particularly those in the USA, simply geo-block all EU countries. Yep.
Did European-based services and news websites switch to a "let us track you or pay now" model. Yes.
Did data brokers exploit the EU's inability to police the matter by incorporating dark patterns, artificial pauses, and obnoxiously long lists to stymmie user's attempts at refusing tracking? Yep.
Did bad actors ignore the regulations. Yep. Was the EU toothless to stop that? Also yes.
So what did happen?
Instead developers of web browsers incorporated anti-fingerprinting technologies to negate the problem, a part of browser development that continues to be an on-going arms race.
Not holding my breath, though.
For instance: if the code/config for a particular site or family of sites becomes out of date for a while due to said site(s) adding a bunch of “legitimate interest”¹ checkboxes, then I may have just given consent (or passed by the opportunity to object) without knowing.
----
[1] In other words “we see your preference not to be stalked by our partner(s), but fuck you and your preferences we want to let them anyway”.
Too often, the consent dialogue takes over a second to load, and when you finally click 'accept' there is a little spinner for what seems like ages before the dialogue goes away and you get to see the content you came to see.
Can we simply detect the "<script src=consent.js..." tag, and simply not load it for the most common and annoying types of popup?
2. Navigate to the "Filter Lists" tab
3. Scroll down to the "Cookie notices" section
4. Check the box that says "EasyList/uBO – Cookie Notices"
How about if you hit the "x" button on the cookie popup instead of either "accept all" or "reject all"?
My assumption is that, despite what the law says/is meant to do, doing anything than going through the checklist will result in all cookies being enabled.
For example bing.com, britishairways.com all show their consent popup. It does try and do that minimize thing, as something flashes to the bottom right. But the model still appears in the same place as always.
- Zap that element (uBo element zapper or custom CSS style rule via Stylus).
- Globally deny ALL cookies for that site, via uMatrix.
Note that uMatrix (and AFAIU Fireox) already block all third party cookies. This just makes that prejudice global to the site itself.
The number of sites for which I require some level of state preservation is parlous few. Hacker News itself is most of them, my Fediverse home the other.
(I largely don't use the Internet for commerce. That's always struck me as a bad idea, getting worse. If I cared ... another very small number of exceptions would deal with that.)
Sometimes it breaks youtube/twitter embeds.
I've rejected all optional cookies/tracking for many years and I've never noticed any missing functionality.
What would've helped is not signing up to Disney+ and pirating all of their content instead.
These days when I see a link to a news outlet or a blog that intend to consume seriously, I just use archive.is. It removes all the annoyances, it's brilliant.
Works pretty well.
Disclaimer; dev here.
Anyone who cares enough to automate this will disable all optional cookies.
Also, don’t we all think the law should have simply required websites to respect the browser setting for this instead of requiring it every goddamned time?
I believe there's one over there <looks at Apple>.
My comment was a bit harsh, and that harshness wasn't aimed at authors of this extension. I'm merely asking Mozilla to be more proactive with extensions that are extremely security sensitive, but also further their own purported mission, like this one.
cookiebanners.service.mode = 1 cookiebanners.service.mode.privateBrowsing = 1 cookiebanners.ui.desktop.enabled = true
EU regulations like this are so poorly thought-out. They should have just banned nefarious tracking cookies outright. The EU never seems to understand the practical consequences of their technical regulation.
Put on a scale what we gain and what we loose, and just let it sit.
Login sessions is one thing that cookies solve well - we'd have to go back to session IDs in URLs with all the problems that causes.
... which also shows that cookies are not the problem because you can track users using an infinite number of different ways.
Now stricter enforcement of consent laws as well as regulating in which ways consent can be asked for, that would make sense.
Trusting advertisers, web developers under coercion, annoying paywall based sites has been proven to be a bad choice over and over in history repeating itself hellscape.
Firefox's "reader view" was the right idea, that doesn't quite go far enough. We need options like "i just want text, non ad pictures, and original videos".
Any higher layers where we allow these brutal dark patterns are too much work to track and fix every little thing they can do with code
That's called an ad blocker.
This is touching on the larger battle for control over user experience, that has been going on since the birth of the WWW.
Most of the sites want you to see everything other than "text, non ad pictures, and original videos" - the latter is a bait and a vector to expose you to ads, dark patterns, and other marketing shenanigans. They'd serve you their page as a PDF if they could get away with. They almost did get away with Flash. They do get away with this with mobile apps. About the only thing stopping them from replacing websites with some ungodly mix of canvas, WebAssembly, and React-like frameworks, is accessibility[0].
Point I'm making is, it's not a PvE game, it's a PvP one. A beefed up Reader Mode is not a solution - try to build one, and half the industry will cry foul, and proceed to invent workarounds. The Web, as we know it today, is funded by the enemy.
--
[0] - specifically, the legal requirements in some scenarios and jurisdictions, which create a sort of back pressure on the industry that keeps the web from full-blown appification.
1. I don’t care
2. It should work better since it aligns with the goal of the site
Then GP's point towards 'it should work better' implies it works over the long-term and not a single interaction.
I find ads frustrating as well, but it is a powerful monetization strategy and that doesn't have a substitute.
Google earned billions of dollars doing contextual ads before tracking user's every motion became the norm
The reason is that so long as some sites show tracking ads, the monetization possible by privacy-friendly ads is almost nothing.
The long term goal must be that no one cheats, so that ad the revenue from well-behaving advertising can go up.
Remember the consent dialogs aren’t ever asking permission to show ads.
Thank you so very, very much to the EU and whatever other government agencies are responsible for making the web more annoying to use.
They didn’t make the web annoying – advertisers did. They were the ones who chose the most annoying way to comply with the laws.
Sadly the ePrivacy implementations were a bit lacking in some member states and the EU directive to replace them with a direct EU-wide law doesn't seem to be fully in effect just yet but I have high hopes we'll see companies fined over these deliberate misdirections soon and that will hopefully put an end to it.
Consent-o-Matic uses this text to describe this category of cookies (for me, it's the first item in extension's config UI):
> Preferences and Functionality: Allow sites to remember choices you make (such as your user name, language or the region you are located in) and provide enhanced, more personal features. For instance, these cookies can be used to remember your login details, changes you have made to text size, fonts and other parts of web pages that you can customize. They may also be used to provide services you have asked for such as watching a video or commenting on a blog. The information in these cookies is not used to track your browsing activity on other websites.
The jury's also still out to what degree third-party cookies need to be disclosed in detail (e.g. whether you really need to keep track of the dozens of cookies Google Maps or YouTube sets or whether you can just refer to their privacy policy for the details). But embeds for YouTube, Twitter, Facebook or Google Maps, or the use of Google Fonts or the use of third-party CDNs for non-essential functionality definitely do require consent (i.e. opt in).