CookiesOK browser plugin
cookiesok.com
cookiesok.com
Cookies are NOT OK, I don't want to see them, and just show me the article (or page I originally came to view), thanks. And after I have viewed it, and if I decide to become a user of your site - then you will have my permission to use cookies.
The click through pages are the worst (like what www.games-workshop.com has). The pop-up/notification bar some news sites have (like bbc.co.uk) is somewhat acceptable, while obnoxious, as it allows you to read the content without accepting the cookies, and just go your merry way when your're done.
So this plug-in is going to auto-accept the cookies on your behalf. But why would you want to do this?
Say I build a website and fill it with content you want to see. I'd run Google Analytics to track popular content etc.
You're saying my default choice is to no longer have analytics on my site at all?
Agreed, all these other solutions are rubbish. But your solution isn't a good solution either.
(In Dutch http://www.nu.nl/internet/2987889/cookiewet-versoepeld.html)
Because anything that adds features costs money. This is a non-issue for most website developers.
But why would you want to do this?
Because, pre-law, I (like many people) were happy to exchange a cookie for access to free content from virtually any website.
Accessibility is king.
For example, if you visit a web shop, you shouldn't need to get any cookies when viewing a product page. If you decide to put it into shopping cart - then you would consent to getting a cookie. But no sooner!
There are tons of reasons why "read-only" could make use of cookies. Here are a few, using your ecommerce example:
1) A/B test 2) General site analytics, to see how many unique visits your shop gets 3) More detailed conversion analytics to figure out things like the value of a visit, how long someone takes before making a purchase, knowing the origination of all conversions, etc. 4) Remembering viewed items so they can be promoted on a future visit 5) Displaying a "Welcome back" message to second time visitors
If you don't do these things you will be beaten by people that do. eCommerce might be the absolute worst example you could have come up with for situations where cookies are not needed.
They need advertising revenue to pay for offices, people in those offices to write the content you want them to "just show", etc. Much of that potential revenue is locked up in advertising networks, and you need cookies to serve them on your site. Even if it were possible to sell out the ad space in-house, you need cookies to accurately track the delivery and results for the advertisers.
They need analytics to bring in the traffic that will view those ads. Especially for large publications, real-time analytics drive the decisions of what content to write, what content to expand, and what content to promote to the front page in order to maximize page views and thus ad views. They're decisions made minute-by-minute throughout the day. You need cookies to do that kind of analytics.
So while technically they can "just show you" the article you want without cookies, the practical implication is that the content you want them to show you wouldn't exist without cookies.
Just because a business model currently relies on cookies, doesn't mean we should get rid of the privacy law. Maybe the business model should change. After all, if the business model required employees to work more than 13 hr shift (Working Time Directive), then tough, your business model needs changing.
However, none of the big advertising networks is going to let the additional value of tracking customer behavior and targeted advertising slip through their fingers.
That's not the same as "needing" cookies for advertising, though, and it is indeed what the directive was meant to put a stop to (among other things).
I talked over a deal yesterday and like most online campaigns it included a frequency cap (in this case 1/24 for desktop and 2/24 for mobile). You cannot do a frequency cap without cookies. I could have instead tried to sell a static image or whatever you think would work, but that deal would not have gotten done. This was a CPM campaign, so let's forget that as a possibility. How would affiliate advertising work without cookies (hint: it doesn't). So that's out too. Let's try CPC. Perhaps you can do the leg-work for me and find someone willing to pay me per click for anonymous users that may or may not exist, but I have yet to find one.
This is all ignoring the fact that without cookies you have absolutely no idea how much inventory you have and what its profile looks like. Say you get 1M page views a month, but no advertiser in the world cares about that they want to know how many unique visit[ors] you get. A forum with 1M page views could have 10k members and be nearly worthless to advertisers, but a blog with 1M page views could be 500k unique visitors that are very desirable for advertisers. Without cookies you don't know and the result is you won't sell ads. It's very simple.
I don't understand the sense of entitlement. The result is annoying, but that's because of the poorly thought out law. If you don't want annoyed, use this extension.
If the law says "you must gain users consent before storing things on their computer", then "well if you don't like it, don't visit my site" is not an acceptable legal defence.
And how do you feel about the 'Do not track' header?
Not a big fan of DNT, it relies on trust which prevents it from working when you want it to most. If you don't want tracked, don't accept cookies. If you can't use a service without cookies and are not happy using something like Incognito mode, stop using that service.
Most sites will state they are assuming consent based on your continued usage of the site.
I always use cookies on a whitelist-only basis, and it is quite common to find web sites that require cookies for no good reason -- sometimes, I suspect, without even realizing it -- and then fail with no message when cookies are disabled.
I believe that cookies should be regarded as a progressive enhancement. If your web site requires cookies to implement a paywall, then detect when they are disabled and say so. If you can add features when cookies are available, great; if they're not, let me know what I'm missing. But don't tell me that "a browser error is preventing me from logging in," as many sites do. Once again, I'm sure this is boilerplate code that the actual site owner isn't even aware of.
I'm in the UK so use a bunch of sites here. What I have noticed is that only large active sites by big companies and orgs actually have cookie notices.
None of the other countless sites actually have it at all. So I'm wondering how long it will be before people just stop putting these things up at all?
From looking into it myself, it looks like UK implementation is stricter than e.g. Irish one.
Visualization and data is here: http://www.demo.hauthaus.net/eurobake/#
I don't know. But just FYI, it would be the local data protection commissioner that would be in charge of enforcing this law AFAIK.
Net, if you wanted to drop all of that and get rid of the advertisers, that is a balance of $160 per person per year (and growing) that would fall to some other solution (like increased service charges).
As others have made the case, cookies are important for advertisers. If you want to fix the problem, need to consider another viable solution that either does not sweep their legs out or does but provides an alternative revenue stream to keep the internet alive.
One problem I have with current cookie law, is that it pretty much forces cookies upon those who actually know how to disable them. If someone browses with cookies disabled, they get all these annoying warnings and yet no way to turn them off - because turning them off requires a cookie! Insanity.
And the relevant governing body has pretty much admitted that you'll probably be ok with just a clear description of cookies used. (See the response to nocookielaw.com)
Oh AND all American websites will just continue as they were before, except now with an extra competitive advantage.
I understand that "free" sites need advertising revenue, and unfortunately a lot of ad networks want to track my every move - how about enforcing a compromise where cookies are allowed for X minutes after I hit the page?
Security-wise, I'm more interested in enforcing that cookies sent over SSL are not readable via standard HTTP. This tool is a step in the right direction, but I think a few more features would make it pretty attractive.
Based the "how does it work" section of their site, I don't think it does any sort of moderation/validation/inspection of cookies before trying to auto-click the consent button. My impression is that it's strictly a DOM-level utility and doesn't hook in at the network level where it could observe or manipulate cookies over the wire.
I think making your cookie notice work with CookiesOK is about as legal as just turning off your cookie notice.
If a web developer wants to make their site compatible with CookiesOK to improve the browsing experience for the subset of their users with the plugin, what's the harm?
How end users indicate their consent should be entirely up to them. Would you prefer users solve a CAPTCHA when opting-in to cookies?
The page has a section on "Making my website Compatible". The plugin explicitly looks for the "CookiesOK" CSS class. This plugin is designed and partially aimed at web developers.
If a web developer wants to make their site compatible with CookiesOK to improve the browsing experience for the subset of their users with the plugin, what's the harm?
Well it's against the law. The harm depends on your country. It could be a fine of thousands of euro, and potentially an injunction shutting down your website.