back
6 comments
How did they not include this to begin with? It’s so obvious as to be poking you in the eye that this would be necessary.

How many cumulative wasted hours have been spent tapping through cookie pop ups?

I made a game about it if you feel like wasting even more of your precious life on pop ups.

http://termsandconditions.game

On one hand, this was required from the beginning (this is just a clarification of original intent, not a change or addition)

However it's deeper since the popups we see today were never recommended nor required by the original regs. The laborious nonsense we endure was invented by websites as a workaround for the regs. So it wasn't obvious that consent parity would ever need to be clarified like this because it wasn't even obvious that the industry would come up with such an awful popup pattern to begin with (though in retrospect we should've known I guess).

The fact the popups were never even compliant anyway is just a combination of wilful ignorance, dark patterns, consulting companies wanting to sell something and - yes - an added set of people innocently misinterpreting regulation.

This should have always had been implemented by the user agent, not by web authors.
You're still thinking of it exclusively in terms of frontend web development (consent popups) whereas the original regulation was largely concerned with reducing data collection by the business in general, at a backend/database level & even things like manual in-person/on-paper collection.

The frontend content screen component of the whole topic was something that emerged afterward as businesses' attempt to get away with continuing rampant unfettered data collection.

This is nonsense talk. How do you differentiate between compliance with the regulation, and a "workaround" to the regulation? I guess it's at each of our discretion, right? It's subjective? Or are they the same thing? You can keep calling them "workarounds" but that distinction only exists in your own mind.
The rules are very clear: if you collect personal data¹ for other purposes than legitimate interest you need to give people an easy choice to deny that collection and the service should not be worse because of it.

I mean the EU published a guideline on what it calls deceptive design patterns. They are quite clear there with what is unacceptable (link to PDF): https://edpb.europa.eu/system/files/2023-02/edpb_03-2022_gui...

When even Google felt they had to make "reject all" equally big and not hise it in a sub menu, you know that everything else is likely not legal.

¹: whether you use cookies for it or not doesn't matter

It was included. The rule hasn't been changed. The interpretation of the rule in one specific case has been confirmed, without having changed the rule. That means that, as written, this dark pattern was always illegal.
i really don’t understand how it came to this anyway. the industry is so stubborn. what is not clear here? you should not spy on your site visitors for marketing purposes.

when you join a poll you do so with consent, when a market/social/political research entity invites you to a focus group (for example) you get at least a coffee and snack if not real money.

websites just get this for granted? it’s like stealing. it will never stop until the industry gets some understanding of these concepts.

We're talking about the advertising industry here. Calling these companies stubborn is a gross understatement.

This is the industry that perfected psychological manipulation in the pursuit of profits. It's built on decades of research into the best ways to associate brand names with positive feelings, and plant a desire to make a purchase in the subconscious mind of consumers. They will do anything humanly possible to deliver ads to your senses, and they've corrupted every media technology to do so since the existence of public broadcasting.

The internet has just given them the most profitable delivery mechanism, and in turn has made technology companies insanely rich. These adtech giants rule the internet, and can build the playground they need to make ad delivery more efficient than ever. Now these profits can trickle down to website owners, which will in turn take the path of least legal resistance, and employ every dark pattern imaginable in order to maximize _their_ profits.

And if this corrupt business model wasn't enough, adtech companies can perpetually multi-dip by selling the data they collect on shady data broker markets.

So, no, it's not just stubbornness, or lack of understanding. Deceit is built into this industry, and these cookie consent forms are just the tip of the iceberg.

The solution requires much stronger regulation than the GDPR. Unfortunately, this is very unlikely to pass given the influence advertisers have on governments.

> websites just get this for granted? it’s like stealing.

Isnt the user getting free content in return?

Absolutely not. If I see a cookie popup or subscribe modal, or even get interrupted reading with a pop-up prompt I immediately leave the site and add it to my blacklist.

Archive for life.

Free content was around before advertising on the web, this whole 'but they get free content' spiel was cooked up by advertisers.

Static we pages are cheap to host. Very rare is the article on [news site] getting mllions of simultaneous hits. But they all want videos embedded everywhere, gifs galore when all I want is to read their 20 min video in 2 minutes. They want their website hosted on the cloud with every new/hot architecture out.

How mant nyt articles are reprints of a reuters article the nyt then turns into 10 pages with aforementioned videos etc.

They did this to themselves.

If the website decides to offer content for free, then it may do so. If not, the website is entirely allowed to put up a paywall, or to display *non-targeted* advertisements. What the website is not allowed to do is mandate payment in the form of private information.
understanding is not the issue, caring is
> How did they not include this to begin with?

A bigger question is: why didn't they go with the DoNotTrack header.

Because the absence of a "DoNotTrack" header does not imply that a user has consented to being tracked, as a user may be using a browser that doesn't support "DoNotTrack". Nor does the setting of a "DoNotTrack" header necessarily correspond to a specific user, as it may have been set by a administrator policy. Nor would it be informed consent, as it is configured before the user has been informed as to the uses for which private data will be applied.

The GDPR requires that consent be informed, explicit, freely-given, and limited to a specific use case. Of these, the "DoNotTrack" header could be at most freely-given. Its design as a binary yes/no that can be configured across all sites prevents it from ever being used as a way to grant permission to track.

While the presence of "DoNotTrack=1" could be used to assume that no permission to track has been granted, this is already the default assumption that the GDPR requires companies to make.

A bigger question is: why didn't they go with the Platform for Privacy Preferences (P3P) header?

> P3P: CP="This is not a P3P policy! See http://www.google.com/support/accounts/bin/answer.py?hl=en&a... for more info."

Thanks for that. This game should probably be mandatory, for anyone involved with the cookie legislation. If they succed, they may propose a new draft.
It became painfully obvious over time that the people who drafted the legislation did not think through either the ways malicious compliance could work against their goals or the incentives of all actors in this story.
I think the possible forms of malicious compliance were considered, and are explicitly forbidden by the GDPR. The GDPR requires that consent be freely given, and be as easy to withdraw as to provide. The various end-runs around that requirement, such as redirects on rejected consent, click-through to privacy policy, click-through to a list of 3rd-parties, and so on, are all violations of the GDPR.

They aren't a form of malicious compliance at all, because they aren't compliant at all.

> How many cumulative wasted hours have been spent tapping through cookie pop ups?

Maybe not quite as privacy conscious, but a quick workaround: (1) Open in incognito (2) Click big, easy to find "Accept" button

Note that "cookie" popups are about tracking, not cookies. If you agree in incognito, they might fingerprint your browser and track you outside of incognito too, since you've agreed.
This is because their goal is to get a consent, not to give the user a choice.
What's the point of that legislation? Set your browser to block third-party cookies by default, problem solved.
That's a good nuclear option, but often we don't actually want to block all cookies. What we want is for sites to use cookies in ways that benefit us, but not use cookies to track us. Blocking them all or selectively allowing specifically chosen cookies puts to onus on the visitor to guess which cookies do what or lose functionality. Making the website owner legally responsible for declaring which cookies are for tracking and which provide functionality is a boon.
The person you replied to did not say block all cookies. They specifically said block all 3rd party cookies. If a site wants to set a 1st party cookie, but through code on their end share that cookie data with 3rd party sites, there's nothing we can do about that. But by gawd we can absolutely block the ones that are too lazy to do it like that and just link someone else's codes.

No banners necessary. Just block 3rd parties.

Cookies aren't the only thing involved here. The banners are asking if they can track you and that includes lots of things, your IP is the most obvious.
If I'm honest I never could quite understand the whole privacy kerfuffle about cookies, they ask the user to remember some token and if they so choose send that token back when they visit again. If cookies are a breach of privacy then so are ticket numbers.

Of course the whole issue is that the most popular user agents (i.e. web browsers) did very little to empower users to act responsibly with their cookies. I mean I consider the Cookie Autodelete extension just basic hygiene at this point, just like having a good ad blocker and some kind of firewall/virus scanner.

Third party cookies are already blocked in safari and Firefox. Cookie prompt is for first party cookie like analytics, ab testing, and rum cookies.
Watch out what you're agreeing to. Sites can share your email and telephone number with data brokers, if you've provided this info and clicked "agree".

You're agreeing to all — otherwise illegal — tracking they can manage to do, not just some cookies.

Unlike Safari, Firefox doesn’t block all third party cookies by default (because that breaks some websites’ legitimate use cases). Firefox does block known tracking cookies (with its “Enhanced Tracking Protection” Block list) and the remaining cookies are sandboxed to each website (“Total Cookie Protection”), so the Google tracking cookies on foo.com don’t know about the Google tracking cookies on bar.com.
If they require that that no response is considered a rejection of all non-essential then we're basically done.

Wow no one opted in? Shocked.

That's already what the law is.
As great as that is I still don't think it will make me hate them any less which is why I love Firefox for trying to address it at the browser level.

As a designer I despise mandatory content blocking modals and each one will still have a new design you have to decipher. Maybe if they clarified some design rules (2 or 3 big buttons with clearly defined text in legible colours/fonts etc) then it would be tolerable.

Regardless making it always have Accept/Reject/Custom is a good step forward, even though fingerprinting and browsers like Firefox blocking 3rd party cookies by default pretty much eliminates their utility.

It should just be a standard browser feature with a JavaScript API. Think of something similar to window.confirm() or a standard based on HTTP headers like Do Not Track. There could then just be a standard setting in the browser preferences and the world could be a better place again ten years from now.
No legal measure prevents your site from seeing the Do Not Track header and automatically rejecting cookies/tracking.

I've only seen a handful of sites do this. Developers inclined to respect Do Not Track seem less likely to add tracking anyway, in which case you also don't need the banner.

I hate that everyone benefits from GDPR and is rooting for Europe, yet very little is being done in North America.
I hate that everyone benefits from GDPR and hates GDPR and Europe for daring to try.
Whereas I hate GDPR, because all it has accomplished is making it harder to browse the web.

Nothing else.

No, it has very much also accomplished the task of showing you in (literal) big bright banners which websites have complete disregard for your data. If a website goes to great lengths to trick you into giving away your data, that’s a fantastic sign you should leave and never come back.
> Whereas I hate GDPR, because all it has accomplished is making it harder to browse the web. Nothing else.

Simply not accurate. The GDPR has other, more important accomplishments. See also: "gdpr unsubscribe", "gdpr do not contact", "gdpr consent". e.g. https://ico.org.uk/for-organisations/guide-to-data-protectio...

There are also other, less visible accomplishments. I've been on the inside of companies doing a GDPR data compliance check, and for some data stores, simply deciding that this one is not the "system of record", that passes beyond usefulness and setting a time-to-live of e.g. a month or a year, so that data about user actions is not retained beyond that.

This _absence_ of retained PII ( https://gdpr.eu/eu-gdpr-personal-data/ ) that has been encouraged by GDPR will inevitably make some breach somewhere less severe, but "what could have happened but did not" is not a visible accomplishment.

Thinking that it's all about your cookie banner is shallow, dismissive and egocentric.

that's like saying the graphic warning on your cigarette packages makes it more difficult for you to enjoy smoking. You're barking up the wrong tree
Well, this new specific detail of the law should get everything in order. Ignoring the banner means refusing for tracking. This was already in gdpr but not directly stated. So, in near future, banners should disappear in the current form
How did it make it harder to browse the web?
There really needs to be some kind of addition to the law that says "Should the user have GDPR_COOKIE_CONSENT=REJECTALL, the site should act as if the user manually rejected and objected all." The fact that third party vendors are having to produce workarounds for this reeks of the kind of American tax system that insists on taxpayers manually filling out their taxes.
Unfortunately this will likely just be used as a part of a unique user fingerprint generation method, similar to Do Not Track.
That's true, though iirc your screen size and fonts are more identifiable than having Do Not Track set.
"Disable cookies" was an option in the very first web browsers, so no, there doesn't need to be any addition to the law. You can disable cookies any time you want. Just don't cry when it turns out that you actually love "tracking" and need it to work for your web experience to be any good.
Here's the thing, kiddo. For most of the time, I'm quite content with disabling Javascript and cookies altogether since it also disables subscription popups and other inconveniences when all I want to do is read an article. When you click "Reject All", you aren't rejecting literally every cookie, otherwise how would it remember that you've rejected all? Instead, "Reject All" is shorthand for "Reject all cookies that aren't strictly necessary." You are simply being obtuse. Do you also froth at the mouth whenever someone says "Universal healthcare is free"?