But of course it’s impossible to convince someone of something when their livelihood depends on their not understanding it.
any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.
> When the law takes effect in January 2027, Californians will see new privacy options in web browsers. When enabled, these controls will automatically inform websites of their privacy preferences, helping to protect personal information from being sold to data brokers and other third parties. This means they will be able to protect their data — like their browsing history, location data, purchase history, and personal interests — across the entire internet with a single step.
However, powerful interest groups like ad companies that profit from your attention (which hysterically virtually powers the Internet today) were able to stop it from happening.
It was debated way back in 2009 when the GDPR was being developed. Iirc the argument was that browsers accept cookies by default so users do not get a fair consent moment. This is obviously easily fixed by regulation requiring browsers to ask users once.
Seems extremely backwards that we chose to forever darken the entire Web browsing experience just so users can "benefit" from a per-site option to let Google profit from them, with virtually zero payoff for the end user (ad relevance?).
P.S. If ad revenue is an essential pillar of Internet survival and fruition, the clear alternative seems to be sharing a fraction of that revenue with the tracked consumer.
;dr
The "cookie banner" is an interactive method used by "adtech" companies to try to get user consent, as required by EU law. The forced interaction makes this method annoying
Google and other "adtech" companies are lobbying EU Member States to vote against giving users a means to non-interactively deny consent
I'm visiting a website, i don't want to make a legal agreement with every website ...
Social media bad for kids? Everyone hand over your ID at the door ...
Need to look up a bus time? Full screen cookie consent with accept buttons drawn OFF THE SCREEN.
So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...
No cookie banner is required for functionally necessary cookies.
Sounds good, as long as it covers the "legitimate interest" bollocks⁰ that is often hidden in inconvenient UI nests as well as the basic preference.
-------
[0] "we see your preference not to be stalked, but we want to anyway, click again for every partner to reconfirm you don't want them following you around"
I don't have a lot of confidence for legislative solutions. Although I admire people who keep trying.
> ...
> You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default.
That's an excellent idea... lets see how its implemented on https://european-union.europa.eu/index_en
Oh... there's a cookie banner.
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
As written, this doesn't eliminate cookie banners completely, only if your browser is sending a Do Not Track header or similar. That's unfortunate news if you use fingerprint protection - those send default headers, so you'll still be bombarded with cookie banners. Hopefully existing anti-fingerprinting solutions will offer a "default headers but with Do Not Track" option.
1: https://www.cnil.fr/fr/cookie-walls-la-cnil-publie-des-premi... (in french, sorry)
I have personally never ever had any problems with the cookie banner since Brave deletes them with 100% accuracy, there's sometimes where a site will refuse to function properly, but it's usually sites I don't care about anyway and if I HAVE to get it working I disable brave shield, turn off all tracking, consent and turn the shields back on.
It is unfortunate that most browsers cannot implement this as it goes against what the companies behind the browsers want. Deleting the cookie prompt would stop people from occasionally just accepting all cookies and opting into tracking after getting tired of it.
Overall this is a common sense solution. The challenge is that a significant industry makes money by collecting and selling data. It makes it harder for businesses who depend on it, they are going to get creative and will eventually come up with some dark pattern to circumvent it.
Sites that easily allow you to simply reject everything are then a short hop, skip and a jump into browser settings where you auto-reject all cookie/tracking nonsense
1. Making tracking impossible/illegal would NOT kill cookie banners, since you need them to record consent for other purposes as well, such as embedding a video from a third party like YouTube.
2. The GDPR explicitly prohibits site-owners from making cookie banners misleading. The law is already there, it is just not very well enforced.
3. "This results in up to 90% of people saying “YES” – even though only around 3% actually want to be tracked online" This claim is grabbed out of thin air and can be dismissed as such.
4. "The solution: automatically communicate your privacy preference" This is nonsense because it does not actually solve anything, because you need to record consent for a variety of purposes, not just analytics/tracking.
5. Killing tracking would kill the value of ads (since they are not targeted anymore), resulting in a reduced ability for small businesses to advertise and a hugely increased amount of ad spam everywhere. Few targeted ads > Many untargeted ads
Unless you want an internet where advertising is no longer possible, this solves nothing apart from stroking a few activists ego.
But we can't have that, can we ? They will lobby to hell and back for that to not happen
> The solution: automatically communicate your privacy preference
Would be lovely and would happen if it weren't for… wait for it… Google and whole effed up ad-busines:
https://ppc.land/eu-council-drops-cookie-signal-after-google...
F*ck google and other BigTech…
There is ZERO cost to abusing the user over, and over, and over again by asking for permission to track them.
We shouldn't have the cookie banners at all because NO company should be able to do anything with tracking data. Just ban the use of user data by companies and most of SillyCon Valley's garbage behaviors are fixed.
Similarly, I should never get "terms of service updates" from digital companies because there should be no changes that they can make. You can provide the obvious service that you're providing; you can't aggregate my data for any purpose other than directly serving me; you can't aggregate my data with that of other users; if you retain my data for any other purpose, the government should take percentages of your revenue. I shouldn't have to wade through the BS that the mercenary corporate lawyers cook up to extract value from me.
It wasn't on EU Commission to "finally propose a solution". The soluton has always been there.
Somehow, Google, aka world's largest tracking and advertising company incidentally making the worlds' dominant browser and completely dominating all web standards, couldn't be bothered, and instead was pushing crap like FLoC
I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies? Who knows.
Another good one to have the "hide Youtube shorts" filter, featured on HN a while back.
So now they'd have a new popup that says "reconfigure your browser to accept tracking, or pay us, or you can't access the page". Which isn't really an improvement.
It's YOUR browser, a locally running software on a physical computer YOU own which memorize the cookie key-value pair a remote host told YOU to memorize and YOU return the same value later. It's YOU who allowed the cookie. If YOU don't want to allow the cookie, YOU simply not allow it.
You are technically 100% control on cookie. These JavaScript implemented in-page UI has no guarantee to respect your wish. But you have a power to disable it.
I guess what I'm saying is, there is no good solution here. I don't want every site I visit to require a usage fee just to browse. Imagine if slashdot turned into WSJ with a paywall for every article.
Kagi already does something like this, and cool - if you use it enough, maybe its worth a subscription. I dont find myself googling (searching) much anymore, so paying to do so just becomes something i need to find a way around. Like API token usage for AI, using it is like making a new recipe in the oven every time. You expect it to work but you have to invest the time and money into the attempt before you can find out the results (whereas you dont have to do this on free chatgpt, google search with ai, etc as comparison). Too much investment without guarantee of results. I'm fine without that guarantee as long as im not wasting my time and money upfront.
Anyways, thanks for letting me rant
I would say, we are like 80% there. Yes, there are still some dark patterns employed by cookie banners, trying to trick you into accepting tracking. But they are not too hard to make out. And they can be fixed by tuning the regulation a bit: Require the opt-out to be the first choice and the only one with highlighting.
Ad tracking is not going away tomorrow. If we ever are going to get rid of it, we first need legislation to defang it so it stops being a cash-cow. "Tracking prohibited by default" is a great end-goal, but we are not there yet.
Reading between the lines, it appears that there is some new solution proposed to "automatically communicate your privacy preference". That's nice, but when e.g. the Do Not Track header was tried, it just fell flat. So until this new solution is implemented and adopted, I'll take my websites with a cookie banner, thank you.
It is an unfortunate choice that the campaign obsesses over the cookie banner, instead of trying to actually advance the solution that would make it obsolete.
Why the fuck do people have to keep stating the same preference over and over again. This is a hellscape of bad government AND corporate policy colliding.
It's great. The current law forces people that don't give a shit about user privacy to have a banner (or any other way of asking for consent first) while giving everyone that cares and everyone not wanting to spy on their visitor a free pass.
There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened.
There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data mining, profiling, and other privacy-related aspects. But in many cases, you could just click "reject" and the banner would also disappear...
To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
As it stands I just hit Accept on literally everything and that’s fine for me.
The default is “no”. Without explicit consent you can’t do a lot of things.
You can’t have a default yes, because how can you agree with consent but automatically to everything?
And if it’s a no, are you saying you can’t ask a user for permission to use their data for a specific purpose?
And if you can ask, that’s what we have right now.
The online safety acts and its EU counterparts are somewhat risky, but nobody wants the mention the only proper alternative: a total ban on "social media." Not just for kids, but for everyone. Or a ban on smart phones, that would work too, at least short term. But: money.
THIS
Holy shit. This is such an obvious fix. And it shuts up those surveillance state goons immediately.
My God, why have we tried to summon up the ghost of 1984 when such a simple fix as this will do.
Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.
The blast radius is zero.
Good God, we need to fast track this into browsers right now. If we hurry we might be able to point to this as the technical fix.
Once some of the infrastructure exists, OS vendors can hook into it.
Firefox devs - please do this right now. Please spearhead this.
I might have to vibe code an advocacy site for the spec and set up a GitHub / RFC process.
Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.
This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.
but the proper functionality would be no cookies that require consent until consent is given
They will fingerprint you with or without cookies. They may or not try to honor your preferences, but their "partners" will not try, and by the time you see that banner, it's all out there.
"Accept" is the close button.
It is known that warnings and pop-ups that show up almost all the time yield diminishing returns. I think it was named "normalization of deviation" by some folks in a blog a while ago, and I believe that name fits. If you get warned about missing https all the time, or that something might be dangerous (even though it does precisely what you want it to do), it will loose its effect by the time you actually need it.
You can argue this is malicious compliance, but if you want it to go away it would probably be easier to go for banning tracking and personalized ads altogether. Eliminate the reason for this behavior, so to speak.
This is exactly what browsers did back the 90s, they asked about every single cookie.
Then browsers got configurable options to simply accept either all cookies, no cookies, or only first party cookies (excluding third party sites unrelated to the domain you visited).
For now well over 20 years I have disabled 3rd party cookies in all browsers I use, and only in a few cases overall did I need to make exemptions.
I think most companies just don't give a fuck about user privacy and therefor have to show one. There are of course exceptions. But I don't know how many of them have been actual (for-profit) companies.
Also I wanna know when websites don't give a shit about my privacy and therefor have to show a cookie banner. While theoretically not consenting should mean not collecting blocking it altogether and modifying page content might mean "all bets are off". If the website expects you to have made a decision that might wrongly consider it consent.
Consent-O-Matic says "I don't consent".
In 2024 Mozilla acquired Anonym from former Meta executives and decided to introduce PPA: https://hn.algolia.com/?q=privacy+preserving+attribution
50% that, and 50% that way more companies than you expect are harvesting and profiting from your data.
I am kind of wanting to f around and found out. I missed the old internet were most of the big websites are run by hobbyist. I know some of them may not be able to pay the bill without ad. May we can figure out something once we leveled the playing field
GDPR is not about cookies; it is about tracking. Whether the tracking is done through cookies or through other means makes absolutely no difference.
You can prevent some tracking via your browser, but definitely not all of it.
Sure, but magazines get a massive portion of their revenue through advertising without trackers. Same with television, or radio, or billboards.
And the ad space isn't exactly very healthy either. Take a large Youtube channel like Linus Tech Tips, for example: AdSense only accounts for 10% of their revenue! Youtube has been drowning people in ads and it still barely pays any money.
I think we should seriously consider the possibility that targeted ads might be less profitable overall. Ad blockers didn't become a thing solely because ads appeared on the web. Ad blockers became popular when ads became obnoxious and privacy-invading. With the current state of the web ad blockers are a hard requirement for a reasonable browsing experience, so the only people seeing ads are the handful of suckers too ignorant to install them.
But if ads aren't as invasive and obnoxious, people would have far fewer reasons to install ad blockers. See for example the Acceptable Ads program of Adblock Plus. If switching to user-respecting ads resulted in a significant portion of people turning off their ad blockers, it could very well result in an increase in ad revenue!
That has been my guess as well. If you run npm install half-the-internet you have no idea what's in there, so just slap on that cookie banner for good measure. Of course the real problem is not knowing what's inside your application, but the thought process is "eh, if a blanket cookie banner does the job then that's good enough for me".
Google knows if you can set this once it's game over for their adverting business. At least with the cookie banners, there's a possibly you won't refuse every banner.
Especially those banners that only have "Accept" or "More options" with all those checkboxes to clear.
E.g. storing your precise geolocation for 12 years: https://x.com/dmitriid/status/1817122117093056541
The fact that we are still talking about this literally a decade after the GDPR was adopted shows that this isn't working. It has turned into a cat-and-mouse game, and the regulators just don't have the manpower to effectively rules-lawyer every tiny change.
> when e.g. the Do Not Track header was tried, it just fell flat.
... because there was no reason to follow it. There was literally zero consequence for ignoring it.
This new proposal makes the Do-Not-Track v2 header legally binding. User sends the header and you still show a consent popup? You're breaking the law, simple as that. No weaseling yourself out of it, a simple screenshot is enough.
Any regulator could build a fully-automated scanner in half a day: ask the local TLD registrar for a mapping of websites to companies, have some script request the page and do a regex search for "cookie" (or use AI if you are feeling fancy), take a screenshot, pass it to an intern to double-check, then automatically send out a €100 fine. Double it every X weeks they haven't fixed it yet. Want to fight it in court? They have screenshot, you lose, now pay.
EU official website in it’s cookie banner glory: https://european-union.europa.eu/index_fr
Or that any actual human is aware that an agreement was made (since an AI can find a checkbox nowadays or software can be configured to bypass it). One way to add balance could be to require people asking for contracts to actually treat them like real serious legal documents, show up for the signing, and figure out who they are making an agreement with.
Clicking those "REJECT!" buttons might make you feel empowered, but it's pointless. Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you.
The whole thing has always been a problem to be properly solved by the browser, and it's probably just the fact that Google makes the only browser that matters, that it's been foisted upon every website owner, who mostly just wants basic analytics and to track conversions from the ads they run, and isn't "selling your data."
The browser is your user agent. If it's sending any information up to web servers on every request that isn't okay with you, why are you using it?
Only engineers have trouble understanding this. It can be a reasonable defense, and it has successfully been used in courts of law many times. The law is not a machine that compiles text like code literally. Imagine someone who coerces a dying or sick person to sign an agreement they couldn’t possibly be in a reasonable state of mind to understand what they were doing -- the law can and does invalidate such “contracts”. That is the same principle behind age of consent laws. The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
Oftentimes the reject flow is substantially more annoying than the accept flow. I click reject myself when it's an option, but I can absolutely understand how people might get conditioned to click accept when clicking reject might result in more popups.
There is one. It's a DNT header. Knucklehead websites ignore it.
When was the last time you read an entire EULA before installing software?
I'm going to guess the time frame is somewhere around "never."
These are nuisance contracts designed to jade people with legalese while stealing their rights to things like class action and enforcing binding arbitration.
Standard contracts sounds like the way to go.
What harm are you worried about?
And for a serious website, front end analytics are kind of a necessity to understand how users interact with pages and improve the experience. Note that it certainly doesn't require tracking the behaviour of individual users, just understanding how controls are used in aggregate.
I know it seems like you could work around this with careful design and maybe focus groups and such, but I can tell you we regularly uncover surprising insights from (aggregate) trends in front-end events.
The value is derived from the people consuming the product. Placing the "incentive to produce value" above the people who presumably are the source of this value seems...misaligned.
Some variant on "reject" takes more effort like 70% of the time. Which is on purpose, of course. The ones that aren't maliciously-complying have a "necessary only" button that insta-closes it, but tons pretend that you might want to allow some spying but not all of it and make you go through another screen if you don't just "accept all".
> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
Then it'd be possible to default it to "nope" (Firefox, and perhaps Safari, might do this) or to allow a "never, anywhere" setting the first time the question is asked, and malware and spyware vendors know that'd mean a much larger proportion of denials.
It already pushes the correct "Reject" button for you on a lot of sites (not all; it works based on rule lists)
On our go-live form there’s a question “do you use cookies” and it’s yes/no. If you say yes legal block the site from going live without the pre approved cookie banner…
When restoring factory defaults, the same question, just in case the phone is sold, gifted, stolen or whatever.
If you are going to give a phone to a minor you should set that option right from the start.
People not reading back on history is still very much a thing.
How often do you get prompted for, say, secure DNS or HTTP? Almost never, because your browser has sane defaults and controls that. So, there you go.
What browsers would those be?
P.S.: No true Scotsman spotted
It’s baffling we’re having this misunderstanding on this site in 2026 still.
So instead everyone stays on Facebook, Instagram, Reddit, and Twitter, which ALSO operate on ads and have far more information on their users than any third-party ad tracker could ever have.
None of this has gotten rid of the privacy problems. It just consolidated them into the worst offenders while jeopardizing the plurality of the web. Now instead of people being tracked by Facebook on a website with a third-party cookie in a like button, they are tracked by Facebook on Facebook in a Facebook page because they never leave Facebook.
It'd be even better if there was a way for people to selectively turn it off for specific devices without MITM the connections. It wouldn't be that hard to come up with a mechanism for that.
Options between "we don't have tech in the house" and "wide-open tech, we have it all" are all some amount of painful, usually for no good reason.
(I remember once investigating how to do some pretty basic stuff for this in Linux, hoping to find something nicer than manually setting some executable permissions and firewall rules and then having to go back and change them all the time, and the closest thing to a guide I found was an old article from Red Hat that basically lead with "LOL, good luck you poor sap, Linux sucks at this" before going on to explain the various bad ways available to sort-of, but not entirely, accomplish it with a lot of work, and significant ongoing time-burden)
The cookie banner isn't about the usage of cookies, it's about _the underlying tracking_. You're allowed to "just" use cookies for normal shit! You can make a website where you use cookies to store login state for a user, without a single banner.
The thing is that every company in the world feels the need to add 1000 tracking cookies to anonymous users to track them through conversion funnels (on top of the ad stuff). That's what you have to inform people about
You can use cookies normally without a banner! You can't track without consent! Every cookie banner is actually a "we want to track you" banner. Calling it a cookie banner is playing into the confusion about what those banners actually are meant to communicate
If people really cared, they’d chose reputable suppliers that sell non toxic food. If they are eating food with lead, they don’t care.
Don’t force your wordview on people through regulation
This is unfortunately the reality.
The other day a friend asked me to help her make her phone safer for her kids to use. I started by asking if she set permissions on the apps she downloaded. She looked at me blankly, "What permissions?". I proceeded to show her how you can granularly control what you allow each app to do on your phone and what access it is allowed. Her head blew up, she had no idea any of this existed and after gong through a few menus, she didn't care any more. It was all too complicated and too much to think about for a busy mum.
This is why governments unfortunately are having to try to protect people from themselves. As tech competent people it all seems so simple to us, but we need to remember the majority of the population just click 'Allow All' and blow past all permission and security questions as they have no idea what any of it means.
> Comments should get more thoughtful and substantive, not less, as a topic gets more divisive.
> When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."
> Don't be curmudgeonly. Thoughtful criticism is fine, but please don't be rigidly or generically negative.
Full guidelines: https://news.ycombinator.com/newsguidelines.html
You're welcome
if they didn't use third party cookies they wouldn't need it
My company scanned 209 European regulated sites in June, and roughly 7 in 10 had tracking that wasn't correctly gated by consent. It's rarely indifference, though. DPOs in the EU hold too much weight for that. It's usually a tag added that was never wired into the CMP or something added by a dev or LLM without going through proper review
Full disclosure: I run https://consentmark.com, which measures what tags actually fire under each consent state to create evidence packs companies can show regulators
I get similarly upset, when I see Google tracking on official websites of government or public institutions.
Prinicipal-agent law predates computers by a very long time.
Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful. We need YOUR help to #KillTheCookieBanner!


You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default.
Therefore, the tracking industry needs you to waive your rights. That’s why they invented cookie banners, which often are deliberately misleading as well as annoying.
This results in up to 90% of people saying “YES” – even though only around 3% actually want to be tracked online. This system is broken by design.


In Autumn 2025, as part of a bigger legal reform*, the EU Commission finally proposed a solution to the cookie banner problem: automated signals that would communicate your privacy preferences between your device and websites or apps. You could then choose whether you want to accept, refuse, or limit tracking.
This idea is neither new nor complex. Your browser already automatically signals other preferences to websites, for example your preferred language. In some US states, such signals for privacy preferences are already legally supported.

This would be a simple solution. But the tracking industry seems afraid that if you can express your preferences efficiently, it could result in lower consent rates for tracking.
Following lobbying efforts spearheaded by Google and the tracking industry, several Member States are now blocking the EU Commission’s proposal to get rid of the cookie banner.
But not only that: industry groups are also lobbying the European Parliament to reject the proposal.


That’s where you come in: the fight to kill the cookie banner is far from over. The Member States and the European Parliament have not yet decided on their position on the issue yet.
You can take action by contacting your representative in the European Parliament or in your Member State and express your frustration.
*This proposal for privacy signals is part of an EU law reform called the Digital Omnibus. Most other parts of this reform are problematic and would weaken people’s rights. We want to make clear that we do not support these other aspects of the proposed reform.
*This proposal for privacy signals is part of an EU law reform called the Digital Omnibus. Most other parts of this reform are problematic and would weaken people’s rights. We want to make clear that we do not support these other aspects of the proposed reform.
I've long since considered that the efforts for online child safety should be pointed at educating parents and spearheading some kind of certification of compliance for child safety of software and websites.
[this product is certified to adhere to EU:CSA]
Then you can block everything not certified, and the software that does the blocking would also be certified, the two major prongs you need (endpoints and sites working together: else they're blocked). The rest of the money goes to education for parents about this fact, and the dangers of not doing it, and how to do it.
This is super "easy" (when comparing to the effort it would take for putting backdoors in everything).
Which is why I think that the reason is definitely not child safety, and more about crime control.
Me talking about UK blocking people unless they ID themselves in 2013: https://news.ycombinator.com/item?id=6979295
Me talking about how its disingenuous because we have superior technical solutions to this particular issue last year: https://news.ycombinator.com/item?id=45010902
https://www.nbcnews.com/news/us-news/disney-says-man-cant-su...
"Disney is trying to have a widower's wrongful death lawsuit dismissed and sent to arbitration because the man had signed up for a Disney+ account several years ago."
Now what happened was that Disney quit fighting over really bad PR. But the court challenge would have liteky succeeded.
Exactly. I use the "I don't care about cookies" extension, which rejects most cookies automatically without me having to see the popups. But even accepting cookies is fine - I'll be closing my browser soon anyway and they'll be gone.
Also, striking an unconscionable term typically does not void the whole contract. Just the term in question.
CA tried this with AB 1856. I wasn't a fan of this (neither was EFF) because of the privacy and tracking concerns of blasting the fact that the user is a child to all websites.
https://www.eff.org/deeplinks/2026/05/one-step-forward-two-s...
It would better for the block to happen at the device level. That is, the browser knows it's on a child's device and has a whitelist of allowed sites.
There is already an RTA (Restriced to Adults) header where the website self-labels that it's for adults only and the browser can block it while protecting the user's privacy. I'd prefer expanding the use of RTA.
In the UK a few news sites have changed cookie banners to "you can accept and see this stuff for free, or you can sign up for a subscription, which would you prefer?". It's the only time I hit accept (and then clear browser history).
If blanket preferences from browser signals became the norm, a segment might open up where you would configure preferences and a data broker would make sure you get something in return for your data. At minimum it might force paywalled publishers to consider that as a "lite" subscription option.
> The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
I haven’t heard of a single case where an agreement was voided because “no one could reasonably be expected to understand it.” Unless the language was so impenetrable or vague that the agreement itself could not be discerned. Lawyers tend not to write such agreements.
If the banner's not required, it ends up saying stuff like "we'd like permission to share your data with 0 partners". Ever see that?
The fact is most website operators want to (or agreed in ignorance to) use your data for non-essential purposes
I mean that both in the sense of "you, plural" (your company should fix that) and "you, personally" (because diffusion of responsibility is a real issue, and someone needs to actually do it).
Just checking, you do know that still counts as tracking and may fall under GDPR rules? GDPR was never just about cookies.
You could, for example, require that user answers very specific questions regarding 10 randomly selected partners and how exactly they can use the data ("is partner x allowed to build very detailed profile of you and target you with political adverts that are designed to manipulate you?").
These banners handle both ePrivacy consent for cookies etc, but also GDPR Art. 6(1)(a) for processing purposes (personalised ads, measurement, audience insights, precise geolocation, even device fingerprinting).
It's not hard to make privacy work when you are the government rather than working against a hostile one.
Consent-O-Matic -> automated configuration to your preferences using the dialog provided.
I still don't care about cookies -> least privacy friendliest option, because it may opt into undesired tracking (its goal is just to remove the annoyance of the dialogs)
The reason this isn't done is because corporations legal departments love writing 10-100 page contracts that absolutely nobody is going to read.
As opposed to enforcing your worldview with a lack of regulation?
Because that's precisely what's happening, with the advertisement industry enforcing their worldview through lack of compliance.
The law really has nothing to do with cookies, it has to do with privacy, tracking, and PII. You can absolutely save preferences and perform analytics. What you can't do is hoard data that is personally identifiable for purposes that are not obvious to the consumer.
Sure, your browser cookie will be gone. But you have already allowed the server-side identifiers of your session to be used for whatever purpose, including reconstituting increasingly larger parts of your identity over multiple disconnected sessions. Please don't make the mistake of thinking that clearing your cookies afterwards is the same as rejecting all server-side processing.
Like it or not, the Web is a two-way street, meaning that the server end of the transaction doesn't owe the client end anything in particular unless there's some relationship in place (like a payment). It appears the "just ignore it" matches the intent of most web users, though, since an overwhelming majority of web visitors accept a bunch of spammy ads + free 'content,' and a slim minority pay for ad-free alternatives.
I haven't set up an Android in a while, but, I doubt it's massively different.
Exactly. The problem is its from the parents side.
See here[0], page 6:
> As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’
0: https://www.edpb.europa.eu/system/files/documents/2024-10/ed...
As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen
Lack of privacy harms journalism and activism, making the government too powerful and not accountable. If only activists and journalists will try to have the privacy, it will be much easier to target them. Everyone should have privacy to protect them. It’s sort of like freedom of speech is necessary not just for journalists, but for everyone, even if you have nothing to say.
Good.
> and you can't run a serious website without some kind of analytics.
I don't believe you.
> Preference-storing does as well, despite any reasonable user expecting that, if they set a preference, it will be saved.
IANAL, but I'm given to understand that this is untrue.
Aside from that many of these contract have terms that might be considered substantive unconscionability - for example if terms state that what you post can be used by the company that owns the service for marketing of the company or the service I feel this would not make it through most legal systems that I feel before the attempt are not inherently corrupt.
They did not read the text to agree.
It was the fastest way to get the banner to go away. Sometimes they force you to confirm multiple times if you click ”none” or ”minimal”.
ads don't require invasve and pervasive tracking
The web is too big and changes too much and that's before we get to the issue of applying laws to a whitelist based on different juristictions worldwide.
And I have to question, who would administer it? The parents? They won't. Google or Apple? Why do they want to deal with irate parents or culture wars around what is or is not on the list?
There is obvious increasing demand for this from parents, politicians are going to act on it, I think a "this is a child" header is the only one that actually really works. It works for the parents because it's easy to setup. It works for websites because they can cleanly identify a child and filter content if appropriate.
It seems to me that every other solution than a "this is a child" header is either impractical or way worse.
What we need is an environment that does not give the producers asymmetric power over consumers and the products will naturally align with that.
So do car alarms.
I'm not convinced this is a business model I want to exist. We had an internet before it, and Google, and Facebook. I'm increasingly sad we can't return to it.
I do not want the gas station, or the airplane I'm on, spying on me to build relevant advertising. That is the end game of "relevant ads": my gas pump already serves me ads, the airplane I'm on serves me ads, my own car now (via a software update that occurred after purchase) serves me ads. Monitors now serve ads. TVs are abusing people's Internet connections, which isn't ads, but it's basically the same problem: if I can abuse the customer without consequence, why shouldn't I?
Just no. The problem is, I as a consumer cannot vote with my wallet: companies can and will go "I could take your money, and earn $X, or I could do that and ads and earn $X + $Y."; there is not reason for them to choose the former, and most markets are so concentrated (e.g., airlines) that there is not ample competition for the market to provide ample "vote with wallet" choices. Further, in the car example, it's just bait and switch: even when I think I can vote with my wallet, the company can just alter the terms of the deal, knowing full well the switching price of a car makes me subservient to them.
However the UK does have its own GDPR regulation (see: <https://www.gov.uk/data-protection>), though my understanding is that it may be less strict in requiring equivalence between "accept" and "reject" actions. (I may be wrong on this.)
UK sites accessed from the EU would have to be under EU GDPR compliance.
Why? Plenty of websites operate just fine with no or near-zero ads. Just look at the one you are currently on!
And what's with confusing "relevant ads" with "privacy-invading targeted ads"? There's still plenty of ads in print media, on television, and on billboards: none of them are invading my privacy, yet they still manage to be relevant by choosing a medium with a certain target demographic. Websites used to do the same, there's no technical reason we can't return to this.
I'm not sure to understand the proposed solution here, but it seems someone could just use a different web browser client who don't inherit these restrictions.
The law that caused the cookie banners also says companies cannot block access to the site if the cookies are not required for the functioning of the site.
Some German news sites have broken this and have "accept or pay" and I think this leaked to news sites in other countries. Facebook even tried it.
So, sure, if DNT is true, try to make people pay. Fine by me.
Mozilla with their Thundermail just tried saying in their ToS that if you're mentioned at all in anything legal, you agree to pay their legal fees.
If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway."
Note that I used "sign any name" as the metaphor, not "show ID," since it is trivial to not allow any important information exchange if you simply delete the cookies yourself, which is easy to configure a browser to do. The end-user has the choice, if it's so important to them, to configure their browser. Even Chrome can be configured for which sites to allow cookies, which to disallow, and which to clear when the browser closes (the smart choice, since accepting them and throwing them away soon after is the undetectable option that accomplishes your main aim).
What do you see as the harm in website owners using aggregated analytics data to improve their sites?
Yes, granted, a globally enforced whitelist probably wouldn't work. I'm referring to bespoke lists that parents control. I know plenty of parents that use this. e.g. here's Apple's feature:
https://support.apple.com/en-us/105121#:~:text=Prevent%20ina...
> It works for websites because they can cleanly identify a child and filter content if appropriate.
This still doesn't solve the problem of different jurisdictions and culture wars of what is or isn't appropriate for kids. All this does is move the liability upstream to websites instead of the devices. That is, instead of the browser deciding what's appropriate, now Youtube, Reddit, etc have to decide. And, as we've seen with the OSA in the UK, typically smaller platforms can't handle the enforcement cost so they just shut down entirely.
https://onlinesafetyact.co.uk/in_memoriam/
The larger platforms often use overbroad CYA measures and throw up age verification where they don't need to (Reddit has done this in the EU), or just ban minors (Anthropic and character.ai did this).
As far as blocking explicit content, a self-labeling requirement like RTA accomplishes the same thing as a "this is a child" header but without the liability CYA and without the privacy concerns.
Where the "this is a child" header solution could theoretically win is allowing kids to access websites in a limited child-safe way, e.g. going to Reddit in child mode automatically shuts off certain subreddits. But, as we've seen, it just doesn't work well in practice and usually frustrates parents by overly broad content policing and liability theater. Kids are also at different levels of maturity and I've seen them get frustrated when they're binned into age categories that they feel they don't deserve. e.g. a 12 year old might be plenty mature enough for the 13-16 age category.
But my real objection to the "this is a child header" is the privacy risk and surveillance risk. I don't think it's worth it.
You need to disclose it in your privacy policy, you need to delete it after a reasonable retention period and you can't use those logs for other purposes like ad targeting, but you don't need a consent banner to track things that you are legitimately using for security purposes.
It was never about the cookies themselves. That just happened to be the most common form of tracking in use when the GDPR was originally written. Cookie-less tracking still requires a consent prompt, tracking-less cookies never required one.
I just visited theguardian.com to see their cookie banner. The banner says this:
> Your Privacy (`x` button to close the tab)
> US residents have certain rights with regard to the sale or sharing of personal information to third parties.
> Guardian News and Media and our partners use information collected through cookies or in other forms to improve experience on our site and pages, analyze how it is used and show personalized advertising.
> You can opt out of the sale of all of your personal information by pressing
> <button>Do not sell or share my personal information</button>
It's 3 sentences, plus a button that says "Do not sell or share my personal information". I actually don't even think this is GDPR compliant, because my layman's understanding says that GDPR consent must be presented as opt-in, rather than opt-out. (I guess they are going for CCPA/CPRA compliance?) But anyway, I would think that a reasonable person could be expected to notice a button that says "Do not sell or share my personal information" and then click it, especially when it's portrayed prominently at the bottom of the page.
I think it's absolutely fair and unlikely to be illegal to use a cookie to remember cookie preferences. Unless the cookie value was not yes/no, but something like a precise timestamp that could be used for uniquely identifying.
And I'd gladly trade today's BS for any version of "The Internet" pre-2007.
But the "Before" Internet wasn't some natural sustainable state.
Before 1997 or so, "the Internet" was being paid for by academic institutions and big companies, and wasn't really all that commercial at all. It was also pretty tiny and blessedly simple. Honestly this version is the most achievable (re-creatable?) today since we can set up indie websites much easier today than we could then. Instead of using your free webspace from your university or employer, 20 of us could share a $5 a month instance, and link to each other's webpages, and add an IRC server to that instance just for fun.
In the 1998-2007 era, the Internet got a lot bigger, but was also still pretty fun and not that enshittified, but that's just because it was being paid for by VC money being burned.
Today we are where we are in terms of business model[1] because Google and Facebook achieved great success with ad-based business models because of the ability to target ads better, and because consumers of The Internet have spoken, loudly, with their closed wallets. They've said "We will only pay for content if it's All The Music and ~$10 a month flat rate, or if it's a big/interesting enough video on-demand service and under $20 a month. We'll never pay for news or text content of any kind." So, the businesses with other types of content do what the public wants them to do: have cost-free content whose access is conditional on being advertised to very annoyingly, or they marginalize themselves with paywalls, subscribed to by only a small minority of users.
[1] i'm setting aside the non-business aspects of our mess, namely the poison that social media, 'engagement' optimization, and ragebait-as-news has wrought on society.
The aim here is to protect the children. "Just let parents protect them" doesn't work when there's millions of parents that won't care.
Also AFAIK the Google Fonts question (is the IP alone already PII, if Google has no way of tying the IP to a person) has not been decided by the ECJ yet. There've only been decisions by lower level German courts that are still in dispute.
But of course, designing the system that pushes people to make this sort of decision was absolutely intentional.
So even when it's incompetence, it's still malicious, just in a way that obscures the explicit decision-making that led to the result.
Practical: Supposedly-aggregated stats have a history of actually being perfectly possible to analyze back into individually identifiable information. Also, it's conveniently the same tech stack in a way that makes it easier to make an actual slippery slope.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
We should just give up and give random individuals access to everyone's camera roll.. no other way.
When prompted by the browser on first login/signup, yes, the same way the password manager works. With stored passwords, keeping the login cookie doesn't even add much value.
Yes, as a parent, you are required to put in more effort into parenting your kid than random hypothetical people. That's obvious, and has been the case forever.
I understand the concept of community, but community is not me sacrificing my privacy for someone 1000 miles away.
If parents don't want to do X, Y, and Z to lock down their devices then that is their right. And I support their rights, so the conversation is over right then and there IMO.
How many requests per second are being served? How many error codes were delivered to clients? How quickly the service responded? Service logs without PII? All perfectly fine to aggregate and analyze without consent.
Because this is there 1 millionth cookie banner, because every site and their momma has one.
Also, 90% of cookie banners are not this good. They tell you nothing, hide the "reject" button behind multiple screens, etc. At that point the consumer is trained to click accept.
Advertisers are willing to pay more for privacy-invading ads because they believe they are more effective. If privacy-invading ads were illegal they'd just go back to context-dependent ads like they have been using for the thousands of years before the internet was invented, and after an adjustment period the revenue will just bounce back to where it was before.
Most advertisers know this already. If privacy-invading ads were so effective, why are all the major brands now using influencers to market their products? Why go through the effort of finding a specific Instagram channel which might be a good fit and convincing the operator to enter a brand deal, when you could also just directly pay Instagram for a highly-targeted ad one swipe away?
Again, that is not a requirement. If your argument is that they give us content for free because of ads, ads don't require pervasive and invasive tracking. Or hiding stuff behind paywalls (since ads pay for it).
(see e.g. https://iapp.org/news/a/cjeu-clarifies-cookie-consent-requir... https://www.edpb.europa.eu/news/edpb-consent-or-pay-models-s... )
This is the definition of informed consent
Sorry that you need the government to "help" people in this way, by forcing other people to give them free things.
Well, there is a skip button. It's labelled "accept all"
For example, in The Netherlands there is a legally mandated three-day period after signing the contract for purchasing a home during which the buyer can still call off the deal.
The reasoning for this is that it is a seller's market, with demand far outnumbering supply. In practice it is very common these days to end up in a bidding war, and even forego any kind of "sale is void if home inspection turns up issues" clause. Want to think about it for a day or two before signing the biggest contract of your life? Too bad, another buyer is willing to sign today.
With the mandatory three-day waiting period you avoid buyers being locked into a contract they basically immediately regret. It gives them some time to do due diligence, reducing the risk of buying a complete lemon. The seller can ask for a similar clause to be inserted, but it is less common. After all, the only risk to the seller is getting slightly less money for it, and that's already mostly dealt with during the bidding process.
However, since we are discussing the banner that The Guardian website shows to US viewers, I assume they’re trying to comply with California privacy law, which does allow opt-out regarding the sale of personal information.
As I said above, if the parties cannot be said to have an agreement because the terms of the agreement itself are inscrutable, then that would probably result in no contract being formed, or the terms at issue interpreted in the light most favorable to the non-drafting party. Like if the terms were presented in so small a font that only someone with a microscope could have read them.
Basically you have to successfully argue that no reasonable person could have read and understood the agreement. You’re unlikely to prevail if you argue only that you, the individual, did not.
Naturally in a camera meeting with a "don't tell anyone we said that" appended right before.
The marketing people in the meeting were very angry that California was "doing it to them".
Bit of a mouthful though.
Greatest minds of our generation couldn’t possibly invent fast profile switching.
Lost technology.
As an example I have an email account with site A. I go to site A and log in, they suddenly spring a large new contract for me to read, I cannot get through to do what I came to do, it will take me 5 minutes to read so I click OK because I am on my way to check my email with site A. Procedurally this is not reasonable behavior.
What would be reasonable?
"Hi, we are changing our terms of service, you can see it at this link and agree. If you don't have the time right now you can do it later, but in three days you will lose access to the service unless you agree to terms."
There are however lots of other laws in the EU which may in fact make this behavior substantively unconscionable anyway. I certainly believe there would also be substantive arguments to be made in this case.
Also, sarcasm isn’t welcome here. Please read the HN guidelines.
Ah yes, I didn't couch my post in any of the various, rampant HN-friendly versions of shitposting. I'll try to follow your example from here on out. Excellent touch citing the guidelines at me after your role in this thread, A+.
Re-reads this thread, taking notes
HN is supposed to have higher than typical standards for participation than most internet fora and is largely self policing. It’s not condescending to tell people when they are misbehaving. Nor is it condescending to explain to people the law and how things work, provided you’re not insulting them in the process. Which I’m not doing.
I find much more concerning people’s certainty of their mistaken understandings and beliefs, combined with the most ludicrous possible interpretation of other’s positions.