But of course it’s impossible to convince someone of something when their livelihood depends on their not understanding it.
This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data mining, profiling, and other privacy-related aspects. But in many cases, you could just click "reject" and the banner would also disappear...
To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
Some variant on "reject" takes more effort like 70% of the time. Which is on purpose, of course. The ones that aren't maliciously-complying have a "necessary only" button that insta-closes it, but tons pretend that you might want to allow some spying but not all of it and make you go through another screen if you don't just "accept all".
> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
Then it'd be possible to default it to "nope" (Firefox, and perhaps Safari, might do this) or to allow a "never, anywhere" setting the first time the question is asked, and malware and spyware vendors know that'd mean a much larger proportion of denials.
But of course, designing the system that pushes people to make this sort of decision was absolutely intentional.
So even when it's incompetence, it's still malicious, just in a way that obscures the explicit decision-making that led to the result.
Naturally in a camera meeting with a "don't tell anyone we said that" appended right before.
The marketing people in the meeting were very angry that California was "doing it to them".
Clicking those "REJECT!" buttons might make you feel empowered, but it's pointless. Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you.
The whole thing has always been a problem to be properly solved by the browser, and it's probably just the fact that Google makes the only browser that matters, that it's been foisted upon every website owner, who mostly just wants basic analytics and to track conversions from the ads they run, and isn't "selling your data."
The browser is your user agent. If it's sending any information up to web servers on every request that isn't okay with you, why are you using it?
Exactly. I use the "I don't care about cookies" extension, which rejects most cookies automatically without me having to see the popups. But even accepting cookies is fine - I'll be closing my browser soon anyway and they'll be gone.
It is known that warnings and pop-ups that show up almost all the time yield diminishing returns. I think it was named "normalization of deviation" by some folks in a blog a while ago, and I believe that name fits. If you get warned about missing https all the time, or that something might be dangerous (even though it does precisely what you want it to do), it will loose its effect by the time you actually need it.
You can argue this is malicious compliance, but if you want it to go away it would probably be easier to go for banning tracking and personalized ads altogether. Eliminate the reason for this behavior, so to speak.
There is one. It's a DNT header. Knucklehead websites ignore it.
Like it or not, the Web is a two-way street, meaning that the server end of the transaction doesn't owe the client end anything in particular unless there's some relationship in place (like a payment). It appears the "just ignore it" matches the intent of most web users, though, since an overwhelming majority of web visitors accept a bunch of spammy ads + free 'content,' and a slim minority pay for ad-free alternatives.
The law that caused the cookie banners also says companies cannot block access to the site if the cookies are not required for the functioning of the site.
Some German news sites have broken this and have "accept or pay" and I think this leaked to news sites in other countries. Facebook even tried it.
So, sure, if DNT is true, try to make people pay. Fine by me.
Oftentimes the reject flow is substantially more annoying than the accept flow. I click reject myself when it's an option, but I can absolutely understand how people might get conditioned to click accept when clicking reject might result in more popups.
If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway."
Note that I used "sign any name" as the metaphor, not "show ID," since it is trivial to not allow any important information exchange if you simply delete the cookies yourself, which is easy to configure a browser to do. The end-user has the choice, if it's so important to them, to configure their browser. Even Chrome can be configured for which sites to allow cookies, which to disallow, and which to clear when the browser closes (the smart choice, since accepting them and throwing them away soon after is the undetectable option that accomplishes your main aim).
However the UK does have its own GDPR regulation (see: <https://www.gov.uk/data-protection>), though my understanding is that it may be less strict in requiring equivalence between "accept" and "reject" actions. (I may be wrong on this.)
UK sites accessed from the EU would have to be under EU GDPR compliance.
What harm are you worried about?
These banners handle both ePrivacy consent for cookies etc, but also GDPR Art. 6(1)(a) for processing purposes (personalised ads, measurement, audience insights, precise geolocation, even device fingerprinting).
Lack of privacy harms journalism and activism, making the government too powerful and not accountable. If only activists and journalists will try to have the privacy, it will be much easier to target them. Everyone should have privacy to protect them. It’s sort of like freedom of speech is necessary not just for journalists, but for everyone, even if you have nothing to say.
This is exactly what browsers did back the 90s, they asked about every single cookie.
Then browsers got configurable options to simply accept either all cookies, no cookies, or only first party cookies (excluding third party sites unrelated to the domain you visited).
For now well over 20 years I have disabled 3rd party cookies in all browsers I use, and only in a few cases overall did I need to make exemptions.
They will fingerprint you with or without cookies. They may or not try to honor your preferences, but their "partners" will not try, and by the time you see that banner, it's all out there.
"Accept" is the close button.
There's a mismatch between the velocity at which people visit sites and the time it takes to navigate the cookie particulars of each site.
And, we can dismiss this as people being uninformed or lazy but the reality it is that's actually not so unreasonable. Cookies are in some ways near the bottom of the list where privacy is concerned, given everything else from breaches to search dossiers to device finger-printing to mobile device location-tracking to the ubiquity of cameras in the real world, and on and on.
The idea that we're clawing back privacy in any meaningful sense by blocking a few cookies here and there is kind of quaint.
People do not have a right (morally speaking, not legally) to access or use a service (or a website) etc without having to read/agree to the terms (applies to analog and digital).
If your terms require people to get a law degree and take a week to parse the 400 page document, then I would argue that it's a tactic to get people to sign up for the service without fully understanding it.
We need legislation that forces companies to communicate the terms in a way that an average person can comprehend.
We really need to stop companies from putting up these insanely complicated legal texts to use basic services when they could all be behind standard contracts.
any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.
The default is “no”. Without explicit consent you can’t do a lot of things.
You can’t have a default yes, because how can you agree with consent but automatically to everything?
And if it’s a no, are you saying you can’t ask a user for permission to use their data for a specific purpose?
And if you can ask, that’s what we have right now.
How often do you get prompted for, say, secure DNS or HTTP? Almost never, because your browser has sane defaults and controls that. So, there you go.
P.S.: No true Scotsman spotted
If people really cared, they’d chose reputable suppliers that sell non toxic food. If they are eating food with lead, they don’t care.
Don’t force your wordview on people through regulation
As opposed to enforcing your worldview with a lack of regulation?
Because that's precisely what's happening, with the advertisement industry enforcing their worldview through lack of compliance.
As it stands I just hit Accept on literally everything and that’s fine for me.
It already pushes the correct "Reject" button for you on a lot of sites (not all; it works based on rule lists)
There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened.
There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
Only engineers have trouble understanding this. It can be a reasonable defense, and it has successfully been used in courts of law many times. The law is not a machine that compiles text like code literally. Imagine someone who coerces a dying or sick person to sign an agreement they couldn’t possibly be in a reasonable state of mind to understand what they were doing -- the law can and does invalidate such “contracts”. That is the same principle behind age of consent laws. The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
> The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
I haven’t heard of a single case where an agreement was voided because “no one could reasonably be expected to understand it.” Unless the language was so impenetrable or vague that the agreement itself could not be discerned. Lawyers tend not to write such agreements.
I just visited theguardian.com to see their cookie banner. The banner says this:
> Your Privacy (`x` button to close the tab)
> US residents have certain rights with regard to the sale or sharing of personal information to third parties.
> Guardian News and Media and our partners use information collected through cookies or in other forms to improve experience on our site and pages, analyze how it is used and show personalized advertising.
> You can opt out of the sale of all of your personal information by pressing
> <button>Do not sell or share my personal information</button>
It's 3 sentences, plus a button that says "Do not sell or share my personal information". I actually don't even think this is GDPR compliant, because my layman's understanding says that GDPR consent must be presented as opt-in, rather than opt-out. (I guess they are going for CCPA/CPRA compliance?) But anyway, I would think that a reasonable person could be expected to notice a button that says "Do not sell or share my personal information" and then click it, especially when it's portrayed prominently at the bottom of the page.
Because this is there 1 millionth cookie banner, because every site and their momma has one.
Also, 90% of cookie banners are not this good. They tell you nothing, hide the "reject" button behind multiple screens, etc. At that point the consumer is trained to click accept.
This is the definition of informed consent
However, since we are discussing the banner that The Guardian website shows to US viewers, I assume they’re trying to comply with California privacy law, which does allow opt-out regarding the sale of personal information.
Also, striking an unconscionable term typically does not void the whole contract. Just the term in question.
Aside from that many of these contract have terms that might be considered substantive unconscionability - for example if terms state that what you post can be used by the company that owns the service for marketing of the company or the service I feel this would not make it through most legal systems that I feel before the attempt are not inherently corrupt.
As an example I have an email account with site A. I go to site A and log in, they suddenly spring a large new contract for me to read, I cannot get through to do what I came to do, it will take me 5 minutes to read so I click OK because I am on my way to check my email with site A. Procedurally this is not reasonable behavior.
What would be reasonable?
"Hi, we are changing our terms of service, you can see it at this link and agree. If you don't have the time right now you can do it later, but in three days you will lose access to the service unless you agree to terms."
There are however lots of other laws in the EU which may in fact make this behavior substantively unconscionable anyway. I certainly believe there would also be substantive arguments to be made in this case.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
https://www.nbcnews.com/news/us-news/disney-says-man-cant-su...
"Disney is trying to have a widower's wrongful death lawsuit dismissed and sent to arbitration because the man had signed up for a Disney+ account several years ago."
Now what happened was that Disney quit fighting over really bad PR. But the court challenge would have liteky succeeded.
The value is derived from the people consuming the product. Placing the "incentive to produce value" above the people who presumably are the source of this value seems...misaligned.
What we need is an environment that does not give the producers asymmetric power over consumers and the products will naturally align with that.
Also, sarcasm isn’t welcome here. Please read the HN guidelines.
Ah yes, I didn't couch my post in any of the various, rampant HN-friendly versions of shitposting. I'll try to follow your example from here on out. Excellent touch citing the guidelines at me after your role in this thread, A+.
Re-reads this thread, taking notes
Or that any actual human is aware that an agreement was made (since an AI can find a checkbox nowadays or software can be configured to bypass it). One way to add balance could be to require people asking for contracts to actually treat them like real serious legal documents, show up for the signing, and figure out who they are making an agreement with.
Prinicipal-agent law predates computers by a very long time.
The law really has nothing to do with cookies, it has to do with privacy, tracking, and PII. You can absolutely save preferences and perform analytics. What you can't do is hoard data that is personally identifiable for purposes that are not obvious to the consumer.
How many requests per second are being served? How many error codes were delivered to clients? How quickly the service responded? Service logs without PII? All perfectly fine to aggregate and analyze without consent.
When was the last time you read an entire EULA before installing software?
I'm going to guess the time frame is somewhere around "never."
These are nuisance contracts designed to jade people with legalese while stealing their rights to things like class action and enforcing binding arbitration.
Standard contracts sounds like the way to go.
So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...
Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.
This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.
When prompted by the browser on first login/signup, yes, the same way the password manager works. With stored passwords, keeping the login cookie doesn't even add much value.
Well, there is a skip button. It's labelled "accept all"
It’s baffling we’re having this misunderstanding on this site in 2026 still.
It's not hard to make privacy work when you are the government rather than working against a hostile one.
The online safety acts and its EU counterparts are somewhat risky, but nobody wants the mention the only proper alternative: a total ban on "social media." Not just for kids, but for everyone. Or a ban on smart phones, that would work too, at least short term. But: money.
This is unfortunately the reality.
The other day a friend asked me to help her make her phone safer for her kids to use. I started by asking if she set permissions on the apps she downloaded. She looked at me blankly, "What permissions?". I proceeded to show her how you can granularly control what you allow each app to do on your phone and what access it is allowed. Her head blew up, she had no idea any of this existed and after gong through a few menus, she didn't care any more. It was all too complicated and too much to think about for a busy mum.
This is why governments unfortunately are having to try to protect people from themselves. As tech competent people it all seems so simple to us, but we need to remember the majority of the population just click 'Allow All' and blow past all permission and security questions as they have no idea what any of it means.
I haven't set up an Android in a while, but, I doubt it's massively different.
We should just give up and give random individuals access to everyone's camera roll.. no other way.
Greatest minds of our generation couldn’t possibly invent fast profile switching.
Lost technology.
Bit of a mouthful though.
When restoring factory defaults, the same question, just in case the phone is sold, gifted, stolen or whatever.
If you are going to give a phone to a minor you should set that option right from the start.
It'd be even better if there was a way for people to selectively turn it off for specific devices without MITM the connections. It wouldn't be that hard to come up with a mechanism for that.
Yes, as a parent, you are required to put in more effort into parenting your kid than random hypothetical people. That's obvious, and has been the case forever.
I understand the concept of community, but community is not me sacrificing my privacy for someone 1000 miles away.
If parents don't want to do X, Y, and Z to lock down their devices then that is their right. And I support their rights, so the conversation is over right then and there IMO.
Options between "we don't have tech in the house" and "wide-open tech, we have it all" are all some amount of painful, usually for no good reason.
(I remember once investigating how to do some pretty basic stuff for this in Linux, hoping to find something nicer than manually setting some executable permissions and firewall rules and then having to go back and change them all the time, and the closest thing to a guide I found was an old article from Red Hat that basically lead with "LOL, good luck you poor sap, Linux sucks at this" before going on to explain the various bad ways available to sort-of, but not entirely, accomplish it with a lot of work, and significant ongoing time-burden)
Exactly. The problem is its from the parents side.
THIS
Holy shit. This is such an obvious fix. And it shuts up those surveillance state goons immediately.
My God, why have we tried to summon up the ghost of 1984 when such a simple fix as this will do.
Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.
The blast radius is zero.
Good God, we need to fast track this into browsers right now. If we hurry we might be able to point to this as the technical fix.
Once some of the infrastructure exists, OS vendors can hook into it.
Firefox devs - please do this right now. Please spearhead this.
I might have to vibe code an advocacy site for the spec and set up a GitHub / RFC process.
CA tried this with AB 1856. I wasn't a fan of this (neither was EFF) because of the privacy and tracking concerns of blasting the fact that the user is a child to all websites.
https://www.eff.org/deeplinks/2026/05/one-step-forward-two-s...
It would better for the block to happen at the device level. That is, the browser knows it's on a child's device and has a whitelist of allowed sites.
There is already an RTA (Restriced to Adults) header where the website self-labels that it's for adults only and the browser can block it while protecting the user's privacy. I'd prefer expanding the use of RTA.
The web is too big and changes too much and that's before we get to the issue of applying laws to a whitelist based on different juristictions worldwide.
And I have to question, who would administer it? The parents? They won't. Google or Apple? Why do they want to deal with irate parents or culture wars around what is or is not on the list?
There is obvious increasing demand for this from parents, politicians are going to act on it, I think a "this is a child" header is the only one that actually really works. It works for the parents because it's easy to setup. It works for websites because they can cleanly identify a child and filter content if appropriate.
It seems to me that every other solution than a "this is a child" header is either impractical or way worse.
Yes, granted, a globally enforced whitelist probably wouldn't work. I'm referring to bespoke lists that parents control. I know plenty of parents that use this. e.g. here's Apple's feature:
https://support.apple.com/en-us/105121#:~:text=Prevent%20ina...
> It works for websites because they can cleanly identify a child and filter content if appropriate.
This still doesn't solve the problem of different jurisdictions and culture wars of what is or isn't appropriate for kids. All this does is move the liability upstream to websites instead of the devices. That is, instead of the browser deciding what's appropriate, now Youtube, Reddit, etc have to decide. And, as we've seen with the OSA in the UK, typically smaller platforms can't handle the enforcement cost so they just shut down entirely.
https://onlinesafetyact.co.uk/in_memoriam/
The larger platforms often use overbroad CYA measures and throw up age verification where they don't need to (Reddit has done this in the EU), or just ban minors (Anthropic and character.ai did this).
As far as blocking explicit content, a self-labeling requirement like RTA accomplishes the same thing as a "this is a child" header but without the liability CYA and without the privacy concerns.
Where the "this is a child" header solution could theoretically win is allowing kids to access websites in a limited child-safe way, e.g. going to Reddit in child mode automatically shuts off certain subreddits. But, as we've seen, it just doesn't work well in practice and usually frustrates parents by overly broad content policing and liability theater. Kids are also at different levels of maturity and I've seen them get frustrated when they're binned into age categories that they feel they don't deserve. e.g. a 12 year old might be plenty mature enough for the 13-16 age category.
But my real objection to the "this is a child header" is the privacy risk and surveillance risk. I don't think it's worth it.
I've long since considered that the efforts for online child safety should be pointed at educating parents and spearheading some kind of certification of compliance for child safety of software and websites.
[this product is certified to adhere to EU:CSA]
Then you can block everything not certified, and the software that does the blocking would also be certified, the two major prongs you need (endpoints and sites working together: else they're blocked). The rest of the money goes to education for parents about this fact, and the dangers of not doing it, and how to do it.
This is super "easy" (when comparing to the effort it would take for putting backdoors in everything).
Which is why I think that the reason is definitely not child safety, and more about crime control.
Me talking about UK blocking people unless they ID themselves in 2013: https://news.ycombinator.com/item?id=6979295
Me talking about how its disingenuous because we have superior technical solutions to this particular issue last year: https://news.ycombinator.com/item?id=45010902
I'm not sure to understand the proposed solution here, but it seems someone could just use a different web browser client who don't inherit these restrictions.
No cookie banner is required for functionally necessary cookies.
EU official website in it’s cookie banner glory: https://european-union.europa.eu/index_fr
Also AFAIK the Google Fonts question (is the IP alone already PII, if Google has no way of tying the IP to a person) has not been decided by the ECJ yet. There've only been decisions by lower level German courts that are still in dispute.
> When the law takes effect in January 2027, Californians will see new privacy options in web browsers. When enabled, these controls will automatically inform websites of their privacy preferences, helping to protect personal information from being sold to data brokers and other third parties. This means they will be able to protect their data — like their browsing history, location data, purchase history, and personal interests — across the entire internet with a single step.
They did not read the text to agree.
It was the fastest way to get the banner to go away. Sometimes they force you to confirm multiple times if you click ”none” or ”minimal”.
In the UK a few news sites have changed cookie banners to "you can accept and see this stuff for free, or you can sign up for a subscription, which would you prefer?". It's the only time I hit accept (and then clear browser history).
If blanket preferences from browser signals became the norm, a segment might open up where you would configure preferences and a data broker would make sure you get something in return for your data. At minimum it might force paywalled publishers to consider that as a "lite" subscription option.
ads don't require invasve and pervasive tracking
(see e.g. https://iapp.org/news/a/cjeu-clarifies-cookie-consent-requir... https://www.edpb.europa.eu/news/edpb-consent-or-pay-models-s... )
Again, that is not a requirement. If your argument is that they give us content for free because of ads, ads don't require pervasive and invasive tracking. Or hiding stuff behind paywalls (since ads pay for it).
Need to look up a bus time? Full screen cookie consent with accept buttons drawn OFF THE SCREEN.
I'm visiting a website, i don't want to make a legal agreement with every website ...
Social media bad for kids? Everyone hand over your ID at the door ...
Sounds good, as long as it covers the "legitimate interest" bollocks⁰ that is often hidden in inconvenient UI nests as well as the basic preference.
-------
[0] "we see your preference not to be stalked, but we want to anyway, click again for every partner to reconfirm you don't want them following you around"
> ...
> You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default.
That's an excellent idea... lets see how its implemented on https://european-union.europa.eu/index_en
Oh... there's a cookie banner.
I don't have a lot of confidence for legislative solutions. Although I admire people who keep trying.