Top
Best
New

Posted by doubletwoyou 3 hours ago

Every Fucking Website (2020)(lxe.github.io)
549 points | 319 comments
jchw 2 hours ago|
Should load much slower.

Also, where is the unrelated autoplaying video that will unmute if you actually click it, that follows your scrolling and only becomes smaller when you dismiss it? Plus, it should probably have text that cuts off letting you know you can have access for just $10/month.

Plus, isn't this website undissmissably "better in the app" after a few minutes of attempting to use it on a phone? Where's that at?

edit: Oh shoot! I forgot, too. This modal needs to also ensure there is absolutely no way to scroll. If you could scroll you might be able to accidentally get to the address bar of your browser to fix the URL to xcancel or even close the page, which isn't using the app as you are intended to do.

Also, it doesn't attempt to hijack the back button to give me stuff I clearly wanted to see before I leave the page.

A lot of work left to do here before it's a "real" website. Although, it has about as much substance as the average website so far, so good work on that.

bee_rider 2 hours ago||
> Plus, isn't this website undissmissably "better in the app" after a few minutes of attempting to use it on a phone? Where's that at?

This is the most annoying thing on the internet. There’s a site I’d like to use, but “try the app” takes up the entire page (and appears to be impossible to dismiss?). Actually, is there a way to permanently request the desktop site for all future visits to a domain on iOS? There is no reason to visit this full-page app advertisement.

dcminter 1 hour ago|||
eBay stops me from typing in the thing I want to search for so they can try to persuade me to use the app that I have expressed zero interest in for a decade or so. Guys, I'm trying to press money into your thieving little hands - why are you trying to stop me?
kmoser 6 minutes ago|||
They see it as a win because you've still been using their site for a decade now, and every time they advertise their app there's still a non-zero chance you'll relent, but if they stop pushing their app, that chance drops to zero.

The only winning move is not to play.

summarybot 39 minutes ago|||
Reminds me of Austin Powers:

21! Blackjack,

"Hit me!"

"...but Austin!"

"I also like to live, dangerously."

heathrow83829 1 hour ago||||
Wells Fargo went so far as to remove their best feature from their website: the Spending breakdown page! they now say go to the app but the app is far worse than the browser version was before they removed it. i might even stop using them just for this mess.
philistine 1 hour ago|||
DO IT! They probably do not even consider the idea that they would lose customers due to UX. Lower rates, promotions, change of circumstances, but there probably isn't a checkmark in their loss of customer forms that include we made our user interface worse.
stickfigure 1 hour ago|||
You should stop using Wells Fargo anyway. It's been what, nine months since their last national scandal? They're overdue.
getpokedagain 1 hour ago||||
Its always confusing to me since I'm already accesing it through an app.
inventor7777 1 hour ago||||
On iOS Safari, tap the three stacked lines on the URL bar (depending on which Safari view you use), tap Website Settings, then you'll see a Request Desktop Website switch, which should persist for that domain.
bee_rider 1 hour ago||
I don’t know if this site did something tricky or if it is something about how I access it, but the switch doesn’t persist.
jchw 2 hours ago||||
I'd recommend using Libredirect if you're on a Firefox-based mobile browser. It can configure redirects to alternate "frontends" that will serve you much more agreeable HTML (though because we live in hell, it will usually still involve antibotting out of sheer necessity. But I accept this.)

For Reddit, my choice for now is safereddit. If I need to view a Reddit link on mobile and old Reddit is blocked as it sometimes is, I just swap the domain to safereddit.com.

For Twitter, my choice has been xcancel for ages. I have no idea how that manages to stay up in spite of Twitter's hostility but it is a Nitter instance that seems to just work.

You can also run these frontends yourself, too, but I assume it requires accounts.

(edit: Also I hope it goes without saying that I don't really have any specific trust that my activity is necessarily more "private" with these frontends, although honestly if I was forced to bet I would have to bet that they are much more respectful to my privacy than Twitter or Reddit are. I just use them for functionality.)

Good luck fellow traveler. If there was more to do in real life, I'd probably had thrown my phone into the ocean by now. I'm about halfway there in spite of the lack of many appealing third spaces.

mey 2 hours ago||||
I have Firefox setup to not launch apps on android with permission. I don't have Instagram/Facebook/etc installed. Attempting to view a Instagram link on mobile is the most hostile thing in existence. You essentially can't, but it so aggressively routes you to the website based Google play store it's horrifying.
FridgeSeal 1 hour ago||
Whichever devs implemented the Instagram behaviour ought to have their computer taken off them.

100% the worst experience. “Oh you don’t have the app? No big deal, let’s (maybe) play the video anyway but remove the audio, obscure half the screen, and make any interaction redirect and then bounce to the App Store. Why won’t you download our app already????”

Sanzig 1 hour ago||
They have to be pushy, it's how they install spyware which use tracking methods that would be a CFAA violation and prison time for anyone else: https://localmess.github.io/
hinkley 1 hour ago||||
And don’t ever save the user’s “no” for next time. We need to needle them to use the app EVERY SINGLE TIME the visitor the website.

I wonder sometimes how the team doing the website feels about being treated as second class. Or if it’s the same team and they have to hold their noses to work on it.

The third dumbest smart person I had to work with obviously hated HTML and kept trying to get us to use a DSL instead. At least it wasn’t an in house one, but he had a couple other devs interested in his madness as well. But the two of us who were doing the bulk of the performance work and tricky bug fixes would have been absolutely sunk if we’d allowed that to happen. One of the worst things about React is trying to track back an HTML bug in someone else’s complex React project to the templates that are misbehaving together. The Grafana UI code is madness to debug.We would have been there very quickly and without the dev toolbox to help.

jchw 1 hour ago||
YouTube does something that makes me irate: it saves the abusive autoplay settings only locally per device. There is no way to set it in your account, so every time I log back in I have to disable autoplaying thumbnails and autoplay next video. Every. Single. Time.

I think a lot of people get progressively worn down by things like this, but for me I actually get angrier each time it happens. It's probably good I no longer work at Google because I would probably feel genuinely enticed to find whoever is most responsible for this and engage in psychological warfare.

hinkley 1 hour ago||
Yeah it’s definitely passive aggressive and those people must be stopped.

But I think it’s sometimes by management design. Scrum makes it pretty easy to keep devs permanently off balance so they can’t think about how wrong what we are building is. Maybe that person really is a piece of work, but maybe they just have never had time to think about how dumb that decision was and go fix it. Similar to you, I’m glad I don’t know where Ken Schwaber lives or when he’s presenting because I’d probably call him a traitor to his stupid face.

quercusa 2 hours ago||||
If the site happens to be a discussion site that starts with 'R', clearing cookies will let you through for a while. In Brave, there's a setting to do so when you leave the page.
yojo 1 hour ago|||
They still haven’t removed “old.reddit.com”. Replace “www” with “old” on any reddit URL and enjoy a relic from when the internet was less ruined.
RattlesnakeJake 1 hour ago|||
The issue is that they just started forcing sign-ins on Old Reddit, allegedly because it's easier for bots to scrape. The ability to casually/anonymously peek at a post that answers your question is getting more rare.
inventor7777 1 hour ago|||
Yes, but it now requires you to have an account.
bee_rider 1 hour ago||||
Nah, it isn’t Reddit. I actually removed Reddit from my search results once they stopped allowing me to use the old interface.

It’s just some random job board that happens to be popular in my niche for whatever reason.

Micrococonut 1 hour ago|||
https://apps.apple.com/us/app/sink-it-for-reddit/id644987363... Here is an iOS safari extension that helps mitigate their bs. Just putting this out there for people.
IAmBroom 49 minutes ago||||
Some Fucking MBA (SFMBA) heard that apps build customer loyalty and increase eyeball time on their sites, so now their company needs an app.

Repeat (without rinsing).

f17428d27584 1 hour ago|||
National cinema chain has a banner on their web site that says something like “film lovers prefer our app” so they manage to employ a little guilt / social proof as well.

It’s such a small thing in the grand scheme of things but it’s just that final straw for me, someone made the decision to be this shitty to their users because they want to employ extra tracking/data collection / advertising in their app.

lxe 2 hours ago|||
Feedback taken. Will ask ai agents to make improvements.
christophilus 44 minutes ago|||
Yeah. No spinners. No pulsing gray placeholders that sit there for minutes and then shift the content when they load. No 10GB video playing in the background. My laptop didn't even get hot or spin up the fans when I viewed this page.
alsetmusic 1 hour ago|||
Where are the third-party ads that interrupt the content I wasn’t able to read? And the popover telling me about singles on my area? Why haven’t I been offered a subscription to a newsletter so I can receive daily updates and offers to pay for additional services?

You’re right. It’s a good start, but there’s still a lot to do.

evandena 41 minutes ago|||
Elements that load slower than the rest of the content, so it bumps the links that you're trying to click down, and you click the wrong thing.
gofreddygo 15 minutes ago|||
Every. SINGLE. Recipe website.

Just search for anything like "egg omelette recipe". Click *any* link for example [1].

[1]: https://www.loveandlemons.com/omelette-recipe/

eviks 1 hour ago|||
> there is absolutely no way to scroll

Or, at the very least, at a widely different speed/acceleration that you're accustomed to

wombat-man 2 hours ago|||
Wild that it is somehow worth it to stream video to every visitor on the hopes that it'll get them to stick around longer or see an ad in the video. That conversion number has to be crazy low.
sidewndr46 1 hour ago|||
No, it definitely hijacked the back button
TZubiri 1 hour ago|||
I don't think the goal is to capture all of the ways a website can break, but to capture all of the tropes that corporations add to websites in order to check boxes of what they feel a website should be based on imitation.
alex1138 1 hour ago|||
Tribunals at the Hague.

(Not for this website, which is obviously a joke/telling commentary. I mean for real 'fucking websites'.)

runlaszlorun 15 minutes ago||
Web Crimes Tribunals
wlesieutre 2 hours ago|||
"We value your privacy! We and our 892 legitimate business partners use cookies to improve your experience."
_trampeltier 1 hour ago|||
The record I saw is more like 1892 partner
alex1138 1 hour ago|||
"They're enforcing GDPR so here's malicious compliance and our own little template verbiage about how much we do actually 'care' about your privacy. Now click me to deny or blindly accept like you have with EVERY OTHER SITE you've visited since this morning"
ripe 1 hour ago||
> this website is "better in the app"

Obligatory xkcd:

https://xkcd.com/1174/

idopmstuff 2 hours ago||
I started an e-commerce brand on a Shopify site. I swore to myself I would never put up one of those stupid things that pops up "Someone bought X product an hour ago!" messages in the corner of the screen.

I ended up trying it. Boosted conversion rate meaningfully. Worth the price I pay in mild self-loathing.

Chesterton's popup, I guess.

ryandrake 1 hour ago||
That's the real problem. Being aggressively annoying works. Dark patterns work. Popups that grab your attention work. Flashing text conveying urgency works. Thumbnails with open-mouth YouTube-face work. Moving buttons around so people mis-click works. Tiny [X] buttons that make people accidentally click an ad work. You're never going to convince someone to stop doing something that is making them money.
gtowey 1 hour ago|||
Yes, but on whom does it work?

Does it work because you're taking advantage of a group of people who are extremely vulnerable to manipulation? People who already struggle with impulse control, who are prone to making bad financial decisions? The elderly, kids?

We have to escape this mentality that anything that makes money is valid, that the money itself is the validation of "rightness".

Some of us, just some think that maybe enterprises that prey on the vulnerable just don't deserve to be in business. Otherwise everything might as well be payday loans and online gambling. I'm not saying OP is definitely in that category, but I would encourage them to think long and hard about weather or not using dark patterns to goose their sales is really the kind of world we want to be fostering.

d3rockk 39 minutes ago|||
>Yes, but on whom does it work?

Hitting the nail on the head here-> know your target audience.

wakamoleguy 1 hour ago||||
On the extreme side, things like blackmail and fraud are generally illegal, even if they can make you money. Most of these dark patterns that "work" tend to follow a similar pattern: by taking advantage of the target, one can extract more money from them.

I would possibly be a terrible salesperson, because these all give me the ick. Your product should provide an offer of genuine value.

toyg 1 hour ago||||
The tech field is increasingly devoid of any resemblance of morality.

I guess it's the inevitable parable of anything started by '70s hippies: sooner or later, we all sell out.

vovavili 1 hour ago|||
Leaving money on the table is never easy.
theappsecguy 1 hour ago|||
I think most fields are like that..?
RoddaWallPro 1 hour ago||||
That's the real problem: selling drugs works! Forming a cartel to produce and distribute addictive products, killing anyone who gets in your way? It's effective! You're never going to convince someone to stop killing people and dumping their bodies into culverts when they're making money. It's just not reasonable to expect that, or do anything about it.
TZubiri 58 minutes ago||
Nuance: if someone actually bought the product 1 hour ago, it's fine. If not, it's fraud.
cm11 46 minutes ago||||
Very much agree, but also (not saying you're saying otherwise) stealing, lying, entitlement (which is possibly just stealing and lying), and scamming "work." These are checked in large part by a person's aversion to it not just by its lack of working. Of course dark patterns work. If what one says increasingly inches towards 100% misrepresention (but shy of it), people will "mistake" what's being said. "Mistake" doing a lot of blame shifting.

"You're never going to convince someone to stop doing something that is making them money." Reasonable, but I would soften from "never". There was less of it at one point—and it seems logical to guess we have less today than we'll have tomorrow. The main reason is likely that we simply didn't know about these tricks yet, but somewhere below that on the list of the reasons is that some people dropped off from doing it at lesser forms of misrepresentation. Or they made the case against it at work resulting in them either winning (and their projects perhaps did less well) or them losing and being overrun by those more willing. With losing possible also leading towards leaving, not getting promoted, or getting fired. This is just a way to say that there are people who do forgo money, they just might not be around or visible for various reasons. And, as implied by the difficulty of convincing people to not make money, their (former) coworkers prefer that on some level even if they don't believe they agree with stealing or lying. But losing or earning less money is not the same as having no choice.

gigatree 1 hour ago|||
Absolutely. Maybe the answer is that everyone should just rank them up to 11 until it stops working and then people have to get creative again.
LollipopYakuza 1 hour ago|||
This reminds me the clickbail title and thumbnail on YouTube. One of my favorite channel apologized for it but explained that the difference compared to NOT doing this is phenomenal and they can't afford stopping.
olyjohn 56 minutes ago|||
If this is the only way to get people to watch your videos, maybe your channel sucks. But glad you are making money tricking people into wasting their time so you can get one more ad impression.
ivanjermakov 1 hour ago|||
Don't get me started on "like and subscribe".
frantathefranta 2 hours ago|||
Out of all the annoying website things, always thought that one was pretty tame. Almost feels like a spiritual successor to the visit-o-meter. Obviously as long is it doesn't put a (1) on my tab or makes a noise and doesn't steal mouse focus.
rao-v 2 hours ago|||
Genuine curiosity - is the pop up vaguely factual or sort of randomly generated?
m4tthumphrey 1 hour ago||
Always randomly generated!
rao-v 1 hour ago||
I salute your honesty! But [he hastens to add, looking furtively around] I also frown disapprovingly at your choices
phoghed 1 hour ago||
You’re saluting the honesty of someone who is not the original person who’s lived experience you were asking for lol
rao-v 40 minutes ago||
Ha!
agumonkey 1 hour ago|||
Is there a law of society / business where everything we hate is on average something that made the society able to function ? it's similar to chesterton but it's not a fence, it's the tree we live on.
bigbuppo 47 minutes ago|||
I actually kind of like those, though I've always been suspicious that those events are fabricated because that's the sort of thing marketing people would do.
m4tthumphrey 1 hour ago||
This is not in the same sport let alone league as the things demoed in OP.
WarmWash 2 hours ago||
Loaded way too fast and is way too responsive.

Also when I checked NoScript, it's only loading js from lxe.github.io

I expect there to be at minimum 8 domains, but often 12-18.

boomlinde 2 hours ago||
All buttons and links need to shift around for a good 10 seconds before the page settles.
Freak_NL 39 minutes ago|||
The page of my bank's website (ABN AMRO) which shows an account's transactions does this in the worst way. It all loads perfectly, it shows the transactions, I move to click on one or the button for a new transfer, and boom a message gets loaded in at the top which shifts every fucking item on the page down 20 pixels or so.

The message is always something inane like 'markets go brrr¹', and it's never something I need at the moment on that page (or anywhere else). I can dismiss the message (hooray?) but it always comes back the next time, so that isn't actually helpful at all.

1: Obviously they use carefully blandified corporate bank language for those messages.

breuleux 2 hours ago||||
I wish we had a UI paradigm where whatever is underneath your cursor is not allowed to change. If you hover a button, that button must remain right there for you to click, if you hover some text, it must remain there for you to select. Browser and OS-enforced, ideally.

We can debate the specifics, maybe it's only in effect for X seconds after you stop moving the cursor, maybe it creates a 100px diameter disk of stability, I don't know. Just let me interact with the stuff I see.

diegocg 1 hour ago||
Oh, that UI paradigm already exist. It's just that browser makers are too busy with things like webasm, webgpu, or allowing pages to launch location/notification popups at users, so they don't have time to fix fundamental flaws.
breuleux 59 minutes ago||
I don't think it does? Popups are one thing, but the very possibility of dynamic content entails that stuff will shift on the page. Sometimes it's just the nature of the thing, like a chatroom or a notification stream -- it'll shift as new content arrives, which is what I want most of the time, but if I'm interacting with a message, that message shouldn't shift. I'd like a general solution to this. Does that exist?
imagent 1 hour ago||||
Better yet, detect mouse clicks and display a popup right where you clicked that says something you didn't want, and show a busy indicator to make sure the user understands that they just agreed to something important.
peterleiser 2 hours ago||||
This. My favorite is when I search for products on a website or app and the results appear in batches, with subsequent results interleaving with the previous results. So when you want to select a particular result and start to move your mouse and click, or move your finger and press, you often end up selecting something unintended because a later result pops into the location.
andypants 2 hours ago||
I do this in the gmail mobile app all the time thanks to their ads injecting themselves in between the emails several seconds late. They must love me, their most engaged ad consumer.
coldpie 2 hours ago||
Handy tip: If you disable all the tab category things in settings and go down to a single category (Primary), it will stop showing you ads entirely.
Sardtok 2 hours ago||||
It's important to have the accept cookies button pop up on top of something you are almost guaranteed to click at just the right moment.
ModernMech 2 hours ago||||
I was waiting for the overlay that hides the content until you turn off your ad blocker. Which of course is a trap because as soon as you do it covers the content in ads.
jabroni_salad 2 hours ago||||
Yes, and put a search bar that loses focus to some piece of crap I dont care about after I enter 3 characters, and some hotkeys that navigate me to a different page when I accidentally activate them because I thought I was going to put text in the search field.

youtube people I know you are in here. Fix your stupid PIP thing.

amarant 2 hours ago||||
..... In such a way that most commonly used button is replaced by an ad 0.001 seconds before you click it
stackghost 2 hours ago|||
js eventListener that intercepts the click/tap event, moves the button somewhere else, and clicks the ad underneath.
john_strinlai 2 hours ago|||
>I expect there to be at minimum 8 domains, but often 12-18.

news sites are the worst for this. bloomberg, nbc, etc. have 20+ domains, and as you click "temporarily allow" on one, it loads in a few more.

foxnews loads 36 domains before temporarily allowing any, which probably approaches 50 once you start allowing.

anygivnthursday 2 hours ago|||
And needs some kind of loop that retries endlessly to make the AdBlock counter go brrr
Gualdrapo 2 hours ago|||
It also loaded too fast because it has no (ai-generated/3d/high color contrast) 10MB background image in the hero section
lxe 2 hours ago|||
I'm sorry
psychoslave 2 hours ago||
And the legitimate mass spying with multi thousand other organizations, of course.
2b3a51 2 hours ago||
I'm filing a bug report...

Steps to reproduce: Open terminal emulator and type;

$ w3m https://lxe.github.io/everywebsite/

I can read the same content as I can read in Firefox.

What I expected to happen: See content similar to the following;

Update your browser Your browser isn't supported any more. To continue your search, upgrade to a recent version. Learn more

bigbuppo 52 minutes ago|
You must upgrade to IE5 to continue.
RivieraKid 2 hours ago||
The cookie thing, I assume it's EU-only, is an example of the EU policy making process being fundamentally broken in some way. If you create a flawed policy and don't fix it many years after it's very visibly obvious that it's a bad policy, something is really wrong.
dijit 2 hours ago||
it's an example of malicious compliance by some, and herd mentality by others.

I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.

bonoboTP 2 hours ago|||
That reasoning isn't wrong, though it seems ridiculous when looked at with techie-brain. But if there is a standard expectation of what serious company websites are like, it makes business sense to look like that too. It's like dressing up appropriately to cultural expectations. You can deviate somewhat but you have to strategically spend your weirdness points.
naravara 2 hours ago||
How nice of the EU to have determined for the rest of the world that the “cultural expectation” should be that every business do the design equivalent of wearing clown makeup.
Arainach 2 hours ago|||
The EU doesn't require banners.

Companies could stop selling and storing your data. They could only use cookies when absolutely essential. They could use lots of kinds of UX.

This is the equivalent of businesses who put a big visible "20% the state says we have to give our employees healthcare" fee on their bill to throw a hissy fit and hope customers get angry at the government for protecting them instead of the business for exploiting them.

nonethewiser 1 hour ago|||
Banners exist to eliminate EU regulatory risk. You can try to convince people they aren’t required but its not going to remove any banners.
Am4TIfIsER0ppos 1 hour ago|||
The EU didn't have to do anything. The User Agent can already handle everything from denying cookies to blocking requests for certain resources.
wizzwizz4 57 minutes ago||
The user agent can refuse to store cookies, but it can't do much against supercookies (cookie-like features not knowingly implemented by the user agent programmers) or fingerprinting: you need something like legislation to curb practices like that.
bonoboTP 2 hours ago|||
I don't care about this. I explained why for an individual business trying to project seriousness, it makes sense to adopt a banner in the current environment. I didn't say it's nice of the EU or anything of the sort. It's an incentive pressure that exists on an individual company in the current situation. That's all I said.
pbhjpbhj 2 hours ago||||
You could have a 'no cookies' badge that links to your cookie policy - 'we use no tracking cookies and so are compliant with EU law ... then list any cookies/local-storage used and explain what they're for.
bborud 2 hours ago|||
That would make you sound a lot more professional too. And trustworthy. (As long as that's actually what happens).

When I see these dialogs listing they have 1289723 gazillion vendors they share data with, I know that whoever is in charge of analytics, privacy or both at the company is incompetent.

tempest_ 2 hours ago||||
Best we can do is a full screen model or annoying toast telling users we dont use cookies and click 4 to 7 check boxes to agree.
Xirdus 2 hours ago|||
But then you can't have tracking cookies.
nonethewiser 1 hour ago||||
No one is tanking UX to stick it to the EU. It would be better for them to simply not piss off their users. They are covering their ass.

The obvious conclusion is that when you try to regulate something like this you arent going to get the behavior you want.

wat10000 1 minute ago|||
They're not covering their ass, they're making a deliberate tradeoff.

It's trivial to make a site that doesn't need a cookie banner: don't set any cookies. Modern web devs have probably forgotten, but this is actually the default behavior. Cookies don't get set unless you do something to make it happen.

And cookies that you actually need for functionality don't need a banner either. If you're setting a session cookie for logged in users so they stay logged in when navigating between pages, you don't need one.

Why, then, does practically every site in existence now have one? Because they set unnecessary cookies. Because they choose to set unnecessary cookies in order to track you for purposes that are not necessary to the actual functionality of the site.

Every single cookie banner you see is a big sign that says, "We value our ability to track you for marketing purposes more than we value your time."

Apparently they're willing to say that. I still see it as a win. No tracking and no banners would be ideal, but at least the regulation forces them to be honest and up front about what they're doing. I'd rather have tracking and cookie banners announcing it than tracking with zero indication of tracking.

quruquru 2 hours ago||||
Many years ago, I used to make informational websites for small, local businesses and they all wanted the cookie banner "just to be safe", even after explaining they didn't need it.
forgotaccount3 1 hour ago|||
But are you a software developer or a lawyer? Do they 'not need it' because the government provided a way to ensure it's not needed or because your interpretation of the law indicates it's unnecessary? Are you willing to indemnify them for legal costs if your guidance was wrong?

Most small business owner's I've spoken to are keenly aware they are only one bad lawsuit away of closing down. Almost no one care's about the cookie banner. Most just mindlessly click to allow cookies and go on with their life. There's almost no cost to having it.

Xirdus 2 hours ago|||
This website contains chemicals known to the State of California to cause cookies.
zippyman55 2 hours ago||
The Irish Republican Army, even at the height of their conflict, would never have stooped to such a website.
bigbuppo 50 minutes ago||||
In my experience, most people come in two camps: 1) they just click to make it go away because they click everything and would agree to sell their own mother to organ scrappers just to get past the annoyance, and 2) they understand what it's asking and are immediately suspicious.
patwolf 2 hours ago||||
I built an ecommerce site long ago, and even though the UI was fairly modern for the time, they insisted we use antiquated styling on the billing forms of the checkout page to help exude trust. As a developer it bugged me because I knew it was just styling, but they probably weren't wrong.
Achterlangs 2 hours ago||||
I have had the same discussion multiple times at multiple companies. Luckily most of them were fine with dismissing the popup with a timer.
Aurornis 2 hours ago||||
> and he said "yeah, but it makes the site seem less legitimate.

He may be right, sadly. I’ve seen the lack of a cookie banner used to suggest that a site was doing something shady or not complying with the law.

Most people don’t have knowledge about the finer details of cookie laws. They’ve been trained to believe that legitimate sites who comply with the laws will implement the cookie banner, and not seeing it feels suspiciously unprofessional.

bborud 2 hours ago||||
I'd say just remove it. Don't ask people who don't actually understand the cost of having it there because you will get the wrong answers. Sometimes people just have to do the right thing, take some heat and then everyone can move on. If it has severe consequences then that's probably a good reason to leave anyway.

Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they couldn't deny that it cost a fraction of what we were paying our supplier and that things took minutes to set up rather than weeks. And that they worked a lot better.

Yes, there was shouting in meeting rooms. And yes, people said "you can't do this". Turns out they were wrong. A few years later I mentioned this to Werner Vogels. During a meeting. Where my CEO and CTO were present. And where everyone was feeling very good about us being one of AWS' biggest customers in our region.

So when someone says "you can't do that", sometimes you should make them prove it.

(At the time AWS was a good idea. Today dependence on a US service provider is a harder sell in Europe. The _first_ question you get today is if we can host it ourselves if we need to or if we can use a local service provider.)

docjay 2 hours ago||
I have the same mindset and often did the same thing, but then I thought about my doctor sneaking into my house while I’m sleeping and injecting me with the “good medicine” I had refused in their office.
bborud 1 hour ago||
I did not anticipate where that sentence ended up :-).
alexpotato 2 hours ago||||
Reminds me of the early days of the CANSPAM act.

One of the best indicators that something was not spam was the unsubscribe button.

kermatt 2 hours ago||||
> but it makes the site seem less legitimate

I have yet to head that cookie prompts are a sign of legitimacy. What business has customers that would think that way?

TheOtherHobbes 1 hour ago||
Not customers. Owners.

Although if you've ever worked retail, you'll know that plenty of customers are idiots.

Whatever "Surely no one is that stupid!" assumptions you make will be proven wrong no matter what you do.

vovavili 2 hours ago||||
>it's an example of malicious compliance

So how would you do ePrivacy Directive compliance/risk avoidance in a non-obnoxious way?

dghlsakjg 2 hours ago||
Don’t use a bunch of unnecessary tracking cookies?

Completely eliminates the need for a cookie permission bar.

pie_flavor 2 hours ago|||
The law does not say 'tracking'. It says 'strictly necessary'. If you remember the user's light/dark theme preference in a cookie, that requires notification. (Or rather, what it requires in practice is that you hire a Highly Paid Consultant.)
dghlsakjg 1 hour ago|||
Okay, but it doesn’t require notification for every user that hits your landing page.

If you want to remember dark mode with a cookie, then you can just gate that setting behind a “allow functional cookies” toggle.

Getting consent for functional cookies doesn’t have to be done with an intrusive cookie bar on landing. You can request consent as it becomes needed. There’s other ways of complying that aren’t dark patterns.

rcxdude 1 hour ago||||
No, it doesn't. If it's reasonably expected as part of the service, you don't need to gather consent. It's not even personal data.
pie_flavor 49 minutes ago||
The law does not say 'reasonably expected', it says 'strictly necessary'.
rcxdude 21 minutes ago||
Sorry, getting my GDPR and e-privacy terms mixed up. The cookie is strictly necessary for the setting to be saved. The user has specifically requested that the setting be saved by changing it. The opinion suggests this should be a session cookie unless you indicate somewhere prominently next to the setting that it uses cookies to store it for longer. This still doesn't require a cookie banner.

What's more, if the 'cookie' is entirely local (i.e. it's never sent back to your own server, e.g. you're using the local storage API), like how this would normally be implemented nowadays, then these requirements don't apply at all.

clan 1 hour ago|||
Nonsense.

You are correct that people keep stating such things. But it is incorrect.

That example would be an essential cookie, also known as a strictly necessary cookie.

A shame this FUD is still being spread.

pie_flavor 50 minutes ago||
That's not what various references (and AIs) say. Strictly necessary means strictly necessary. They didn't bother defining it in the law. However, user preferences were called out specifically in the WP29 opinion as something that wouldn't count as strictly necessary if scoped any wider than the browser session. So if the plain English meaning and the drafters' opinion contradicts your opinion, why should I risk significant fines to trust it?
vovavili 1 hour ago|||
I am obviously referring to a scenario where tracking cookies would be highly beneficial to expanding the business, e.g. e-commerce.
dijit 1 hour ago|||
Don't set a tracking cookie, use of IP addresses is allowed for legitimate purposes (Art 6(1)(f)) as long as they're not stored.

At least for GDPR...

The only ways to actually track without a consent pop-up are:

(1) stay off the device entirely and process server-transmitted data under legitimate interests with a privacy notice, or

(2) confine any device storage to what's strictly necessary for the service the user requested

vovavili 1 hour ago||
This goes to show that the assertion that cookie banners are just "malicious compliance" isn't quite correct. These are significant trade-offs here.
dijit 42 minutes ago||
you don’t need to track users by giving them an ID they send with every request.

in fact. you probably don’t need to track users.

ranger207 1 hour ago|||
tracking cookies are so obviously beneficial to e-commerce that they passed an entire law to disclose them because people... liked them so much?
vovavili 1 hour ago||
I don't exactly see how these two statements are contradictory. Policy is about conflicting interests.
0xbadcafebee 1 hour ago||||
Good point. The page should have 200MB of assets so that it loads slowly, making it look like there's serious engineering going on.
Mistletoe 1 hour ago|||
CFO should be fired immediately.
zetanor 2 hours ago|||
The EU said "you have to ask for permission before forcefully sodomizing your users", and webdevs thought "let's ask for permission" rather than "let's not forcefully sodomize our users". Of course, the law could have said "don't forcefully sodomize users", but it seems the west is still under the impression that some people will do the right thing, just because, sometimes. (maybe 20 years ago they would have, just because, sometimes, but they won't now)
nirava 2 hours ago|||
Not web devs per se, I’d be hard pressed to find a serious web dev who wanted to “forcefully sodomize users”. Thats a management thing
bborud 2 hours ago|||
Many of them can't help themselves.

I used to have long conversations with frontend developers that "no, when I log on I don't want to be forced through a look-at-the-new-feature-we-made" sequences. And then they went ahead and did it anyway. And usually whatever flag they tried to set to make sure you only saw it once would malfunction, so next time you'd get to click through it all over again.

(If you want to tell users about new features, show a unread flag on a notification icon and make it a one-click affair to make it go away. Don't get in users' face with stuff they don't want)

zetanor 2 hours ago|||
"No."

If every webdev who would say no can be trivially replaced by webdevs who won't say no, then yes, it is webdevs.

zamadatix 2 hours ago|||
You don't really need a web dev to add a cookie banner these days, but you probably still want one to build the actual site (unless it's simple enough to be fully site-as-a-service, in which case there is really no webdev at all).

Be it the EU for regulating disclosure and consent requirements, users for being "lazy" and usually just accepting all, or the webdev for not staking their livelihood on denying the banner - I'm sure they'll all get blamed before someone sees the ones actually demanding it be done can be the problem.

StableAlkyne 2 hours ago||||
"Damn, I'm being asked to put a cookie into this site that will maybe result in some guy seeing an ad about a toothpaste he might buy at some point in the future.

I'm going to risk months of unemployment and explain to my family why this is more important than eating when I get home. The internet is serious business, they'll understand."

-- the hypothetical webdev in that scenario, I guess?

zetanor 1 hour ago||
If you can get replaced over something so minor, it means there's dozens of capable bootlickers lined up and ready to do it as soon as you're gone, so yes, there is a webdev problem.
StableAlkyne 1 hour ago||
> bootlickers

Mate, it's just a cookie on a site.

clan 1 hour ago||
Not quite. That would just be boiling the frog.

It is an important fight for our future with our tech overlords. But sure - some will be happy owning nothing.

This is really one of those "First They Came" moments.

Unfortunately convenience trumps all. So for many "its just a cookie".

bonoboTP 2 hours ago||||
You can try to put the blame on the grunts, like trying to focus on the engineers in the VW Dieselgate, etc, but that is very weak leverage. You have to intervene at the root cause of the incentive. But of course the higher you go, the more there is a blur between legislators and business owners and they won't be harsh to themselves.
clan 1 hour ago||
So morals are good at a certain pay level?

Thank god I am just a minion who now can go home worry free. Yay!

edoceo 2 hours ago|||
It's silly to blame the individual who doesn't have the authority or power at the business making these choices.
clan 1 hour ago||
Unsure if you are saying there is no collective responsibility or think it is time to bring out the pitchforks?
mmillin 2 hours ago|||
I see a lot of people below arguing that this isn’t the fault of the EU policy but the companies. I think that’s being overly charitable to the policy. While you can be rightly upset with the companies behavior, ultimately policy has to work with the incentives it creates. The policy in its current form allows for meeting requirements with annoying cookie banner opt-outs while keeping the lucrative business of tracking. If we don’t want that, the policy should be changed. Don’t expect companies to go against their interests here, even if some will actually be thoughtful and find a way to do so. The “Purpose Of a System Is What It Does” principle applies, and the purpose of the EU policy seems to be cookie banners for most sites.
mnewme 2 hours ago|||
Actually the purpose was not to invade our privacy as much, which we do and there is active lobbying (for example by Google) against any better solution: https://noyb.eu/en/eu-member-states-and-google-suddenly-want...
nonethewiser 1 hour ago||||
Classic over-regulation producing unintended side effects
clan 1 hour ago||
Really?

Because the industry really respected DNT[0]?

Regulations are needed when the kids cannot play nice in the school yard.

GDPR is actually not that bad if you read it rather than subscribing to much of the malicious compliance we see.

[0] https://en.wikipedia.org/wiki/Do_Not_Track

tempest_ 2 hours ago||||
Nah fuck the companies and their horse shit.

99% percent of them intentionally turn the "decline" choice into a 5 - 10 step game of dark patterns even though the EU policy says it should be equally easy to decline. They know its bullshit but they also know the chance that someone will drag them through court is low.

naravara 2 hours ago|||
I’ve long believed that making companies liable for paying damages if PII is leaked in a data breach would be the best way to stop excessive tracking. If you force them to have to manage user data like they’re handling radioactive waste then the expense and overhead involved is a natural drag on the business logic that drives the bottomless appetite for data collection. They’ll collect it if they actually need it, and they’ll take great pains to secure it.
mnewme 2 hours ago|||
Actually having worked in big companies,many of them just track everything, but don’t actually use the data, which is even worse.
dgellow 2 hours ago||||
That’s already part of the EU regulations people in the comments complain about
Aurornis 2 hours ago|||
The most valuable data breach content isn’t your advertising tracking data, though.

It would be your payment information, which is orthogonal to most of the tracking data.

The black market demand for leaked advertising-related tracking data is basically nil, except maybe in cases where it’s related to something else exploitable or usable for blackmail like if someone frequents cryptocurrency exchanges or porn sites. Nobody cares to pay for black market data about you shopping for towels on Amazon or things like that.

cindyllm 2 hours ago||
[dead]
mnewme 2 hours ago|||
Actually cookies are not mandated by the EU, but this was the solution the big companies agreed on and now Google and Co try to lobby against better solutions.

Check out: https://killthecookiebanner.eu/

mingus88 2 hours ago|||
Most US sites are giving the cookie bag to US users. It may simply be easier for leadership to say add the widget than it is to say we won’t accept traffic from the EU or risk the consequences

It feels similar to how CA environmental regs become the national standard simply because the market is so large it’s not worth splitting on it. So they just slap a cancer warning on everything

qurren 2 hours ago||
1. It's also a piece of cake to just not display the cookie banner for non-EU IPs

2. If you are a purely US entity with no actual business presence in the EU, you only need to comply with US laws and nothing else. If the EU doesn't like a purely-foreign website, it's on them to set up a national firewall and block it.

Case in point 1: It's not on you to comply with China's laws, it's on them to block it if they want to

Case in point 2: China's local businesses with no EU presence do not follow GDPR and do not display cookie banners even if accessed from the EU

dgellow 2 hours ago||
GDPR applies to EU citizens data. It doesn’t matter where your business is located in the world, if you process European personal data you’re on the hook. Of course you can decide to ignore and argue the EU doesn’t have jurisdiction
qurren 2 hours ago||
Exactly, they don't have jurisdiction outside their borders. If you don't have a presence there, they cannot subject you to their laws.

1. When is the last time you saw China enforcing its laws outside their borders? Why would EU be any different?

2. China has laws that are directly contradictory to GDPR laws; you may be required to retain data regardless of consent; if your website is based in China you have to follow local laws first before you follow contradictory foreign laws that have no jurisdiction over you.

frollogaston 6 minutes ago||
If you have any presence in the EU, you can be on the hook for EU customers visiting your non-bannered US site.
logseman 2 hours ago|||
Do Not Track was the right implementation (browser-based, activate only once) and it was sabotaged by ad peddlers. It is bad policy that has been reached after every better alternative was rejected.
dgellow 2 hours ago||
Do not track has been used by ad companies to track users, it’s one of the datapoints that can be used to identify your fingerprint
LastTrain 17 minutes ago|||
The banners force sites to divulge that they are tracking you in a very obvious way. It’s fucking great and site owners can make it go away any time they want by choosing not to tack their users.
Havoc 2 hours ago|||
Policy making assumed good faith actors - specifically that tracking outside of necessary for website to function to be minimal. Because like…not necessary.

It’s only broken to the extent that it collided with a messed up world where websites track even when they don’t need to and then send that to 2000 partners for more profit extraction on top of what the website does commercially.

Something is deeply fucked up there and it’s not the EU part. They just make a good scapegoat because the banner is what users see

ryanfreeborn 1 hour ago|||
Policy should never assume good faith actors. There wouldn't need to be policy if an assumption of good faith was a valid substrate for the policy. The policy is bad because its authors built it in a vacuum, without any thought or care put towards how its compliance would actually instatiate. This is a consistent problem with EU regulators. The 'tax' the policy levies on invasive cookie use (which I agree is broken and horrific) is forwarded to the user, via this terrible, omnipresent popup. The policy has made the problem worse, by further densensitizing humanity at large to this terrible practice. Shameful behavior by EU regulators and they should absolutely be pilloried for the present state.
f6v 2 hours ago||||
> Policy making assumed good faith actors

Let's not paint the policymakers naïve when they're in fact incompetent.

mnewme 2 hours ago|||
They are not incompetent in general. Most stuff works pretty well in Europe and better than in most of the world. We just focus on the bad regulations
vovavili 1 hour ago||
>Most stuff works pretty well in Europe

Bold thing to say.

t. European

Havoc 1 hour ago|||
Let’s not paint the policymakers incompetent when they’re in fact naive
dragonwriter 1 hour ago|||
So, let’s not paint them as <term meaning lacking the combination of knowledge and skill to do a job effectively> when they are in fact <term meaning particularly lacking wisdom, experience, and/or judgement>

Are you sure?

f6v 1 hour ago|||
If you think about it, a naïve policy maker isn't competent.
Xirdus 2 hours ago|||
The biggest positive outcome of the whole GDPR affair is that people finally believe me when I say that yes, they are selling your data to thousands of 3rd parties, and no, I'm not making these numbers up or exagerrating at all.
buildsjets 40 minutes ago|||
WARNING: Reading his post can expose you to photons, which are known to the State of California to cause cancer. For more information go to www.P65Warnings.ca.gov
ganzsz 2 hours ago|||
The most used banners at least have a quick way of dismissing without opting in. When the cases against too obvious dark patterns started that fixed itself at least.
umeshunni 1 hour ago|||
It's the EU equivalent of the California Prop 65 warning that tells you that every building causes cancer: https://en.wikipedia.org/wiki/1986_California_Proposition_65...
gdcbe 2 hours ago|||
I have yet to see an actual part of that policy which requires a cookie banner though. Seems more to me that it's a combination of (a) websites allowing all kind of fcked up use cases of cookies on their site (most sites do not even need cookies for real) and (b) not respecting http headers that ask to not be tracked... They much rather have a very confusing popup that kinda forces you to accept all :) How convenient.

Just like websites also give zero fcks about accept-language header... sure do geoip lookup, so much easier... not

dd8601fn 56 minutes ago|||
I’m certain it’s often just the California “literally everything is known to cause cancer” problem.

It’s simplest just to put the bullshit everywhere and the dipshit bureaucrats will leave everyone alone.

devmor 2 hours ago|||
I have always seen the cookie banner as a sort of punishment to the public for daring to have demanded better treatment.

“Oh you want consent involved in this interaction? Then we’ll annoy you about it constantly instead of respecting the intent of the regulation.”

TZubiri 57 minutes ago|||
What is the consequence of not complying with the cookie thing? Assuming you sell out of a jurisdiction outside of the EU
charles_f 1 hour ago|||
Once again, as everytime I see this, the policy only dictates that you ask for consent to track personal information from people. The problem is not the cookie banner, it's that every fucking website extracts your pants size to sell it to Facebook.
6510 1 hour ago|||
You are free to set cookies if you need them for site functionality.
iwontberude 1 hour ago|||
[dead]
skrebbel 2 hours ago|||
Bullshit. There’s no need to track every visitor. Just stop tracking and you don’t need a cookie banner.

The only mistake EU policymakers made was underestimating how willing companies were to deface their websites.

PerryUlyssesCox 2 hours ago|||
"Every time you visit the websites managed by the European Commission, you will be prompted to accept or refuse cookies." https://european-union.europa.eu/cookies_en
frollogaston 4 minutes ago|||
So much for "it's corps doing malicious compliance"
skrebbel 13 minutes ago|||
Wow this is terrible and embarrassing.
ryanfreeborn 1 hour ago||||
>The only mistake EU policymakers made was underestimating how willing companies were to deface their websites.

Yes and that is a MASSIVE mistake for a policymaker to commit. They should absolutely be pilloried for their incredible lack of foresight and understanding of how internet companies handle compliance. The policy has set back humanity by further desensitizing internet users around the world to the terrible, endemic use of cookies by most websites.

NetMageSCW 2 hours ago||||
That shows the same fundamental misunderstanding of the modern web that led to the ignorance of EU regulations.
zigzag312 2 hours ago|||
The policy is both, good, but also flawed. For example, you cannot persist settings, because one policy says that website settings should be ephemeral unless user agrees to persist them.
dgellow 2 hours ago||
That’s not true, it’s even explicitly called out by the EU guidelines.

Copy pasting an older comment because it’s really coming up all the time…

https://news.ycombinator.com/item?id=49060456

===

That's not true and is a very common misinformation people repeat online. You can save user preferences in cookies without any consent banner, if the cookie isn't used for tracking. See here[0], page 6: > As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’ 0: https://www.edpb.europa.eu/system/files/documents/2024-10/ed... As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen

zigzag312 50 minutes ago||
The guidelines you linked state: "These Guidelines do not address the circumstances under which a processing operation may fall within the exemptions from the consent requirement provided for by the ePD".

Let's check what "Opinion 04/2012 on Cookie Consent Exemption" [0] says under section 3.6:

"""

3.6 UI customization cookies

User interface customization cookies are used to store a user’s preference regarding a service across web pages and not linked to other persistent identifiers such as a username. They are only set if the user has explicitly requested the service to remember a certain piece of information, for example, by clicking on a button or ticking a box.

...

These customization functionalities are thus explicitly enabled by the user of an information society service (e.g. by clicking on button or ticking a box) although in the absence of additional information the intention of the user could not be interpreted as a preference to remember that choice for longer than a browser session (or no more than a few additional hours). As such only session (or short term) cookies storing such information are exempted under CRITERION B. The addition of additional information in a prominent location (e.g. “uses cookies” written next to the flag) would constitute sufficient information for valid consent to remember the user’s preference for a longer duration, negating the requirement to apply an exemption in this case.

"""

See that you need to provide provide "information in a prominent location (e.g. “uses cookies” written next to the flag)" to be able to store user preferences in persistent cookies. You don't need consent banner for that (which I didn't say you need), but you need to clearly inform the user. The act of setting a preference together with clear information about persistence counts as a valid consent.

[0] https://ec.europa.eu/justice/article-29/documentation/opinio...

sghiassy 2 hours ago|||
It’s an EU law, but it impacts us all in America as well… because you know, every fucking website
mnewme 2 hours ago||
It is not an EU law. Nowhere in GDPR are cookie banners mandated.

Actually big tech is to blame: https://killthecookiebanner.eu/

mr_mitm 2 hours ago||
The cookie disaster is thanks to the ePrivacy Directive, which came before GDPR:

- https://www.edps.europa.eu/data-protection/our-work/subjects...

- https://en.wikipedia.org/wiki/EPrivacy_Directive

mnewme 2 hours ago||
we could have settled on privacy compliant tracking without cookies, which is possible or use browser preferences and respect those (which would be perfectly legal)
nathell 1 hour ago|||
No it’s not, it’s a testimony to how broken the Internet is.

There’s a perfectly valid and simple way to comply with the EU policies, including GDPR, and not impose annoying popups on your users: just don’t set cookies (if you need to have a login, you can ask for permissions at login time) and don’t collect personal data. That a lot of sites elect not to do that is an indication of how they treat the user, not of the brokenness of EU law.

4ndrewl 2 hours ago||
It's not a cookies banner. It's a request to harvest your data and share it with third parties for purposes that are not required for the service you're offering.

No harvest data to 936 partners? No need for a banner!

kwertyoowiyop 2 hours ago||
Needs a Google login popup, required for any site that there is no reason at all to have an account with.
robertjwebb 2 hours ago||
It should appear a second after the page seems to have finished loading, so that it hijacks the input if the user is navigating with the keyboard or typing something into a form.
Dwedit 2 hours ago|||
Or even better, something that pretends to be a real "Sign in with Google" button but instead phishes your username and password.
malfist 2 hours ago|||
It also needs to ask the browser for your location and to send you notifications.
JKCalhoun 2 hours ago||
Notifications?

How about an email popup. My browser will happily auto-populate it.

VCFundedGenYer 1 hour ago||
Some graybeard advice - Any time you need to use a website that doesn't require active cognitive interaction - click the button in your browser that enables Reader View to get the content and strip out everything else. It's not perfect, but it makes the web more usable (especially on mobile, my goodness it's gotten bad).

Firefox also has an extension called "Auto Reader View" in which you can set sites to automatically change to that mode.

cg5280 2 hours ago||
So many websites do popups and it feels so anti-user. Maybe I get unusually annoyed, but I do not need a Gemini popup ad in Google Docs. Just let me do what I came to the website to do!
dylan604 2 hours ago|
But you could obviously be doing it faster/smarter by using Gemini /s
SamBam 2 hours ago||
If they make it hard enough to interact with the actual website, we'll have to use AI!
dylan604 2 hours ago||
See, there you go thinking being able to use a website is a right
andy99 2 hours ago||
Needs to autoplay a video which when dismissed just moves to another window and continues playing. With sound.
six_seven 2 hours ago||
and hijack your clipboard and back button
tamimio 2 hours ago||
And you can’t dismiss it because the X is somehow hidden behind another popup
fantasizr 2 hours ago|
it's funny sometimes there will be an archived espn.com (like this https://proxy.espn.com/espn/page2/story?page=simmons/030418) and it's hard to argue the web was not better like this, i.e. readable
More comments...