[HN Gopher] Firefox may soon reject Cookie prompts automatically
___________________________________________________________________
Firefox may soon reject Cookie prompts automatically
Author : goplayoutside
Score : 181 points
Date : 2023-04-18 20:06 UTC (2 hours ago)
(HTM) web link (www.ghacks.net)
(TXT) w3m dump (www.ghacks.net)
| eternityforest wrote:
| There's no auto-accept feature? I still wouldn't use it, or
| Firefox, because that kind of automated interaction seems
| unreliable, but I _really_ don 't want auto- reject breaking
| stuff.
| marssaxman wrote:
| I never accept or reject cookie banners - I just delete them,
| using uBlock Origin. This works out fine, basically all the
| time, so far as my experience goes.
| pmontra wrote:
| I also use NoScript. The cookie banner of ghacks didn't show
| either because I uBlocked it time ago or because it was
| displayed by a script that didn't run.
| stonogo wrote:
| The law that triggered these banners already mandates that the
| website may not reduce functionality if the user rejects the
| cookies. Functionality-tied cookies are already exempted from
| the acceptance requirement.
|
| These banners are the most-user-hostile possible response to
| the law, so it makes sense to automate getting rid of them.
| eternityforest wrote:
| Not everyone actually follows the law though, sometimes they
| mix in essential cookies and you have to click through a
| bunch of layers to turn them off without turning off
| essential ones.
|
| I wouldn't be surprised if they find some way to defeat this
| in a not quite legal way and break stuff for people who use
| it.
| mminer237 wrote:
| That's not true. Directive 2002/58/EC explicitly says that
| it's fine to condition use of websites upon acceptance of
| cookies:
|
| > Access to specific website content may still be made
| conditional on the well-informed acceptance of a cookie or
| similar device, if it is used for a legitimate purpose.
|
| https://eur-
| lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX....
| kytazo wrote:
| Honestly those are more like gimmicks from an advanced user
| standpoint as the I still don't care about cookies extension does
| the job just fine as far as I'm concerned, and while this may
| indeed make a good headline or feature I think development may
| lack emphasis on the core of firefox and what makes it a good
| browser.
|
| There is much more fundamental and core functionality missing
| which has been requested for years like this for example
| https://bugzilla.mozilla.org/show_bug.cgi?id=1325692
|
| In general it would be good having such functionality built-in, I
| guess they're gonna have to maintain it as well.
|
| All and all, I'm glad to see any kind of progress on the browser
| and in any case wish them the very best.
| nine_k wrote:
| Advanced users are already well-served; it's not for them.
|
| Also, the mobile version may have limitations on extensions.
| focusedone wrote:
| https://github.com/cavi-au/Consent-O-Matic - this has worked well
| for me. It'll be nice when similar functionality is built in.
| WhereIsTheTruth wrote:
| I'm pretty sure this is against GDPR, it requires explicit choice
| from the user
|
| Users should decide themselves what to filter, so the bad actors
| with aggressive cookie policy gets automatically filtered out
| over time
|
| I was looking for a recipe last time, I googled what I wanted,
| clicked the 1st link, bunch of popups for cookie/ad, I
| immediately hit "previous page" then I checked the next link, I
| bookmarked the one without fuss
| rektide wrote:
| My choice as a user is that it's all bad, all of it is no good,
| no one gets any cookies.
|
| Firefox as a user-agent is mirroring me-the-user's choice.
|
| Admittedly that doesn't hold for every user. Some users might
| make other choices.
| [deleted]
| crote wrote:
| It is not. The GDPR requires websites to obtain explicit
| _consent_ to misuse your data. The default state is an absence
| of consent, so such an addon doesn 't change anything.
| WhereIsTheTruth wrote:
| I will have to read the whole thing again, it's been a
| while..
| [deleted]
| retrocryptid wrote:
| cool. stack exchange might become useful again.
| kevin_thibedeau wrote:
| There's always tracking via the googleapis.com domain which
| breaks the site if you try to block it.
| aziaziazi wrote:
| Things may changes "soon" in the legislation
|
| > the absence of any option for refusing/rejecting/not consenting
| cookies at the same level as the one provided for accepting their
| storage constitutes a breach of the legislation [0]
|
| GO Europe GO !
|
| [0] https://www.cnil.fr/en/edpb-adopts-final-report-outcome-
| cook...
| jonplackett wrote:
| How did they not include this to begin with? It's so obvious as
| to be poking you in the eye that this would be necessary.
|
| How many cumulative wasted hours have been spent tapping
| through cookie pop ups?
|
| I made a game about it if you feel like wasting even more of
| your precious life on pop ups.
|
| http://termsandconditions.game
| rlpb wrote:
| It was included. The rule hasn't been changed. The
| interpretation of the rule in one specific case has been
| confirmed, without having changed the rule. That means that,
| as written, this dark pattern was always illegal.
| dmix wrote:
| As great as that is I still don't think it will make me hate
| them any less which is why I love Firefox for trying to address
| it at the browser level.
|
| As a designer I despise mandatory content blocking modals and
| each one will still have a new design you have to decipher.
| Maybe if they clarified some design rules (2 or 3 big buttons
| with clearly defined text in legible colours/fonts etc) then it
| would be tolerable.
|
| Regardless making it always have Accept/Reject/Custom is a good
| step forward, even though fingerprinting and browsers like
| Firefox blocking 3rd party cookies by default pretty much
| eliminates their utility.
| [deleted]
| pvorb wrote:
| It should just be a standard browser feature with a
| JavaScript API. Think of something similar to
| window.confirm() or a standard based on HTTP headers like Do
| Not Track. There could then just be a standard setting in the
| browser preferences and the world could be a better place
| again ten years from now.
| retrac wrote:
| I still smile sometimes at the pop-ups. I mean, you can try and
| store a cookie. I'm still gonna automatically delete it in a few
| minutes.
|
| This never needed a legal solution in this form. Browsers should
| just not accept cookies, unless the user explicitly wants
| something stored on their device. That might have been better to
| legislate. Software on a user's device should not store or enable
| tracking by remote services, without disclaimer.
| eternityforest wrote:
| That would also be terrible to legislate. Browsers for privacy
| conscious people should offer it as an option, it's a non-issue
| for everyone else.
|
| If the government wants to get involved they can make public
| service announcements and try to convince people to care.
| anonymous_sorry wrote:
| With a purely client-side solution how do you stop a company
| using the same identifying token for basic session management
| and invasive tracking/data gathering?
| ZiiS wrote:
| Tracking a single session doesn't really worry me and I
| seriously doubt any law will stop it. What we want to do is
| prevent them correlating two sessions. With FF in full
| defensive mode. No canvas, restricted JS, deleted cookies I
| can at least make it hard for them.
| DelightOne wrote:
| But.. what if it asks to allow tracking based on your
| internet provider? Then the provider delivers who you are
| automatically instead of anything you control.
| andrepd wrote:
| Exactly. Cookie autodelete (remove cookies when all tabs
| from a domain are closed) + I don't care about cookies
| (remove the popups).
| PeterisP wrote:
| Rejection is required to ensure that for functionally required
| cookies (e.g. session cookies when logged in) you refuse
| permission to use them for any other purpose, and that you
| refuse permission to use any of the many non-cookie tracking
| methods.
| sonium wrote:
| AFAIK it's not actually about cookies but a website tracking
| you by any technical means. Could be your IP or user agent as
| well
| circuit10 wrote:
| As far as I know the law only applies to tracking cookies, I'm
| not sure if the browser can distinguish those from normal ones
| so it has be done via the law. Asking for consent for any kind
| of cookie whatsoever would be a bit much
| musicale wrote:
| Tracking probably won't go away if you remove client side
| cookies - it will just move server side (think a new server-
| side google analytics) and to more aggressive client
| fingerprinting.
|
| Is that the best outcome?
| taftster wrote:
| I mean, I am pretty sure (have seen first hand) that this
| already happens regardless of whether client cookies are
| enabled. There's so many other (good?) ways to track users
| beyond just a cookie.
| dariosalvi78 wrote:
| I use stardust cookie cutter: https://www.stardustnetwork.com/
| PaulHoule wrote:
| Europe should have just mandated Do-not-Track, what they did was
| a billion dollar mistake.
| josefx wrote:
| Not honoring "do-not-track" isn't as visible. Sure a site could
| just do the bare minimum to look like it upholds the law while
| breaking it, but instead we got tons of user hostile dark
| pattern filed dialogs that outright screamed "look at us, we
| are violating the law".
| Deukhoofd wrote:
| The EU is planning to do just that. The new ePrivacy Regulation
| is currently in trilogue negotiations, and should go into force
| between later this year and 2025.
|
| > the cookie provision, which has resulted in an overload of
| consent requests for internet users, will be streamlined. The
| new rule will be more user-friendly as browser settings will
| provide an easy way to accept or refuse tracking cookies and
| other identifiers. The proposal also clarifies that no consent
| is needed for non-privacy intrusive cookies that improve
| internet experience, such as cookies to remember shopping-cart
| history or to count the number of website visitors.
|
| https://digital-strategy.ec.europa.eu/en/policies/eprivacy-r...
| scarface74 wrote:
| Yes I'm sure the EU's answer to an over complicated 99
| section 11 chapter law - passing yet another law - will work
| out really well this time.
| swapfile wrote:
| [dead]
| mrkeen wrote:
| I like do-not-track, but it's not for everyone. Informed
| consent is a good start anyway.
| julianlam wrote:
| If only there were an agreed upon best practice for
| communicating a sites handling of user data... a... "Privacy
| Policy", of sorts... Humm......
| JohnFen wrote:
| Privacy Policy pages aren't really a solution to this, in
| my opinion. I don't think they reasonably count towards
| satisfying "informed consent".
|
| First, because they don't actually inform you of much.
|
| Second, because they're tricky to understand if you're not
| a lawyer. Most of them mean "you have no privacy", but
| worded in a way that leads you to think you do.
|
| Third, because it's a bit ridiculous to expect everyone to
| read them. You'd spend more of your time reading those
| damned things than the page you want to read -- and you'd
| have to read them on every visit because they can change at
| any time without notice.
|
| Better is if sites would just give basic, truthful warnings
| at the moments where you are making a privacy-impacting
| decision.
| musicale wrote:
| Legal requirements are probably the only way to handle server
| side tracking, data brokers, etc..
|
| Though they might be hard to enforce.
| harel wrote:
| I hate those cookie prompts so much I get Cookie Rage every time
| they appear. I rather be tracked from here to infinity than see
| another cookie prompt in a site i approved yesterday.
| robswc wrote:
| Do they not remember your decision? Most sites I visit never
| have them and if they do, only need to select it once.
| keketi wrote:
| I use incognito mode, which means throughout the day I have
| to click through cookie consent screens on every single
| website I visit.
| [deleted]
| vitehozonage wrote:
| You are likely keeping all your cookies which is a huge
| privacy problem. If sites remember who you are between
| sessions then of course they can track you. With addons like
| Cookie AutoDelete this doesnt happen.
|
| If security conscious it would be recommended to also use
| disposable VMs for browser sessions like with Qubes OS.
| Otherwise, with persistence like you describe, it's crazy to
| me that one bad click could so easily compromise you forever
| hewlett wrote:
| If you reject cookies, the site has no way of knowing you
| have rejected cookies the next time you visit. You need a
| cookie in order to store the cookie decision
| serial_dev wrote:
| I think this is false?
|
| A rejected cookie preference could be stored client side in
| local storage and depending on that value you could decide
| whether to show the cookie prompt.
| mminer237 wrote:
| Directive 2002/58/EC applies to any "hidden information"
| stored on users' computers. It's irrelevant whether you
| use cookies or localStorage or IndexedDB. Regardless of
| what you use to store data on the user's computer, you
| have to "ensure that users are made aware of information
| being placed on the terminal equipment", and users must
| "have the opportunity to refuse to have a cookie or
| similar device stored on their terminal equipment."
|
| Source: https://eur-
| lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX...
|
| However, the ICO has suggested that saying "I refuse to
| allow any cookies on my computer" could be taken as
| implied consent to allow a cookie stating such.
| aden1ne wrote:
| Functional cookies like that are explicitly allowed.
| mminer237 wrote:
| There's no exception for "functional cookies". There's an
| exception for cookies "strictly necessary" for an
| "explicitly requested" service. I don't see how
| remembering you don't want cookies is strictly necessary
| or explicitly requested. Unless you have a separate
| optional check for "remember my decision" I would argue
| that not asking every session would be a violation of the
| ePrivacy law.
| asddubs wrote:
| prompts are not necessary for functional cookies
| Raicuparta wrote:
| Browsers provide multiple ways to store data like that
| locally, you don't need cookies. And even if you did, you
| wouldn't need consent to store that preference.
| louthy wrote:
| Install the consent-o-matic extension. It fills out the forms
| automatically. It doesn't catch everything, but is mostly
| pretty good...
|
| Chrome: https://chrome.google.com/webstore/detail/consent-o-
| matic/md...
|
| Firefox: https://addons.mozilla.org/en-
| US/firefox/addon/consent-o-mat...
|
| The thing that really grinds my gears is the phrase "We care
| about your privacy". Bullshit! If you cared you wouldn't even
| need to ask for consent!
| bombolo wrote:
| doesn't work in most cases
| c7DJTLrn wrote:
| I'm beyond Cookie Rage. I'm into Cookie Despair, maybe even
| Cookie Depression.
| frereubu wrote:
| You're almost there. The five stages of cookie despair:
| Denial, Anger, Bargaining, Depression, Acceptance.
|
| (https://en.wikipedia.org/wiki/Five_stages_of_grief in case
| the reference is too niche)
| c7DJTLrn wrote:
| To reach Cookie Acceptance I might need a Cookie Therapist.
|
| (sorry, I'm in a silly mood)
| exrook wrote:
| Try adding the EasyList Cookie List[0] to your adblocker to
| block them all.
|
| It's present in the uBlock Origin filter list settings under
| Annoyances but not enabled by default. HN readers may also find
| some of the other default disabled filter lists interesting
| such as the AdGuard URL Tracking Protection list which strips
| tracking parameters from URLs.
|
| [0] https://easylist.to/#easylist-cookie-list
| suralind wrote:
| there's a chrome extension which I think is called "I don't
| care about cookies" :)
| Quarrel wrote:
| Which was bought by Avast, so lots of people switched to the
| forked open version [1] (thank you GPL).
|
| [1] https://github.com/OhMyGuus/I-Still-Dont-Care-About-
| Cookies
| stickfigure wrote:
| I want my browser to send a header: X-I-Dont-
| Give-A-Fuck-About-Cookies: true
|
| ...and let the world wide web stop torturing me. I have a nice
| button that clears cookies and websites can't do anything about
| it. This whole dance is stupid.
| rwalle wrote:
| ...which will make it easier to websites to identify and track
| you.
| ximm wrote:
| > Certain regulations, like the GDPR, the General Data Protection
| Regulation, by the European Union, require that sites get consent
| for placing cookies and data on user devices.
|
| Well, that is bullshit. GDPR requires that you have some form of
| legal basis for storing cookies. Consent is the last ditch effort
| if you were not able to find any other justification. So by
| nearly by definition, denying that consent is in the user's
| interest.
|
| I think there is some other EU regulation that requires cookie
| banners. But don't blame it on the GDPR!
| ragebol wrote:
| The cookie dialog must be there in case you want to do cracking
| cookies. If you don't place the tracking cookies, no need for a
| dialog IIRC.
|
| But most sites didn't get the hint of "just don't track" and
| still want to track you.
| progval wrote:
| > GDPR requires that you have some form of legal basis for
| storing cookies.
|
| Not even that. It requires a legal basis for storing and
| processing personal data.
| musicale wrote:
| Great, now I just want a preference for [X] NO,
| I do not want to subscribe to your newsletter
| basisword wrote:
| The irony that I have to click through one of the ultra-shitty
| agree/learn more cookie popups just to read this article. Maybe
| if GHacks didn't comply with the legislation in such a user
| hostile manner, browser developers wouldn't have to waste time on
| such features.
| jokethrowaway wrote:
| nope, any cookie banner is pure cancer
|
| I don't even care about all the dark patterns of now allowing
| you to dismiss and ignore with one click.
|
| Thank you Europe
| solarkraft wrote:
| > nope, any cookie banner is pure cancer
|
| I agree, sites shouldn't be doing the things that require
| showing one.
|
| > I don't even care about all the dark patterns of now
| allowing you to dismiss and ignore with one click.
|
| How is this a dark pattern?
|
| > Thank you Europe
|
| Indeed! If such tracking has to be allowed, I'm happy that at
| least I can opt out of it.
| seppel wrote:
| > Maybe if GHacks didn't comply with the legislation in such a
| user hostile manner, browser developers wouldn't have to waste
| time on such features.
|
| You need the same feature for visiting EU government websites:
|
| https://www.consilium.europa.eu/ (best example)
|
| https://commission.europa.eu/
|
| https://european-union.europa.eu/
| tobr wrote:
| These just require a single click to reject, unlike the one
| on ghacks.net.
| Deukhoofd wrote:
| There's a major difference between a two button UI with a
| clear "I refuse cookies" screen, and a screen where you first
| need to click "Learn More", then manually toggle 5 toggles
| about what you don't want to allow, then click the greyed out
| "View our partners" button, then block all of those. The
| second one is definitely extremely user hostile.
| skywal_l wrote:
| As it happens, GHacks cookie popup is defeated by NoScript. You
| might give it a try.
| rickstanley wrote:
| Not OP. I've been using NoScript until today, works as
| expected of course, but the hassle to have to enable specific
| scripts to make a useful website work outweighs its
| usefulness _for me_.
|
| There's "NoJS", a extension where you can enable all JS
| through a switch, but it doesn't handle iframes very well at
| the moment.
| dp-hackernews wrote:
| Use uMatrix by uBlockOrigin author - now deprecated, but
| still useful
| JohnMakin wrote:
| Came here to post this. This is a pretty malicious pattern.
| aziaziazi wrote:
| And there is even worse : sometimes the "partner" list does
| not have a reject all AND each partner requires a two click
| steps - waiting for an animation in between.
|
| Edit: remove double post of link
| [deleted]
| swapfile wrote:
| [dead]
| BlueTemplar wrote:
| These days, this just makes me immediately click Reader Mode.
| marcosdumay wrote:
| An outright dishonest cookie prompt, where "reject" or "manage
| choices" aren't even shown on the first screen.
|
| I imagine the company behind this site is hosted at the US.
| There are not many places one can still do this.
| sva_ wrote:
| Most of the big German news sites require you to either
| accept ads, or pay for a subscription.
|
| It is sadly perfectly legal afaik. Nobody is entitled to your
| content without agreeing to some terms. Luckily, archive.is
| works very well. Wish there were more alternatives.
| math_dandy wrote:
| How do they make you accept ads? Do they sniff ad blockers
| or something? And is this "ads or pay" dichotomy related to
| cookie modals?
| solarkraft wrote:
| I also read that it's legal, but can't see how it's in the
| spirit of the law.
| marcosdumay wrote:
| The site doesn't require that you accept the ads. It just
| uses dark patterns to make you accept tracking.
| lbotos wrote:
| Aside: I can't remember what site I was on recently, but I saw
| the craziest cookie prompt. The options were:
|
| Basic / Premium / Ultra
|
| With you guessed it, Ultra being the most tracking cookies. I
| was flabbergasted.
| tux3 wrote:
| They should make Ultra have a limited time countdown, to
| stress people into FOMOclicking.
|
| But of course, for maximum trap potential, we need to find a
| wording such that Premium is the option without, while Ultra
| tracking and Basic tracking should both do roughly the same
| amount of tracking (modulo not really relevant details). With
| a sufficiently discouraging wall of text, a bad UX, and a
| limited time option, no one would spend the time to figure
| out they need to click the middle option.
|
| (This tweet brought to you by our sponsor, Moloch.)
| thedailymail wrote:
| Congratulations on being selected to enjoy the Diamond Elite
| Tier sponsor engagement experience!
| solarkraft wrote:
| Ultimate tracking experience
| subarctic wrote:
| Honestly for the first 10 seconds after I clicked the link, I
| thought the banner must be a joke because the irony is just too
| perfect
| bombolo wrote:
| It's actually illegal, reject should be as fast as accept.
___________________________________________________________________
(page generated 2023-04-18 23:00 UTC)