[HN Gopher] Firefox may soon reject Cookie prompts automatically
       ___________________________________________________________________
        
       Firefox may soon reject Cookie prompts automatically
        
       Author : goplayoutside
       Score  : 181 points
       Date   : 2023-04-18 20:06 UTC (2 hours ago)
        
 (HTM) web link (www.ghacks.net)
 (TXT) w3m dump (www.ghacks.net)
        
       | eternityforest wrote:
       | There's no auto-accept feature? I still wouldn't use it, or
       | Firefox, because that kind of automated interaction seems
       | unreliable, but I _really_ don 't want auto- reject breaking
       | stuff.
        
         | marssaxman wrote:
         | I never accept or reject cookie banners - I just delete them,
         | using uBlock Origin. This works out fine, basically all the
         | time, so far as my experience goes.
        
           | pmontra wrote:
           | I also use NoScript. The cookie banner of ghacks didn't show
           | either because I uBlocked it time ago or because it was
           | displayed by a script that didn't run.
        
         | stonogo wrote:
         | The law that triggered these banners already mandates that the
         | website may not reduce functionality if the user rejects the
         | cookies. Functionality-tied cookies are already exempted from
         | the acceptance requirement.
         | 
         | These banners are the most-user-hostile possible response to
         | the law, so it makes sense to automate getting rid of them.
        
           | eternityforest wrote:
           | Not everyone actually follows the law though, sometimes they
           | mix in essential cookies and you have to click through a
           | bunch of layers to turn them off without turning off
           | essential ones.
           | 
           | I wouldn't be surprised if they find some way to defeat this
           | in a not quite legal way and break stuff for people who use
           | it.
        
           | mminer237 wrote:
           | That's not true. Directive 2002/58/EC explicitly says that
           | it's fine to condition use of websites upon acceptance of
           | cookies:
           | 
           | > Access to specific website content may still be made
           | conditional on the well-informed acceptance of a cookie or
           | similar device, if it is used for a legitimate purpose.
           | 
           | https://eur-
           | lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX....
        
       | kytazo wrote:
       | Honestly those are more like gimmicks from an advanced user
       | standpoint as the I still don't care about cookies extension does
       | the job just fine as far as I'm concerned, and while this may
       | indeed make a good headline or feature I think development may
       | lack emphasis on the core of firefox and what makes it a good
       | browser.
       | 
       | There is much more fundamental and core functionality missing
       | which has been requested for years like this for example
       | https://bugzilla.mozilla.org/show_bug.cgi?id=1325692
       | 
       | In general it would be good having such functionality built-in, I
       | guess they're gonna have to maintain it as well.
       | 
       | All and all, I'm glad to see any kind of progress on the browser
       | and in any case wish them the very best.
        
         | nine_k wrote:
         | Advanced users are already well-served; it's not for them.
         | 
         | Also, the mobile version may have limitations on extensions.
        
       | focusedone wrote:
       | https://github.com/cavi-au/Consent-O-Matic - this has worked well
       | for me. It'll be nice when similar functionality is built in.
        
       | WhereIsTheTruth wrote:
       | I'm pretty sure this is against GDPR, it requires explicit choice
       | from the user
       | 
       | Users should decide themselves what to filter, so the bad actors
       | with aggressive cookie policy gets automatically filtered out
       | over time
       | 
       | I was looking for a recipe last time, I googled what I wanted,
       | clicked the 1st link, bunch of popups for cookie/ad, I
       | immediately hit "previous page" then I checked the next link, I
       | bookmarked the one without fuss
        
         | rektide wrote:
         | My choice as a user is that it's all bad, all of it is no good,
         | no one gets any cookies.
         | 
         | Firefox as a user-agent is mirroring me-the-user's choice.
         | 
         | Admittedly that doesn't hold for every user. Some users might
         | make other choices.
        
           | [deleted]
        
         | crote wrote:
         | It is not. The GDPR requires websites to obtain explicit
         | _consent_ to misuse your data. The default state is an absence
         | of consent, so such an addon doesn 't change anything.
        
           | WhereIsTheTruth wrote:
           | I will have to read the whole thing again, it's been a
           | while..
        
       | [deleted]
        
       | retrocryptid wrote:
       | cool. stack exchange might become useful again.
        
         | kevin_thibedeau wrote:
         | There's always tracking via the googleapis.com domain which
         | breaks the site if you try to block it.
        
       | aziaziazi wrote:
       | Things may changes "soon" in the legislation
       | 
       | > the absence of any option for refusing/rejecting/not consenting
       | cookies at the same level as the one provided for accepting their
       | storage constitutes a breach of the legislation [0]
       | 
       | GO Europe GO !
       | 
       | [0] https://www.cnil.fr/en/edpb-adopts-final-report-outcome-
       | cook...
        
         | jonplackett wrote:
         | How did they not include this to begin with? It's so obvious as
         | to be poking you in the eye that this would be necessary.
         | 
         | How many cumulative wasted hours have been spent tapping
         | through cookie pop ups?
         | 
         | I made a game about it if you feel like wasting even more of
         | your precious life on pop ups.
         | 
         | http://termsandconditions.game
        
           | rlpb wrote:
           | It was included. The rule hasn't been changed. The
           | interpretation of the rule in one specific case has been
           | confirmed, without having changed the rule. That means that,
           | as written, this dark pattern was always illegal.
        
         | dmix wrote:
         | As great as that is I still don't think it will make me hate
         | them any less which is why I love Firefox for trying to address
         | it at the browser level.
         | 
         | As a designer I despise mandatory content blocking modals and
         | each one will still have a new design you have to decipher.
         | Maybe if they clarified some design rules (2 or 3 big buttons
         | with clearly defined text in legible colours/fonts etc) then it
         | would be tolerable.
         | 
         | Regardless making it always have Accept/Reject/Custom is a good
         | step forward, even though fingerprinting and browsers like
         | Firefox blocking 3rd party cookies by default pretty much
         | eliminates their utility.
        
           | [deleted]
        
           | pvorb wrote:
           | It should just be a standard browser feature with a
           | JavaScript API. Think of something similar to
           | window.confirm() or a standard based on HTTP headers like Do
           | Not Track. There could then just be a standard setting in the
           | browser preferences and the world could be a better place
           | again ten years from now.
        
       | retrac wrote:
       | I still smile sometimes at the pop-ups. I mean, you can try and
       | store a cookie. I'm still gonna automatically delete it in a few
       | minutes.
       | 
       | This never needed a legal solution in this form. Browsers should
       | just not accept cookies, unless the user explicitly wants
       | something stored on their device. That might have been better to
       | legislate. Software on a user's device should not store or enable
       | tracking by remote services, without disclaimer.
        
         | eternityforest wrote:
         | That would also be terrible to legislate. Browsers for privacy
         | conscious people should offer it as an option, it's a non-issue
         | for everyone else.
         | 
         | If the government wants to get involved they can make public
         | service announcements and try to convince people to care.
        
         | anonymous_sorry wrote:
         | With a purely client-side solution how do you stop a company
         | using the same identifying token for basic session management
         | and invasive tracking/data gathering?
        
           | ZiiS wrote:
           | Tracking a single session doesn't really worry me and I
           | seriously doubt any law will stop it. What we want to do is
           | prevent them correlating two sessions. With FF in full
           | defensive mode. No canvas, restricted JS, deleted cookies I
           | can at least make it hard for them.
        
             | DelightOne wrote:
             | But.. what if it asks to allow tracking based on your
             | internet provider? Then the provider delivers who you are
             | automatically instead of anything you control.
        
             | andrepd wrote:
             | Exactly. Cookie autodelete (remove cookies when all tabs
             | from a domain are closed) + I don't care about cookies
             | (remove the popups).
        
         | PeterisP wrote:
         | Rejection is required to ensure that for functionally required
         | cookies (e.g. session cookies when logged in) you refuse
         | permission to use them for any other purpose, and that you
         | refuse permission to use any of the many non-cookie tracking
         | methods.
        
         | sonium wrote:
         | AFAIK it's not actually about cookies but a website tracking
         | you by any technical means. Could be your IP or user agent as
         | well
        
         | circuit10 wrote:
         | As far as I know the law only applies to tracking cookies, I'm
         | not sure if the browser can distinguish those from normal ones
         | so it has be done via the law. Asking for consent for any kind
         | of cookie whatsoever would be a bit much
        
         | musicale wrote:
         | Tracking probably won't go away if you remove client side
         | cookies - it will just move server side (think a new server-
         | side google analytics) and to more aggressive client
         | fingerprinting.
         | 
         | Is that the best outcome?
        
           | taftster wrote:
           | I mean, I am pretty sure (have seen first hand) that this
           | already happens regardless of whether client cookies are
           | enabled. There's so many other (good?) ways to track users
           | beyond just a cookie.
        
       | dariosalvi78 wrote:
       | I use stardust cookie cutter: https://www.stardustnetwork.com/
        
       | PaulHoule wrote:
       | Europe should have just mandated Do-not-Track, what they did was
       | a billion dollar mistake.
        
         | josefx wrote:
         | Not honoring "do-not-track" isn't as visible. Sure a site could
         | just do the bare minimum to look like it upholds the law while
         | breaking it, but instead we got tons of user hostile dark
         | pattern filed dialogs that outright screamed "look at us, we
         | are violating the law".
        
         | Deukhoofd wrote:
         | The EU is planning to do just that. The new ePrivacy Regulation
         | is currently in trilogue negotiations, and should go into force
         | between later this year and 2025.
         | 
         | > the cookie provision, which has resulted in an overload of
         | consent requests for internet users, will be streamlined. The
         | new rule will be more user-friendly as browser settings will
         | provide an easy way to accept or refuse tracking cookies and
         | other identifiers. The proposal also clarifies that no consent
         | is needed for non-privacy intrusive cookies that improve
         | internet experience, such as cookies to remember shopping-cart
         | history or to count the number of website visitors.
         | 
         | https://digital-strategy.ec.europa.eu/en/policies/eprivacy-r...
        
           | scarface74 wrote:
           | Yes I'm sure the EU's answer to an over complicated 99
           | section 11 chapter law - passing yet another law - will work
           | out really well this time.
        
         | swapfile wrote:
         | [dead]
        
         | mrkeen wrote:
         | I like do-not-track, but it's not for everyone. Informed
         | consent is a good start anyway.
        
           | julianlam wrote:
           | If only there were an agreed upon best practice for
           | communicating a sites handling of user data... a... "Privacy
           | Policy", of sorts... Humm......
        
             | JohnFen wrote:
             | Privacy Policy pages aren't really a solution to this, in
             | my opinion. I don't think they reasonably count towards
             | satisfying "informed consent".
             | 
             | First, because they don't actually inform you of much.
             | 
             | Second, because they're tricky to understand if you're not
             | a lawyer. Most of them mean "you have no privacy", but
             | worded in a way that leads you to think you do.
             | 
             | Third, because it's a bit ridiculous to expect everyone to
             | read them. You'd spend more of your time reading those
             | damned things than the page you want to read -- and you'd
             | have to read them on every visit because they can change at
             | any time without notice.
             | 
             | Better is if sites would just give basic, truthful warnings
             | at the moments where you are making a privacy-impacting
             | decision.
        
         | musicale wrote:
         | Legal requirements are probably the only way to handle server
         | side tracking, data brokers, etc..
         | 
         | Though they might be hard to enforce.
        
       | harel wrote:
       | I hate those cookie prompts so much I get Cookie Rage every time
       | they appear. I rather be tracked from here to infinity than see
       | another cookie prompt in a site i approved yesterday.
        
         | robswc wrote:
         | Do they not remember your decision? Most sites I visit never
         | have them and if they do, only need to select it once.
        
           | keketi wrote:
           | I use incognito mode, which means throughout the day I have
           | to click through cookie consent screens on every single
           | website I visit.
        
           | [deleted]
        
           | vitehozonage wrote:
           | You are likely keeping all your cookies which is a huge
           | privacy problem. If sites remember who you are between
           | sessions then of course they can track you. With addons like
           | Cookie AutoDelete this doesnt happen.
           | 
           | If security conscious it would be recommended to also use
           | disposable VMs for browser sessions like with Qubes OS.
           | Otherwise, with persistence like you describe, it's crazy to
           | me that one bad click could so easily compromise you forever
        
           | hewlett wrote:
           | If you reject cookies, the site has no way of knowing you
           | have rejected cookies the next time you visit. You need a
           | cookie in order to store the cookie decision
        
             | serial_dev wrote:
             | I think this is false?
             | 
             | A rejected cookie preference could be stored client side in
             | local storage and depending on that value you could decide
             | whether to show the cookie prompt.
        
               | mminer237 wrote:
               | Directive 2002/58/EC applies to any "hidden information"
               | stored on users' computers. It's irrelevant whether you
               | use cookies or localStorage or IndexedDB. Regardless of
               | what you use to store data on the user's computer, you
               | have to "ensure that users are made aware of information
               | being placed on the terminal equipment", and users must
               | "have the opportunity to refuse to have a cookie or
               | similar device stored on their terminal equipment."
               | 
               | Source: https://eur-
               | lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX...
               | 
               | However, the ICO has suggested that saying "I refuse to
               | allow any cookies on my computer" could be taken as
               | implied consent to allow a cookie stating such.
        
             | aden1ne wrote:
             | Functional cookies like that are explicitly allowed.
        
               | mminer237 wrote:
               | There's no exception for "functional cookies". There's an
               | exception for cookies "strictly necessary" for an
               | "explicitly requested" service. I don't see how
               | remembering you don't want cookies is strictly necessary
               | or explicitly requested. Unless you have a separate
               | optional check for "remember my decision" I would argue
               | that not asking every session would be a violation of the
               | ePrivacy law.
        
             | asddubs wrote:
             | prompts are not necessary for functional cookies
        
             | Raicuparta wrote:
             | Browsers provide multiple ways to store data like that
             | locally, you don't need cookies. And even if you did, you
             | wouldn't need consent to store that preference.
        
         | louthy wrote:
         | Install the consent-o-matic extension. It fills out the forms
         | automatically. It doesn't catch everything, but is mostly
         | pretty good...
         | 
         | Chrome: https://chrome.google.com/webstore/detail/consent-o-
         | matic/md...
         | 
         | Firefox: https://addons.mozilla.org/en-
         | US/firefox/addon/consent-o-mat...
         | 
         | The thing that really grinds my gears is the phrase "We care
         | about your privacy". Bullshit! If you cared you wouldn't even
         | need to ask for consent!
        
           | bombolo wrote:
           | doesn't work in most cases
        
         | c7DJTLrn wrote:
         | I'm beyond Cookie Rage. I'm into Cookie Despair, maybe even
         | Cookie Depression.
        
           | frereubu wrote:
           | You're almost there. The five stages of cookie despair:
           | Denial, Anger, Bargaining, Depression, Acceptance.
           | 
           | (https://en.wikipedia.org/wiki/Five_stages_of_grief in case
           | the reference is too niche)
        
             | c7DJTLrn wrote:
             | To reach Cookie Acceptance I might need a Cookie Therapist.
             | 
             | (sorry, I'm in a silly mood)
        
         | exrook wrote:
         | Try adding the EasyList Cookie List[0] to your adblocker to
         | block them all.
         | 
         | It's present in the uBlock Origin filter list settings under
         | Annoyances but not enabled by default. HN readers may also find
         | some of the other default disabled filter lists interesting
         | such as the AdGuard URL Tracking Protection list which strips
         | tracking parameters from URLs.
         | 
         | [0] https://easylist.to/#easylist-cookie-list
        
         | suralind wrote:
         | there's a chrome extension which I think is called "I don't
         | care about cookies" :)
        
           | Quarrel wrote:
           | Which was bought by Avast, so lots of people switched to the
           | forked open version [1] (thank you GPL).
           | 
           | [1] https://github.com/OhMyGuus/I-Still-Dont-Care-About-
           | Cookies
        
       | stickfigure wrote:
       | I want my browser to send a header:                   X-I-Dont-
       | Give-A-Fuck-About-Cookies: true
       | 
       | ...and let the world wide web stop torturing me. I have a nice
       | button that clears cookies and websites can't do anything about
       | it. This whole dance is stupid.
        
         | rwalle wrote:
         | ...which will make it easier to websites to identify and track
         | you.
        
       | ximm wrote:
       | > Certain regulations, like the GDPR, the General Data Protection
       | Regulation, by the European Union, require that sites get consent
       | for placing cookies and data on user devices.
       | 
       | Well, that is bullshit. GDPR requires that you have some form of
       | legal basis for storing cookies. Consent is the last ditch effort
       | if you were not able to find any other justification. So by
       | nearly by definition, denying that consent is in the user's
       | interest.
       | 
       | I think there is some other EU regulation that requires cookie
       | banners. But don't blame it on the GDPR!
        
         | ragebol wrote:
         | The cookie dialog must be there in case you want to do cracking
         | cookies. If you don't place the tracking cookies, no need for a
         | dialog IIRC.
         | 
         | But most sites didn't get the hint of "just don't track" and
         | still want to track you.
        
         | progval wrote:
         | > GDPR requires that you have some form of legal basis for
         | storing cookies.
         | 
         | Not even that. It requires a legal basis for storing and
         | processing personal data.
        
       | musicale wrote:
       | Great, now I just want a preference for                   [X] NO,
       | I do not want to subscribe to your newsletter
        
       | basisword wrote:
       | The irony that I have to click through one of the ultra-shitty
       | agree/learn more cookie popups just to read this article. Maybe
       | if GHacks didn't comply with the legislation in such a user
       | hostile manner, browser developers wouldn't have to waste time on
       | such features.
        
         | jokethrowaway wrote:
         | nope, any cookie banner is pure cancer
         | 
         | I don't even care about all the dark patterns of now allowing
         | you to dismiss and ignore with one click.
         | 
         | Thank you Europe
        
           | solarkraft wrote:
           | > nope, any cookie banner is pure cancer
           | 
           | I agree, sites shouldn't be doing the things that require
           | showing one.
           | 
           | > I don't even care about all the dark patterns of now
           | allowing you to dismiss and ignore with one click.
           | 
           | How is this a dark pattern?
           | 
           | > Thank you Europe
           | 
           | Indeed! If such tracking has to be allowed, I'm happy that at
           | least I can opt out of it.
        
         | seppel wrote:
         | > Maybe if GHacks didn't comply with the legislation in such a
         | user hostile manner, browser developers wouldn't have to waste
         | time on such features.
         | 
         | You need the same feature for visiting EU government websites:
         | 
         | https://www.consilium.europa.eu/ (best example)
         | 
         | https://commission.europa.eu/
         | 
         | https://european-union.europa.eu/
        
           | tobr wrote:
           | These just require a single click to reject, unlike the one
           | on ghacks.net.
        
           | Deukhoofd wrote:
           | There's a major difference between a two button UI with a
           | clear "I refuse cookies" screen, and a screen where you first
           | need to click "Learn More", then manually toggle 5 toggles
           | about what you don't want to allow, then click the greyed out
           | "View our partners" button, then block all of those. The
           | second one is definitely extremely user hostile.
        
         | skywal_l wrote:
         | As it happens, GHacks cookie popup is defeated by NoScript. You
         | might give it a try.
        
           | rickstanley wrote:
           | Not OP. I've been using NoScript until today, works as
           | expected of course, but the hassle to have to enable specific
           | scripts to make a useful website work outweighs its
           | usefulness _for me_.
           | 
           | There's "NoJS", a extension where you can enable all JS
           | through a switch, but it doesn't handle iframes very well at
           | the moment.
        
             | dp-hackernews wrote:
             | Use uMatrix by uBlockOrigin author - now deprecated, but
             | still useful
        
         | JohnMakin wrote:
         | Came here to post this. This is a pretty malicious pattern.
        
           | aziaziazi wrote:
           | And there is even worse : sometimes the "partner" list does
           | not have a reject all AND each partner requires a two click
           | steps - waiting for an animation in between.
           | 
           | Edit: remove double post of link
        
         | [deleted]
        
         | swapfile wrote:
         | [dead]
        
         | BlueTemplar wrote:
         | These days, this just makes me immediately click Reader Mode.
        
         | marcosdumay wrote:
         | An outright dishonest cookie prompt, where "reject" or "manage
         | choices" aren't even shown on the first screen.
         | 
         | I imagine the company behind this site is hosted at the US.
         | There are not many places one can still do this.
        
           | sva_ wrote:
           | Most of the big German news sites require you to either
           | accept ads, or pay for a subscription.
           | 
           | It is sadly perfectly legal afaik. Nobody is entitled to your
           | content without agreeing to some terms. Luckily, archive.is
           | works very well. Wish there were more alternatives.
        
             | math_dandy wrote:
             | How do they make you accept ads? Do they sniff ad blockers
             | or something? And is this "ads or pay" dichotomy related to
             | cookie modals?
        
             | solarkraft wrote:
             | I also read that it's legal, but can't see how it's in the
             | spirit of the law.
        
             | marcosdumay wrote:
             | The site doesn't require that you accept the ads. It just
             | uses dark patterns to make you accept tracking.
        
         | lbotos wrote:
         | Aside: I can't remember what site I was on recently, but I saw
         | the craziest cookie prompt. The options were:
         | 
         | Basic / Premium / Ultra
         | 
         | With you guessed it, Ultra being the most tracking cookies. I
         | was flabbergasted.
        
           | tux3 wrote:
           | They should make Ultra have a limited time countdown, to
           | stress people into FOMOclicking.
           | 
           | But of course, for maximum trap potential, we need to find a
           | wording such that Premium is the option without, while Ultra
           | tracking and Basic tracking should both do roughly the same
           | amount of tracking (modulo not really relevant details). With
           | a sufficiently discouraging wall of text, a bad UX, and a
           | limited time option, no one would spend the time to figure
           | out they need to click the middle option.
           | 
           | (This tweet brought to you by our sponsor, Moloch.)
        
           | thedailymail wrote:
           | Congratulations on being selected to enjoy the Diamond Elite
           | Tier sponsor engagement experience!
        
           | solarkraft wrote:
           | Ultimate tracking experience
        
         | subarctic wrote:
         | Honestly for the first 10 seconds after I clicked the link, I
         | thought the banner must be a joke because the irony is just too
         | perfect
        
         | bombolo wrote:
         | It's actually illegal, reject should be as fast as accept.
        
       ___________________________________________________________________
       (page generated 2023-04-18 23:00 UTC)