Hi,

In Spain (and probably other places in Europe) we’ve recently seen a deluge of cookie banners that offer you the option to reject tracking cookies for a fee. The regular GDPR forms are therefore slightly broken, as you get several options: accept, reject (which doesn’t work in most cases), and buy a subscription to reject. Consent-O-Matic, for example, is having a hard time. I don’t doubt it’ll get corrected in time, but I want to talk about something tangential.

Cookie consent has (at least) two layers: the browser layer (where we might delete cookies, reject third party cookies, etc) and the site UI layer (where we’re presented with an option when we load the page). This means we can reject third-party cookies at the browser layer and then accept whatever form at the site UI layer.

With the set up mentioned above, is there really any difference between accepting cookies and rejecting cookies? No tracking cookie are going to get installed in my computer anyway. This, combined with an ad blocker, makes the browsing experience exactly the same whether I accept or reject the cookie form. Is there anything I’m missing here?

Night Monkey
link
fedilink
01Y

Zap the banners out of existence with unlock origin

Ublock Origin->Cookie Notices->Check all 4.

@rinze@infosec.pub
creator
link
fedilink
21Y

Yes, I’m aware those filters exist, but I’m asking about the practical implications of the set up I mentioned in the post.

It is an excellent question, but there is a third option, which is also blocking at the DNS level. Firefox and Safari block 3rd party cookies by default too.

In your example I do not think there is a difference, and my firewall logs seem to confirm this.

When I see this, the only viable option I see is to close the site and boycott it. Any other choice would encourage more companies to do this blackmail.

Agility0971
link
fedilink
11Y

In duckduckgo search results there is a link to block this domain. I always block shitty domains that farm clicks

@rinze@infosec.pub
creator
link
fedilink
1
edit-2
1Y

Where’s that? I just ran a test search but I can’t see it :-?

Agility0971
link
fedilink
21Y

Hmm… I cannot see it anymore either. They appeared under each search entry as hyperlink.

While I agree, and I use TOR or Orbot for everything( which means quite a few things are blocked for me), this doesn’t answer OP’s question.

Engywuck
link
fedilink
7
edit-2
1Y

Interesting question. IMHO you’re right: if you reject 3rd party cookies at browser level, so “accepting” them from the GDPR form shouldn’t really matter. Plus, many browsers nowadays forbid 3rd party websites to access cookies from other websites (in my understanding)…

I’d like someone with a more deep knowledge to contribute to the discussion.

Atemu
link
fedilink
2
edit-2
1Y

Cookie banners are not really about cookies.

What they’re actually asking for is consent to process your data for profit in unethical ways. That usually involves cookies but could theoretically be done entirely without. They’re just a technological standard.

You might aswell say: “We use https. [consent] [settings]”

deleted by creator

I recommend you look into web fingerprinting. IP and login data are no longer the only data required to pin point you on the web.

@beta_tester@lemmy.ml
link
fedilink
0
edit-2
1Y

deleted by creator

How do you know they don’t use “advanced techniques”? I think you gravely overestimate the complexity of adding them to a website.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 3.13K Posts
  • 78.3K Comments
  • Modlog