Cookie popups are yet another example of malicious complience by an industry that wants to use and abuse data about us all.
@OatPotato @borup To this day, many websites still don't ask for consent. Cookie banners are just cookies wall with only OK/Accept button
At best there's a hidden Refuse grey link/submenu, which is illegal, as refusing should by as easy as accepting.
While still
- place tracking cookies at 1st load before the banner is even loaded 🤡
- continue to use tracking after users have refused
- such banner often ignore non-cookie based trackers (hidden pixel, AT Internet/piano/google tracking scripts…)
Some even have a shitton of individually actionable on/off switches¹ for like 10 or more processing purposes + several hundreds of switches for "parteners", with no "Refuse all" button, and a big green "Accept all"…
The ones using IAB TCF form are the worst offenders…
1. Or they seem turned off but each and every PII processing purpose switch is doubled with a hidden and/or greyed out "legimate interest" although many purposes have nothing to do with "Legitimate interest".
@devnull @borup for the "shitton of individual switches", some countries have made this illegal: the law says you MUST show a button to refuse everything on one click. But not all companies are doing it still.
And yes, the "legitimate interest" is the worst thing EU could let open, the line between legitimate and not really legitimate can be very flexible…
@jrosell Assuming it's an ecommerce website that supports guest checkout… Which many websites are not
Also, most ecommerce websites force users to create accounts by NOT allowing guest checkout and by misusing email addresses for unsolicited "news" letters…
For many websites, it's actually just login/session cookies…
Either way, all these cookie types are clearly distinct from tracking cookies… Not using tracking cookies by default and w/o consent is NOT hard…
Except no one talked about "asking for permission for functional cookies such as login, guest checkout, shoping carts"
From the very beginning, it was all about enabling TRACKING cookies AND non-cookie-based tracking (script trackers, hidden pixels…) by default, without consent…
@jrosell No, data processing which is (actually!) necessary to accomplish what users asked for (perfomance of a contract) is a valid legal basis distinct from consent.
You're supposed to inform users about each data processing purpose (including all cookies) in a legible page. And not in a an intrusive annoying cookie banner with broad BS such as "to enhance user experience", forcing users to click "I accept" just to get rid of the banner (that's a dark pattern)
@devnull @ShadSterling @OatPotato @borup cart using session cookie (no constent asked) vs cart persist weeks (personalization cookie that requires consent). Isn't it?
The user should be able to click accept, refuse and define settings for each purpose... Not only "I accept."
@jrosell I'm not sure whether a persistent cart cookie would be actually considered as personalization or functional. But it wouldn't survive cookie cleaning (especially automatic cleaning)
I'd rather have
- session only cart cookies
- no stupid automatic "empty cart after x minutes“
- the ability to export/import cart
Yes it requires a few extra clicks for export/import but it survives cookies cleaning and can be used from another browser/profile/computer.
@ShadSterling Cart export is just plaintext (such as CSV) with unique identifiers (SKU, part number, EAN, ISBN… depending RL what you're selling) and human readable names for controlling file content even offline/before uploading…
I fail to see how it would enable you to "get free stuff" since the price is calculated by the website based on the current price at order time
As for the decompression bomb… If you just accept random files with no input control […]
1/2
@ShadSterling […] then it's your problem… By that "logic", "import/upload" should not exist on any site at all…
"Sorry, you can't upload your own avatar picture, it would enable decompression bomb. Just use our built-in pics. Nope sorry, this photo hosting site doesn't enable you to upload your photos, decompression bomb! Generate ones with our AI! Nope, you can't upload your own files on our file sharing plateform. AI rewrite it for you or else decompression bomb!"
@ShadSterling Forcing someone to create an account because they need to buy a single stuff once from a specific shop¹, is annoying as f… (often using accounts creation as an excuse to keep PI forever and misusing it…)
1. Either because they don't find it elsewhere or because it's much more expensive/only available there & on "marketplaces" => Random people buying stuff en masse to empty stocks, then reselling it 1,5-3× it's price without being able to handle warranty