Rejecting Cookies

cross-posted from: https://piefed.world/c/shit/p/1135788/rejecting-cookies

392 points · 68 comments · view on lemmy.world

68 Comments

unmagical@lemmy.ml · 73 pts · 94d (1 reply)

We and our 19,324 legitimate business partners use cookies to offer you the best experience possible!

ultrafastsloth@lemmy.world · 1 pts · 92d

Now, to disable all cookies, you have to click all 19,324 toggles

ollie@pawb.social · 45 pts · 94d (5 replies)

consent-o-matic my goat

fonix232@fedia.io · 19 pts · 94d (4 replies)

I just wish it was a native feature of browsers instead of something that is part of the page. Like, all the other permissions - camera, microphone, Bluetooth, USB, etc access - are native, why can't be the "hey let me write some crap onto your device that other pages may or may not read" and "hey lemme see what I wrote onto your device when invoked from another website" requests be native too?

RustyNova@lemmy.world · 3 pts · 93d

Librewolf doesn't save cookies by default, and you can toggle them on if you need to

Axolotl_cpp@feddit.it · 1 pts · 93d (2 replies)

Because it would be harder, there are 2 types of cookies: essential ones, necessary for the site to work correctly (remember login, preferences and a bunch of other things) and there are other cookies that are not necessary, and there is no real way to add this distinction since the browser doesn't really have any way to understand which are which; Also, before anyone reply "but if i don't want to remember my login?" Some sites still write temporary cookies to work

You can also see what cookies are wrote on your device with Developer tools

fonix232@fedia.io · 2 pts · 93d (1 reply)

Adding support for two types of cookies instead of one (and having a default the browser sends to the site) isn't black magic fuckery or some unachievable alchemical process. It's done easily.

Axolotl_cpp@feddit.it · 1 pts · 93d

Yep, but would companies use them? I doubt, they want profit, they ain't using that and companies often define standards, so the only hope is to propose to the EU to enforce it or smth

axh@lemmy.world · 25 pts · 93d (5 replies)

I love the concept of "Legitimate interest"... Like, why the hell anyone even consider storing my data in ILLEGITIMATE interest?

Viking_Hippie@lemmy.dbzer0.com · 13 pts · 93d (3 replies)

Yeah, and apparently "we're legitimately interested in your data" is enough to clear that ridiculously low threshold 🤬

Geobloke@aussie.zone · 4 pts · 93d (2 replies)

I would love to know how much my data is actually worth, like to the cent and why.

axh@lemmy.world · 1 pts · 92d (1 reply)

to the cent

I don't know the answer but I feel like you value your data much higher than they do.

My guess is that they just want to squeeze every single cent out of us all, and if violating our privacy and making our experience worse can give them one additional dollar for every 1000 or 10000 users, that is a price they are willing to pay... or to be precise, that's the price they are willing to sell us for.

black0ut@pawb.social · 2 pts · 92d

Your data is worth much more than that, actually.

Proton calculates your data is worth, on average, $700/year. Granted, they have a financial interest in making that number as high as possible, because it's basically an ad for them.

I've read somewhere that data price varies a lot per demographic, with some data being worth just a few $ per year and some other data being worth way more than $1000/y. I can't find the source I read that on, so take it with a grain of salt.

Either way, it's very certainly more than a few cents per year per person.

osanna@lemmy.vg · 3 pts · 92d

I don’t even know what legitimate interest means. Are they saying they’re going to sell my data to someone if they have a legit interest in my data? Who would buy data if they DIDNT have a legit interest in it? I don’t get it

9point6@lemmy.world · 25 pts · 94d (4 replies)

Just install the Consent-o-matic extension and you get the benefit of rejecting without the faff 90% of the time

snowydroopz@lemmy.world · 2 pts · 93d (3 replies)

What browsers support it?

Az_1@piefed.zip · 11 pts · 93d (1 reply)

Not sure about chromium ones but it works on all firefox based browsers

9point6@lemmy.world · 2 pts · 93d

I think the only one you can't use it in is chrome mobile since it doesn't support extensions

Valmond@lemmy.dbzer0.com · 1 pts · 92d

Firefox does.

janakali@lemmy.4d2.org · 22 pts · 93d (8 replies)
  1. install ublock origin
  2. enable "cookie notices" filters
yakko@feddit.uk · 6 pts · 93d (7 replies)

Gasp

I'm so dumb. I didn't even know I had to enable that... God it should physically hurt to be this stupid

helpImTrappedOnline@lemmy.world · 3 pts · 93d (6 replies)

Not really, its kind of one those things; if you don't know, how could you? Unless you're the kinda person to sit there and read every option of everything.

yakko@feddit.uk · 2 pts · 93d (5 replies)

What if I want it to hurt? :3

helpImTrappedOnline@lemmy.world · 5 pts · 92d (4 replies)

Add https://* to your filter list.

yakko@feddit.uk · 3 pts · 92d (2 replies)

lmaoooooo asked and answered

helpImTrappedOnline@lemmy.world · 1 pts · 92d (1 reply)

Surprisingly, it doesn't actually block sites, it just makes them all look like they're from 1992.

http://* really blocks them.

MalMen@masto.pt · 1 pts · 92d

@helpImTrappedOnline @yakko when the internet was gud

TotallyWorthLife@lemmy.world · 1 pts · 92d

Waow

msage@programming.dev · 16 pts · 93d

I hoped it would be mentioned before, but in the EU It shall be as easy to withdraw as to give consent.

Report such sites for non-compliance.

fox2263@lemmy.world · 10 pts · 93d (1 reply)

I like the button that says reject non essential. That should be a required button.

HK65@sopuli.xyz · 13 pts · 93d

It is actually.

Enforcement is crap.

wiccan2@thelemmy.club · 10 pts · 94d (3 replies)

Or worse: pay to decline cookies

YoSoySnekBoi@kbin.earth · 7 pts · 94d

Surefire way for a site to ensure they immediately make my blocklist

prti@szmer.info · 2 pts · 93d

My old email provider added that and I still have some accounts linked to it... IMAP is now the only way I access that mailbox

gurty@lemmy.world · 2 pts · 93d

“You are our product, user”

xkbx@startrek.website · 9 pts · 94d

You need to add 500 surveillance devices at the end of the top segment, and 498 at the end of the bottom segment

pewpew@feddit.it · 8 pts · 93d

(for websites you don't use often)

  1. Open link in private tab
  2. Accept all
OriginEnergySux@lemmy.world · 7 pts · 93d

Me on the work laptop

kyub@discuss.tchncs.de · 7 pts · 93d (1 reply)

On many websites, the cookies are created no matter what you choose. It's a dark pattern to get you to accept all, yes, but In the end it's often meaningless.

Use a decent browser like librewolf which isolates cookies so only the site that created them can access them and clears all cookies on exit - this protects you from bad effects of cookies so you can just accept all. However, you're still susceptible to other methods of tracking (like IP address or browser fingerprint based tracking) unless you use Tor Browser or something similar.

osanna@lemmy.vg · 1 pts · 92d

I use a ff plugin called cookie auto delete. I white list some sites like the self hosted stuff, but for the most part, nothing is exempt.

puchaczyk@lemmy.world · 7 pts · 92d

I'm using Consent-O-Matic and it works surprisingly well.

Fmstrat@lemmy.world · 6 pts · 92d (2 replies)

I am authoring an IETF draft to help with this. The agreement formats recently got approved by IEEE.

Gonzako@lemmy.world · 3 pts · 92d (1 reply)

Oh, where can I inform myself more about your work?

Fmstrat@lemmy.world · 4 pts · 92d

The main site: https://myterms.info/

My draft, which will likely be introduced to the list this week with a BOF (meeting) request for IETF 126 in Vienna: https://datatracker.ietf.org/doc/draft-curtis-myterms/

It's focused on contractual agreements overall, but it supports machine negotiation based on headers, which is how our reference implementations handles cookie banners.

imetators@lemmy.dbzer0.com · 5 pts · 93d (1 reply)

I recently got an ad about these rail chairs for elderly to get up and down the stairs. I am inu 30s and I am proud that me clicking out all non-essential cookies doesn't bring me related ads.

Also, that ad somehow passed through ublock. Not sure how 😅

shneancy@lemmy.world · 6 pts · 93d

i used to get spam calls about back pain medication, i'm 26, no back pain yet, thankfully. but they kept calling me nonetheless

thankfully i'm european so one day i cited the law to be forgotten, and once they told me "sorry we can't :(" and i replied "well you better fix that because that's illegal :)" they hung up immediately and never called me again :D

markz@suppo.fi · 4 pts · 92d

Why would you put extra effort into telling them you want cookies? Just block everything.

While you're wasting your time on clicking shitty popups, I'm already reading the page.

FatherPeanut@pawb.social · 4 pts · 93d

Got librewolf, turned the settings a bit more strict than what comes base so cookies and site data don't even get saved. Makes me feel good, with that level of ease.

db_null@lemmy.dbzer0.com · 4 pts · 93d (1 reply)

UBlock handles them well if you enable the cookie notice list. If one slips through, I now accept all because cookies are erased as soon as I close my browser

janakali@lemmy.4d2.org · 1 pts · 93d

I just zap the banner and make a mental note not to use this website again. If it’s something essential to me, I’d probably add a custom filter - but that hasn’t been an issue so far.

JTskulk@lemmy.world · 4 pts · 93d (4 replies)
Turret3857@infosec.pub · 4 pts · 93d (1 reply)

Isnt this a feature in base Firefox? You can tell it to delete all cookies on close except for sites you add exceptions for

unexposedhazard@discuss.tchncs.de · 2 pts · 93d

By default firefox can only do this on browser close not on tab close. I never used this extension but this seems like a good upgrade to only deleting on exit.

JennaR8r@lemmy.dbzer0.com · 2 pts · 93d (1 reply)

Thank you!!

JTskulk@lemmy.world · 2 pts · 92d

<3

Kaligalis@lemmy.world · 2 pts · 92d (1 reply)

What browsers really should implement is to store all third party cookies in a jar for the specific site I am on until I navigate to another domain or close the tab. The cookies are saved and returned to the 3rd party sites embedded in the site I use. But if the same 3rd party sites are also embedded in other sites, they have to send fresh cookies.
Cookies become useless for tracking and all the legislation specifically around them can be axed.

justme@lemmy.dbzer0.com · 4 pts · 92d

That feature is called containers on Firefox

DarkCloud@lemmy.world · 2 pts · 94d

Settings > Privacy > Manage> Select unwanted cookies and remove them.

Solrac@lemmy.world · 2 pts · 92d

Just open dev tools, storage, nuke them

OwOarchist@pawb.social · 2 pts · 94d

Reject all cookies by default + noscript.

Occasional websites I use frequently that use cookies for session management get a whitelist exception.

Blackmist@feddit.uk · 2 pts · 92d

I just use the I Don't Care About Cookies addon.

I don't know if it's just agreeing or disagreeing, but I suspect they're all selling your data regardless of what you pick.

Little1Lost@gehirneimer.de · 2 pts · 93d
SkunkWorkz@lemmy.world · 1 pts · 92d

ALT+F4 also works or cmd+Q

Epzillon@lemmy.world · 1 pts · 93d (1 reply)

I just run uMatrix and AdNauseam on Zen. If a banner shows up after allowing scripts its the good ol' right click > block element.

pineapplelover@lemmy.dbzer0.com · 1 pts · 93d

I used to run umatrix, I wonder why I stopped. I think people said it was unsupported or something so I use NoScript now

diabetic_porcupine@lemmy.world · 1 pts · 93d (1 reply)

I mean do you really think they don’t use cookies when you don’t press accept anyway?

osanna@lemmy.vg · 1 pts · 92d

“Strictly necessary” my fat arse

chunes@lemmy.world · 1 pts · 92d

just hide cookie-related shit with ublock origin