Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful. We need YOUR help to #KillTheCookieBanner!

you are viewing a single comment's thread
view the rest of the comments
[–] 13 points 1 day ago (13 children)

For the past 10 years or so tracking is done with hardware fingerprinting anyways. Cookies are of the past.

  • source
  • hideshow 13 child comments
  • [–] 4 points 19 hours ago* (2 children)

    Genuinely curious, why can't browsers add some (non meaningful to users) jitter to values used in fingerprints such that fingerprints become random for a single user?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 6 points 19 hours ago (1 child)

    They totally can. They just don't really care, because they are mostly funded by advertisers.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 15 hours ago

    And technically since very few people do such things, they are usually fairly obviously not the real details and the faked details end up being unique enough to just dump you into the "hates advertising" ad bucket which just means they try (and often succeed) at marketing to you through other means.

  • source
  • parent
  • [–] 10 points 23 hours ago (4 children)

    I understand the argument, but afaik the laws that made poeple create cookie banners do not really care whether it's a cookie or some other identification. Consent has to be granted for any sort of tracking.

    However, as far as I understand, at least in some parts of the world, this is only true for 3rd party tracking solutions. So long as people can't be identified and everything stays with your own host, consent would legally be unnecessary anyway.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 20 points 23 hours ago* (last edited 23 hours ago)

    More accurately, there has never been a EU law that forced people to create cookie banners.

    The EU law required websites to have the users' consent to use personal data and tracking. The law never even mentioned the word "banner" but this is what the industry chose as a solution.

    Furthermore consent is not needed for functional cookies. So all websites that enforce cookie banners upon users do really use tracking/data sharing or their partners (such as Google Analytics) do.

  • source
  • parent
  • [–] 2 points 22 hours ago (2 children)

    I am not against cookie banners, I own a few web apps and each of them have proper configurable cookie settings (including the banner).

    All I am saying is that most companies (especially one's that do not reside in EU) do not care and will track you across websites by fingerprinting your hardware when visiting their website. Some do not even use cookies at all.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 19 hours ago* (1 child)

    I own a few web apps and each of them have proper configurable cookie settings (including the banner).

    Configurable cookie settings are not "proper." Unconfigurable eschewing of not-strictly-functional cookies is "proper."

    Don't delude yourself into thinking your goddamned malicious compliance is "proper!"

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 19 hours ago* (1 child)

    Laws don't care about technical 'gotchas'. If the law says tracking is illegal, it's illegal whether it relies on cookies, fingerprinting, magic pixie dust, or literally any other applied phlebotinum you could possibly think of. It simply does not matter what the means are if the intent is to track.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 3 hours ago

    That's not how the industry works.

    Also, here, fixed your statement for you: Privacy laws generally don't let you evade a restriction simply by changing the technical mechanism used to achieve the same tracking or identification. Whether something is a cookie, fingerprint, local-storage identifier, or another technique is often less important than what the technique does and what legal rule applies to that activity. However, the mechanism can still matter because different laws and provisions regulate different technical activities, and lawful tracking is not necessarily prohibited merely because its purpose is to track.

  • source
  • parent
  • [–] -3 points 20 hours ago (2 children)

    Hardware fingerprinting doesn't work very well when the hash changes significantly when your battery charge changes one percent.

  • source
  • parent
  • hideshow 2 child comments