Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful. We need YOUR help to #KillTheCookieBanner!

  • _MadBits@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    15
    arrow-down
    1
    ·
    2 days ago

    For the past 10 years or so tracking is done with hardware fingerprinting anyways. Cookies are of the past.

    • Skasi@lemmy.world
      link
      fedilink
      arrow-up
      13
      arrow-down
      1
      ·
      2 days ago

      I understand the argument, but afaik the laws that made poeple create cookie banners do not really care whether it’s a cookie or some other identification. Consent has to be granted for any sort of tracking.

      However, as far as I understand, at least in some parts of the world, this is only true for 3rd party tracking solutions. So long as people can’t be identified and everything stays with your own host, consent would legally be unnecessary anyway.

      • blackbeans@lemmy.zip
        link
        fedilink
        arrow-up
        20
        ·
        edit-2
        2 days ago

        More accurately, there has never been a EU law that forced people to create cookie banners.

        The EU law required websites to have the users’ consent to use personal data and tracking. The law never even mentioned the word “banner” but this is what the industry chose as a solution.

        Furthermore consent is not needed for functional cookies. So all websites that enforce cookie banners upon users do really use tracking/data sharing or their partners (such as Google Analytics) do.

      • _MadBits@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        2
        ·
        2 days ago

        I am not against cookie banners, I own a few web apps and each of them have proper configurable cookie settings (including the banner).

        All I am saying is that most companies (especially one’s that do not reside in EU) do not care and will track you across websites by fingerprinting your hardware when visiting their website. Some do not even use cookies at all.

        • grue@lemmy.world
          link
          fedilink
          arrow-up
          3
          arrow-down
          1
          ·
          1 day ago

          I own a few web apps and each of them have proper configurable cookie settings (including the banner).

          Configurable cookie settings are not “proper.” Unconfigurable eschewing of not-strictly-functional cookies is “proper.”

          Don’t delude yourself into thinking your goddamned malicious compliance is “proper!”

          • _MadBits@lemmy.dbzer0.com
            link
            fedilink
            arrow-up
            2
            ·
            17 hours ago

            My web apps lack any telemetry, the only cookies that get set are for sessions, users settings and various redux like storage on client side which can be opted out. It’s more than proper. :)

    • yes_this_time@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      1 day ago

      Genuinely curious, why can’t browsers add some (non meaningful to users) jitter to values used in fingerprints such that fingerprints become random for a single user?

        • Snot Flickerman@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 day ago

          And technically since very few people do such things, they are usually fairly obviously not the real details and the faked details end up being unique enough to just dump you into the “hates advertising” ad bucket which just means they try (and often succeed) at marketing to you through other means.

    • grue@lemmy.world
      link
      fedilink
      arrow-up
      2
      arrow-down
      1
      ·
      1 day ago

      Laws don’t care about technical ‘gotchas’. If the law says tracking is illegal, it’s illegal whether it relies on cookies, fingerprinting, magic pixie dust, or literally any other applied phlebotinum you could possibly think of. It simply does not matter what the means are if the intent is to track.

      • _MadBits@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        1
        ·
        17 hours ago

        That’s not how the industry works.

        Also, here, fixed your statement for you: Privacy laws generally don’t let you evade a restriction simply by changing the technical mechanism used to achieve the same tracking or identification. Whether something is a cookie, fingerprint, local-storage identifier, or another technique is often less important than what the technique does and what legal rule applies to that activity. However, the mechanism can still matter because different laws and provisions regulate different technical activities, and lawful tracking is not necessarily prohibited merely because its purpose is to track.

      • _MadBits@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        2
        ·
        17 hours ago

        First of all, you’re the one to choose what you’re fingerprinting for, and if you include the battery or such changing factors maybe you should rethink your career as an engineer.

      • boonhet@lemmy.zip
        link
        fedilink
        arrow-up
        6
        ·
        1 day ago

        Which hash exactly? They don’t have to include your battery percentage if they don’t want it.