Kill The Cookie Banner

(killthecookiebanner.eu)

367 points | by rapnie 6 hours ago

42 comments

  • chrismorgan 2 hours ago
    The other approach to killing the cookie banner is simply to declare that such a thing cannot constitute “informed consent”. (Perhaps: “ticking a checkbox and/or clicking a button cannot constitute informed consent”; and see what they try next.) From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way. Just as shrink-wrap licenses and even simple contracts have at times in some jurisdictions essentially been neutered, so that only terms that a reasonable person would expect to be there are enforceable, at which point it becomes obvious that the whole thing needs tearing down in favour of standard licenses/contracts. In the Australian state Victoria, for example, there are standard rent and property sale contracts; for renting you must use that contract <https://www.consumer.vic.gov.au/housing/renting/starting-and...>, and I got the impression that residential sales practically always use the standard contract.

    But of course it’s impossible to convince someone of something when their livelihood depends on their not understanding it.

    • ethin 1 minute ago
      IMO any contract, waver, etc., shouldn't be legally enforceable unless the signatory has actually read it. It's always seemed to me to be one hell of a pathway of abuse (in a way) to just be able to bind someone to be legally required to do anything you want, for example, by just relying on them not reading the thing they signed.
    • kleiba2 55 minutes ago
      > it’s well-understood that very few people actually read those things, they just want to get them out of the way.

      This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data mining, profiling, and other privacy-related aspects. But in many cases, you could just click "reject" and the banner would also disappear...

      To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.

      • readread 46 minutes ago
        "Accept all" always makes it go away immediately.

        Some variant on "reject" takes more effort like 70% of the time. Which is on purpose, of course. The ones that aren't maliciously-complying have a "necessary only" button that insta-closes it, but tons pretend that you might want to allow some spying but not all of it and make you go through another screen if you don't just "accept all".

        > To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.

        Then it'd be possible to default it to "nope" (Firefox, and perhaps Safari, might do this) or to allow a "never, anywhere" setting the first time the question is asked, and malware and spyware vendors know that'd mean a much larger proportion of denials.

        • jackson1442 16 minutes ago
          "necessary only" also tends to have a malicious compliance aspect where they don't store a cookie recording your preference and show the banner on every single page until you click accept.
      • fnord123 4 minutes ago
        > To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.

        There is one. It's a DNT header. Knucklehead websites ignore it.

      • ablob 36 minutes ago
        It's a nag-box that appears every time someone visits a new website. Of course people are going to click it away as fast as possible. In the few cases you repeatedly visit a website one might want to reconsider, but by then it's out of mind due to not being shown after giving consent.

        It is known that warnings and pop-ups that show up almost all the time yield diminishing returns. I think it was named "normalization of deviation" by some folks in a blog a while ago, and I believe that name fits. If you get warned about missing https all the time, or that something might be dangerous (even though it does precisely what you want it to do), it will loose its effect by the time you actually need it.

        You can argue this is malicious compliance, but if you want it to go away it would probably be easier to go for banning tracking and personalized ads altogether. Eliminate the reason for this behavior, so to speak.

      • nickff 36 minutes ago
        I believe myself to be fairly well-informed, and usually accept the cookies, because I don’t foresee any potential harms, and it helps the people running the website. I am worried about many things like phishing and hacking/data leaks, but the valuable data isn’t cookie-related.

        What harm are you worried about?

        • layer8 4 minutes ago
          Tracking usually happens across websites, meaning the information is shared with third parties outside the people running the website where you accepted the cookies. Knowing your interests, behavior and preferences makes you prone to manipulation. The selection of information shown to you will be crafted such as it maximizes engagement. For example, showing you information that upsets you, in order to get you to react. Or just information with a slant or spin to influence your opinion. Nobody is immune to being affected by the distribution of what they are being shown.
        • fsflover 27 minutes ago
          These popups aren't about cookies but really about spying. It seems you have nothing to hide. I understand: I also don't. However, the problem with spying is not about individual secrets but about the society and democracy.

          Lack of privacy harms journalism and activism, making the government too powerful and not accountable. If only activists and journalists will try to have the privacy, it will be much easier to target them. Everyone should have privacy to protect them. It’s sort of like freedom of speech is necessary not just for journalists, but for everyone, even if you have nothing to say.

      • ryukafalz 45 minutes ago
        > But in many cases, you could just click "reject" and the banner would also disappear...

        Oftentimes the reject flow is substantially more annoying than the accept flow. I click reject myself when it's an option, but I can absolutely understand how people might get conditioned to click accept when clicking reject might result in more popups.

      • dv_dt 23 minutes ago
        if ever there were a need for a small local ai plugin...
      • unclebucknasty 45 minutes ago
        >This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept"

        There's a mismatch between the velocity at which people visit sites and the time it takes to navigate the cookie particulars of each site.

        And, we can dismiss this as people being uninformed or lazy but the reality it is that's actually not so unreasonable. Cookies are in some ways near the bottom of the list where privacy is concerned, given everything else from breaches to search dossiers to device finger-printing to mobile device location-tracking to the ubiquity of cameras in the real world, and on and on.

        The idea that we're clawing back privacy in any meaningful sense by blocking a few cookies here and there is kind of quaint.

    • basch 1 hour ago
      Cookie control always should have been a browser control. The legal route always should have been to force it to be built into browsers that provide sane defaults, and make it illegal to circumvent what the browser declares as far as fingerprinting etc.

      any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.

      • MassiveQuasar 35 minutes ago
      • nickff 35 minutes ago
        If people really cared, they’d choose browsers that have better control, but that’s obviously not a priority for them. Why do you think this sort of thing should be regulated to suit your preferences when most people don’t seem to agree with you?
        • preg_match 2 minutes ago
          Because everyone agrees - cookies banners are annoying and need to go away. Everyone is on the same page about this. The easiest way to make that happen is "move them into the browser".

          How often do you get prompted for, say, secure DNS or HTTP? Almost never, because your browser has sane defaults and controls that. So, there you go.

        • ablob 28 minutes ago
          I think that's a stretch. People can care, but be unwilling to spend the time researching it or accept the trade offs that come with small browsers (which are often unsupported for applications you might want to use). There are many things someone might care about and at some point you have to prioritize. This topic in particular is practically a cold war where you always have to catch up on how things are, lest you loose it all. The required effort is disproportionate to the result.

          P.S.: No true Scotsman spotted

        • ClumsyPilot 11 minutes ago
          > If people really cared, they’d choose browsers that have better control

          If people really cared, they’d chose reputable suppliers that sell non toxic food. If they are eating food with lead, they don’t care.

          Don’t force your wordview on people through regulation

    • otterley 1 hour ago
      > From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way

      There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened.

      There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.

      • znnajdla 1 hour ago
        > “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement

        Only engineers have trouble understanding this. It can be a reasonable defense, and it has successfully been used in courts of law many times. The law is not a machine that compiles text like code literally. Imagine someone who coerces a dying or sick person to sign an agreement they couldn’t possibly be in a reasonable state of mind to understand what they were doing -- the law can and does invalidate such “contracts”. That is the same principle behind age of consent laws. The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.

        • otterley 1 hour ago
          I am an attorney, and am aware of certain exceptions. But these are exceptions and not the general rule, which is what I am speaking of.

          > The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.

          I haven’t heard of a single case where an agreement was voided because “no one could reasonably be expected to understand it.” Unless the language was so impenetrable or vague that the agreement itself could not be discerned. Lawyers tend not to write such agreements.

          • IsTom 1 hour ago
            EULAs are restricted in power in EU and at least to me these cookie banners are similar in spirit.
          • tempestn 1 hour ago
            "I didn't read it," sure. But, "A reasonable person would not read it?"
            • ChadNauseam 54 minutes ago
              Why would a reasonable person not read it?

              I just visited theguardian.com to see their cookie banner. The banner says this:

              > Your Privacy (`x` button to close the tab)

              > US residents have certain rights with regard to the sale or sharing of personal information to third parties.

              > Guardian News and Media and our partners use information collected through cookies or in other forms to improve experience on our site and pages, analyze how it is used and show personalized advertising.

              > You can opt out of the sale of all of your personal information by pressing

              > <button>Do not sell or share my personal information</button>

              It's 3 sentences, plus a button that says "Do not sell or share my personal information". I actually don't even think this is GDPR compliant, because my layman's understanding says that GDPR consent must be presented as opt-in, rather than opt-out. (I guess they are going for CCPA/CPRA compliance?) But anyway, I would think that a reasonable person could be expected to notice a button that says "Do not sell or share my personal information" and then click it, especially when it's portrayed prominently at the bottom of the page.

              • troupo 43 minutes ago
                This is indeed a rather good implementation of ehat GDPR requires: clear unambiguous language, an opt-out available immediately.

                This is the definition of informed consent

          • tacitusarc 1 hour ago
            But it is complicated, no? Even if you click you agree, if the you thought you were agreeing to one thing but actually agreed to another because they buried the lede, “I didn’t read it” is a reasonable defense.
            • SiempreViernes 35 minutes ago
              Why would you claim the false "I didn't read it" ahead of the true "I read it but understood it differently"? The latter allows for adding the fault shifting claim "because the other party wrote it deceptively", while "intentionally didn't read" makes it much harder to blame the other guy.
            • otterley 47 minutes ago
              It just won’t fly in court. Full stop. There are perhaps other defenses to be raised, like unconscionable terms, but not that one.
      • victorbjorklund 1 hour ago
        It can and has been in many cases in many legal systems. For example, let’s say you walk into my store to buy a dish washer. I say ”here is an extended warranty that I will give you. Just sign” you sign it instead of reading 15 pages of boilerplate. In the end of the document it says you now owe me 10 billion dollars. Doubt I will be able to enforce it in most legal systems.
        • otterley 1 hour ago
          That’s not an “I didn’t read it” defense. That’s a “term is this contract is unconscionable” defense. They’re not the same thing. I was speaking strictly of the former.

          Also, striking an unconscionable term typically does not void the whole contract. Just the term in question.

          • bryanrasmussen 55 minutes ago
            As a general rule I believe many online terms of use, eulas and similar online contracts are examples of procedural unconscionability, in that length is often too long that one can be expected to read it in the day to day action of "surfing the web", I believe this is also the opinion of the EU and many of its member states, hence the limitations found on enforcement of such contracts.

            Aside from that many of these contract have terms that might be considered substantive unconscionability - for example if terms state that what you post can be used by the company that owns the service for marketing of the company or the service I feel this would not make it through most legal systems that I feel before the attempt are not inherently corrupt.

            • otterley 52 minutes ago
              I would personally be shocked if the EU voids click-wrap agreements for unconscionableness based on the process alone. I’m not super familiar with EU law; is that what it truly says? I rather doubt it because I do business in the EU and have been asked to agree to terms as a condition of making purchases online there.
        • nekusar 53 minutes ago
          This is bullshit.

          https://www.nbcnews.com/news/us-news/disney-says-man-cant-su...

          "Disney is trying to have a widower's wrongful death lawsuit dismissed and sent to arbitration because the man had signed up for a Disney+ account several years ago."

          Now what happened was that Disney quit fighting over really bad PR. But the court challenge would have liteky succeeded.

          • Paracompact 41 minutes ago
            What's bullshit? You mean to say the dishwasher buyer would legally be on the hook for billions?
      • c0_0p_ 1 hour ago
        That argument has actually worked in some cases, especially when you need to click away to actually access the document. I assume it's why we see more and more examples where you need to scroll the full body of text in order to "agree".
      • bluGill 1 hour ago
        Of you need a nonstandard contract then you need to provide proof that it was understood. These are not provided in a context where I would expect anyone reading it to have a lawyer to advise so they obviously don't understand it
        • otterley 1 hour ago
          By that same logic, do you believe ignorance of the law is a valid defense to a criminal charge? Laws are also written by lawyers.
      • Avicebron 1 hour ago
        > There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.

        The value is derived from the people consuming the product. Placing the "incentive to produce value" above the people who presumably are the source of this value seems...misaligned.

        • otterley 1 hour ago
          If there’s no product or service to be consumed, there’s no value produced either. That’s the point: it’s harmful to eliminate the incentive to produce.
          • Avicebron 1 hour ago
            People will _always_ need things. There are very few things that will eliminate people's need for things and producers will of course adapt to the environment.

            What we need is an environment that does not give the producers asymmetric power over consumers and the products will naturally align with that.

          • inigyou 1 hour ago
            What if only the incentive to produce bad things is eliminated
            • monkpit 1 hour ago
              * definition of bad is subjective and may vary depending upon which lobby group has the most cash to throw around
              • inigyou 1 hour ago
                no, I referred to actual bad things
                • otterley 1 hour ago
                  The point is still correct. People often disagree on what is good and what is bad. It’s a judgement, not an indisputable fact.
                  • inigyou 9 minutes ago
                    so why do anything if it's impossible to tell what's good and what's bad?
                    • otterley 4 minutes ago
                      See my sibling comment.
                  • readread 40 minutes ago
                    Oh good, nothing's possible then, we should give up on regulating bad things because hitmen think murder isn't bad when they do it.
                    • otterley 35 minutes ago
                      How did you arrive at that conclusion? Laws are the result of debate between sides and the prevailing opinion. The fact that laws aren’t identical in every jurisdiction worldwide reflects that there isn’t universal agreement on every question.

                      Also, sarcasm isn’t welcome here. Please read the HN guidelines.

                      • readread 30 minutes ago
                        > Also, sarcasm isn’t welcome here. Please read the HN guidelines.

                        Ah yes, I didn't couch my post in any of the various, rampant HN-friendly versions of shitposting. I'll try to follow your example from here on out. Excellent touch citing the guidelines at me after your role in this thread, A+.

                        Re-reads this thread, taking notes

      • deaton 1 hour ago
        But "its specifically engineered to ensure that nobody reads it" is a real argument
        • otterley 1 hour ago
          Where has this ever been adjudicated?
    • ymolodtsov 1 hour ago
      Websites need cookies. I don't get why I have to suffer through this for a few puritans who literally lose nothing in the process of this transaction but act as if Stasi is watching them.
      • estebarb 1 hour ago
        Session cookies do not require a banner.
        • tempestn 1 hour ago
          Aggregated analytics do, and you can't run a serious website without some kind of analytics. Preference-storing does as well, despite any reasonable user expecting that, if they set a preference, it will be saved.
          • tappio 33 minutes ago
            There are many analytics solutions that dont require cookies. You can do aggregated analytics just fine without. Saving preferences does not require consent either.
            • tempestn 24 minutes ago
              My understanding is that any front-end analytics solution will require consent. You're right about explicitly set preferences. I was mixing that up with inferred preferences.
  • Phemist 2 hours ago
    > Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.

    So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...

    • mike_hock 2 hours ago
      Don't fall for the "we are just stupid" propaganda, which is used constantly by governments acting in bad faith.

      Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.

      This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.

      • Jtarii 14 minutes ago
        Is there any reason to believe that the current laws being passed by the UK, EU are against the will of the people? Everything I have seen makes the "anti-porn" laws or whatever seem extremely popular.
      • inigyou 1 hour ago
        I think it's because every single website breaks if you don't allow cookies at the browser level. Some knowledge of what the specific cookie does was necessary.
      • aspbee555 2 hours ago
        changing IP is not really enough for privacy, there is many ways to fingerprint your machine/browser and uniquely identify you across networks

        https://creepjs.org/checker

    • echelon 2 hours ago
      >>>>>>> now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...

      THIS

      Holy shit. This is such an obvious fix. And it shuts up those surveillance state goons immediately.

      My God, why have we tried to summon up the ghost of 1984 when such a simple fix as this will do.

      Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.

      The blast radius is zero.

      Good God, we need to fast track this into browsers right now. If we hurry we might be able to point to this as the technical fix.

      Once some of the infrastructure exists, OS vendors can hook into it.

      Firefox devs - please do this right now. Please spearhead this.

      I might have to vibe code an advocacy site for the spec and set up a GitHub / RFC process.

      • tangotaylor 35 minutes ago
        > Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.

        CA tried this with AB 1856. I wasn't a fan of this (neither was EFF) because of the privacy and tracking concerns of blasting the fact that the user is a child to all websites.

        https://www.eff.org/deeplinks/2026/05/one-step-forward-two-s...

        It would better for the block to happen at the device level. That is, the browser knows it's on a child's device and has a whitelist of allowed sites.

        There is already an RTA (Restriced to Adults) header where the website self-labels that it's for adults only and the browser can block it while protecting the user's privacy. I'd prefer expanding the use of RTA.

      • alexandre_m 46 minutes ago
        That works well for controlled devices like phones, tablets, and TVs, but it’s much harder on desktops unless you expect parents to become IT administrators.
        • Paracompact 28 minutes ago
          What's wrong with asking the user on account creation and OS install?
      • dijit 1 hour ago
        I agree, and I agree with the enthusiasm on which you bring in.

        I've long since considered that the efforts for online child safety should be pointed at educating parents and spearheading some kind of certification of compliance for child safety of software and websites.

        [this product is certified to adhere to EU:CSA]

        Then you can block everything not certified, and the software that does the blocking would also be certified, the two major prongs you need (endpoints and sites working together: else they're blocked). The rest of the money goes to education for parents about this fact, and the dangers of not doing it, and how to do it.

        This is super "easy" (when comparing to the effort it would take for putting backdoors in everything).

        Which is why I think that the reason is definitely not child safety, and more about crime control.

        Me talking about UK blocking people unless they ID themselves in 2013: https://news.ycombinator.com/item?id=6979295

        Me talking about how its disingenuous because we have superior technical solutions to this particular issue last year: https://news.ycombinator.com/item?id=45010902

      • inigyou 1 hour ago
        California AB1043, in other words
      • spiderfarmer 2 hours ago
        Make a website about that. I’ll spread it.
    • tgv 2 hours ago
      The problem there is that parent's won't know how to do it, or won't care. Many can hardly operate the most user-friendly phone, let alone manage accounts.

      The online safety acts and its EU counterparts are somewhat risky, but nobody wants the mention the only proper alternative: a total ban on "social media." Not just for kids, but for everyone. Or a ban on smart phones, that would work too, at least short term. But: money.

      • alt227 2 hours ago
        > The problem there is that parent's won't know how to do it, or won't care.

        This is unfortunately the reality.

        The other day a friend asked me to help her make her phone safer for her kids to use. I started by asking if she set permissions on the apps she downloaded. She looked at me blankly, "What permissions?". I proceeded to show her how you can granularly control what you allow each app to do on your phone and what access it is allowed. Her head blew up, she had no idea any of this existed and after gong through a few menus, she didn't care any more. It was all too complicated and too much to think about for a busy mum.

        This is why governments unfortunately are having to try to protect people from themselves. As tech competent people it all seems so simple to us, but we need to remember the majority of the population just click 'Allow All' and blow past all permission and security questions as they have no idea what any of it means.

        • dijit 2 hours ago
          "is this device for you, or a child" is one of the first options when setting up an iphone.

          I haven't set up an Android in a while, but, I doubt it's massively different.

          • alt227 2 hours ago
            Yeah but most parents devices are for them, they just let their kid use it too.
            • dijit 1 hour ago
              Ah, I guess it's impossible to have a quick enable kids mode then.

              We should just give up and give random individuals access to everyone's camera roll.. no other way.

              • dwedge 12 minutes ago
                Is there a term for agreeing with someone's stance but disagreeing with the person because they're so insufferable and sarcastic in the way they present the argument?
        • SoftTalker 2 hours ago
          Make the default "allow none" or "child-safe" and then if the parent does nothing that's what they get.
      • Kuyawa 2 hours ago
        When we buy a new phone, the configuration process should ask if the device will be used by a kid. Easy and simple.

        When restoring factory defaults, the same question, just in case the phone is sold, gifted, stolen or whatever.

        If you are going to give a phone to a minor you should set that option right from the start.

      • readread 33 minutes ago
        I've build some moderately sophisticated server systems up on "bare metal" (as the kids say), know my way around a shell better than most programmers, understand networking better than most programmers, et c., and I still find restricting and monitoring kids' devices to be a huge pain in the ass. The only places it's not extremely shitty are the Switch (which still isn't great) and Apple devices.

        Options between "we don't have tech in the house" and "wide-open tech, we have it all" are all some amount of painful, usually for no good reason.

        (I remember once investigating how to do some pretty basic stuff for this in Linux, hoping to find something nicer than manually setting some executable permissions and firewall rules and then having to go back and change them all the time, and the closest thing to a guide I found was an old article from Red Hat that basically lead with "LOL, good luck you poor sap, Linux sucks at this" before going on to explain the various bad ways available to sort-of, but not entirely, accomplish it with a lot of work, and significant ongoing time-burden)

      • SoftTalker 2 hours ago
        That's why the setting should be on the device, not the browser or individual apps. One setting that you could even get pre-configured when you buy the phone.
        • alt227 2 hours ago
          It still doesnt solve the problem of the millions of parents that just dont care.
          • GaryBluto 1 hour ago
            Why should I care that they don't?
          • SoftTalker 1 hour ago
            More parents will care if you make it easier.
      • broken-kebab 2 hours ago
        It's ok if parents won't care. It's a choice too.
        • SoftTalker 1 hour ago
          Yes, you can't make parents care, but make it easy for the ones who do, and you'll also pick up some number of those who care but only if it's not too difficult. There's no reason a parent should have to set permissions separately in 10 differents apps on a child's device.
      • conception 2 hours ago
        That’s not true. Every TV app has a parent setting. That’s really easy to use browser support profiles just like TV apps do bad. UX doesn’t mean that it can’t be set up easily for parents. Windows itself could have profiles for kids that has all this set automatically. It’s not hard. There’s just no will to do it.
        • alt227 2 hours ago
          > There’s just no will to do it.

          Exactly. The problem is its from the parents side.

          • monkpit 1 hour ago
            Spoken like someone who has never used parental controls. They’re a shitshow.
      • BiteCode_dev 1 hour ago
        A child can still access knives if the parents don't care.
  • jsrozner 7 minutes ago
    Cookie banners are just a kind of ad. If you're at the site, the demand you have for the content on the site is probably close to inelastic (especially on services websites). The site exploits its effective monopoly on the content to raise prices to the user (in this case your time, attention, and experience).

    There is ZERO cost to abusing the user over, and over, and over again by asking for permission to track them.

    We shouldn't have the cookie banners at all because NO company should be able to do anything with tracking data. Just ban the use of user data by companies and most of SillyCon Valley's garbage behaviors are fixed.

    Similarly, I should never get "terms of service updates" from digital companies because there should be no changes that they can make. You can provide the obvious service that you're providing; you can't aggregate my data for any purpose other than directly serving me; you can't aggregate my data with that of other users; if you retain my data for any other purpose, the government should take percentages of your revenue. I shouldn't have to wade through the BS that the mercenary corporate lawyers cook up to extract value from me.

  • pverheggen 8 minutes ago
    Here's the full text of the bill (Articles 88a and 88b):

    https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

    As written, this doesn't eliminate cookie banners completely, only if your browser is sending a Do Not Track header or similar. That's unfortunate news if you use fingerprint protection - those send default headers, so you'll still be bombarded with cookie banners. Hopefully existing anti-fingerprinting solutions will offer a "default headers but with Do Not Track" option.

    • MetaWhirledPeas 6 minutes ago
      The good news is if you're doing Do Not Track you're probably in a good position to block cookie banners too.
  • himata4113 25 minutes ago
    Okay, but you can quite literally just delete the cookie banner. Cookie banner forces websites to ask for consent, no cookie banner = no consent = less tracking since they usually hold off on ALL tracking until you interact with the cookie prompt.

    I have personally never ever had any problems with the cookie banner since Brave deletes them with 100% accuracy, there's sometimes where a site will refuse to function properly, but it's usually sites I don't care about anyway and if I HAVE to get it working I disable brave shield, turn off all tracking, consent and turn the shields back on.

    It is unfortunate that most browsers cannot implement this as it goes against what the companies behind the browsers want. Deleting the cookie prompt would stop people from occasionally just accepting all cookies and opting into tracking after getting tired of it.

  • tezza 2 hours ago
    Even well meaning bodies like TFL (Transport for London) have cookie warnings that impede the actual access of the website.

    Need to look up a bus time? Full screen cookie consent with accept buttons drawn OFF THE SCREEN.

    • inigyou 1 hour ago
      They obviously aren't well-meaning if they're endlessly tracking everything you do
      • Jtarii 11 minutes ago
        More likely it was designed by some firm that put the cookie banner there because "that is just what you do in current year"
        • inigyou 10 minutes ago
          Yes and my "peanut allergy friendly" cookies say "may contain peanuts" because that's just what you do
      • igregoryca 1 hour ago
        Sloppy, non-privacy-preserving "analytics" set up by some communications intern ≠ malice. They can mean well and still do a poor job. True privacy on the internet is notoriously hard.
  • dspillett 1 hour ago
    > automated signals that would communicate your privacy preferences between your device and websites or apps0

    Sounds good, as long as it covers the "legitimate interest" bollocks⁰ that is often hidden in inconvenient UI nests as well as the basic preference.

    -------

    [0] "we see your preference not to be stalked, but we want to anyway, click again for every partner to reconfirm you don't want them following you around"

  • shagie 1 hour ago
    > Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful.

    > ...

    > You may think that EU privacy law requires cookie banners. But the law is clear: online tracking is prohibited by default.

    That's an excellent idea... lets see how its implemented on https://european-union.europa.eu/index_en

    Oh... there's a cookie banner.

    • Cyberdog 18 minutes ago
      Don't worry. I'm sure EU legislation will solve nuisances that are solely a creation of EU legislation.
  • tysilva 2 hours ago
    Wow, finally. This would be a major quality of life update for browsing the web. As others have stated, not all sites merit the same preferences. Hopefully they can adapt a middleground of default settings with the ability to customize site by site.
    • convolvatron 2 hours ago
      under what circumstances as user would I want to explicitly agree to have my browsing history sent to tens or hundreds of third party tracking aggregators?
      • scbrg 1 hour ago
        I've seen people argue, with a straight face, that they prefer to get ads that are "relevant to them". Including here on Hacker News.
        • jsrozner 4 minutes ago
          "I like being manipulated by people who want to extract maximal value from me"
      • tysilva 2 hours ago
        I don't disagree. The ideal state here is really layers of customation for the defaults. Options like reject all, or strictly necessary would be at the forefront. And then it's really up to the individual how they want to proceed when those options are not available.
      • broken-kebab 2 hours ago
        If offered something in return, I guess
      • PaulRobinson 2 hours ago
        Devil's advocate argument: if they were giving you something in return, and that could be cash, but it might also be "you can have this content for free".

        In the UK a few news sites have changed cookie banners to "you can accept and see this stuff for free, or you can sign up for a subscription, which would you prefer?". It's the only time I hit accept (and then clear browser history).

        If blanket preferences from browser signals became the norm, a segment might open up where you would configure preferences and a data broker would make sure you get something in return for your data. At minimum it might force paywalled publishers to consider that as a "lite" subscription option.

        • inigyou 1 hour ago
          That's been ruled illegal in the EU, but EU sites still do it. Basically, the consent exception only applies if the user isn't coerced into it. Because coerced consent isn't consent.
        • troupo 2 hours ago
          > but it might also be "you can have this content for free".

          ads don't require invasve and pervasive tracking

          • alt227 2 hours ago
            You seem to have missed the point. No ads dont require those things, but companies could start offering content in return for those things instead of ads.
            • Alpha3031 1 hour ago
              As I understand it, it is the position of several DPAs that denial of access entirely (i.e. "consent or pay") could contravene the "freely given" requirement of GDPR in most cases, though this has thus far not been tested in court.

              (see e.g. https://iapp.org/news/a/cjeu-clarifies-cookie-consent-requir... https://www.edpb.europa.eu/news/edpb-consent-or-pay-models-s... )

            • troupo 48 minutes ago
              > but companies could start offering content in return for those things instead of ads.

              Again, that is not a requirement. If your argument is that they give us content for free because of ads, ads don't require pervasive and invasive tracking. Or hiding stuff behind paywalls (since ads pay for it).

      • alt227 2 hours ago
        Ask that question to the 99% of people who click 'Allow All' on cookie banners.
        • fmbb 1 hour ago
          Its the biggest button.

          They did not read the text to agree.

          It was the fastest way to get the banner to go away. Sometimes they force you to confirm multiple times if you click ”none” or ”minimal”.

      • inigyou 1 hour ago
        Sometimes I do it to reward the website for being less shit than most websites.
  • ezoe 58 minutes ago
    It's technically stupid in the first place.

    It's YOUR browser, a locally running software on a physical computer YOU own which memorize the cookie key-value pair a remote host told YOU to memorize and YOU return the same value later. It's YOU who allowed the cookie. If YOU don't want to allow the cookie, YOU simply not allow it.

    You are technically 100% control on cookie. These JavaScript implemented in-page UI has no guarantee to respect your wish. But you have a power to disable it.

    • frollogaston 54 minutes ago
      It's not quite the same thing since the same cookie used for login (doesn't require consent) could be used for tracking (requires consent). But also, basically nobody cares.
    • troupo 41 minutes ago
      This has nothing to do with cookies, and everything with pervasive and evasive tracking.

      E.g. storing your precise geolocation for 12 years: https://x.com/dmitriid/status/1817122117093056541

  • hollowturtle 1 hour ago
    I always wondered though why a website in the eu, for the love of their users, won't just drop cookie usage and instrusive third party scripts. Just do analytics on the backend and don't set any cookie, except for tokens in authenticated areas
    • tempestn 1 hour ago
      You can't even save user preferences (like language or other settings) without showing a cookie banner. Edit: I was mistaken. You can't save inferred preferences, but can save explicit user-saved options.

      And for a serious website, front end analytics are kind of a necessity to understand how users interact with pages and improve the experience. Note that it certainly doesn't require tracking the behaviour of individual users, just understanding how controls are used in aggregate.

      I know it seems like you could work around this with careful design and maybe focus groups and such, but I can tell you we regularly uncover surprising insights from (aggregate) trends in front-end events.

      • dgellow 37 minutes ago
        That's not true and is a very common misinformation people repeat online. You can save user preferences in cookies without any consent banner, if the cookie isn't used for tracking.

        See here[0], page 6:

        > As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’

        0: https://www.edpb.europa.eu/system/files/documents/2024-10/ed...

        As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen

        • tempestn 26 minutes ago
          You're right; I haven't looked into this in detail in some time. You can't save inferred preferences, but can save things that the user has explicitly selected to save.
    • reddalo 1 hour ago
      That's what I'm doing with a service I made. But I don't have any ads, and ad-supported websites can't easily do that.
      • tappio 29 minutes ago
        There are privacy respecting ad brokers that dont require user tracking. Its just that people are too lazy or greedy to use those.
  • Retr0id 1 hour ago
    I think this would be a net benefit, but I can see an issue. A lot of news sites today do "accept tracking, or pay us, or you can't access the page". The orgs doing this are reputable-ish so I assume it's considered legal, on some level at least.

    So now they'd have a new popup that says "reconfigure your browser to accept tracking, or pay us, or you can't access the page". Which isn't really an improvement.

    • JoshTriplett 1 hour ago
      "accept tracking or pay" has already been ruled against, it just hasn't been universally enforced yet because enforcement takes time.
  • hash872 1 hour ago
    Also there's a big difference between the sites that easily allow you to simply reject whatever their premade cookie settings are. And, the sites that only allow you to use them after you've accepted (example, politico.eu). Or, the sites that do have a 'reject' option, but you have to click through multiple screens and then manually reject each individual option.

    Sites that easily allow you to simply reject everything are then a short hop, skip and a jump into browser settings where you auto-reject all cookie/tracking nonsense

  • alt227 2 hours ago
    I still don't get why every website has a cookie banner by default. I am data controller for several companies and have lots of exposure to GDPR. All my websites have no cookie banner, as they are not required.

    I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies? Who knows.

    • reorder9695 2 hours ago
      Don't underestimate the argument of "just to be on the safe side". Someone running a business who doesn't know a lot about cookies will often just put a banner on as an easy arse covering mechanism even when not required.
      • JoshTriplett 1 hour ago
        Perhaps someone could publish a clear A/B test on how many views/conversions you lose by having a cookie banner?
      • SoftTalker 1 hour ago
        Or they had their site developed by an agency and the cookie banner is just part of their standard scaffolding for a new site.
      • inigyou 1 hour ago
        Let businesses who don't know what they're doing be outcompeted by businesses who know what they're doing.
    • tete 1 hour ago
      > I guess that most companies just chuck it up there as a default so they dont have to read the law

      I think most companies just don't give a fuck about user privacy and therefor have to show one. There are of course exceptions. But I don't know how many of them have been actual (for-profit) companies.

    • kuerbel 1 hour ago
      If you use social media pixels, ad tracking, or performance analytics tools like Google Analytics a cookie banner and consent is required. If not, then not.
      • alex_suzuki 1 hour ago
        Side note: there’s plenty of Analytics tools that don’t require cookies. Plausible (https://plausible.io) is one of them, there are many others. Not affiliated, just a happy customer.
        • charcircuit 20 minutes ago
          If you want to prevent a single user hitting F5 a million times from messing with your analytics you need to track IPs which requires the banner.
    • esperent 2 hours ago
      > I guess that most companies just chuck it up there as a default

      50% that, and 50% that way more companies than you expect are harvesting and profiting from your data.

    • maccard 2 hours ago
      I’ve made a few sites for work that aren’t our primary focus. The sites used cookies for login and for “required purposes” (storing in progress state). We did all the tracking on the backend, no cookies or client side trackers.

      On our go-live form there’s a question “do you use cookies” and it’s yes/no. If you say yes legal block the site from going live without the pre approved cookie banner…

      • JoshTriplett 1 hour ago
        Sounds like your legal department is broken. You should fix that.

        I mean that both in the sense of "you, plural" (your company should fix that) and "you, personally" (because diffusion of responsibility is a real issue, and someone needs to actually do it).

      • jarofgreen 2 hours ago
        > We did all the tracking on the backend

        Just checking, you do know that still counts as tracking and may fall under GDPR rules? GDPR was never just about cookies.

        • maccard 1 hour ago
          I do but we shouldn’t be talking about cookies in our cookie banner then.
    • HiPhish 2 hours ago
      > I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies?

      That has been my guess as well. If you run npm install half-the-internet you have no idea what's in there, so just slap on that cookie banner for good measure. Of course the real problem is not knowing what's inside your application, but the thought process is "eh, if a blanket cookie banner does the job then that's good enough for me".

  • ChadMoran 2 hours ago
    What does enforcement of not having these banners look like? Wha tif people just... didn't.
  • righthand 13 minutes ago
    The captchas are worse imo (from an usability standpoint) especially the newer Cloudflare infront of everything to check for bots trend.
  • imhoguy 1 hour ago
    And guess who makes the most of devices and the most popular browser, I already see post install "Get most of the browsing experience by agreeing to these defaults."
  • richard_chase 1 hour ago
    It would have been funny to get a cookie banner on this site. They missed a good opportunity.
  • rpdillon 2 hours ago
    The insanity around cookie banners is a good target.

    > Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.

    Fortunately, if you have uBlock Origin, you can enable Easylist cookie notices under annoyances and avoid most of them. Combine with blocking third-party cookies, and the problem pretty much disappears.

    The fact that the EU tried to regulate this stuff is a shame, because regulation is not a good remedy. End-users have agency here. The solution is to enable end-users to have control in their browser (which they always did, so it's an issue of education, like so many things).

    Shame that Google is trying to kill uBO though. Extremely pleased that Brave continues to support it.

    • mrkeen 2 hours ago
      If it's not cookies, it will be something else. IP addresses, tracking pixels, browser fingerprinting.

      The Do Not Track header is the only technology needed. The rest is compelling companies to obey it.

    • cwnyth 2 hours ago
      Didn't know that about Brave, but it's moot for me since Firefox also supports it and these days I find that Firefox is the better experience, not Chrome or even Chromium.
  • troupo 3 hours ago
    > he EU Commission finally proposed a solution to the cookie banner problem: automated signals that would communicate your privacy preferences between your device and websites or apps.

    It wasn't on EU Commission to "finally propose a solution". The soluton has always been there.

    Somehow, Google, aka world's largest tracking and advertising company incidentally making the worlds' dominant browser and completely dominating all web standards, couldn't be bothered, and instead was pushing crap like FLoC

    • cube00 57 minutes ago
      > Somehow, [...] couldn't be bothered

      Google knows if you can set this once it's game over for their adverting business. At least with the cookie banners, there's a possibly you won't refuse every banner.

      Especially those banners that only have "Accept" or "More options" with all those checkboxes to clear.

  • SeriousM 1 hour ago
    It's a "Dick over".
  • sandeepkd 2 hours ago
    Usually government mandating something is concerning cause it seems to favor the government for its existence. However with EU commission its actually interesting combination, its representing multiple individual governments at once which somehow works good for the citizens.

    Overall this is a common sense solution. The challenge is that a significant industry makes money by collecting and selling data. It makes it harder for businesses who depend on it, they are going to get creative and will eventually come up with some dark pattern to circumvent it.

  • ktosobcy 48 minutes ago
    Uhm…

    > The solution: automatically communicate your privacy preference

    Would be lovely and would happen if it weren't for… wait for it… Google and whole effed up ad-busines:

    https://ppc.land/eu-council-drops-cookie-signal-after-google...

    F*ck google and other BigTech…

  • tgma 1 hour ago
    I am old enough to remember Do Not Track and its failure and problems associated with it. What's new here? Why wasn't it adopted in the first place for GDPR?
    • pmlnr 20 minutes ago
      Nothing.

      People not reading back on history is still very much a thing.

  • mmarq 2 hours ago
    As if the DNT thingy didn’t exist…
    • pndy 22 minutes ago
      Mozilla removed DNT as of Firefox 135, after 13 years since introducing it in 2011 with Firefox 4

      In 2024 Mozilla acquired Anonym from former Meta executives and decided to introduce PPA: https://hn.algolia.com/?q=privacy+preserving+attribution

    • reddalo 1 hour ago
      The problem of DNT is that Internet Explorer 11 set it to true as default, and then all companies started ignoring it on purpose.
    • IshKebab 1 hour ago
      DNT tried to do this without any legal backing which was obviously stupid.
  • drnick1 2 hours ago
    uBlock Origin with all "annoyance" filters enabled. I haven't seen a cookie banner in years.

    Another good one to have the "hide Youtube shorts" filter, featured on HN a while back.

    • jsrozner 3 minutes ago
      Does this still work on new chrome versions?
    • tete 1 hour ago
      There is Consent-O-Matic.

      Also I wanna know when websites don't give a shit about my privacy and therefor have to show a cookie banner. While theoretically not consenting should mean not collecting blocking it altogether and modifying page content might mean "all bets are off". If the website expects you to have made a decision that might wrongly consider it consent.

      Consent-O-Matic says "I don't consent".

    • alex1138 50 minutes ago
      That didn't work for me and so now I've added the specific cookie banner options. it's in the filter lists
  • hieKVj2ECC 3 hours ago
    Yes please!
  • johndhi 47 minutes ago
    how about: -if we really don't like targeted advertising, just outlaw it -then let websites do whatever they want with our cookies so long as they aren't targeted advertising

    instead of building websites and writing laws over the span of decades that just seem to want to ban targeted advertising but don't actually do it. FFS.

  • the__alchemist 2 hours ago
    Keep fighting! For now: browser plugins.
    • pndy 29 minutes ago
      Extensions; plugins are nearly dead nowadays anyway
    • hborscht 2 hours ago
      is there a specific one you would recommend?
      • tcfhgj 2 hours ago
        uBlock Origin -> allows blocking dialogs (legally implies refusal of everything not necessary, because you don't agree to something requiring agreement)

        Consent-O-Matic -> automated configuration to your preferences using the dialog provided.

        I still don't care about cookies -> least privacy friendliest option, because it may opt into undesired tracking (its goal is just to remove the annoyance of the dialogs)

      • the__alchemist 2 hours ago
        I use "I still don't care about cookies"; it works well, but I don't have a current comparison to other options.
  • charcircuit 1 hour ago
    Even if you communicated your preferences sites would still want to ask for an exception to them. At least you won't see them ask for consent if you preapprove it.
  • nektro 37 minutes ago
    can we also kill the dark pattern of "accept all" and "choose your preferences" ?
  • paulddraper 3 hours ago
    Doesn't this lead to an all-or-nothing approach?

    I don't want randomnewssite to track me. But a favorite online store...I do want help with recommendations.

    • joeframbach 2 hours ago
      You would presumably be logged in to your favorite store site, and they would be using your identifying session to make recommendations, not anonymous tracking cookies.
      • paulddraper 2 hours ago
        Eh, maybe.

        It's easier to click a single button than hunt for how to create/access an account for the brand.

    • dymk 3 hours ago
      Then sign in, thats enough signal for them to track you
      • frollogaston 30 minutes ago
        Logging in isn't consent for tracking. They can even support login by itself without a tracking banner.
    • qurren 3 hours ago
      Just disable cookies on your browser by default, and enable it for the sites that you need to log in to.

      Ironically, this has the effect of cookie banners reappearing every time because they cannot place a cookie that says that you have rejected them.

      • Phemist 2 hours ago
        Malicious compliance. You do not need a cookie to "store" the fact you have rejected them. They can simply assume you have rejected them from the lack of cookies. They can store a cookie once you (have gone out of your way to) accept them.
        • frollogaston 29 minutes ago
          Lack of cookies could mean you never visited the site before.
      • mzajc 2 hours ago
        Unless disabling cookies means treating all cookies as session cookies (meaning you can still be followed within a session), this has the fun side effect of breaking pretty much every CAPTCHA firewall like Anubis, Cloudflare Turnstile, and any other that relies on cookies.

        Unfortunately this means you have to view a lot of the web through archive.today or web.archive.org - I would know because I have uMatrix configured this way.

        • frollogaston 28 minutes ago
          Session cookies for non-whitelisted sites is a nice balance between usability and privacy.

          Session cookies for all sites would be fine if passkeys weren't like "We support passkeys. Do you want to use a passkey? Press ok again to use your passkey. Do you consent to using your passkey? Now please authenticate yourself to use the passkey... √ Thank you for using passkeys. Press ok to continue."

        • qurren 38 minutes ago
          Honestly I've found that it's often the local businesses that shoot themselves in the foot more by this.

          I disable cookies for Amazon because I need to login; if a local business wants me to buy from them directly they need to:

          1. Not give me a CAPTCHA or cloudflare shit

          2. Give me free shipping and a lower price than Amazon minus 5% cashback that I would get on Amazon

          3. No registration needed to check out

          and I'll buy from the local website. It's really not a high bar, they need to learn to not shoot themselves in the foot.

          As for the news websites -- bleh. If they want me to read it, make it easy to read. As in, I click into it, show me the content. If I get a popup, banner, anything that covers up the content, I bounce. I'll get the news from social media anyway. If they'd rather I get it from their news website, they need to learn to not make me bounce.

          I'm not opposed to advertising if they want to get revenue from that, but it should not track me, not cover up content, and not load megabytes of JavaScript to do it.

      • tcfhgj 2 hours ago
        you can be tracked without cookies - the cookie dialogs are about tracking and processing of personal data in general.

        -> not really sensible

    • amelius 3 hours ago
      Just configure your browser to ask for cookies for that store only?
  • wrqvrwvq 1 hour ago
    or we could glass the continent
  • openquery 1 hour ago
    Finally yes yes yes.

    I've wanted the option to select your cookie preferences once and forget in a brower for ever.

    I assume the reason this wasn't done initially was corporate pressure (most people would opt-out of everything by default).

    1.2 billion exposed users × 8.17 years×365×3 banners/day×4 seconds÷36 is roughly 10-15 billion human hours lost to dealing with damn cookies since GDPR took effect on May 2018.

    That's about 17,000 human lives.

  • srijanbaniyal 2 hours ago
    [flagged]
  • dfaoidsoi 2 hours ago
    [dead]
  • SadErn 1 hour ago
    [dead]
  • doodlebugging 1 hour ago
    No need to kill the cookie banner. Just change the system so that everyone in every organization who supports cookies and other forms of user tracking and engagement will have every detail of their own existence and their family's existence broadcast in real time globally 24/7/365. Anyone who tries to opt out is jailed under 24 hour surveillance for a minimum of one year.

    EDIT: It's obvious that people really hate this option. Maybe too many here have their incomes too closely tied to the metrics that cookies are designed to collect. It could also be that it is an unrealistic option for everything except the most extreme societal changes.

    If you are old enough and look back far enough you may remember the time before all this bullshit like I do. Once marketing and advertising get involved and gain power in an organization, things tend to go to shit fast.

    • jsrozner 0 minutes ago
      Hypocrisy is the name of the game in SillyCon valley. Push YouTube autoplay slop on kids globally, but no ipads for children of the tech elite. Computer-based instruction for public schools, but 2:1 teacher:student ratios in the local private grade schools that cost as much as an Ivy League University. Etcetera.
  • tete 1 hour ago
    No, please don't!

    It's great. The current law forces people that don't give a shit about user privacy to have a banner (or any other way of asking for consent first) while giving everyone that cares and everyone not wanting to spy on their visitor a free pass.

    • inigyou 1 hour ago
      People click yes too often because it's the easier way to make it go away. This new thing could actually result in a 0% tracking cookie consent rate, effectively making them illegal.
  • TechSquidTV 2 hours ago
    The EU has been on a decade-long crusade to destroy the internet.
    • PaulRobinson 2 hours ago
      I think you'll find that's Google and Meta.

      Just step back and ask yourself what each side of that debate is trying to achieve and why. What is motivating them? Why are they motivated in that way?

      Don't just recite what you "know", think, look, research, figure it out. It might sound good to have a one-liner like this in your back pocket, but do you really believe it after looking at the publicly available information that it is their real intention to conduct a "crusade to destroy the internet"?

    • tcfhgj 2 hours ago
      Advertisement has been on a decade-long crusade to destroy the internet.
      • amelius 1 hour ago
        You mean: the planet.

        (because it drives consumerism)

    • yankfatigue 2 hours ago
      [flagged]
  • W3cUYxYwmXb5c 2 hours ago
    This is conflating different things. They are trying to use people's annoyance with the banner THEY caused to build support for another legislation.

    Cookies were never a problem. Just get rid of the banner.

    This other legislation should pass/fail on its own merit.