Andrew's WebLog

Pretend I wrote a pun about cookies in the title

A website for a campaign to kill cookie banners cropped up on Hacker News lately. A while back I posted my thoughts on this subject in a comment but it's buried under all my other comments, so I'd like to rewrite that rant reiterate those thoughts here.

You already know cookie banners are terrible. Websites shouldn't be trusted with implementing them in the first place!

This responsibility belongs to browser vendors. Cookie blocking should work like hardware permissions, which are granted on a site-by-site basis. Add a little banner or popup to Chrome, Firefox, Safari, and the rest. Display it the first time a site tries to set a cookie. Or have it always reject every cookie unless I whitelist a site. This would result in a consistent user-experience across the board, and I'd actually be able to trust that I'm not being tracked… at least not by cookies.

Instead, we are trusting the very websites we've accused of tracking us (in the most deceitful, malicious ways possible) to self-regulate and implement these controls. So now every website gets a shitty cookie pop-up banner when you first visit in addition to all the other annoying in-page banners and popups which are a staple of 2020s web design. All these banners look different, are positioned differently on the page, and appear at varying times after the page finishes loading.

There are some commonalities. Most likely, a prominently placed "allow all" button is the easiest control to find, and is guaranteed to instantly close the banner. If there's no "reject all" button, well, get ready, because once you click "customize" you're in for a crash-course in the multiplicity of uses for website cookies. You will almost certainly be greeted by a much larger banner with a list of toggle switches, each accompanied by a needlessly detailed description of exactly which type of cookies will be disabled if you dare to turn the switch off. And don't even think of getting rid of "strictly necessary cookies." Yes, there's a toggle for them too, but it's greyed out to let you know what a fool you were to even consider this.

The fact that these banners all have different layouts is great for trackers. They're counting on you to get tired of navigating through labyrinthine interfaces every time you visit a new site. So you give up trying, opting instead for the path of least resistance, in the form of an "allow all" button. You click it and think "I don't have time to worry about this bullshit… who does?"

You may be wondering whether any of those "strictly-necessary" or "crucial for site functionality" cookies are the ones you wanted to block to begin with. Well, it gets better, because cookies don't even matter when you can fingerprint someone's browser in an instant with just a script. So install the noscript plugin, but be prepared for it to break random websites right when you're doing something important, even though you thought you whitelisted all the relevant domain names…

But I digress. We're looking at the end result of a scenario where we've asked websites to self-regulate no differently than the US's vitamin and supplement industry, except it's worse: I don't have to click a fucking banner before I take a capsule of what may or may not be vitamin C.

Shift the responsibility to browser vendors. Get them to implement controls that actually block cookies - by default if necessary. The worst case? Some websites pester you to enable them, while disabling certain features if you refuse. That will be a given for most online storefronts. The best case is a world where the majority of websites are pressured towards being stateless, just how it was in the early days of the web. There's also a middle-ground here, where websites end up shamelessly fingerprinting your browser, storing user preferences server-side… but I'm prepared to cross that bridge when we come to it.

#software #web