CookiesOK browser plugin(cookiesok.com)
cookiesok.com
CookiesOK browser plugin
http://cookiesok.com/
9 comments
Popular "read-only" sites need cookies. Take sites like NY Times or TMZ.
They need advertising revenue to pay for offices, people in those offices to write the content you want them to "just show", etc. Much of that potential revenue is locked up in advertising networks, and you need cookies to serve them on your site. Even if it were possible to sell out the ad space in-house, you need cookies to accurately track the delivery and results for the advertisers.
They need analytics to bring in the traffic that will view those ads. Especially for large publications, real-time analytics drive the decisions of what content to write, what content to expand, and what content to promote to the front page in order to maximize page views and thus ad views. They're decisions made minute-by-minute throughout the day. You need cookies to do that kind of analytics.
So while technically they can "just show you" the article you want without cookies, the practical implication is that the content you want them to show you wouldn't exist without cookies.
They need advertising revenue to pay for offices, people in those offices to write the content you want them to "just show", etc. Much of that potential revenue is locked up in advertising networks, and you need cookies to serve them on your site. Even if it were possible to sell out the ad space in-house, you need cookies to accurately track the delivery and results for the advertisers.
They need analytics to bring in the traffic that will view those ads. Especially for large publications, real-time analytics drive the decisions of what content to write, what content to expand, and what content to promote to the front page in order to maximize page views and thus ad views. They're decisions made minute-by-minute throughout the day. You need cookies to do that kind of analytics.
So while technically they can "just show you" the article you want without cookies, the practical implication is that the content you want them to show you wouldn't exist without cookies.
They do not need cookies for adverstising. In fact using cookies for advert networks is sorta what this law is aimed at. Be careful when using them.
Just because a business model currently relies on cookies, doesn't mean we should get rid of the privacy law. Maybe the business model should change. After all, if the business model required employees to work more than 13 hr shift (Working Time Directive), then tough, your business model needs changing.
Just because a business model currently relies on cookies, doesn't mean we should get rid of the privacy law. Maybe the business model should change. After all, if the business model required employees to work more than 13 hr shift (Working Time Directive), then tough, your business model needs changing.
They do need cookies for advertising. Have you ever sold online advertising before?
Current advertising networks use cookies for analytics and cross site profiling. While useful for advertisers it does have privacy implications and there is no, technical, reason why an advertising network could not serve advertisements without the 3rd party cookies.
I think rmc is saying ads only require cookies because ad networks require them, but they're not absolutely necessary. Newspapers, magazines, billboards, TV ads, and other physical media don't have the equivalent of cookies and companies still pay to advertise that way. I don't know anything about advertising but I don't see why an online ad couldn't just consist of a jpg or text, a url and a contract between 2 parties. Obviously that type of ad wouldn't just be a JS snippet you drop into a page. I'm picturing a process like 1. Create some good content 2. Show it to an perspective advertiser with a 'Your Ad Here' placeholder 3. Agree to display an exclusive ad for a certain amount of time. The advertiser can check you're actually showing the ad however they do for physical media. They can also estimate it's effectiveness however they do for physical media. Obviously reputation would play a big role. If the content creator becomes popular enough advertisers will flock to them, if they're just starting out they'll have to solicit companies to sell advertising at a super low prices or give it away for a while. People would have to talk to each other, establish a little trust with each other and take a few monetary risks but isn't that what business is all about? The JS snippet ads could stay around too, but if this law spreads, which I hope it does NOT, it's going to annoy the hell out of people, a browser plugin is more annoying IMO, so that's not the solution. Again, I don't jack about advertising so I'm probably just being idealistic.
Print publications have circulation audits. TV has ratings. Cookies ad similar legitimacy for websites. It also enables much more in depth accountability which has created a massive new advertising market that could not exist without it (good luck with CPC without cookies). If the same could happen in print or broadcast it most definitely would be used.
Websites have ratings in all kinds of varieties and could have audits of some kind. Maybe the techniques for estimating ratings, audits and click-through without cookies can't be completely automated or 100% accurate, but so what, someone can make a business out of doing that well. Maybe website owners would have to start allowing ad companies to run some code on their servers, LOL. I'm sure cookie like strategies could happen in print and broadcast with extreme measures but it would be expensive and the privacy violations would likely be so glaringly obvious that no one would stand for it. Just because it's easy to do and hide on the web doesn't mean it should be done. CPC is just one business model, maybe it's not the only feasible one. I'm not saying I despise the current model or that I think that law is a good idea, I don't even care about privacy myself and I don't want to have to click more buttons than I have to, but many people do care and have no idea how deeply they're being tracked. Some think something should be done about that, enough to influence some governments. I'm sure there are a lot of historical failed attempts at other models but a lot has changed, I don't think it could hurt to at least consider implementing some other ideas, new and old. Not me of course, someone else.
It would be perfectly possible to serve ads without cookies (they work just fine if you disable cookies, after all).
However, none of the big advertising networks is going to let the additional value of tracking customer behavior and targeted advertising slip through their fingers.
That's not the same as "needing" cookies for advertising, though, and it is indeed what the directive was meant to put a stop to (among other things).
However, none of the big advertising networks is going to let the additional value of tracking customer behavior and targeted advertising slip through their fingers.
That's not the same as "needing" cookies for advertising, though, and it is indeed what the directive was meant to put a stop to (among other things).
I presume you have never sold an online ad? While yes, you can technically do anything you'd like, in reality online advertising requires cookies.
I talked over a deal yesterday and like most online campaigns it included a frequency cap (in this case 1/24 for desktop and 2/24 for mobile). You cannot do a frequency cap without cookies. I could have instead tried to sell a static image or whatever you think would work, but that deal would not have gotten done. This was a CPM campaign, so let's forget that as a possibility. How would affiliate advertising work without cookies (hint: it doesn't). So that's out too. Let's try CPC. Perhaps you can do the leg-work for me and find someone willing to pay me per click for anonymous users that may or may not exist, but I have yet to find one.
This is all ignoring the fact that without cookies you have absolutely no idea how much inventory you have and what its profile looks like. Say you get 1M page views a month, but no advertiser in the world cares about that they want to know how many unique visit[ors] you get. A forum with 1M page views could have 10k members and be nearly worthless to advertisers, but a blog with 1M page views could be 500k unique visitors that are very desirable for advertisers. Without cookies you don't know and the result is you won't sell ads. It's very simple.
I talked over a deal yesterday and like most online campaigns it included a frequency cap (in this case 1/24 for desktop and 2/24 for mobile). You cannot do a frequency cap without cookies. I could have instead tried to sell a static image or whatever you think would work, but that deal would not have gotten done. This was a CPM campaign, so let's forget that as a possibility. How would affiliate advertising work without cookies (hint: it doesn't). So that's out too. Let's try CPC. Perhaps you can do the leg-work for me and find someone willing to pay me per click for anonymous users that may or may not exist, but I have yet to find one.
This is all ignoring the fact that without cookies you have absolutely no idea how much inventory you have and what its profile looks like. Say you get 1M page views a month, but no advertiser in the world cares about that they want to know how many unique visit[ors] you get. A forum with 1M page views could have 10k members and be nearly worthless to advertisers, but a blog with 1M page views could be 500k unique visitors that are very desirable for advertisers. Without cookies you don't know and the result is you won't sell ads. It's very simple.
That's exactly my point? You do not technically need cookies to serve ads. You just find it highly desirable to do so. And yes, I am totally aware that ad networks have built their business models around having this information available and that the marketplace has been shaped by these business model. That still doesn't make them needed in a technical sense. If cookies had never existed, then we'd still have online advertising, just as we have advertising in other media that lack this form of feedback.
If you don't want my cookie, feel free to not use my website which is provided to you free of charge (and ironically, if it was not free you would definitely need to accept the cookie). It does me no good to provide you a service when I can't monetize it.
I don't understand the sense of entitlement. The result is annoying, but that's because of the poorly thought out law. If you don't want annoyed, use this extension.
I don't understand the sense of entitlement. The result is annoying, but that's because of the poorly thought out law. If you don't want annoyed, use this extension.
I guess if you are putting some service out there, you actually WANT people viewing your content/using the service. Way to antagonize your potential customers which such "my way or the highway" attitude!
And how do you feel about the 'Do not track' header?
And how do you feel about the 'Do not track' header?
What if the service comes with accepting a cookie? A potential "customer" that does not accept cookies is simply a waste of bandwidth.
Not a big fan of DNT, it relies on trust which prevents it from working when you want it to most. If you don't want tracked, don't accept cookies. If you can't use a service without cookies and are not happy using something like Incognito mode, stop using that service.
Not a big fan of DNT, it relies on trust which prevents it from working when you want it to most. If you don't want tracked, don't accept cookies. If you can't use a service without cookies and are not happy using something like Incognito mode, stop using that service.
The law doesn't work that way.
If the law says "you must gain users consent before storing things on their computer", then "well if you don't like it, don't visit my site" is not an acceptable legal defence.
If the law says "you must gain users consent before storing things on their computer", then "well if you don't like it, don't visit my site" is not an acceptable legal defence.
Of course, the point was no I will not let you access my content before you decide about a cookie. The OP finds having to make this decision to be annoying and thinks the site should just not set any cookies.
Why can't sites just provide simple $INSERT_ANYTHING_HERE experience
Because anything that adds features costs money. This is a non-issue for most website developers.
But why would you want to do this?
Because, pre-law, I (like many people) were happy to exchange a cookie for access to free content from virtually any website.
Accessibility is king.
Because anything that adds features costs money. This is a non-issue for most website developers.
But why would you want to do this?
Because, pre-law, I (like many people) were happy to exchange a cookie for access to free content from virtually any website.
Accessibility is king.
I am somewhat upset that Rails sets a drive-by session cookie when I visit a site with no intention of logging in or doing anything.
There are other reasons to have sessions than to facilitate logging in (message flashing being a biggie for Rails, but it's also critical in things like A/B testing). What's the harm? If you don't want to play nice, don't accept the cookie. You will probably never know what you're missing.
Well my point is I guess there should be no cookie set for the read-only experience. Once you do something that requires tracking some state server-side, then the session cookie might be set. For example if you are searching, or you submit some data (that might trigger the message flashed), I guess the page where you perform said action could contain the cookie notice and notify user that to perform such stateful action user will need to accept the cookie.
For example, if you visit a web shop, you shouldn't need to get any cookies when viewing a product page. If you decide to put it into shopping cart - then you would consent to getting a cookie. But no sooner!
For example, if you visit a web shop, you shouldn't need to get any cookies when viewing a product page. If you decide to put it into shopping cart - then you would consent to getting a cookie. But no sooner!
That's a bizarre way to look at things. The good news is you can very easily make this your reality by changing a setting in your browser.
There are tons of reasons why "read-only" could make use of cookies. Here are a few, using your ecommerce example:
1) A/B test 2) General site analytics, to see how many unique visits your shop gets 3) More detailed conversion analytics to figure out things like the value of a visit, how long someone takes before making a purchase, knowing the origination of all conversions, etc. 4) Remembering viewed items so they can be promoted on a future visit 5) Displaying a "Welcome back" message to second time visitors
If you don't do these things you will be beaten by people that do. eCommerce might be the absolute worst example you could have come up with for situations where cookies are not needed.
There are tons of reasons why "read-only" could make use of cookies. Here are a few, using your ecommerce example:
1) A/B test 2) General site analytics, to see how many unique visits your shop gets 3) More detailed conversion analytics to figure out things like the value of a visit, how long someone takes before making a purchase, knowing the origination of all conversions, etc. 4) Remembering viewed items so they can be promoted on a future visit 5) Displaying a "Welcome back" message to second time visitors
If you don't do these things you will be beaten by people that do. eCommerce might be the absolute worst example you could have come up with for situations where cookies are not needed.
...unless there is an A/B test running.
Why do you set cookies on Celtic Knot Creator?
Why?
Those banners (in most cases) are not you turning on or off cookies. The bbc sets cookies immediately (they do allow you to unset some here http://www.bbc.co.uk/privacy/cookies/managing/cookie-setting...), but you already have a session cookie that will last 4 years once the page is loaded.
Most sites will state they are assuming consent based on your continued usage of the site.
Most sites will state they are assuming consent based on your continued usage of the site.
That's oversimplifying things a little.
Say I build a website and fill it with content you want to see. I'd run Google Analytics to track popular content etc.
You're saying my default choice is to no longer have analytics on my site at all?
Agreed, all these other solutions are rubbish. But your solution isn't a good solution either.
Say I build a website and fill it with content you want to see. I'd run Google Analytics to track popular content etc.
You're saying my default choice is to no longer have analytics on my site at all?
Agreed, all these other solutions are rubbish. But your solution isn't a good solution either.
Note that (at least in The Netherlands) the cookie law does allow you to use Google Analytics for measuring anonymized user statistics, without asking a visitor to accept cookies.
(In Dutch http://www.nu.nl/internet/2987889/cookiewet-versoepeld.html)
(In Dutch http://www.nu.nl/internet/2987889/cookiewet-versoepeld.html)
Perhaps web browsers should just include an option to disable cookies. That way, websites wouldn't have to display these kind of alerts, and users wouldn't have to trust that all sites will actually display these warnings before setting a cookie. One could even imagine an advanced web browser feature which would allow users to allow or deny cookies on a per-site basis.
Sarcasm aside, it's curious that lawmakers (even in Europe) thought it better to make a requirement of O(N^N) site owners rather than "require" that O(5) browsers implement a feature which they all do already.
I always use cookies on a whitelist-only basis, and it is quite common to find web sites that require cookies for no good reason -- sometimes, I suspect, without even realizing it -- and then fail with no message when cookies are disabled.
I believe that cookies should be regarded as a progressive enhancement. If your web site requires cookies to implement a paywall, then detect when they are disabled and say so. If you can add features when cookies are available, great; if they're not, let me know what I'm missing. But don't tell me that "a browser error is preventing me from logging in," as many sites do. Once again, I'm sure this is boilerplate code that the actual site owner isn't even aware of.
I always use cookies on a whitelist-only basis, and it is quite common to find web sites that require cookies for no good reason -- sometimes, I suspect, without even realizing it -- and then fail with no message when cookies are disabled.
I believe that cookies should be regarded as a progressive enhancement. If your web site requires cookies to implement a paywall, then detect when they are disabled and say so. If you can add features when cookies are available, great; if they're not, let me know what I'm missing. But don't tell me that "a browser error is preventing me from logging in," as many sites do. Once again, I'm sure this is boilerplate code that the actual site owner isn't even aware of.
I didn't realize this was sarcasm. Rare find on hacker news. Better access to the cookie controls without hunting in preference panels would be nice, but I'm sure extensions can fix that.
[deleted]
"CookiesOK searches for the accept buttons and triggers the click event" So what happens when someone injects something other than just the cookie code? My browser will auto-accept that as well?
that's why I didn't go down this route; most sites keep serving cookies until you tell them not to so I've found that an adblock filterlist works very well: https://github.com/r4vi/block-the-eu-cookie-shit-list where we just hide the entire cookie cruft every time or block the cookie prompt script if it's a widely deployed plugin
Does anybody know if this is actually being enforced in any way? (The cookie law that is?)
I'm in the UK so use a bunch of sites here. What I have noticed is that only large active sites by big companies and orgs actually have cookie notices.
None of the other countless sites actually have it at all. So I'm wondering how long it will be before people just stop putting these things up at all?
I'm in the UK so use a bunch of sites here. What I have noticed is that only large active sites by big companies and orgs actually have cookie notices.
None of the other countless sites actually have it at all. So I'm wondering how long it will be before people just stop putting these things up at all?
It's not (yet). Typical 'Big Gov' solution. Extra dumb are websites that force you to accept the cookies each and every time you visit them. Oh yeah, even the government's own sites are not all up to date.
Not really our government's fault though; to their credit they did actually try and fight it a bit. IIRC our regulation (in the UK) has a few differences from the EU one.
All EU countries implement all EU law slightly differently (just look the EU Working Time Directive). EU law just gives the minimum that countries have to do.
From looking into it myself, it looks like UK implementation is stricter than e.g. Irish one.
From looking into it myself, it looks like UK implementation is stricter than e.g. Irish one.
[deleted](1)
Errmmm, you seem to not understand what cookies are for...
I did some screen-scraping research, and it turns out that the top visited domains (as defined by Alexa) actually set a fair amount of cookies:
Visualization and data is here: http://www.demo.hauthaus.net/eurobake/#
Visualization and data is here: http://www.demo.hauthaus.net/eurobake/#
Does anybody know if this is actually being enforced in any way? (The cookie law that is?)
I don't know. But just FYI, it would be the local data protection commissioner that would be in charge of enforcing this law AFAIK.
I don't know. But just FYI, it would be the local data protection commissioner that would be in charge of enforcing this law AFAIK.
no it isn't, check this out http://nocookielaw.com/
There is a pretty simple economic argument that people need to consider before jumping into the cookies are bad camp. The market for display ad inventory alone in the past year was to the tune of $40b in the US. There are 250m active internet users. That $40b dollars goes into the pockets of content producers on the internet that make it the tool it is.
Net, if you wanted to drop all of that and get rid of the advertisers, that is a balance of $160 per person per year (and growing) that would fall to some other solution (like increased service charges).
As others have made the case, cookies are important for advertisers. If you want to fix the problem, need to consider another viable solution that either does not sweep their legs out or does but provides an alternative revenue stream to keep the internet alive.
Net, if you wanted to drop all of that and get rid of the advertisers, that is a balance of $160 per person per year (and growing) that would fall to some other solution (like increased service charges).
As others have made the case, cookies are important for advertisers. If you want to fix the problem, need to consider another viable solution that either does not sweep their legs out or does but provides an alternative revenue stream to keep the internet alive.
This is great, thought about making something like this myself for a while.
One problem I have with current cookie law, is that it pretty much forces cookies upon those who actually know how to disable them. If someone browses with cookies disabled, they get all these annoying warnings and yet no way to turn them off - because turning them off requires a cookie! Insanity.
And the relevant governing body has pretty much admitted that you'll probably be ok with just a clear description of cookies used. (See the response to nocookielaw.com)
Oh AND all American websites will just continue as they were before, except now with an extra competitive advantage.
One problem I have with current cookie law, is that it pretty much forces cookies upon those who actually know how to disable them. If someone browses with cookies disabled, they get all these annoying warnings and yet no way to turn them off - because turning them off requires a cookie! Insanity.
And the relevant governing body has pretty much admitted that you'll probably be ok with just a clear description of cookies used. (See the response to nocookielaw.com)
Oh AND all American websites will just continue as they were before, except now with an extra competitive advantage.
Does CookiesOK do any type of moderation over the cookies? Checking for domain scope, cookie flags, reasonable expiration of the cookie?
I understand that "free" sites need advertising revenue, and unfortunately a lot of ad networks want to track my every move - how about enforcing a compromise where cookies are allowed for X minutes after I hit the page?
Security-wise, I'm more interested in enforcing that cookies sent over SSL are not readable via standard HTTP. This tool is a step in the right direction, but I think a few more features would make it pretty attractive.
I understand that "free" sites need advertising revenue, and unfortunately a lot of ad networks want to track my every move - how about enforcing a compromise where cookies are allowed for X minutes after I hit the page?
Security-wise, I'm more interested in enforcing that cookies sent over SSL are not readable via standard HTTP. This tool is a step in the right direction, but I think a few more features would make it pretty attractive.
> Does CookiesOK do any type of moderation over the cookies? Checking for domain scope, cookie flags, reasonable expiration of the cookie?
Based the "how does it work" section of their site, I don't think it does any sort of moderation/validation/inspection of cookies before trying to auto-click the consent button. My impression is that it's strictly a DOM-level utility and doesn't hook in at the network level where it could observe or manipulate cookies over the wire.
Based the "how does it work" section of their site, I don't think it does any sort of moderation/validation/inspection of cookies before trying to auto-click the consent button. My impression is that it's strictly a DOM-level utility and doesn't hook in at the network level where it could observe or manipulate cookies over the wire.
This plugin has a way for web developers to make their website compatible with this plugin. This seems pointless. The law is clear that, although you the developer can rely on web browser settings, those settings must give the user consent (default web browser 'accept all cookies' do not meet this). Using this plugin would not meet the "give the user consent", so you cannot rely on this plugin and be inside the law.
I think making your cookie notice work with CookiesOK is about as legal as just turning off your cookie notice.
I think making your cookie notice work with CookiesOK is about as legal as just turning off your cookie notice.
I think you are missing the point. The plugin is for end users who want automate the process of giving consent, similar to how a password manager plugin might help you automate the login process.
If a web developer wants to make their site compatible with CookiesOK to improve the browsing experience for the subset of their users with the plugin, what's the harm?
How end users indicate their consent should be entirely up to them. Would you prefer users solve a CAPTCHA when opting-in to cookies?
If a web developer wants to make their site compatible with CookiesOK to improve the browsing experience for the subset of their users with the plugin, what's the harm?
How end users indicate their consent should be entirely up to them. Would you prefer users solve a CAPTCHA when opting-in to cookies?
The plugin is for end users who want automate the process of giving consent, similar to how a password manager plugin might help you automate the login process.
The page has a section on "Making my website Compatible". The plugin explicitly looks for the "CookiesOK" CSS class. This plugin is designed and partially aimed at web developers.
If a web developer wants to make their site compatible with CookiesOK to improve the browsing experience for the subset of their users with the plugin, what's the harm?
Well it's against the law. The harm depends on your country. It could be a fine of thousands of euro, and potentially an injunction shutting down your website.
The page has a section on "Making my website Compatible". The plugin explicitly looks for the "CookiesOK" CSS class. This plugin is designed and partially aimed at web developers.
If a web developer wants to make their site compatible with CookiesOK to improve the browsing experience for the subset of their users with the plugin, what's the harm?
Well it's against the law. The harm depends on your country. It could be a fine of thousands of euro, and potentially an injunction shutting down your website.
Cookies are NOT OK, I don't want to see them, and just show me the article (or page I originally came to view), thanks. And after I have viewed it, and if I decide to become a user of your site - then you will have my permission to use cookies.
The click through pages are the worst (like what www.games-workshop.com has). The pop-up/notification bar some news sites have (like bbc.co.uk) is somewhat acceptable, while obnoxious, as it allows you to read the content without accepting the cookies, and just go your merry way when your're done.
So this plug-in is going to auto-accept the cookies on your behalf. But why would you want to do this?