this post was submitted on 10 Sep 2026
303 points (100.0% liked)

Privacy

50879 readers
896 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
 

Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. Unfortunately, the tracking industry is pushing back – and so far, they’ve been successful. We need YOUR help to #KillTheCookieBanner!

top 45 comments
sorted by: hot top controversial new old
[–] SirLeToet@lemmy.world 20 points 1 day ago* (last edited 1 day ago)

I would wish the EU would be more strict in its laws. Cookiebanners are NOT required when you only use functional cookies that the website technically needs to work. I never had to show the banner for my websites, because I simply don't include 3rd party bullshit, no ads, no tracking.

Same with the new age rating rules, websites and communities that aim at CHILDREN are required to not be invasive when checking for age (ID checks are last fucking resorts!). If your website or community is obviously 18+, like porn, gore and such websites. There is no requirement for an age check!

Fuck the companies abusing our EU systems and that put the EU in a bad spotlight because of RABBLE RABBLE RABBLE social media ragebait.

Why the fuck is it socially acceptable for billion dollar (foreign!) tech companies to manipulate our children?

Why did we normalize getting our asses spied on? And why are we accepting the excuse of these tech companies to scan our ID's and passports?

The GDPR does not allow scanning of identity cards/passports except for a very limited section. Like: banks, your employer, your health insurance and your government. These tech companies are not on the GDPR VIP list.

[–] dreadbeef@lemmy.dbzer0.com 46 points 2 days ago (2 children)

The EU back when they were deciding GDPR decided not to use the browser's "do not track me". The W3C even tried to help them and during the making of GDPR a commission even recommended using DNT signals.

Capitalism and advertisers won of course and they decided not to follow DNT signals from the browser. Why will they change their mind this time?

[–] cheat700000007@lemmy.world 7 points 2 days ago

Because it actually impacts themselves in a visible way

Maybe because before it was out of sight and out of mind. But now it's in all their constituents' faces, and we're annoyed

[–] umbrella@lemmy.ml 20 points 2 days ago (1 children)

it's all done with fingerprinting now anyway

[–] Squizzy@lemmy.world 2 points 1 day ago (2 children)

Time to find the most restrictive browser in terms of shared info

[–] catdog@lemmy.ml 1 points 17 hours ago

Share nonsense and periodically change it. Restrictions are a fingerprint itself.

[–] umbrella@lemmy.ml 3 points 1 day ago (1 children)
[–] Squizzy@lemmy.world 1 points 1 day ago (1 children)

Isnt that like a whole other network though. Its own domains and browsers unreachable by traditional browsers

[–] umbrella@lemmy.ml 2 points 1 day ago (2 children)

you can access the regular clearnet through tor.

every tor browser is standardized therefore resistant to fingerprinting, plus you get a different IP every time.

[–] Squizzy@lemmy.world 1 points 1 day ago (1 children)

Do you expose yourself by joining the network, is there precautions to take? Is it the onion browser?

[–] umbrella@lemmy.ml 1 points 1 day ago

yes, the tor browser is the easiest way to use tor. you expose to your ISP that you are using tor, but what you do in there is encrypted.

if you live in a place that frowns upon merely using tor, the standard precaution is using the available tor bridges. it's good practice to keep the tor browser stock.

[–] freely1333@reddthat.com 1 points 1 day ago (1 children)

Mullvad browser being a non tor alternative.

[–] umbrella@lemmy.ml 3 points 1 day ago (1 children)

and also a non private, fingerprintable one

[–] freely1333@reddthat.com 1 points 1 day ago* (last edited 1 day ago) (1 children)

It’s tor browser without the tor network. You can use a vpn. Unless you’re trying to hide from a three letter agency or nation state, it is generally enough. And nobody who doesn’t already know this is going to have good enough opsec to make the difference matter when it comes to that.

[–] umbrella@lemmy.ml 2 points 1 day ago* (last edited 22 hours ago) (1 children)

It’s tor browser without the tor network.

i don't get what you mean by this. a browser is not a tor browser without going through the tor network.

vpns completely expose you to the vpn provider, AND won't help with anything related to privacy when using a regular browser that can be fingerprinted anyway.

fingerprinting is the main way in which you are tracked on the internet.

[–] pineapple@lemmy.ml 1 points 21 hours ago (1 children)

The alternative is exposing yourself to your isp. So it depends which one you trust more.

Either way with https and dns over https browser traffic and dns requests should be well hidden from the isp or vpn provider.

[–] umbrella@lemmy.ml 1 points 19 hours ago (1 children)

you are right. though as i said, what matter most is that the https site on the other end is 9/10 compromised by facebook, google or twitter scripts plus a slew of other ad companies. they are the ones tracking you everywhere.

[–] pineapple@lemmy.ml 1 points 18 hours ago

This is the main concern. Which is why using ublock with the right filters is so important as well. Although it still doesn't protect from fingerprinting.

[–] slazer2au@lemmy.world 39 points 2 days ago (3 children)

I am in favour. Until then you can use consent-o-mattic to actively deny cookies instead of just hiding the element.

[–] GalacticGrapefruit@lemmy.world 15 points 2 days ago

I was about to recommend Consent-O-Matic! Digi-gods bless Aarhus University and their compsci students for building something so wonderfully useful.

[–] 3scene@lemmygrad.ml 5 points 2 days ago (1 children)

Denying consent is just 1 part of the puzzle. You will still be accepting all "legitimate interests".

[–] yxc999@lemmy.ml 2 points 2 days ago

Who the fuck defines "legitimate" interest anyway, they can go fuck themselves with their "legitimate", I hate it so much

[–] _MadBits@lemmy.dbzer0.com 14 points 2 days ago (4 children)

For the past 10 years or so tracking is done with hardware fingerprinting anyways. Cookies are of the past.

[–] Skasi@lemmy.world 12 points 2 days ago (2 children)

I understand the argument, but afaik the laws that made poeple create cookie banners do not really care whether it's a cookie or some other identification. Consent has to be granted for any sort of tracking.

However, as far as I understand, at least in some parts of the world, this is only true for 3rd party tracking solutions. So long as people can't be identified and everything stays with your own host, consent would legally be unnecessary anyway.

[–] blackbeans@lemmy.zip 20 points 2 days ago* (last edited 2 days ago)

More accurately, there has never been a EU law that forced people to create cookie banners.

The EU law required websites to have the users' consent to use personal data and tracking. The law never even mentioned the word "banner" but this is what the industry chose as a solution.

Furthermore consent is not needed for functional cookies. So all websites that enforce cookie banners upon users do really use tracking/data sharing or their partners (such as Google Analytics) do.

[–] _MadBits@lemmy.dbzer0.com 2 points 2 days ago (1 children)

I am not against cookie banners, I own a few web apps and each of them have proper configurable cookie settings (including the banner).

All I am saying is that most companies (especially one's that do not reside in EU) do not care and will track you across websites by fingerprinting your hardware when visiting their website. Some do not even use cookies at all.

[–] grue@lemmy.world 2 points 2 days ago* (last edited 2 days ago) (1 children)

I own a few web apps and each of them have proper configurable cookie settings (including the banner).

Configurable cookie settings are not "proper." Unconfigurable eschewing of not-strictly-functional cookies is "proper."

Don't delude yourself into thinking your malicious compliance is "proper!"

[–] _MadBits@lemmy.dbzer0.com 2 points 1 day ago

My web apps lack any telemetry, the only cookies that get set are for sessions, users settings and various redux like storage on client side which can be opted out. It's more than proper. :)

[–] yes_this_time@lemmy.world 4 points 2 days ago* (last edited 2 days ago) (1 children)

Genuinely curious, why can't browsers add some (non meaningful to users) jitter to values used in fingerprints such that fingerprints become random for a single user?

[–] dubs@lemmy.dbzer0.com 6 points 2 days ago (1 children)

They totally can. They just don't really care, because they are mostly funded by advertisers.

And technically since very few people do such things, they are usually fairly obviously not the real details and the faked details end up being unique enough to just dump you into the "hates advertising" ad bucket which just means they try (and often succeed) at marketing to you through other means.

[–] grue@lemmy.world 1 points 2 days ago* (last edited 2 days ago) (1 children)

Laws don't care about technical 'gotchas'. If the law says tracking is illegal, it's illegal whether it relies on cookies, fingerprinting, magic pixie dust, or literally any other applied phlebotinum you could possibly think of. It simply does not matter what the means are if the intent is to track.

[–] _MadBits@lemmy.dbzer0.com 1 points 1 day ago

That's not how the industry works.

Also, here, fixed your statement for you: Privacy laws generally don't let you evade a restriction simply by changing the technical mechanism used to achieve the same tracking or identification. Whether something is a cookie, fingerprint, local-storage identifier, or another technique is often less important than what the technique does and what legal rule applies to that activity. However, the mechanism can still matter because different laws and provisions regulate different technical activities, and lawful tracking is not necessarily prohibited merely because its purpose is to track.

[–] moldy_rice@piefed.keyboardvagabond.com -2 points 2 days ago (2 children)

Hardware fingerprinting doesn't work very well when the hash changes significantly when your battery charge changes one percent.

[–] _MadBits@lemmy.dbzer0.com 2 points 1 day ago

First of all, you're the one to choose what you're fingerprinting for, and if you include the battery or such changing factors maybe you should rethink your career as an engineer.

[–] boonhet@lemmy.zip 6 points 2 days ago

Which hash exactly? They don't have to include your battery percentage if they don't want it.

[–] blackbrook@mander.xyz 4 points 2 days ago

Why just email one? It would be nice if they gave you a comma separated list of them all...

[–] kehet@sopuli.xyz 10 points 2 days ago (1 children)

I hope this becomes mandatory, I think DNT failed because it wasn't

[–] lime@feddit.nu 8 points 2 days ago

dnt failed because it relied on you sending more information to sites you visited.

[–] yxc999@lemmy.ml 0 points 2 days ago (1 children)

Well I mean I support the message, but please pay an artist instead of using these ugly AI generated images.

[–] taco_shale032@lemmy.ml 2 points 2 days ago (1 children)

What AI generated images are you talking about?

[–] yxc999@lemmy.ml 0 points 1 day ago (1 children)

First image: why is she typing on the edges of the keyboard, why is the keyboard just one rectangle, why is the trackpad split in two

Second image: the server is the most unsymmetrical thing I have ever seen and her hands don't make sense

Third image: the guy is just holding the sign with his wrist, not with his hand and the sign itself is so straight it looks photoshopped in. Well or just placed in by an AI. Also, the backglow of the sign appears behind the people, not behind the sign

Fourth image: the guy had five fingers on the megaphone, the woman only has four. The woman has five fingers on the paper, the guy has a crab hand

This is some mayor fucking AI slop.

[–] taco_shale032@lemmy.ml 0 points 1 day ago

I could be wrong but I don’t believe the art is generated and I’d say I’m pretty good at spotting that type of content.