Hi,

In Spain (and probably other places in Europe) we’ve recently seen a deluge of cookie banners that offer you the option to reject tracking cookies for a fee. The regular GDPR forms are therefore slightly broken, as you get several options: accept, reject (which doesn’t work in most cases), and buy a subscription to reject. Consent-O-Matic, for example, is having a hard time. I don’t doubt it’ll get corrected in time, but I want to talk about something tangential.

Cookie consent has (at least) two layers: the browser layer (where we might delete cookies, reject third party cookies, etc) and the site UI layer (where we’re presented with an option when we load the page). This means we can reject third-party cookies at the browser layer and then accept whatever form at the site UI layer.

With the set up mentioned above, is there really any difference between accepting cookies and rejecting cookies? No tracking cookie are going to get installed in my computer anyway. This, combined with an ad blocker, makes the browsing experience exactly the same whether I accept or reject the cookie form. Is there anything I’m missing here?

  • beta_tester
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    10 months ago

    I know how web fingerprinting works. I don’t visit sites regularly that use advanced techniques which shouldn’t get my info, and if, I would overthink my web browsing behavior. For regular websites it’s just too much of a hassle to use advanced fingerprinting methods

    • RovingFox@infosec.pub
      link
      fedilink
      arrow-up
      1
      ·
      10 months ago

      How do you know they don’t use “advanced techniques”? I think you gravely overestimate the complexity of adding them to a website.