this post was submitted on 15 May 2025
48 points (100.0% liked)

Privacy

0 readers
11 users here now

Everything about privacy (the confidentiality pillar of security) -- but not restricted to infosec. Offline privacy is also relevant here.

founded 2 years ago
MODERATORS
 

Those annoying “consent” cookie pop ups that Big Tech has been using as part of their malicious compliance efforts to convince you that data protection law in the EU is a nuisance?

Turns out they’re illegal.

https://www.iccl.ie/digital-data/eu-ruling-tracking-based-advertising-by-google-microsoft-amazon-x-across-europe-has-no-legal-basis/

#TCF #consent #data #privacy #EU #GDPR #BigTech #maliciousCompliance #SiliconValley #adtech #technoFascism

all 19 comments
sorted by: hot top controversial new old
[–] [email protected] 8 points 2 weeks ago

Check out the Consent-o-matic plugin for Firefox. It will deal with the majority of those for you. https://addons.mozilla.org/en-US/firefox/addon/consent-o-matic/

[–] [email protected] 3 points 2 weeks ago

Ublock has an "annoyances" filter section that removes 95% of these

[–] [email protected] 2 points 2 weeks ago

Now we just need someone to explain it to them in language they can understand. So don't charge them peanuts or “I'll pay out of my petty cash as a tip”, but in a way that has a real learning effect or, even better, a deterrent effect for these grifter actors.

@[email protected]

[–] [email protected] 2 points 2 weeks ago

@[email protected]

It's great to see it being actively called out in a court of law. How will this be enforced? Companies will not comply unless compelled to do so.

It would be great if part of the requirements on these companies is that they're already collected databases (and any/all backups) had to be 100% wiped.

Along with that, a respected tech outlet should detail how the average person can install add-ons (Ghostery, uBlock Origin, etc) to their browser to help negate this sort of thing from happening again.

Then offer a more advanced method (ie. PiHole with suggested block lists) for those more savvy.

[–] [email protected] 2 points 2 weeks ago (1 children)

@[email protected]

The "cookies" thing is a red herring.
Two observations:

  • Most sites have already set cookies before the pop-up. After it, they set at least one more.
  • The cookies themselves are fairly harmless. The harm comes from the 3rd-party objects that many web pages pull in. google analytics, google fonts, facebook icons etc. I've even found banking web pages that access google even though (or before) you decline.
[–] [email protected] 1 points 2 weeks ago* (last edited 2 weeks ago)

I can't remember if the latest recommendation is that using LocalCDN or Decentraleyes is good because it blocks those CDNs from tracking you, or bad because it makes your browser fingerprint more unique.

[–] [email protected] 1 points 2 weeks ago

@[email protected] keeping all weblings employed

[–] [email protected] 1 points 2 weeks ago

@[email protected] i'll confess to ignorance here. I see a lot of popups and I know the big lines of gdpr, but I don't know what TCF actually is. I couldn't understand from the link or a quick search. Is there a 5-year-old-with-IT-background explanation somewhere?

[–] [email protected] 1 points 2 weeks ago
[–] [email protected] 1 points 2 weeks ago

@[email protected] that’s one way to fix the internet!

[–] [email protected] 1 points 2 weeks ago (1 children)

@[email protected] I see those warnings as:

"Don't visit this site"

It often works since my mouse clicks on the little cross 😀

[–] [email protected] 1 points 2 weeks ago

@[email protected] This is the first time I've encountered the phrase "malicious compliance", and it's so concise, descriptive and accurate. Thanks!

[–] [email protected] 1 points 2 weeks ago

@[email protected]
So is a huge fine being sent to all of them or just a slap on the wrist?
#Google, #Meta, #Amazon, #Apple, etc don't care about #EU ruling. Until fines TRULY hurt their pockets, they prefer to continue with their profits and pay the price once in a while.
How many of these companies have been fined for similar behaviour in the past? Have they changed it? Yes, they are making their malpractices more hidden and sophisticated.
Bureaucrats don't understand tech well enough to punish them.

[–] [email protected] 1 points 2 weeks ago

@[email protected] "- What pop ups?"
...says the guy using consent-o-matic.

Seriously: i recomend it, it's a great tool directly addressing such malicious compliance and associated dark patterns.
https://consentomatic.au.dk/

(note: on mobile you have to use FireFox as other mobile browsers do not support extensions)