Hacker News new | ask | show | jobs
by Phemist 2 days ago
> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.

So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...

4 comments

Don't fall for the "we are just stupid" propaganda, which is used constantly by governments acting in bad faith.

Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.

This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.

But I don't want to delete cookies? I want websites to use cookies that are technically necessary e.g. for keeping me logged in. I just don't want them to use it to track my behavior especially inter-website.
The EU law already allowed technically necessary cookies without any banner.

Every time you get a cookie banner with options, the website wants to know more about you than the law permits by default.

... or cargo culted a site that did. I think this is far more common. It's almost like you're not a serious web site if you don't have a cookie popup of some kind.
Interwebsite is solved by partitioning and login cookies are solved by explicit whitelisting.
You think the average user is going to explicitly whitelist? The law requires sites to whitelist their own cookies under penalty of law, instead.
> You think the average user is going to explicitly whitelist

When prompted by the browser on first login/signup, yes, the same way the password manager works. With stored passwords, keeping the login cookie doesn't even add much value.

What about the other 200 unskippable prompts you get just by opening the website?

Well, there is a skip button. It's labelled "accept all"

It’s not about cookies. It’s about what the site is allowed to do with your data. Cookies are an implementation detail.

It’s baffling we’re having this misunderstanding on this site in 2026 still.

Is there any other way to get that data? It's clearly about cookies but it's specifically about tracking cookies.
Sure but these are all the same thing as cookies.

And BYW, browser headers can even be a violation if it's determined that you are using them for tracking users in a way that violates ePrivacy demands.

It's still a cookies thing.

Browser fingerprinting is not cookies. Cookies are a very specific technical thing.
GDPR is not about cookies, and what data do you mean? The data about how you use the site, tied to anything they can identify you with?
This framing of the banners as cookie banners is a dodge. It's not about cookies.

The cookie banner isn't about the usage of cookies, it's about _the underlying tracking_. You're allowed to "just" use cookies for normal shit! You can make a website where you use cookies to store login state for a user, without a single banner.

The thing is that every company in the world feels the need to add 1000 tracking cookies to anonymous users to track them through conversion funnels (on top of the ad stuff). That's what you have to inform people about

You can use cookies normally without a banner! You can't track without consent! Every cookie banner is actually a "we want to track you" banner. Calling it a cookie banner is playing into the confusion about what those banners actually are meant to communicate

changing IP is not really enough for privacy, there is many ways to fingerprint your machine/browser and uniquely identify you across networks

https://creepjs.org/checker

No, but it's the obvious starting point. You can then put additional laws on top banning fingerprinting out of band (if you care about window dressing), fund development of anti-fingerprinting technologies, fund Tor, run exit nodes in a transparent and publicly auditable fashion, etc.

It's not hard to make privacy work when you are the government rather than working against a hostile one.

We have those laws. You need consent regardless of how you get the data. That’s they say “we value your data” (a phrase you can read in two ways) and ask if 1368 partners can have it for various uses.
Is there any reason to believe that the current laws being passed by the UK, EU are against the will of the people? Everything I have seen makes the "anti-porn" laws or whatever seem extremely popular.
Exactly. Nobody wants to go to a news website/entertainment website/informational website that relies on ad revenue because they will get bombarded by banners and then by a huge number of ads that were increased because those banners slashed their ad revenue.

So instead everyone stays on Facebook, Instagram, Reddit, and Twitter, which ALSO operate on ads and have far more information on their users than any third-party ad tracker could ever have.

None of this has gotten rid of the privacy problems. It just consolidated them into the worst offenders while jeopardizing the plurality of the web. Now instead of people being tracked by Facebook on a website with a third-party cookie in a like button, they are tracked by Facebook on Facebook in a Facebook page because they never leave Facebook.

I think it's because every single website breaks if you don't allow cookies at the browser level. Some knowledge of what the specific cookie does was necessary.
You mean we had the DNT flag in the browser.
The problem there is that parent's won't know how to do it, or won't care. Many can hardly operate the most user-friendly phone, let alone manage accounts.

The online safety acts and its EU counterparts are somewhat risky, but nobody wants the mention the only proper alternative: a total ban on "social media." Not just for kids, but for everyone. Or a ban on smart phones, that would work too, at least short term. But: money.

> The problem there is that parent's won't know how to do it, or won't care.

This is unfortunately the reality.

The other day a friend asked me to help her make her phone safer for her kids to use. I started by asking if she set permissions on the apps she downloaded. She looked at me blankly, "What permissions?". I proceeded to show her how you can granularly control what you allow each app to do on your phone and what access it is allowed. Her head blew up, she had no idea any of this existed and after gong through a few menus, she didn't care any more. It was all too complicated and too much to think about for a busy mum.

This is why governments unfortunately are having to try to protect people from themselves. As tech competent people it all seems so simple to us, but we need to remember the majority of the population just click 'Allow All' and blow past all permission and security questions as they have no idea what any of it means.

"is this device for you, or a child" is one of the first options when setting up an iphone.

I haven't set up an Android in a while, but, I doubt it's massively different.

Yeah but most parents devices are for them, they just let their kid use it too.
Ah, I guess it's impossible to have a quick enable kids mode then.

We should just give up and give random individuals access to everyone's camera roll.. no other way.

It is probably technically possible, but as almost twenty years hasn't been enough to implement this feature in either of the big mobile systems, it's obviously a huge practical challenge for Apple and Google.
Is there a term for agreeing with someone's stance but disagreeing with the person because they're so insufferable and sarcastic in the way they present the argument?
it's very simpler, i recently got an android tablet for my child and it would take a lot of effort to miss all the stuff about setting it up for a child
Make the default "allow none" or "child-safe" and then if the parent does nothing that's what they get.
UK mobile operators already defaulted to blocking adult sites before OSA, and lets the subscriber turn it off, which seems like a reasonable option.

It'd be even better if there was a way for people to selectively turn it off for specific devices without MITM the connections. It wouldn't be that hard to come up with a mechanism for that.

When we buy a new phone, the configuration process should ask if the device will be used by a kid. Easy and simple.

When restoring factory defaults, the same question, just in case the phone is sold, gifted, stolen or whatever.

If you are going to give a phone to a minor you should set that option right from the start.

It's ok if parents won't care. It's a choice too.
Yes, you can't make parents care, but make it easy for the ones who do, and you'll also pick up some number of those who care but only if it's not too difficult. There's no reason a parent should have to set permissions separately in 10 differents apps on a child's device.
I've build some moderately sophisticated server systems up on "bare metal" (as the kids say), know my way around a shell better than most programmers, understand networking better than most programmers, et c., and I still find restricting and monitoring kids' devices to be a huge pain in the ass. The only places it's not extremely shitty are the Switch (which still isn't great) and Apple devices.

Options between "we don't have tech in the house" and "wide-open tech, we have it all" are all some amount of painful, usually for no good reason.

(I remember once investigating how to do some pretty basic stuff for this in Linux, hoping to find something nicer than manually setting some executable permissions and firewall rules and then having to go back and change them all the time, and the closest thing to a guide I found was an old article from Red Hat that basically lead with "LOL, good luck you poor sap, Linux sucks at this" before going on to explain the various bad ways available to sort-of, but not entirely, accomplish it with a lot of work, and significant ongoing time-burden)

That's why the setting should be on the device, not the browser or individual apps. One setting that you could even get pre-configured when you buy the phone.
It still doesnt solve the problem of the millions of parents that just dont care.
Why should I care that they don't?
Right, this is the big picture nobody acknowledges. I'm not paying the price for your kid because I don't know them. I couldn't care about them even if I wanted, because their existence doesn't even intersect with my life.

Yes, as a parent, you are required to put in more effort into parenting your kid than random hypothetical people. That's obvious, and has been the case forever.

I understand the concept of community, but community is not me sacrificing my privacy for someone 1000 miles away.

If parents don't want to do X, Y, and Z to lock down their devices then that is their right. And I support their rights, so the conversation is over right then and there IMO.

Because we live in a society and trillion dollar companies exploiting children for the crime of having negligent parents is bad.

The aim here is to protect the children. "Just let parents protect them" doesn't work when there's millions of parents that won't care.

More parents will care if you make it easier.
That’s not true. Every TV app has a parent setting. That’s really easy to use browser support profiles just like TV apps do bad. UX doesn’t mean that it can’t be set up easily for parents. Windows itself could have profiles for kids that has all this set automatically. It’s not hard. There’s just no will to do it.
> There’s just no will to do it.

Exactly. The problem is its from the parents side.

Spoken like someone who has never used parental controls. They’re a shitshow.
You miss my point. It is that parents dont care. However good the parental controls are, there are millions of parents who just dont and wont ever care.
You replied to a comment saying the companies don’t care to make it easy. Then, you shifted the blame to parents instead of the companies. I got your point just fine.
Oh thank god! Thats a fantastic reason to abandon the tens of millions that do!
if parents wont make the slightest bit of effort why should the rest of us pay to keep their children safe?
Because children shouldn't be the ones paying for the crime of having bad parents. Children should be safe regardless of what the parents do, because they're independent people and not property.
you can say that about a lot of things, but we do largely trust parents. but all these social media bans seem to stem from parents who claim to be helpless, when really they are lazy and the wider impact of these laws is massive. no technical way exists to do this without taking the privacy of everyone
A bit of empathy goes a long way. That child may be your nurse one day, taking care either of you or candy crush.
It should be by default, rather than relying on the parent proactively.
A child can still access knives if the parents don't care.
That's exactly what the California's Digital Age Assurance Act does but that wasn't well-received either.
>>>>>>> now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...

THIS

Holy shit. This is such an obvious fix. And it shuts up those surveillance state goons immediately.

My God, why have we tried to summon up the ghost of 1984 when such a simple fix as this will do.

Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.

The blast radius is zero.

Good God, we need to fast track this into browsers right now. If we hurry we might be able to point to this as the technical fix.

Once some of the infrastructure exists, OS vendors can hook into it.

Firefox devs - please do this right now. Please spearhead this.

I might have to vibe code an advocacy site for the spec and set up a GitHub / RFC process.

> Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.

CA tried this with AB 1856. I wasn't a fan of this (neither was EFF) because of the privacy and tracking concerns of blasting the fact that the user is a child to all websites.

https://www.eff.org/deeplinks/2026/05/one-step-forward-two-s...

It would better for the block to happen at the device level. That is, the browser knows it's on a child's device and has a whitelist of allowed sites.

There is already an RTA (Restriced to Adults) header where the website self-labels that it's for adults only and the browser can block it while protecting the user's privacy. I'd prefer expanding the use of RTA.

It reads like AB1856 needs website operators to prove they didnt serve their content to the wrong age bracket, which requires way heavier methods than simply trusting the emitted "user is child" header (or rather, trusting that the lack of such header is not a false negative)
No offense but if you're proposing a solution that involves whitelists... that solution has already failed.

The web is too big and changes too much and that's before we get to the issue of applying laws to a whitelist based on different juristictions worldwide.

And I have to question, who would administer it? The parents? They won't. Google or Apple? Why do they want to deal with irate parents or culture wars around what is or is not on the list?

There is obvious increasing demand for this from parents, politicians are going to act on it, I think a "this is a child" header is the only one that actually really works. It works for the parents because it's easy to setup. It works for websites because they can cleanly identify a child and filter content if appropriate.

It seems to me that every other solution than a "this is a child" header is either impractical or way worse.

> that solution has already failed.

Yes, granted, a globally enforced whitelist probably wouldn't work. I'm referring to bespoke lists that parents control. I know plenty of parents that use this. e.g. here's Apple's feature:

https://support.apple.com/en-us/105121#:~:text=Prevent%20ina...

> It works for websites because they can cleanly identify a child and filter content if appropriate.

This still doesn't solve the problem of different jurisdictions and culture wars of what is or isn't appropriate for kids. All this does is move the liability upstream to websites instead of the devices. That is, instead of the browser deciding what's appropriate, now Youtube, Reddit, etc have to decide. And, as we've seen with the OSA in the UK, typically smaller platforms can't handle the enforcement cost so they just shut down entirely.

https://onlinesafetyact.co.uk/in_memoriam/

The larger platforms often use overbroad CYA measures and throw up age verification where they don't need to (Reddit has done this in the EU), or just ban minors (Anthropic and character.ai did this).

As far as blocking explicit content, a self-labeling requirement like RTA accomplishes the same thing as a "this is a child" header but without the liability CYA and without the privacy concerns.

Where the "this is a child" header solution could theoretically win is allowing kids to access websites in a limited child-safe way, e.g. going to Reddit in child mode automatically shuts off certain subreddits. But, as we've seen, it just doesn't work well in practice and usually frustrates parents by overly broad content policing and liability theater. Kids are also at different levels of maturity and I've seen them get frustrated when they're binned into age categories that they feel they don't deserve. e.g. a 12 year old might be plenty mature enough for the 13-16 age category.

But my real objection to the "this is a child header" is the privacy risk and surveillance risk. I don't think it's worth it.

You are confusing a lot of different lines of argument, and in the end I'm not even sure what you are arguing against. I think you are mostly agreeing with the proposed solution by echelon?

You mentioned AB1856 which seems waaaaay broader than emitting an age bracket header based on user settings. It puts the onus on the website operator to not only prevent presenting content to wrong age bracket users, but also to determine the age bracket of the user.

Websites are shutting down wholesale because they cannot reasonably afford the CYA, or dont want to out of principle.

In echelons scheme the parent would be voluntarily setting the age bracket on the childs device right, so if a 12 year old is more mature, then go ahead and set their device to emit the 13-16 age bracket header. If you as a parent dont believe in this, then leave the bracket unset.

For a website operator it would be trivial to block the user from accessing the site if the suggested age bracket is too low (as long as we can agree on a single way of doing things, of course). Larger operators can do more heavy content moderation and present a filtered view to those same age bracketed users.

It is true you are adding more tracking signals, and I am sensitive to the free speech issues, but children are not fully emancipated members of society yet and parents need tools to deal with the difficulties of raising children in a digital society. The alternative now seems to be OSA-like, which is even more intrusive and a risk to privacy and perhaps free society as a whole.

Of course, OSA is really the goal and not the method, and we have to remember it is never about the children. Would children have been protected from e.g. andrew mountbatten if OSA had been around at that time?

> I'm not even sure what you are arguing against.

I am against legally requiring devices to transmit a signal that the user is a child to websites. What I want instead is to handle any content blocks client-side. Instead of legally requiring adult sites to verify the age of users, I'd prefer requiring that these sites self-label (or move to an obvious TLD like .xxx), which makes it easy for the device to block it. This accomplishes the same thing without the tracking infrastructure and privacy concerns. I don't want my kid's device blasting that they're under 13 to every sketchy website that asks.

> It puts the onus on the website operator to not only prevent presenting content to wrong age bracket users, but also to determine the age bracket of the user.

I believe AB 1856 does not do that any more. As of July 1st, they amended it to remove all requirements on website operators, except one. What it does now is make the app's age signal apply "across all platforms of an application, including an internet website [owned by the same developer]." e.g. the Facebook app gets the age signal, now facebook.com knows the same signal.

Also AB1856 (and the DAAA which it amends) has no content policing requirements. All it does it force apps and websites to know the age of their users, which then triggers liability under other laws like the up-and-coming social media ban AB 1709 (which I'm against). Or CA's Age Appropriate Design Code act (which I believe is getting tossed around in the courts for First Amendment concerns).

As far as presenting a filtered view of a website, e.g. Reddit blocking some subreddits for kids, I'm open to debating this. I personally think it doesn't work and platforms will just over-regulate or wholesale ban minors (Claude, character.ai) rather than comply with the patchwork of laws in different jurisdictions. Or they'll spin off a heavily locked-down version for kids only, like YouTube Kids.

Steam is an illustrative example of how hard it is to get the filtering right. They're trying to comply with OSA but there's still a lot of information leakage between the kid-safe portion and the rest of the platform: https://youtu.be/hOaGUfy6NTw

I agree, and I agree with the enthusiasm on which you bring in.

I've long since considered that the efforts for online child safety should be pointed at educating parents and spearheading some kind of certification of compliance for child safety of software and websites.

[this product is certified to adhere to EU:CSA]

Then you can block everything not certified, and the software that does the blocking would also be certified, the two major prongs you need (endpoints and sites working together: else they're blocked). The rest of the money goes to education for parents about this fact, and the dangers of not doing it, and how to do it.

This is super "easy" (when comparing to the effort it would take for putting backdoors in everything).

Which is why I think that the reason is definitely not child safety, and more about crime control.

Me talking about UK blocking people unless they ID themselves in 2013: https://news.ycombinator.com/item?id=6979295

Me talking about how its disingenuous because we have superior technical solutions to this particular issue last year: https://news.ycombinator.com/item?id=45010902

This will work... if you think this is their true motivation, and the panopticon itself isn't the true end goal.
That works well for controlled devices like phones, tablets, and TVs, but it’s much harder on desktops unless you expect parents to become IT administrators.
What's wrong with asking the user on account creation and OS install?
It'd need to be vertically integrated from OS to user space apps, and restricting what can be installed.

I'm not sure to understand the proposed solution here, but it seems someone could just use a different web browser client who don't inherit these restrictions.

California AB1043, in other words
Make a website about that. I’ll spread it.