Hacker News new | ask | show | jobs
by chrismorgan 2 days ago
The other approach to killing the cookie banner is simply to declare that such a thing cannot constitute “informed consent”. (Perhaps: “ticking a checkbox and/or clicking a button cannot constitute informed consent”; and see what they try next.) From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way. Just as shrink-wrap licenses and even simple contracts have at times in some jurisdictions essentially been neutered, so that only terms that a reasonable person would expect to be there are enforceable, at which point it becomes obvious that the whole thing needs tearing down in favour of standard licenses/contracts. In the Australian state Victoria, for example, there are standard rent and property sale contracts; for renting you must use that contract <https://www.consumer.vic.gov.au/housing/renting/starting-and...>, and I got the impression that residential sales practically always use the standard contract.

But of course it’s impossible to convince someone of something when their livelihood depends on their not understanding it.

7 comments

> it’s well-understood that very few people actually read those things, they just want to get them out of the way.

This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data mining, profiling, and other privacy-related aspects. But in many cases, you could just click "reject" and the banner would also disappear...

To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.

"Accept all" always makes it go away immediately.

Some variant on "reject" takes more effort like 70% of the time. Which is on purpose, of course. The ones that aren't maliciously-complying have a "necessary only" button that insta-closes it, but tons pretend that you might want to allow some spying but not all of it and make you go through another screen if you don't just "accept all".

> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.

Then it'd be possible to default it to "nope" (Firefox, and perhaps Safari, might do this) or to allow a "never, anywhere" setting the first time the question is asked, and malware and spyware vendors know that'd mean a much larger proportion of denials.

"necessary only" also tends to have a malicious compliance aspect where they don't store a cookie recording your preference and show the banner on every single page until you click accept.
Perhaps I am overly optimistic in thinking this is just incompetence.
Yes, you are. The legislative process around EPD/EPR fully anticipated the malicious compliance and it became a back-and-forth political football long before anything was passed. The legislators were never dumb and the corporations were always greedy+powerful.
I had one of the providers recommending us that we leave the "Decline All" button out of Europe, since it's not widely prosecuted, buy recommended that we add it to California, since chances are slimmer.

Naturally in a camera meeting with a "don't tell anyone we said that" appended right before.

The marketing people in the meeting were very angry that California was "doing it to them".

If they fully anticipated this then surely they could've fully anticipated how annoying and useless cookie banners are?

There is nothing stopping a website from using cookies regardless of the banner. If they are outside EU jurisdiction then there won't be any consequences either.

The legislators were and are dumb. They have wasted an enormous amount of collective time for no benefit. Big corporations continued doing what they were doing and nefarious third parties could still track you.

Well, maybe it is... but then the PM never prioritizes testing or fixing the problem. They're not intentionally trying to get more people to accept cookies, it's just that there are always more important features to build and fires to fight, and fixing the cookie banner won't move any of the metrics executives are breathing down their necks about, and it won't look good in the perf packet...

But of course, designing the system that pushes people to make this sort of decision was absolutely intentional.

So even when it's incompetence, it's still malicious, just in a way that obscures the explicit decision-making that led to the result.

I don't see that as malicious. Is my consent record "strictly necessary"? No. Don’t get me wrong. I’m sure they love that, but if sites saved that preference when only necessary was selected, I’m sure a bunch of people would be screaming that they weren’t following the law.
The entire banner is malicious. They don't need consent for necessary or functional cookies. They only need consent to track you - at no benefit to you ever.
I don't think anything is actually "necessary" if you want to be strict on definitions.

I think it's absolutely fair and unlikely to be illegal to use a cookie to remember cookie preferences. Unless the cookie value was not yes/no, but something like a precise timestamp that could be used for uniquely identifying.

Yes, it is strictly necessary to properly honour the user's choice. Not storing a rejection of consent but storing acceptance violates the GDPR because it creates an asymmetry between the effort required to accept vs the effort required to reject user data processing.
The malicious compliance aspect is that they're not offering a choice between "tracking" and "no tracking", but bundling "no tracking" + "painfully degraded functionality" (like repeating the question on every page) = "strictly necessary cookies only"
There is no legal requirement to ask for consent for first party functional cookies. The cookie banner is only for invasive 3rd party trackers.
which they can be sued for as that's not compliant way to handle it. Just that nobody bothers
IIRC it was ruled by a court that "reject all" must be as easy to use as "accept all", but nobody actually follows it because enforcement is lacking.
It literally does not matter what you pick on these things - most of them don't work anyway. Think about it: Of course they don't. All the third-party javascript is already on the page. Anything you do inside the sandbox with UI provided by, usually, some other third-party, can't just magically force all that other code to behave in a specific way, unless someone has done a great deal of work to integrate the cookie banner code. If the first-party site were that competent at instrumenting every bit of third-party code the marketing department threw at the website department, they wouldn't even need the third-party cookie banner vendor in the first place.

Clicking those "REJECT!" buttons might make you feel empowered, but it's pointless. Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you.

The whole thing has always been a problem to be properly solved by the browser, and it's probably just the fact that Google makes the only browser that matters, that it's been foisted upon every website owner, who mostly just wants basic analytics and to track conversions from the ads they run, and isn't "selling your data."

The browser is your user agent. If it's sending any information up to web servers on every request that isn't okay with you, why are you using it?

Captain Compliance consent banners work but most do not and that is the issue but in time enforcement will make it that they will all work or else there will be consequences.
While I don't usually laud Wordpress plugins, I know of at least one WP plugin, that gets it right and that allows one to specify all kinds of scripts and stuff to load after consenting. Of course people still manage to use that wrongly and load third party stuff before consent. What I want to get at is, that one of the most widely used things to make websites, that even businesses use, has all the means to do it correctly, but businesses decide to do a shitty job and do illegal shit. Very often at the behest and nagging of marketing departments, who are chasing pointless metrics and "KPIs".
> Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you

Exactly. I use the "I don't care about cookies" extension, which rejects most cookies automatically without me having to see the popups. But even accepting cookies is fine - I'll be closing my browser soon anyway and they'll be gone.

I'll be closing my browser soon anyway and they'll be gone

Sure, your browser cookie will be gone. But you have already allowed the server-side identifiers of your session to be used for whatever purpose, including reconstituting increasingly larger parts of your identity over multiple disconnected sessions. Please don't make the mistake of thinking that clearing your cookies afterwards is the same as rejecting all server-side processing.

Sure, but "rejecting all server-side processing" is basically trusting the website to honor my wishes. I don't put much faith in that at all.

They'll have my IP and browser fingerprint. Using Firefox mobile narrows me down to 1-2% of the world, but also lets me run ad blockers and noscript, to block some of the more troublesome trackers.

It's all tradeoffs...

Despite this being called a "cookie banner", this is not _just_ about cookie. When you click "Accept all" you are giving your consent to any form of tracking and information sharing mentioned in the details. The site you visit may share everything they know about you with any third party they mentioned. They can even use fingerprinting (if you've agreed to it) to keep tracking you after you've deleted the cookies.
And then? What's the practical, concrete, real-life consequence for me? Nothing, not even a bit more relevant ads as these run into my adblocker anyway.
It's not only about you. It is about a practice, that is manipulative and even endangering certain kinds of people. By not caring about these things, we as a society have made the Internet a dangerous place in some regions for journalists and other types of people.
Yeah honestly I just assume sites fingerprint and track to the extent the visitors allow.
The naming of that extension is misleading then. You do care about cookies ... not ending up on your device. Does it really reject the cookies, or does it just default to accepting everything, because "one doesn't care"?
Yeah they can, they can also get fined 2% of a year's gross revenue for doing so
Well, joke's on me: I use that extension too. And I never close my browser.
I think you're right that many (most?) CMPs are broken, though usually not deliberately. Most try to gate analytics and ad tracking on consent, just often misconfigured. The common exception is companies that deliberately hide Reject All, which is not complaint

My company scanned 209 European regulated sites in June, and roughly 7 in 10 had tracking that wasn't correctly gated by consent. It's rarely indifference, though. DPOs in the EU hold too much weight for that. It's usually a tag added that was never wired into the CMP or something added by a dev or LLM without going through proper review

Full disclosure: I run https://consentmark.com, which measures what tags actually fire under each consent state to create evidence packs companies can show regulators

I don't buy it. 70% of the CMPs being "misconfigured" tells us that even if these panels were broken by design, the companies using them must all conveniently not notice this. Strange, given that even a small risk of large fines or prolonged legal process with public entities would warrant someone paying at least a moment of attention to this. I suspect they are, and the choice of leaving things misconfigured is deliberate.

> something added by a dev or LLM without going through proper review

FWIW, this was a problem long before LLMs were a thing, and it didn't get worse with LLMs. If anything, I'd expect LLMs to get it right by default, because ones ~everyone is using are all trained straight, they won't just silently read between the lines and write code/configs to facilitate one's illegal business model.

> I suspect they are, and the choice of leaving things misconfigured is deliberate.

That honestly doesn't fit our data or my experience. In our scanning, about 60% of the misconfigured sites had a CMP with blocking active but one or two tags bypassing consent controls

Generally those misconfigurations aren't valuable to the business. We don't see for example lots of ad targeting and conversion tracking firing without consent on an otherwise compliant site.

What we do see is things like sites with CMPs generally working, but one or two analytics events tags firing because consent wasn't properly added to a trigger, or embedded Youtube cookies set without consent, or unexpected data from a URL or query param being accidentally ingested by tracking, or devs adding performance monitoring or observability tools to applications without realising the compliance implications

There's not much business logic in paying for a CMP, blocking your own ad stack, but then letting three analytics events pass through

> FWIW, this was a problem long before LLMs were a thing, and it didn't get worse with LLMs.

This isn't supported by our experience. In the last 18 months, we've seen a big increase in ungated tracking that we catch in CI (albeit with overall much higher velocity in general). LLMs will happily add non-compliant tracking to sites, often following defaults that might be acceptable in the US but not EU. If you push back, they'll also happily implement compliant tracking, but it's definitely not the natural default you can rely on

But your comment left me curious, so I just ran an experiment via Codex -p (gpt-5.6-sol) and Opus 5 via Bedrock

Codex returned the vendor quickstart on 5 of 5 neutral prompts. It gated properly when told the company is Irish, with full Consent Mode v2 defaults denied, GA4 only mounting after consent, with a reject button

So models can produce compliant/non-compliant code based on the context you give them, which reflects what we've seen in industry

Our business is giving devs and increasingly LLMs efficient tests to check the tracking they add is as expected for the EU and then providing signed evidence packs that prove that behaviour at a given time

Another tiny data point example: A previous company used Stripe for a very niche feature (most companies who used our product didn't ever enable it) but having the SDK in the bundle drops their "anti-fraud" cookies, whatever they are). That is exactly the kind of thing that a CMP won't be able to fix without deeper engineering work, and which doesn't actually matter anyway because no one is profiting from that -- but that's the kind of thing that a company could be sued or fined for. A complete distraction from what actually matters.
It's a nag-box that appears every time someone visits a new website. Of course people are going to click it away as fast as possible. In the few cases you repeatedly visit a website one might want to reconsider, but by then it's out of mind due to not being shown after giving consent.

It is known that warnings and pop-ups that show up almost all the time yield diminishing returns. I think it was named "normalization of deviation" by some folks in a blog a while ago, and I believe that name fits. If you get warned about missing https all the time, or that something might be dangerous (even though it does precisely what you want it to do), it will loose its effect by the time you actually need it.

You can argue this is malicious compliance, but if you want it to go away it would probably be easier to go for banning tracking and personalized ads altogether. Eliminate the reason for this behavior, so to speak.

> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.

There is one. It's a DNT header. Knucklehead websites ignore it.

Including the one we're posting on
What tracking does HN do?
That is for Y Combinator. I would characterize HN as less than a fair bit;

> Hacker News Information: If you create a Hacker News account (ID and profile), we do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field (“HN Information”). Your submissions to, and comments you make on, the Hacker News site are not Personal Information and are not "HN Information" as defined in this Privacy Policy.

Because it doesn't mean anything specific and breaks entire business models (merely logging that you landed from an ad click and seeing if you check out counts as 'tracking,' doesn't it?) if interpreted purely literally. So, the only way to treat it is to either ignore it or to just send back an error code and message that says "Sorry, having some tracking is the condition to get this free content. Accept or don't."

Like it or not, the Web is a two-way street, meaning that the server end of the transaction doesn't owe the client end anything in particular unless there's some relationship in place (like a payment). It appears the "just ignore it" matches the intent of most web users, though, since an overwhelming majority of web visitors accept a bunch of spammy ads + free 'content,' and a slim minority pay for ad-free alternatives.

>breaks entire business models

So do car alarms.

I'm not convinced this is a business model I want to exist. We had an internet before it, and Google, and Facebook. I'm increasingly sad we can't return to it.

Let me be clear, I can't stand the social-media industrial complex and the advertising universe. I've seen the bottom that we've raced to, with absolute bullshit popping up everywhere and entire sites full of slop with clickbait "headlines" just rigged to get ad impressions.

And I'd gladly trade today's BS for any version of "The Internet" pre-2007.

But the "Before" Internet wasn't some natural sustainable state.

Before 1997 or so, "the Internet" was being paid for by academic institutions and big companies, and wasn't really all that commercial at all. It was also pretty tiny and blessedly simple. Honestly this version is the most achievable (re-creatable?) today since we can set up indie websites much easier today than we could then. Instead of using your free webspace from your university or employer, 20 of us could share a $5 a month instance, and link to each other's webpages, and add an IRC server to that instance just for fun.

In the 1998-2007 era, the Internet got a lot bigger, but was also still pretty fun and not that enshittified, but that's just because it was being paid for by VC money being burned.

Today we are where we are in terms of business model[1] because Google and Facebook achieved great success with ad-based business models because of the ability to target ads better, and because consumers of The Internet have spoken, loudly, with their closed wallets. They've said "We will only pay for content if it's All The Music and ~$10 a month flat rate, or if it's a big/interesting enough video on-demand service and under $20 a month. We'll never pay for news or text content of any kind." So, the businesses with other types of content do what the public wants them to do: have cost-free content whose access is conditional on being advertised to very annoyingly, or they marginalize themselves with paywalls, subscribed to by only a small minority of users.

[1] i'm setting aside the non-business aspects of our mess, namely the poison that social media, 'engagement' optimization, and ragebait-as-news has wrought on society.

> achieved great success with ad-based business models because of the ability to target ads better

There's an old saying in advertising, "Half the money I spend on advertising is wasted, and the trouble is I don’t know which half." - https://quoteinvestigator.com/2022/04/11/advertising/

The supposed benefit of the current model is to find and eliminate that wasted half.

Facebook has shown me ads for dick pills and boob surgery, ads I can't read because I don't know the Cyrillic alphabet, and ads for services that only apply to citizens of nations I've never been a citizen of who moved to a country I had in fact moved out of.

The reports I hear from people who buy ad slots are mostly unimpressed with the results; the word on the grapevine is that the "success" cases are not even average customers, but those who are vulnerable to getting scammed.

I don’t know, back in the day you could just buy a newspaper and read it.

Now, if you want to read an article you have to pay $20/month to that news organization in perpetuity. I don’t see how that can be expected to work.

Their targeted ads suck. I've been a professional developer for quite a while and fb keeps peddling me programming courses for beginners to become a developer.

Or, I liked one single page of an amputee woman (I am myself) and now all I see are amputee women.

They just buy all the competitors, but they aren't good at all.

>We'll never pay for news or text content of any kind... or they marginalize themselves with paywalls, subscribed to by only a small minority of users.

You should definitely consider supporting your favourite news sources directly. ft.com, economist.com, lwn.net, etc. Maybe your outlook might change regarding whether they are marginalising themselves or making sure their financial motivations are more correctly aligned with high quality output.

> "Sorry, having some tracking is the condition to get this free content. Accept or don't."

The law that caused the cookie banners also says companies cannot block access to the site if the cookies are not required for the functioning of the site.

Some German news sites have broken this and have "accept or pay" and I think this leaked to news sites in other countries. Facebook even tried it.

So, sure, if DNT is true, try to make people pay. Fine by me.

> Some German news sites have broken this and have "accept or pay" and I think this leaked to news sites in other countries. Facebook even tried it.

One annoying example: Golem. Some people in my circles sometimes share a Golem link every now and then. I don't even click them any longer.

The most annoying thing about that is not even the "accept or pay" banners. There are more:

- even if you accept the tracking, you might still not be able to read the article, because while the site may be free in principle if you accept ads, that specific article is not.

- and the most annoying thing is that such paywalled articles show up on Google News. Not sure if they're tricking Google into showing them (by showing the full article to search crawlers, but the paywall to actual users), or if this is some understanding between Google and EU news providers, but it's annoying...

Speaking of the news-type sites you bring up:

I hate all these patterns too, but interestingly it feels like I hate it more because the whole Internet has been designed around the "free to read with ads" paradigm -- we've been taught that if you can see something, get the URL and share it, so that others can reference the thing you're trying to either comment on or raise awareness about.

With paper newspapers or magazines it wasn't ever a problem, because if I subscribed to the Dallas Morning News, I automatically got all their articles, and even stories that weren't local to Dallas were covered by them too. I didn't need a subscription to the San Francisco Chronicle and didn't miss it.

Today, if someone is reading an article in the Chronicle, or even the Verge, it's a huge problem for them to share it with someone else even if the other person actually pays for subscriptions to say, NY Times and Bloomberg. Even if all four of those publications each have articles just summarizing the same 5 bullet points.

I'd blame the "news" industry as a whole for not implementing some kinds of reciprocal agreements. Even giant news conglomerates like Media News Group[1] who publish dozens of major US papers don't give you a simple subscription that at least covers all their own properties. I'd argue that they should try harder to stand up some shared subscription services with heavy reciprocal benefits and revenue sharing, so that most people would be able to read most paywalled articles with one monthly subscription. That industry has no one to blame but themselves for not figuring this one out.

[1] https://www.medianewsgroup.com/about-us/

> "Sorry, having some tracking is the condition to get this free content. Accept or don't."

OK great! Lets have that! Honesty on websites! And then people will turn elsewhere, because they don't actually consent. They would go to places where this tracking is not precondition to see/read content. Then we will have revealed what people actually want and what they don't want.

Oh, but of course most businesses are too much of cowards to actually do this, fearing exactly, that their content isn't really worth that much to the viewer, and that they would lose whatever they gained through non-consensual tracking and ads.

> breaks entire business models

Good. No one is entitled to a business model working in perpetuity. Doubly so when it's ethically dubious.

The very thing entrepreneurs are glorified for - their ability to invent and execute on new business models. They'll manage, don't worry about them. Hopefully they'll settle on more honest models this time.

> But in many cases, you could just click "reject" and the banner would also disappear...

Oftentimes the reject flow is substantially more annoying than the accept flow. I click reject myself when it's an option, but I can absolutely understand how people might get conditioned to click accept when clicking reject might result in more popups.

A lot of UK sites (Reach local news stuff) now explicitly say take cookies or pay, which tbh I always thought was illegal.
It's wild to me that anyone thinks that would be a reasonable law (whether or not it is law, I have no clue, I don't live in UK or EU).

If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway."

Note that I used "sign any name" as the metaphor, not "show ID," since it is trivial to not allow any important information exchange if you simply delete the cookies yourself, which is easy to configure a browser to do. The end-user has the choice, if it's so important to them, to configure their browser. Even Chrome can be configured for which sites to allow cookies, which to disallow, and which to clear when the browser closes (the smart choice, since accepting them and throwing them away soon after is the undetectable option that accomplishes your main aim).

Allowing bad actors to act badly against all but the most sophisticated users is exactly where lawmakers should be stepping in. Sorry you find that controversial.
YouTube is a site that pretty much everyone has an account already for (and therefore have already consented), but say you make YouTube 2, you can only make money if people allow personalized ads (they pay 10-20x untargeted ads). 90% less revenue means your business model doesn't work. The government in the area has decided you can't refuse service to customers that cost you money (people who don't consent).

You simply will have to go out of business.

This is also why you see many large companies fighting for more regulation. It's harder for a competitor to emerge if they have to navigate mountains of red tape.

We ask more sophistication of drivers to understand the rules of right of way than we would be asking of users to hit Settings -> Privacy and Cookies and read the plain language there.

Sorry that you need the government to "help" people in this way, by forcing other people to give them free things.

You're fooling yourself if you think clearing cookies does anything. Everyone is doing browser fingerprinting instead these days.
> If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway."

More: "To view the private content on my website, you have to either pay me, or let more businesses connect the dots between this content and the rest of your internet browsing habits, than there were students and teachers combined in your high school."

Yes, it is technically possible to fake this content, or to auto-delete it.

But https://xkcd.com/2501/ applies. "It's easy to forget that the average person probably only knows the privacy settings for Safari and one or two Chromium derivatives."

(Real world user familiarity with software is much, much worse; this is an old survey now, but look at the chart near the bottom: https://www.nngroup.com/articles/computer-skill-levels/)

I'm in agreement with you that most computer users haven't bothered to learn anything about how to use their browser or computer.

But still, let's say I agree that there's even an important problem to be solved.

We can (A) regulate the browser to dumb this down for these ignorant people, and have the problem guaranteed solved, or (B) we can burden every single company that operates a website, and rely on enforcement since otherwise it's all honor-system.

The EU and so far multiple US states, have chosen the stupid option B.

This is a false analogy. The cookie banner stuff is explicitly about sharing data with third parties. If that were the case in your example, it'd be a different thing, right.
It is illegal, but compliance is not enforced to the degree that it should. Companies get away with a lot of GDPR infractions, unfortunately.
They're in UK, not EU, and it has a different law.
UK GDPR is simmilar to the EU one and German news websites do the same thing in the EU.
The UK is somewhat famously no longer part of the EU (you may have heard of a thing called "Brexit" a few years back).

However the UK does have its own GDPR regulation (see: <https://www.gov.uk/data-protection>), though my understanding is that it may be less strict in requiring equivalence between "accept" and "reject" actions. (I may be wrong on this.)

UK sites accessed from the EU would have to be under EU GDPR compliance.

>This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept"

There's a mismatch between the velocity at which people visit sites and the time it takes to navigate the cookie particulars of each site.

And, we can dismiss this as people being uninformed or lazy but the reality it is that's actually not so unreasonable. Cookies are in some ways near the bottom of the list where privacy is concerned, given everything else from breaches to search dossiers to device finger-printing to mobile device location-tracking to the ubiquity of cameras in the real world, and on and on.

The idea that we're clawing back privacy in any meaningful sense by blocking a few cookies here and there is kind of quaint.

I believe myself to be fairly well-informed, and usually accept the cookies, because I don’t foresee any potential harms, and it helps the people running the website. I am worried about many things like phishing and hacking/data leaks, but the valuable data isn’t cookie-related.

What harm are you worried about?

These popups aren't about cookies but really about spying. It seems you have nothing to hide. I understand: I also don't. However, the problem with spying is not about individual secrets but about the society and democracy.

Lack of privacy harms journalism and activism, making the government too powerful and not accountable. If only activists and journalists will try to have the privacy, it will be much easier to target them. Everyone should have privacy to protect them. It’s sort of like freedom of speech is necessary not just for journalists, but for everyone, even if you have nothing to say.

A right to privacy also includes the freedom to forgo privacy in return for other benefits.
"A right to not be raped also includes the right to be raped in exchange for benefits"
It's called consentual sex
"Participating in basic society" isn't a "benefit"
Tracking usually happens across websites, meaning the information is shared with third parties outside the people running the website where you accepted the cookies. Knowing your interests, behavior and preferences makes you prone to manipulation. The selection of information shown to you will be crafted such as it maximizes engagement. For example, showing you information that upsets you, in order to get you to react. Or just information with a slant or spin to influence your opinion. Nobody is immune to being affected by the distribution of what they are being shown.
No one in history has ever had an opinion independent of "influence"
Sure, but influence tailored to the person is much worse than non-personalized influence by the general environment.
For instance, ICE buys this data.
The banner is not just about cookies, but also about data sharing, so by accepting you increase the amount of your data that can be leaked.

These banners handle both ePrivacy consent for cookies etc, but also GDPR Art. 6(1)(a) for processing purposes (personalised ads, measurement, audience insights, precise geolocation, even device fingerprinting).

Well, the whole thing is theater anyway. It does not matter what you choose.

They will fingerprint you with or without cookies. They may or not try to honor your preferences, but their "partners" will not try, and by the time you see that banner, it's all out there.

"Accept" is the close button.

Because 90% don't even do anything? It turns out it's actually one of those really annoying problems to delay cookies which were supposed to be sent already in the HTTP request response until a user interaction has happened. And on a lot of pages, non technical people embed random 3rd party resources. And these 3rd party resources might claim to use only "technically necessary" cookies, but of course that's nonsense; I'm not visiting the 3rd party.
The law is actually about tracking, not about cookies.
Most people reasonably assume that if they click Reject they won't get the page they're looking for.
"To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning."

This is exactly what browsers did back the 90s, they asked about every single cookie.

Then browsers got configurable options to simply accept either all cookies, no cookies, or only first party cookies (excluding third party sites unrelated to the domain you visited).

For now well over 20 years I have disabled 3rd party cookies in all browsers I use, and only in a few cases overall did I need to make exemptions.

Usually when you hit reject it opens some insane modal with 5 million checkboxes. While accept always makes it go away fastest.
The amount of sites that don’t persist rejecting feels very high, or it’s extremely painful when encountering. The cost of clicking reject is extreme if you have to do it on every page load as you navigate a site.
Well, you would be surprised how many people think that blocking cookies means "no or fewer ads", even people in IT. No tracking, of course, just means it will show less relevant ads, not fewer of them.

So I'm not onboard with the "just block everything by default" crowd. If you frame the question as "Would you like ads to be more relevant to you" instead of "Do you want to allow tracking" you probably get a very different answer from users.

I would like the cookie banner to be changed to a browser setting, but I also would like the option to allow some sites to show relevant ads to me.

People expect visiting a website to be read only or contained within a sandbox to not read other files on their computer which is correct. Most people just don’t care about tracking and want to get to the content.
There is also the fact that by rejecting, the cookie that remembers that preference expires after like a day, so you have to click that dumb banner almost every time you visit the site.
And that is malicious, it is not supposed to happen
I run two plugins to just invisibly make them go away, I don't care, they are a waste of my time :)
if ever there were a need for a small local ai plugin...
I suggest looking at "consent-O-matic" which might not be AI but takes care of the issue for you
I have it, it only seems to operate on maybe 60% of sites
Long time (former) user of consent-o-matic here and i concur, it doesn't seem to work on many sites these days.

"I still don't care about cookies" works seamlessly so far.

https://addons.mozilla.org/en-US/firefox/addon/istilldontcar...

uBlock Origin's "annoyances" filter lists also do the job.
This happens when countless websites continue to do the illegal thing of making rejection take more effort than accepting, without being sued into oblivion for repeat offenders. Roughly 9 out of 10 websites today will be doing this illegal shit, and we are too timid to tear them down.
If only there was a short little text file that websites could use to keep track of the setting...
Agreeing to terms and contracts without reading or at least skimming them is not responsible adult behavior and should not be used as a model for legislation, no matter how many people do it. I agree that we do have a culture where private law is not taken very seriously, and that's very unfortunate.

People do not have a right (morally speaking, not legally) to access or use a service (or a website) etc without having to read/agree to the terms (applies to analog and digital).

Try to get anything done then, there's so many places these days where you have to approve 300 page legal documents to e.g. record day care times, pick up packages and so forth. There is literally not enough time in the day. The option for me would be to not put my kid in daycare (I lose the spot if I don't put in the daycare times, and the only way to do that is a 3rd party service) and not pick up packages (have to agree to the EULA to get the app that I need to unlock the pickup locker) and dozens of other places.

We really need to stop companies from putting up these insanely complicated legal texts to use basic services when they could all be behind standard contracts.

They're usually not that complicated. And most of them say usually almost the same things with some edits thrown here and there. E.g. compare the disclaimer of warranty/liability sections of two different EULAs. E.g. this kind of text in Apple macOS Tahoe EULA is found almost everywhere:

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE APPLE SOFTWARE AND SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE”

https://www.apple.com/legal/sla/docs/macOSTahoe.pdf

The same point applies to most of the text. But yes, some text is specific to the service. E.g. the same doc above says in bold:

"By using the Content Caching Features of the Apple Software, you agree that Apple may download and cache such Apple Eligible Content on your Caching Enabled Mac."

I'd say that's something worth knowing if you use that OS.

Terms of services and contracts are written for lawyers and not the average people.

If your terms require people to get a law degree and take a week to parse the 400 page document, then I would argue that it's a tactic to get people to sign up for the service without fully understanding it.

We need legislation that forces companies to communicate the terms in a way that an average person can comprehend.

I'm an average person and I read them all the time. It's not usually 400 pages long. More like 3-4 pages. If a person genuinely can't understand, they should not use the service. That's not sarcasm, I, myself, do not like to sign contracts I cannot understand -- but that's rare when you can look up stuff.
Terms of service aren't even legally binding!
Wikipedia and a few other sites I saw say otherwise for the US. https://en.wikipedia.org/wiki/Terms_of_service Wouldn't make much sense otherwise.
How much of https://www.ycombinator.com/legal/ have you actually read?
All of it, if it was presented for me to accept when signing up for this account. Don't remember explicitly. As I said to others, most of it is boilerplate, so you just learn to skim and see the stuff that's really different.
Cookie control always should have been a browser control. The legal route always should have been to force it to be built into browsers that provide sane defaults, and make it illegal to circumvent what the browser declares as far as fingerprinting etc.

any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.

In a way it is - or rather it wouldn’t t change anything if we added more features.

The default is “no”. Without explicit consent you can’t do a lot of things.

You can’t have a default yes, because how can you agree with consent but automatically to everything?

And if it’s a no, are you saying you can’t ask a user for permission to use their data for a specific purpose?

And if you can ask, that’s what we have right now.

They are asked _once_ during browser setup, same way on iOS users are asked once during setup if they want to allow Apps to track unique IDs (memory is hazy, they did that a couple years ago). And surprise surprise IIRC 96% of users said no.
Yeah I think it probably does mean you should be banned from asking in most cases. If you have a legitimate interest you don't need to ask. If you need to ask your interest is not actually legitimate and you know it.
Legitimate interest is not currently enough to read or write cookies. You need either consent or it must be "strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service." (or "sole purpose of carrying out the transmission of a communication over an electronic communications network", but that's harder to apply to cookies)
Which part says legitimate interest doesn't apply to cookies?
"legitimate interest" is legal basis in GDPR. ePD (which governs access to cookies) does not have such legal basis, only consent and the two exceptions.

Other processing (like after value is read) can happen under GDPR if the data is personal data.

If people really cared, they’d choose browsers that have better control, but that’s obviously not a priority for them. Why do you think this sort of thing should be regulated to suit your preferences when most people don’t seem to agree with you?
Because everyone agrees - cookies banners are annoying and need to go away. Everyone is on the same page about this. The easiest way to make that happen is "move them into the browser".

How often do you get prompted for, say, secure DNS or HTTP? Almost never, because your browser has sane defaults and controls that. So, there you go.

What is the sane default response to "we and our 242 partners value your privacy"?

I mean, it's even the literal truth: they value your privacy in the sense of having their software do a little internal auction to put a price on it.

I think that's a stretch. People can care, but be unwilling to spend the time researching it or accept the trade offs that come with small browsers (which are often unsupported for applications you might want to use). There are many things someone might care about and at some point you have to prioritize. This topic in particular is practically a cold war where you always have to catch up on how things are, lest you loose it all. The required effort is disproportionate to the result.

P.S.: No true Scotsman spotted

> If people really cared, they’d choose browsers that have better control

If people really cared, they’d chose reputable suppliers that sell non toxic food. If they are eating food with lead, they don’t care.

Don’t force your wordview on people through regulation

> Don’t force your wordview on people through regulation

As opposed to enforcing your worldview with a lack of regulation?

Because that's precisely what's happening, with the advertisement industry enforcing their worldview through lack of compliance.

That was suppose to be a reductio ad absurdum, not a genuine argument
Poe's law strikes again! My fault here, sorry for the misunderstanding!
> If people really cared, they’d choose browsers that have better control

What browsers would those be?

IMO any contract, waver, etc., shouldn't be legally enforceable unless the signatory has actually read it. It's always seemed to me to be one hell of a pathway of abuse (in a way) to just be able to bind someone to be legally required to do anything you want, for example, by just relying on them not reading the thing they signed.
How to know if they actually read it? The signature implies that the contract has been read, understood, and accepted. I see no need for any alternative mechanism.
Well, if you presented them with list of 100 partners each with 20 page of privacy policies and they accept it within 10 seconds it should be tricky to argue that user actually read it all.

You could, for example, require that user answers very specific questions regarding 10 randomly selected partners and how exactly they can use the data ("is partner x allowed to build very detailed profile of you and target you with political adverts that are designed to manipulate you?").

If you did this people would only use the same half dozen sites and competitors would emerge.

We're borderline already there today when the cost of switching is typing a different url at the top of the screen. You add some mandatory 20 minute wait and you'll never see a new site again.

Google and Facebook would love it though.

Plus sites that don't track you
Well for instance if the other party is pressuring you to sign it then it can't be assumed that you had adequate time to read it and understand it
Contract law of every civilised land already has a process for considering and accounting for duress.
It only accounts for "sign this or I'll kill you" not for "you have ten seconds to make a decision or the dream vacation goes to the next person"
Some countries already have provisions for this.

For example, in The Netherlands there is a legally mandated three-day period after signing the contract for purchasing a home during which the buyer can still call off the deal.

The reasoning for this is that it is a seller's market, with demand far outnumbering supply. In practice it is very common these days to end up in a bidding war, and even forego any kind of "sale is void if home inspection turns up issues" clause. Want to think about it for a day or two before signing the biggest contract of your life? Too bad, another buyer is willing to sign today.

With the mandatory three-day waiting period you avoid buyers being locked into a contract they basically immediately regret. It gives them some time to do due diligence, reducing the risk of buying a complete lemon. The seller can ask for a similar clause to be inserted, but it is less common. After all, the only risk to the seller is getting slightly less money for it, and that's already mostly dealt with during the bidding process.

Is that not what the courts are for? I imagine that if a court had to enforce a requirement like this, knowledge would generally be the best kind of proof. If you know what the contract said (or even it's terms in general) that would be enough.

The reason this isn't done is because corporations legal departments love writing 10-100 page contracts that absolutely nobody is going to read.

The solution for the problem caused by regulation is more regulation. Sure, we didn't anticipate the negative consequences the first dozen times, but this time there will absolutely not be any unanticipated consequences.
So, what, have no regulations whatsoever then? What an absurd suggestion. It’s a cat and mouse game, sure, but that’s like saying “there was a security hole in the software, might as well give up on trying to secure it.”
> From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way

There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened.

There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.

> “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement

Only engineers have trouble understanding this. It can be a reasonable defense, and it has successfully been used in courts of law many times. The law is not a machine that compiles text like code literally. Imagine someone who coerces a dying or sick person to sign an agreement they couldn’t possibly be in a reasonable state of mind to understand what they were doing -- the law can and does invalidate such “contracts”. That is the same principle behind age of consent laws. The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.

I am an attorney, and am aware of certain exceptions. But these are exceptions and not the general rule, which is what I am speaking of.

> The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.

I haven’t heard of a single case where an agreement was voided because “no one could reasonably be expected to understand it.” Unless the language was so impenetrable or vague that the agreement itself could not be discerned. Lawyers tend not to write such agreements.

EULAs are restricted in power in EU and at least to me these cookie banners are similar in spirit.
"I didn't read it," sure. But, "A reasonable person would not read it?"
Why would a reasonable person not read it?

I just visited theguardian.com to see their cookie banner. The banner says this:

> Your Privacy (`x` button to close the tab)

> US residents have certain rights with regard to the sale or sharing of personal information to third parties.

> Guardian News and Media and our partners use information collected through cookies or in other forms to improve experience on our site and pages, analyze how it is used and show personalized advertising.

> You can opt out of the sale of all of your personal information by pressing

> <button>Do not sell or share my personal information</button>

It's 3 sentences, plus a button that says "Do not sell or share my personal information". I actually don't even think this is GDPR compliant, because my layman's understanding says that GDPR consent must be presented as opt-in, rather than opt-out. (I guess they are going for CCPA/CPRA compliance?) But anyway, I would think that a reasonable person could be expected to notice a button that says "Do not sell or share my personal information" and then click it, especially when it's portrayed prominently at the bottom of the page.

> Why would a reasonable person not read it?

Because this is there 1 millionth cookie banner, because every site and their momma has one.

Also, 90% of cookie banners are not this good. They tell you nothing, hide the "reject" button behind multiple screens, etc. At that point the consumer is trained to click accept.

From Europe it's this text:

> Personalised advertising - it's your choice

> Independent, quality original journalism needs your support.

> Please choose an option.

> * Accept personalised advertising and all cookies

> We use cookies and similar technologies to support the Guardian and personalise your experience in other ways. To do this we work with a cross section of [139 partners].

> - or -

> * Reject all and subscribe to Guardian Ad-Lite for €5 per month

> Read the Guardian website without personalised advertising. This does not include ad-free. You will still see non-personalised advertising and we may still use cookies and similar technologies to improve our site.

Followed by:

> Some cookies are necessary to help our website work properly and can’t be switched off. Find out more in our privacy policy and cookie policy, and manage the choices available to you at any time by going to ‘Privacy settings’ at the bottom of any page.

> Cookies and similar technologies collect information from your device and may be used to access personal data about you including page visits and IP addresses. We use this information about you, your devices and your online interactions with us to provide, analyse and improve our services. We use cookies and similar technologies for the following purposes:

> * Store and/or access information on a device

> * Personalised advertising, advertising measurement, audience research and services development

> * Personalised content and content measurement

And finally the buttons:

> ( Accept all ) ( Reject all and subscribe )

> If you already have Guardian Ad-Lite or read the Guardian ad-free, [sign in]

Notice how they show you those three sentences and don't just put a bunch of small print at the bottom of the page. Because if they did, it would be invalid.
This is indeed a rather good implementation of ehat GDPR requires: clear unambiguous language, an opt-out available immediately.

This is the definition of informed consent

But it is complicated, no? Even if you click you agree, if the you thought you were agreeing to one thing but actually agreed to another because they buried the lede, “I didn’t read it” is a reasonable defense.
Why would you claim the false "I didn't read it" ahead of the true "I read it but understood it differently"? The latter allows for adding the fault shifting claim "because the other party wrote it deceptively", while "intentionally didn't read" makes it much harder to blame the other guy.
It just won’t fly in court. Full stop. There are perhaps other defenses to be raised, like unconscionable terms, but not that one.
I think that means one of three things: the court system is broken, you are wrong, or I failed to be clear and you misunderstood me. So, to be clear, if a company buries or obscures terms while making it seem like they have presented them, so you agree without reading the actual terms, you cannot defend yourself by explaining that situation?
It really depends on the term they're trying to rely on. We have the "red hand rule" in England and Wales that means that unusual and onerous terms will not be incorporated unless it can be expressly shown they were fairly brought to the parties attention.
It can and has been in many cases in many legal systems. For example, let’s say you walk into my store to buy a dish washer. I say ”here is an extended warranty that I will give you. Just sign” you sign it instead of reading 15 pages of boilerplate. In the end of the document it says you now owe me 10 billion dollars. Doubt I will be able to enforce it in most legal systems.
That’s not an “I didn’t read it” defense. That’s a “term is this contract is unconscionable” defense. They’re not the same thing. I was speaking strictly of the former.

Also, striking an unconscionable term typically does not void the whole contract. Just the term in question.

As a general rule I believe many online terms of use, eulas and similar online contracts are examples of procedural unconscionability, in that length is often too long that one can be expected to read it in the day to day action of "surfing the web", I believe this is also the opinion of the EU and many of its member states, hence the limitations found on enforcement of such contracts.

Aside from that many of these contract have terms that might be considered substantive unconscionability - for example if terms state that what you post can be used by the company that owns the service for marketing of the company or the service I feel this would not make it through most legal systems that I feel before the attempt are not inherently corrupt.

I would personally be shocked if the EU voids click-wrap agreements for unconscionableness based on the process alone. I’m not super familiar with EU law; is that what it truly says? I rather doubt it because I do business in the EU and have been asked to agree to terms as a condition of making purchases online there.
Online retailers in the nordics occasionally try to post terms and conditions that contradict consumer protection laws, for instance retailers being on the hook for warrantying product(ion) defects for 5 years after purchases of products that ought to be durable, like electronics. The retailers win out on a substantial amount of the population not contesting it, but if you as a consumer go through the process the findings is basically always in your favor, despite there being agreements to something else. Telecommunications providers also have a long history of having their consumer invoices being voided for being unconscionable despite service agreements, especially in cases with children playing with devices (but otherwise also), going all the way back to the landline age.
The council directive on unfair terms in consumer contracts puts every pre-canned contract in scope, and unfair provisions on a contract are rule non-binding (if the contract can keep existing after the unfair bits are taken out).

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...

All of these cookie forms have the same set of toggles. At a high level all anyone is saying is that we should just declare any kind of tracking cookies unconscionable terms for this kind of dialog box. Caching, shopping carts, explicit log in, these are totally fine and you don't need a dialog. The tracking stuff is not that hard to define and it should just be declared unconscionable.
No, it is literally ”I didn’t read the contract”. Let me guess you don’t have a law degree in Swedish law and you are just making statements on every legal system in the whole world?

Just read avtalslagen paragraf 30. It says just that. And it is different from paragraf 36.

I read it. The law expressed therein appears to be consistent with typical contract law in the West, including the UK (from which US law is derived) and other European countries. I don't see any major differences. (Also, I'm not sure why you brought up paragraph 30 as that is about fraudulent inducement.)

See also https://svjt.se/svjt/1959/497 "En person borde sålunda bli bunden av ordalagen i det dokument han undertecknat utan att äga att ursäkta sig med att han icke läst igenom dokumentet."

No, I have a Swedish law degree and you have totally misunderstood article 30 if you claim it is about unjust contracts. You are mixing it up with art 36.

You are referring to a 60 year article and the sentence you highlighted is NOT his opinion on the old contract law (the contract law currently in effect is from 2020) but rather he is explaining the opinion on German law from another person.

Of course you as an American sees no difference between contract law in continental European law and common law.

That's why billionaires don't buy their own dishwashers
This is bullshit.

https://www.nbcnews.com/news/us-news/disney-says-man-cant-su...

"Disney is trying to have a widower's wrongful death lawsuit dismissed and sent to arbitration because the man had signed up for a Disney+ account several years ago."

Now what happened was that Disney quit fighting over really bad PR. But the court challenge would have liteky succeeded.

You get that US is a tiny part of the worlds entire legal systems right? Just because US is messed up doesn’t mean the rest of the world is. Most people don’t live in US.
What's bullshit? You mean to say the dishwasher buyer would legally be on the hook for billions?
Its bullshit that a terms of use can "agree" to what amounts to unconscionable terms.

Mozilla with their Thundermail just tried saying in their ToS that if you're mentioned at all in anything legal, you agree to pay their legal fees.

That argument has actually worked in some cases, especially when you need to click away to actually access the document. I assume it's why we see more and more examples where you need to scroll the full body of text in order to "agree".
Of you need a nonstandard contract then you need to provide proof that it was understood. These are not provided in a context where I would expect anyone reading it to have a lawyer to advise so they obviously don't understand it
By that same logic, do you believe ignorance of the law is a valid defense to a criminal charge? Laws are also written by lawyers.
No, but I do believe that if the jury doesn't find it was obviously a crime without any being told the law then it wasn't a crime. That is the text of the law isn't important until guilty is decided. (So the jury can decide degree if that is a question for the jury, otherwise the judge needs to know for sentencing but the jury doesn't care)
> There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.

The value is derived from the people consuming the product. Placing the "incentive to produce value" above the people who presumably are the source of this value seems...misaligned.

If there’s no product or service to be consumed, there’s no value produced either. That’s the point: it’s harmful to eliminate the incentive to produce.
People will _always_ need things. There are very few things that will eliminate people's need for things and producers will of course adapt to the environment.

What we need is an environment that does not give the producers asymmetric power over consumers and the products will naturally align with that.

What if only the incentive to produce bad things is eliminated
* definition of bad is subjective and may vary depending upon which lobby group has the most cash to throw around
no, I referred to actual bad things
I don’t see how we could possibly prove that the person who clicked “I agree” is still the person using the computer.

Or that any actual human is aware that an agreement was made (since an AI can find a checkbox nowadays or software can be configured to bypass it). One way to add balance could be to require people asking for contracts to actually treat them like real serious legal documents, show up for the signing, and figure out who they are making an agreement with.

That doesn’t matter. If you authorize an agent—human or mechanical—to enter into agreements on your behalf (even by mistake), and the agent presents itself as operating on your behalf, the agent’s decisions will be treated as though they were your own.

Prinicipal-agent law predates computers by a very long time.

What if an IT guy installs one of those “cookie banner be gone” extensions without the user’s permission?
But "its specifically engineered to ensure that nobody reads it" is a real argument
Where has this ever been adjudicated?
Good grief no. Using websites in the UK and the EU is an exercise in pain. Every single one of them has the doorway effect where you follow a link to them and you’re faced with some Subway sandwich grade range of choices to be made and you’ve forgotten why you were there in the first place.

As it stands I just hit Accept on literally everything and that’s fine for me.

You could use Consent-O-Matic https://addons.mozilla.org/en-US/firefox/addon/consent-o-mat...

It already pushes the correct "Reject" button for you on a lot of sites (not all; it works based on rule lists)

I used this for a bit and then some sites would just not work. I get it. It’s a hard thing to do and I admire it but getting blank result is far more frustrating than clicking accept each time.
How cookie consent has been deployed by the data sponges is my go-to demonstration of malicious compliance.
Websites need cookies. I don't get why I have to suffer through this for a few puritans who literally lose nothing in the process of this transaction but act as if Stasi is watching them.
Session cookies do not require a banner.
Aggregated analytics do, and you can't run a serious website without some kind of analytics. Preference-storing does as well, despite any reasonable user expecting that, if they set a preference, it will be saved.
You don't need cookies for basic aggregated analytics. Now if you want to track and record mouse movement, you do, and that's a privacy concern.

The law really has nothing to do with cookies, it has to do with privacy, tracking, and PII. You can absolutely save preferences and perform analytics. What you can't do is hoard data that is personally identifiable for purposes that are not obvious to the consumer.

You need cookies if you simply want to run conversion analytics or any kind of performance marketing for media/ecommerce.
Actually you can't send any cookie that is not essential to the operation of the website without consent and that would include analytics regardless of PII. same for pixel tracking / fingerprinting, it's all a no-no.
There's "legitimate business interest" which I think is a catch-all for things you want to do as long as they don't invade privacy?
There are many analytics solutions that dont require cookies. You can do aggregated analytics just fine without. Saving preferences does not require consent either.
My understanding is that any front-end analytics solution will require consent. You're right about explicitly set preferences. I was mixing that up with inferred preferences.
It depends on what is to be analyzed.

How many requests per second are being served? How many error codes were delivered to clients? How quickly the service responded? Service logs without PII? All perfectly fine to aggregate and analyze without consent.

that's not true at all, plausible can be configured to require 0 consent
> Aggregated analytics do,

Good.

> and you can't run a serious website without some kind of analytics.

I don't believe you.

> Preference-storing does as well, despite any reasonable user expecting that, if they set a preference, it will be saved.

IANAL, but I'm given to understand that this is untrue.

You're right about explicitly set preferences.

What do you see as the harm in website owners using aggregated analytics data to improve their sites?

Abstract: It's still spying on users.

Practical: Supposedly-aggregated stats have a history of actually being perfectly possible to analyze back into individually identifiable information. Also, it's conveniently the same tech stack in a way that makes it easier to make an actual slippery slope.

if you're talking about cross site cookies, which are the big ones that require consent: no they don't!
Consent has nothing to do with crosssiteness except insofar as that proves it isn't needed for the operation of your own site.
lol sounds like it does then