Hacker News new | ask | show | jobs
by kleiba2 2 days ago
> it’s well-understood that very few people actually read those things, they just want to get them out of the way.

This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data mining, profiling, and other privacy-related aspects. But in many cases, you could just click "reject" and the banner would also disappear...

To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.

21 comments

"Accept all" always makes it go away immediately.

Some variant on "reject" takes more effort like 70% of the time. Which is on purpose, of course. The ones that aren't maliciously-complying have a "necessary only" button that insta-closes it, but tons pretend that you might want to allow some spying but not all of it and make you go through another screen if you don't just "accept all".

> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.

Then it'd be possible to default it to "nope" (Firefox, and perhaps Safari, might do this) or to allow a "never, anywhere" setting the first time the question is asked, and malware and spyware vendors know that'd mean a much larger proportion of denials.

"necessary only" also tends to have a malicious compliance aspect where they don't store a cookie recording your preference and show the banner on every single page until you click accept.
Perhaps I am overly optimistic in thinking this is just incompetence.
Yes, you are. The legislative process around EPD/EPR fully anticipated the malicious compliance and it became a back-and-forth political football long before anything was passed. The legislators were never dumb and the corporations were always greedy+powerful.
I had one of the providers recommending us that we leave the "Decline All" button out of Europe, since it's not widely prosecuted, buy recommended that we add it to California, since chances are slimmer.

Naturally in a camera meeting with a "don't tell anyone we said that" appended right before.

The marketing people in the meeting were very angry that California was "doing it to them".

If they fully anticipated this then surely they could've fully anticipated how annoying and useless cookie banners are?

There is nothing stopping a website from using cookies regardless of the banner. If they are outside EU jurisdiction then there won't be any consequences either.

The legislators were and are dumb. They have wasted an enormous amount of collective time for no benefit. Big corporations continued doing what they were doing and nefarious third parties could still track you.

> surely they could've fully anticipated how annoying and useless cookie banners are

They did. The laws were airtight in this regard. They simply lost -- whether through a last minute "tweak" or undermined enforcement mechanism I do not know, but I do know that the current state of affairs was fully anticipated and headed off at the point where I reviewed the proposal. Your vitriol is bass ackwards -- the lesson is to strengthen the walls between corporations and the legislative process and support enforcement mechanisms, because those were the places where the process failed. Not the intelligence of legislators. Otherwise you will keep losing to the corporations, and you will deserve to.

Well, maybe it is... but then the PM never prioritizes testing or fixing the problem. They're not intentionally trying to get more people to accept cookies, it's just that there are always more important features to build and fires to fight, and fixing the cookie banner won't move any of the metrics executives are breathing down their necks about, and it won't look good in the perf packet...

But of course, designing the system that pushes people to make this sort of decision was absolutely intentional.

So even when it's incompetence, it's still malicious, just in a way that obscures the explicit decision-making that led to the result.

I don't see that as malicious. Is my consent record "strictly necessary"? No. Don’t get me wrong. I’m sure they love that, but if sites saved that preference when only necessary was selected, I’m sure a bunch of people would be screaming that they weren’t following the law.
The entire banner is malicious. They don't need consent for necessary or functional cookies. They only need consent to track you - at no benefit to you ever.
I don't think anything is actually "necessary" if you want to be strict on definitions.

I think it's absolutely fair and unlikely to be illegal to use a cookie to remember cookie preferences. Unless the cookie value was not yes/no, but something like a precise timestamp that could be used for uniquely identifying.

Yes, it is strictly necessary to properly honour the user's choice. Not storing a rejection of consent but storing acceptance violates the GDPR because it creates an asymmetry between the effort required to accept vs the effort required to reject user data processing.
The malicious compliance aspect is that they're not offering a choice between "tracking" and "no tracking", but bundling "no tracking" + "painfully degraded functionality" (like repeating the question on every page) = "strictly necessary cookies only"
There is no legal requirement to ask for consent for first party functional cookies. The cookie banner is only for invasive 3rd party trackers.
which they can be sued for as that's not compliant way to handle it. Just that nobody bothers
IIRC it was ruled by a court that "reject all" must be as easy to use as "accept all", but nobody actually follows it because enforcement is lacking.
It literally does not matter what you pick on these things - most of them don't work anyway. Think about it: Of course they don't. All the third-party javascript is already on the page. Anything you do inside the sandbox with UI provided by, usually, some other third-party, can't just magically force all that other code to behave in a specific way, unless someone has done a great deal of work to integrate the cookie banner code. If the first-party site were that competent at instrumenting every bit of third-party code the marketing department threw at the website department, they wouldn't even need the third-party cookie banner vendor in the first place.

Clicking those "REJECT!" buttons might make you feel empowered, but it's pointless. Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you.

The whole thing has always been a problem to be properly solved by the browser, and it's probably just the fact that Google makes the only browser that matters, that it's been foisted upon every website owner, who mostly just wants basic analytics and to track conversions from the ads they run, and isn't "selling your data."

The browser is your user agent. If it's sending any information up to web servers on every request that isn't okay with you, why are you using it?

Captain Compliance consent banners work but most do not and that is the issue but in time enforcement will make it that they will all work or else there will be consequences.
While I don't usually laud Wordpress plugins, I know of at least one WP plugin, that gets it right and that allows one to specify all kinds of scripts and stuff to load after consenting. Of course people still manage to use that wrongly and load third party stuff before consent. What I want to get at is, that one of the most widely used things to make websites, that even businesses use, has all the means to do it correctly, but businesses decide to do a shitty job and do illegal shit. Very often at the behest and nagging of marketing departments, who are chasing pointless metrics and "KPIs".
> Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you

Exactly. I use the "I don't care about cookies" extension, which rejects most cookies automatically without me having to see the popups. But even accepting cookies is fine - I'll be closing my browser soon anyway and they'll be gone.

I'll be closing my browser soon anyway and they'll be gone

Sure, your browser cookie will be gone. But you have already allowed the server-side identifiers of your session to be used for whatever purpose, including reconstituting increasingly larger parts of your identity over multiple disconnected sessions. Please don't make the mistake of thinking that clearing your cookies afterwards is the same as rejecting all server-side processing.

Sure, but "rejecting all server-side processing" is basically trusting the website to honor my wishes. I don't put much faith in that at all.

They'll have my IP and browser fingerprint. Using Firefox mobile narrows me down to 1-2% of the world, but also lets me run ad blockers and noscript, to block some of the more troublesome trackers.

It's all tradeoffs...

Despite this being called a "cookie banner", this is not _just_ about cookie. When you click "Accept all" you are giving your consent to any form of tracking and information sharing mentioned in the details. The site you visit may share everything they know about you with any third party they mentioned. They can even use fingerprinting (if you've agreed to it) to keep tracking you after you've deleted the cookies.
And then? What's the practical, concrete, real-life consequence for me? Nothing, not even a bit more relevant ads as these run into my adblocker anyway.
It's not only about you. It is about a practice, that is manipulative and even endangering certain kinds of people. By not caring about these things, we as a society have made the Internet a dangerous place in some regions for journalists and other types of people.
Yeah honestly I just assume sites fingerprint and track to the extent the visitors allow.
The naming of that extension is misleading then. You do care about cookies ... not ending up on your device. Does it really reject the cookies, or does it just default to accepting everything, because "one doesn't care"?
Yeah they can, they can also get fined 2% of a year's gross revenue for doing so
Well, joke's on me: I use that extension too. And I never close my browser.
I think you're right that many (most?) CMPs are broken, though usually not deliberately. Most try to gate analytics and ad tracking on consent, just often misconfigured. The common exception is companies that deliberately hide Reject All, which is not complaint

My company scanned 209 European regulated sites in June, and roughly 7 in 10 had tracking that wasn't correctly gated by consent. It's rarely indifference, though. DPOs in the EU hold too much weight for that. It's usually a tag added that was never wired into the CMP or something added by a dev or LLM without going through proper review

Full disclosure: I run https://consentmark.com, which measures what tags actually fire under each consent state to create evidence packs companies can show regulators

I don't buy it. 70% of the CMPs being "misconfigured" tells us that even if these panels were broken by design, the companies using them must all conveniently not notice this. Strange, given that even a small risk of large fines or prolonged legal process with public entities would warrant someone paying at least a moment of attention to this. I suspect they are, and the choice of leaving things misconfigured is deliberate.

> something added by a dev or LLM without going through proper review

FWIW, this was a problem long before LLMs were a thing, and it didn't get worse with LLMs. If anything, I'd expect LLMs to get it right by default, because ones ~everyone is using are all trained straight, they won't just silently read between the lines and write code/configs to facilitate one's illegal business model.

> I suspect they are, and the choice of leaving things misconfigured is deliberate.

That honestly doesn't fit our data or my experience. In our scanning, about 60% of the misconfigured sites had a CMP with blocking active but one or two tags bypassing consent controls

Generally those misconfigurations aren't valuable to the business. We don't see for example lots of ad targeting and conversion tracking firing without consent on an otherwise compliant site.

What we do see is things like sites with CMPs generally working, but one or two analytics events tags firing because consent wasn't properly added to a trigger, or embedded Youtube cookies set without consent, or unexpected data from a URL or query param being accidentally ingested by tracking, or devs adding performance monitoring or observability tools to applications without realising the compliance implications

There's not much business logic in paying for a CMP, blocking your own ad stack, but then letting three analytics events pass through

> FWIW, this was a problem long before LLMs were a thing, and it didn't get worse with LLMs.

This isn't supported by our experience. In the last 18 months, we've seen a big increase in ungated tracking that we catch in CI (albeit with overall much higher velocity in general). LLMs will happily add non-compliant tracking to sites, often following defaults that might be acceptable in the US but not EU. If you push back, they'll also happily implement compliant tracking, but it's definitely not the natural default you can rely on

But your comment left me curious, so I just ran an experiment via Codex -p (gpt-5.6-sol) and Opus 5 via Bedrock

Codex returned the vendor quickstart on 5 of 5 neutral prompts. It gated properly when told the company is Irish, with full Consent Mode v2 defaults denied, GA4 only mounting after consent, with a reject button

So models can produce compliant/non-compliant code based on the context you give them, which reflects what we've seen in industry

Our business is giving devs and increasingly LLMs efficient tests to check the tracking they add is as expected for the EU and then providing signed evidence packs that prove that behaviour at a given time

Another tiny data point example: A previous company used Stripe for a very niche feature (most companies who used our product didn't ever enable it) but having the SDK in the bundle drops their "anti-fraud" cookies, whatever they are). That is exactly the kind of thing that a CMP won't be able to fix without deeper engineering work, and which doesn't actually matter anyway because no one is profiting from that -- but that's the kind of thing that a company could be sued or fined for. A complete distraction from what actually matters.
It's a nag-box that appears every time someone visits a new website. Of course people are going to click it away as fast as possible. In the few cases you repeatedly visit a website one might want to reconsider, but by then it's out of mind due to not being shown after giving consent.

It is known that warnings and pop-ups that show up almost all the time yield diminishing returns. I think it was named "normalization of deviation" by some folks in a blog a while ago, and I believe that name fits. If you get warned about missing https all the time, or that something might be dangerous (even though it does precisely what you want it to do), it will loose its effect by the time you actually need it.

You can argue this is malicious compliance, but if you want it to go away it would probably be easier to go for banning tracking and personalized ads altogether. Eliminate the reason for this behavior, so to speak.

> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.

There is one. It's a DNT header. Knucklehead websites ignore it.

Including the one we're posting on
What tracking does HN do?
That is for Y Combinator. I would characterize HN as less than a fair bit;

> Hacker News Information: If you create a Hacker News account (ID and profile), we do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field (“HN Information”). Your submissions to, and comments you make on, the Hacker News site are not Personal Information and are not "HN Information" as defined in this Privacy Policy.

Because it doesn't mean anything specific and breaks entire business models (merely logging that you landed from an ad click and seeing if you check out counts as 'tracking,' doesn't it?) if interpreted purely literally. So, the only way to treat it is to either ignore it or to just send back an error code and message that says "Sorry, having some tracking is the condition to get this free content. Accept or don't."

Like it or not, the Web is a two-way street, meaning that the server end of the transaction doesn't owe the client end anything in particular unless there's some relationship in place (like a payment). It appears the "just ignore it" matches the intent of most web users, though, since an overwhelming majority of web visitors accept a bunch of spammy ads + free 'content,' and a slim minority pay for ad-free alternatives.

>breaks entire business models

So do car alarms.

I'm not convinced this is a business model I want to exist. We had an internet before it, and Google, and Facebook. I'm increasingly sad we can't return to it.

Let me be clear, I can't stand the social-media industrial complex and the advertising universe. I've seen the bottom that we've raced to, with absolute bullshit popping up everywhere and entire sites full of slop with clickbait "headlines" just rigged to get ad impressions.

And I'd gladly trade today's BS for any version of "The Internet" pre-2007.

But the "Before" Internet wasn't some natural sustainable state.

Before 1997 or so, "the Internet" was being paid for by academic institutions and big companies, and wasn't really all that commercial at all. It was also pretty tiny and blessedly simple. Honestly this version is the most achievable (re-creatable?) today since we can set up indie websites much easier today than we could then. Instead of using your free webspace from your university or employer, 20 of us could share a $5 a month instance, and link to each other's webpages, and add an IRC server to that instance just for fun.

In the 1998-2007 era, the Internet got a lot bigger, but was also still pretty fun and not that enshittified, but that's just because it was being paid for by VC money being burned.

Today we are where we are in terms of business model[1] because Google and Facebook achieved great success with ad-based business models because of the ability to target ads better, and because consumers of The Internet have spoken, loudly, with their closed wallets. They've said "We will only pay for content if it's All The Music and ~$10 a month flat rate, or if it's a big/interesting enough video on-demand service and under $20 a month. We'll never pay for news or text content of any kind." So, the businesses with other types of content do what the public wants them to do: have cost-free content whose access is conditional on being advertised to very annoyingly, or they marginalize themselves with paywalls, subscribed to by only a small minority of users.

[1] i'm setting aside the non-business aspects of our mess, namely the poison that social media, 'engagement' optimization, and ragebait-as-news has wrought on society.

> achieved great success with ad-based business models because of the ability to target ads better

There's an old saying in advertising, "Half the money I spend on advertising is wasted, and the trouble is I don’t know which half." - https://quoteinvestigator.com/2022/04/11/advertising/

The supposed benefit of the current model is to find and eliminate that wasted half.

Facebook has shown me ads for dick pills and boob surgery, ads I can't read because I don't know the Cyrillic alphabet, and ads for services that only apply to citizens of nations I've never been a citizen of who moved to a country I had in fact moved out of.

The reports I hear from people who buy ad slots are mostly unimpressed with the results; the word on the grapevine is that the "success" cases are not even average customers, but those who are vulnerable to getting scammed.

There are lots of ads that don't work, but I can tell you from experience that there are a lot that do. A company I worked for a couple jobs ago basically just added a new pretty color of a clothing item, then ran ads with models wearing it on Instagram (targeted to female, right age range and income level) and the resulting cost per conversion was way below our margin. It was incredibly easy. What made it work though was how the Meta algorithm understood which of the users in that broad filter was into stuff like we were selling, based on all their on-platform activity.

I suspect hackers are far tougher to target - it's kind of a special case.

Megagiantcorp Proctor & Gamble cancelled all internet advertising, with no loss in sales.
I don’t know, back in the day you could just buy a newspaper and read it.

Now, if you want to read an article you have to pay $20/month to that news organization in perpetuity. I don’t see how that can be expected to work.

Their targeted ads suck. I've been a professional developer for quite a while and fb keeps peddling me programming courses for beginners to become a developer.

Or, I liked one single page of an amputee woman (I am myself) and now all I see are amputee women.

They just buy all the competitors, but they aren't good at all.

>We'll never pay for news or text content of any kind... or they marginalize themselves with paywalls, subscribed to by only a small minority of users.

You should definitely consider supporting your favourite news sources directly. ft.com, economist.com, lwn.net, etc. Maybe your outlook might change regarding whether they are marginalising themselves or making sure their financial motivations are more correctly aligned with high quality output.

> "Sorry, having some tracking is the condition to get this free content. Accept or don't."

The law that caused the cookie banners also says companies cannot block access to the site if the cookies are not required for the functioning of the site.

Some German news sites have broken this and have "accept or pay" and I think this leaked to news sites in other countries. Facebook even tried it.

So, sure, if DNT is true, try to make people pay. Fine by me.

> Some German news sites have broken this and have "accept or pay" and I think this leaked to news sites in other countries. Facebook even tried it.

One annoying example: Golem. Some people in my circles sometimes share a Golem link every now and then. I don't even click them any longer.

The most annoying thing about that is not even the "accept or pay" banners. There are more:

- even if you accept the tracking, you might still not be able to read the article, because while the site may be free in principle if you accept ads, that specific article is not.

- and the most annoying thing is that such paywalled articles show up on Google News. Not sure if they're tricking Google into showing them (by showing the full article to search crawlers, but the paywall to actual users), or if this is some understanding between Google and EU news providers, but it's annoying...

Speaking of the news-type sites you bring up:

I hate all these patterns too, but interestingly it feels like I hate it more because the whole Internet has been designed around the "free to read with ads" paradigm -- we've been taught that if you can see something, get the URL and share it, so that others can reference the thing you're trying to either comment on or raise awareness about.

With paper newspapers or magazines it wasn't ever a problem, because if I subscribed to the Dallas Morning News, I automatically got all their articles, and even stories that weren't local to Dallas were covered by them too. I didn't need a subscription to the San Francisco Chronicle and didn't miss it.

Today, if someone is reading an article in the Chronicle, or even the Verge, it's a huge problem for them to share it with someone else even if the other person actually pays for subscriptions to say, NY Times and Bloomberg. Even if all four of those publications each have articles just summarizing the same 5 bullet points.

I'd blame the "news" industry as a whole for not implementing some kinds of reciprocal agreements. Even giant news conglomerates like Media News Group[1] who publish dozens of major US papers don't give you a simple subscription that at least covers all their own properties. I'd argue that they should try harder to stand up some shared subscription services with heavy reciprocal benefits and revenue sharing, so that most people would be able to read most paywalled articles with one monthly subscription. That industry has no one to blame but themselves for not figuring this one out.

[1] https://www.medianewsgroup.com/about-us/

I don't think the web (I think you mean web, not Internet, but that's hair splitting maybe) has been "designed around around the 'free to read with ads' paradigm". It has been designed around hypertext and putting information online. Ads is just one cancer that has befallen the web a long time ago.
> "Sorry, having some tracking is the condition to get this free content. Accept or don't."

OK great! Lets have that! Honesty on websites! And then people will turn elsewhere, because they don't actually consent. They would go to places where this tracking is not precondition to see/read content. Then we will have revealed what people actually want and what they don't want.

Oh, but of course most businesses are too much of cowards to actually do this, fearing exactly, that their content isn't really worth that much to the viewer, and that they would lose whatever they gained through non-consensual tracking and ads.

> breaks entire business models

Good. No one is entitled to a business model working in perpetuity. Doubly so when it's ethically dubious.

The very thing entrepreneurs are glorified for - their ability to invent and execute on new business models. They'll manage, don't worry about them. Hopefully they'll settle on more honest models this time.

> But in many cases, you could just click "reject" and the banner would also disappear...

Oftentimes the reject flow is substantially more annoying than the accept flow. I click reject myself when it's an option, but I can absolutely understand how people might get conditioned to click accept when clicking reject might result in more popups.

A lot of UK sites (Reach local news stuff) now explicitly say take cookies or pay, which tbh I always thought was illegal.
It's wild to me that anyone thinks that would be a reasonable law (whether or not it is law, I have no clue, I don't live in UK or EU).

If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway."

Note that I used "sign any name" as the metaphor, not "show ID," since it is trivial to not allow any important information exchange if you simply delete the cookies yourself, which is easy to configure a browser to do. The end-user has the choice, if it's so important to them, to configure their browser. Even Chrome can be configured for which sites to allow cookies, which to disallow, and which to clear when the browser closes (the smart choice, since accepting them and throwing them away soon after is the undetectable option that accomplishes your main aim).

Allowing bad actors to act badly against all but the most sophisticated users is exactly where lawmakers should be stepping in. Sorry you find that controversial.
YouTube is a site that pretty much everyone has an account already for (and therefore have already consented), but say you make YouTube 2, you can only make money if people allow personalized ads (they pay 10-20x untargeted ads). 90% less revenue means your business model doesn't work. The government in the area has decided you can't refuse service to customers that cost you money (people who don't consent).

You simply will have to go out of business.

This is also why you see many large companies fighting for more regulation. It's harder for a competitor to emerge if they have to navigate mountains of red tape.

What if I want to start a restaurant that can only make money if I use expired ingredients, run the fridge at a higher temperature to save on electricity, and don't waste my employee's time by washing their hands? These food safety laws mean my business model doesn't work.

I simply will have to go out of business.

We ask more sophistication of drivers to understand the rules of right of way than we would be asking of users to hit Settings -> Privacy and Cookies and read the plain language there.

Sorry that you need the government to "help" people in this way, by forcing other people to give them free things.

Are you proposing a licensing scheme to use the internet?
You're fooling yourself if you think clearing cookies does anything. Everyone is doing browser fingerprinting instead these days.
> If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway."

More: "To view the private content on my website, you have to either pay me, or let more businesses connect the dots between this content and the rest of your internet browsing habits, than there were students and teachers combined in your high school."

Yes, it is technically possible to fake this content, or to auto-delete it.

But https://xkcd.com/2501/ applies. "It's easy to forget that the average person probably only knows the privacy settings for Safari and one or two Chromium derivatives."

(Real world user familiarity with software is much, much worse; this is an old survey now, but look at the chart near the bottom: https://www.nngroup.com/articles/computer-skill-levels/)

I'm in agreement with you that most computer users haven't bothered to learn anything about how to use their browser or computer.

But still, let's say I agree that there's even an important problem to be solved.

We can (A) regulate the browser to dumb this down for these ignorant people, and have the problem guaranteed solved, or (B) we can burden every single company that operates a website, and rely on enforcement since otherwise it's all honor-system.

The EU and so far multiple US states, have chosen the stupid option B.

Option A is insufficient, as cookies are a mere implementation detail about how tracking is done, and the tracking is the concern.
This is a false analogy. The cookie banner stuff is explicitly about sharing data with third parties. If that were the case in your example, it'd be a different thing, right.
It is illegal, but compliance is not enforced to the degree that it should. Companies get away with a lot of GDPR infractions, unfortunately.
They're in UK, not EU, and it has a different law.
UK GDPR is simmilar to the EU one and German news websites do the same thing in the EU.
The UK is somewhat famously no longer part of the EU (you may have heard of a thing called "Brexit" a few years back).

However the UK does have its own GDPR regulation (see: <https://www.gov.uk/data-protection>), though my understanding is that it may be less strict in requiring equivalence between "accept" and "reject" actions. (I may be wrong on this.)

UK sites accessed from the EU would have to be under EU GDPR compliance.

>This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept"

There's a mismatch between the velocity at which people visit sites and the time it takes to navigate the cookie particulars of each site.

And, we can dismiss this as people being uninformed or lazy but the reality it is that's actually not so unreasonable. Cookies are in some ways near the bottom of the list where privacy is concerned, given everything else from breaches to search dossiers to device finger-printing to mobile device location-tracking to the ubiquity of cameras in the real world, and on and on.

The idea that we're clawing back privacy in any meaningful sense by blocking a few cookies here and there is kind of quaint.

I believe myself to be fairly well-informed, and usually accept the cookies, because I don’t foresee any potential harms, and it helps the people running the website. I am worried about many things like phishing and hacking/data leaks, but the valuable data isn’t cookie-related.

What harm are you worried about?

These popups aren't about cookies but really about spying. It seems you have nothing to hide. I understand: I also don't. However, the problem with spying is not about individual secrets but about the society and democracy.

Lack of privacy harms journalism and activism, making the government too powerful and not accountable. If only activists and journalists will try to have the privacy, it will be much easier to target them. Everyone should have privacy to protect them. It’s sort of like freedom of speech is necessary not just for journalists, but for everyone, even if you have nothing to say.

A right to privacy also includes the freedom to forgo privacy in return for other benefits.
"A right to not be raped also includes the right to be raped in exchange for benefits"
It's called consentual sex
"Participating in basic society" isn't a "benefit"
Tracking usually happens across websites, meaning the information is shared with third parties outside the people running the website where you accepted the cookies. Knowing your interests, behavior and preferences makes you prone to manipulation. The selection of information shown to you will be crafted such as it maximizes engagement. For example, showing you information that upsets you, in order to get you to react. Or just information with a slant or spin to influence your opinion. Nobody is immune to being affected by the distribution of what they are being shown.
No one in history has ever had an opinion independent of "influence"
Sure, but influence tailored to the person is much worse than non-personalized influence by the general environment.
For instance, ICE buys this data.
The banner is not just about cookies, but also about data sharing, so by accepting you increase the amount of your data that can be leaked.

These banners handle both ePrivacy consent for cookies etc, but also GDPR Art. 6(1)(a) for processing purposes (personalised ads, measurement, audience insights, precise geolocation, even device fingerprinting).

Well, the whole thing is theater anyway. It does not matter what you choose.

They will fingerprint you with or without cookies. They may or not try to honor your preferences, but their "partners" will not try, and by the time you see that banner, it's all out there.

"Accept" is the close button.

Because 90% don't even do anything? It turns out it's actually one of those really annoying problems to delay cookies which were supposed to be sent already in the HTTP request response until a user interaction has happened. And on a lot of pages, non technical people embed random 3rd party resources. And these 3rd party resources might claim to use only "technically necessary" cookies, but of course that's nonsense; I'm not visiting the 3rd party.
The law is actually about tracking, not about cookies.
Most people reasonably assume that if they click Reject they won't get the page they're looking for.
"To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning."

This is exactly what browsers did back the 90s, they asked about every single cookie.

Then browsers got configurable options to simply accept either all cookies, no cookies, or only first party cookies (excluding third party sites unrelated to the domain you visited).

For now well over 20 years I have disabled 3rd party cookies in all browsers I use, and only in a few cases overall did I need to make exemptions.

Usually when you hit reject it opens some insane modal with 5 million checkboxes. While accept always makes it go away fastest.
The amount of sites that don’t persist rejecting feels very high, or it’s extremely painful when encountering. The cost of clicking reject is extreme if you have to do it on every page load as you navigate a site.
Well, you would be surprised how many people think that blocking cookies means "no or fewer ads", even people in IT. No tracking, of course, just means it will show less relevant ads, not fewer of them.

So I'm not onboard with the "just block everything by default" crowd. If you frame the question as "Would you like ads to be more relevant to you" instead of "Do you want to allow tracking" you probably get a very different answer from users.

I would like the cookie banner to be changed to a browser setting, but I also would like the option to allow some sites to show relevant ads to me.

People expect visiting a website to be read only or contained within a sandbox to not read other files on their computer which is correct. Most people just don’t care about tracking and want to get to the content.
There is also the fact that by rejecting, the cookie that remembers that preference expires after like a day, so you have to click that dumb banner almost every time you visit the site.
And that is malicious, it is not supposed to happen
I run two plugins to just invisibly make them go away, I don't care, they are a waste of my time :)
if ever there were a need for a small local ai plugin...
I suggest looking at "consent-O-matic" which might not be AI but takes care of the issue for you
I have it, it only seems to operate on maybe 60% of sites
Long time (former) user of consent-o-matic here and i concur, it doesn't seem to work on many sites these days.

"I still don't care about cookies" works seamlessly so far.

https://addons.mozilla.org/en-US/firefox/addon/istilldontcar...

uBlock Origin's "annoyances" filter lists also do the job.
This happens when countless websites continue to do the illegal thing of making rejection take more effort than accepting, without being sued into oblivion for repeat offenders. Roughly 9 out of 10 websites today will be doing this illegal shit, and we are too timid to tear them down.
If only there was a short little text file that websites could use to keep track of the setting...
Agreeing to terms and contracts without reading or at least skimming them is not responsible adult behavior and should not be used as a model for legislation, no matter how many people do it. I agree that we do have a culture where private law is not taken very seriously, and that's very unfortunate.

People do not have a right (morally speaking, not legally) to access or use a service (or a website) etc without having to read/agree to the terms (applies to analog and digital).

Try to get anything done then, there's so many places these days where you have to approve 300 page legal documents to e.g. record day care times, pick up packages and so forth. There is literally not enough time in the day. The option for me would be to not put my kid in daycare (I lose the spot if I don't put in the daycare times, and the only way to do that is a 3rd party service) and not pick up packages (have to agree to the EULA to get the app that I need to unlock the pickup locker) and dozens of other places.

We really need to stop companies from putting up these insanely complicated legal texts to use basic services when they could all be behind standard contracts.

They're usually not that complicated. And most of them say usually almost the same things with some edits thrown here and there. E.g. compare the disclaimer of warranty/liability sections of two different EULAs. E.g. this kind of text in Apple macOS Tahoe EULA is found almost everywhere:

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE APPLE SOFTWARE AND SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE”

https://www.apple.com/legal/sla/docs/macOSTahoe.pdf

The same point applies to most of the text. But yes, some text is specific to the service. E.g. the same doc above says in bold:

"By using the Content Caching Features of the Apple Software, you agree that Apple may download and cache such Apple Eligible Content on your Caching Enabled Mac."

I'd say that's something worth knowing if you use that OS.

Terms of services and contracts are written for lawyers and not the average people.

If your terms require people to get a law degree and take a week to parse the 400 page document, then I would argue that it's a tactic to get people to sign up for the service without fully understanding it.

We need legislation that forces companies to communicate the terms in a way that an average person can comprehend.

I'm an average person and I read them all the time. It's not usually 400 pages long. More like 3-4 pages. If a person genuinely can't understand, they should not use the service. That's not sarcasm, I, myself, do not like to sign contracts I cannot understand -- but that's rare when you can look up stuff.
Terms of service aren't even legally binding!
Wikipedia and a few other sites I saw say otherwise for the US. https://en.wikipedia.org/wiki/Terms_of_service Wouldn't make much sense otherwise.
How much of https://www.ycombinator.com/legal/ have you actually read?
All of it, if it was presented for me to accept when signing up for this account. Don't remember explicitly. As I said to others, most of it is boilerplate, so you just learn to skim and see the stuff that's really different.