News: 1619699186

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Vivaldi update unleashes the 'Cookie Crumbler' to simply block any services asking for consent (sites may break)

(2021/04/29)


The latest release of Chromium-based browser [1]Vivaldi has extended ad blocking to handle cookie warning dialogs and sent a shot across the bows of Google's ad technology, FLoC.

That first bit will appeal to anyone tired of the cookie dialogs and banners that have popped up in websites as a result of [2]regulation . While the aim of the questions is noble, for users it can be annoying and can leave them preferring to hit the Accept All button rather than wading through what can sometimes be pages of options to turn off every setting.

[3]

Vivaldi's take is to add cookie warnings to its ad blocking sources. Once enabled, the "Cookie Crumbler" simply blocks the service asking for consent or hides the dialog.

It is an interesting approach. It is also not enabled by default – handy, because we came across a few websites that took great exception to a lack of cookie consent. Vivaldi noted as much: "Some sites may not let you in at all and may not work as you expect them to as they actually require cookie consent for some functionality."

It also admitted: "This is not a perfect solution, as there will be a few websites that use other tactics to obtain cookie consent."

[4]

And, to be fair, there are some good reasons why a website might want to use cookies in order to function rather than just for commercial and tracking purposes. Hence the requirement for the user to make the decision to turn the functionality on (and add favoured sites, like The Reg , to the exception list).

The setting lurks in the ad-blocking sources. Should things go well, there is every chance it might be enabled by default in a future version.

FLoC moved from naughty step to blacklist

The new version also makes good on the company's threat to block Google's Federated Learning of Cohorts (FLoC) component, which is Mountain View's take on ad personalisation in a post-third-party cookie world. It's safe to say that browser makers [5]have not been keen on the idea . Up until now, Google's FLoC experiment had been "prevented from working by not setting the hidden settings that it needed in order to run" in Vivaldi.

Today's release ups the ante somewhat and shunts the FLoC component to Vivaldi's blacklist. "This means it will not be downloaded and will be removed if it has already been downloaded," the company said.

[6]

The release also features some light polishing to the user interface and some tweaks to bookmark functionality. However, it is the built-in cookie popup blocker that makes it worth a test drive, just to see what happens if you did indeed say no to all those pleadings from sites around the web. ®

Get our [7]Tech Resources



[1] https://vivaldi.com/blog/vivaldi-crumbles-cookie-dialogs-raises-privacy/

[2] https://www.theregister.com/2018/08/21/boffins_say_cookie_consent_banners_up_16_postgdpr/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YIrYG6WoxXfsCqKsZKYHoAAAAI4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YIrYG6WoxXfsCqKsZKYHoAAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2021/04/14/browser_makers_reject_google_floc/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YIrYG6WoxXfsCqKsZKYHoAAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://whitepapers.theregister.com/

mark l 2

Considering that all browser makers (including Google) have decided that third party cookies support has or will be removed from the browser. Will all those cookie consent forms be relevant going forward?

As they are annoying and I often ad them to my ublock origin block list so they don't keep coming back

Brewster's Angle Grinder

The consent dialogs penalise users who are doing the right thing. I reset cookies when my browser quits. So I have to re-assent every session. I view them popping up as proof it's working. But it's a huge annoying penalty to pay for being security conscious.

And they are getting ever more annoying - the YouTube ones are particularly bad; whereas El Reg's is sitting here at the bottom of the screen unclicked...

Charlie Clark

Permission is required for non-essential cookies. As state cannot be preserved in a browser without cookies, the cookie that needs to be set representing your decision, must be reset every session, hence the banner for you in every session. That's not the issue: the issue is the way websites attempt to gain consent for everything with misleading "accept all" buttons.

Anonymous Coward

> And they are getting ever more annoying - the YouTube ones are particularly bad; whereas El Reg's is sitting here at the bottom of the screen unclicked...

Youtube are clearly abusing the legislation in order to 'encourage' users to create accounts and sign-in rather than use the service anonymously.

Well done the EU on this legislation which has clearly prevented all tracking.

I think I'd quite like a mode that clicked yes on my behalf automatically but then cleared all cookies when the session ended.

This.

Joe W

" for users it can be annoying and can leave them preferring to hit the Accept All button "

As I understand it, the common practice of making a big "ACEEPT ALL" button and a small, grey "edit" button, which leads to a menu with

1) a bajillion little settings to turn off

2) a flashing "ACEEPT ALL" button

3) a small, grey "none"

4) an even smaller "save these settings"

is not ok as per the regulations. Yes, ElReg, I'm looking at you as well.

There are some websites that have a big "yes" / "no" choice, and a small "edit" one. This is how it should work.

Re: This.

Aoyagi Aichou

It's just two clicks here. Hardly a dark pattern.

Re: This.

katrinab

It is supposed to be opt-in, not opt-out. If it is one click to opt in, and anything more than one click to not opt in, then you have an opt-out system.

Re: This.

Aoyagi Aichou

As far as I know, the EU regs require *consent*, not opt in.

Re: This.

Halfmad

INFORMED consent, not just consent.

They also require that you are not penalised for not consenting, you know like made to jump through hoops to disable individual options, get a spinning "we're changing your settings" dial then a wait for the site to reload.

It should be accept all, accept only functional, reject all or edit. Not what we currently get.

Re: This.

Elfo74

The Register, unlike some sites, does not have a "reject all" button alongside the "accept all" button.

Shame on you.

And no, you can't hide behind the "b...b...but it's the law! I HAVE TO DO IT" excuse.

Re: This.

Pascal Monett

More and more, I am seeing websites that have the popup contain two buttons : ont to accept all, in green (obviously), and one to check - in red.

Psychological wars aside, I am often surprised by a page that lists possible cookies in 3 sections : indispensable, operational and marketing - and often it's only the indispensable that is pre-allowed.

In other words, good behavior is spreading.

Of course, that may be a statistical quirk of the subset of websites that I visit vs the rest of them. YMMV.

Re: This.

Neil Barnes

I too have been pleasantly surprised in this way recently - though the uninformed cynic in me does tend to wonder 'indispensable to whom?'...

katrinab

The GDPR doesn't require consent for "cookies", it requires consent for "tracking technologies" of which cookies are one implementation. Cookies used for purposes other than tracking are not tracking technologies, and therefore not covered by the GDPR.

Aoyagi Aichou

Interestingly enough, these "tracking technologies" of yours aren't mentioned once in the GDPR.

The eternal popup predicament

Pascal Monett

" While the aim of the questions is noble, for users it can be annoying and can leave them preferring to hit the Accept All button rather than wading through what can sometimes be pages of options to turn off every setting, "

This problem is not new. It is the eternal issue of the fact that users invariably view a popup as an impediment to Get Stuff Done, so the knee-jerk reaction is to get rid of it the fastest way possible.

It is well known that users can click OK, Accept or whatever without even reading the text of the popup. They are even capable of spending more time making sure they get rid of said popup as fast as possible than they would reading it.

Disgusted Of Tunbridge Wells

> (and add favoured sites, like The Reg, to the exception list).

With those full page background ads that you accidentally click 90 times a visit? No thanks.

I don't care about cookie warnings

Fonant

Recommended browser plugin: [1]https://www.i-dont-care-about-cookies.eu

[1] https://www.i-dont-care-about-cookies.eu

Say what you will about FLoC

aerogems

I largely agree with the assessments of others, that as it is right now FLoC would, at best, make it only marginally harder for unscrupulous companies to put together profiles on you... at least they had something to offer as an alternative. Most of the time all you hear is "tracking cookies bad! grrrrrr!" Which is fine as an opinion, but less than useful when trying to figure out a different approach besides one of scorched earth. If Google actually considers the criticisms leveled at FLoC and incorporates some changes to address them, and works with some of the researchers who panned the current implementation, they could be onto something.

Choose your paranoia level:-

Roger Greenwood

1 - 1 device, 1 browser for everything (don't care/no money/clueless/life is too short)

2 - many devices, 1 browser for everything (still don't care but has money)

3 - many devices, different browsers for different tasks (care a bit)

4 - different device per task (overpaid/overthinking/properly cautious)

I think I am generally level 3 with a bit of level 4 for some tasks....

You know, the very powerful and the very stupid have one thing in common:
they don´t alter their views to fit the facts; they alter the facts to fit
their views.
-- Doctor Who: The fourth Doctor