Don't fall for the "we are just stupid" propaganda, which is used constantly by governments acting in bad faith.
Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.
This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.
But I don't want to delete cookies? I want websites to use cookies that are technically necessary e.g. for keeping me logged in. I just don't want them to use it to track my behavior especially inter-website.
Interwebsite is solved by partitioning and login cookies are solved by explicit whitelisting.
You think the average user is going to explicitly whitelist? The law requires sites to whitelist their own cookies under penalty of law, instead.
> You think the average user is going to explicitly whitelist
When prompted by the browser on first login/signup, yes, the same way the password manager works. With stored passwords, keeping the login cookie doesn't even add much value.
What about the other 200 unskippable prompts you get just by opening the website?
Well, there is a skip button. It's labelled "accept all"
It’s not about cookies. It’s about what the site is allowed to do with your data. Cookies are an implementation detail.
It’s baffling we’re having this misunderstanding on this site in 2026 still.
Is there any reason to believe that the current laws being passed by the UK, EU are against the will of the people? Everything I have seen makes the "anti-porn" laws or whatever seem extremely popular.
changing IP is not really enough for privacy, there is many ways to fingerprint your machine/browser and uniquely identify you across networks
https://creepjs.org/checker
No, but it's the obvious starting point. You can then put additional laws on top banning fingerprinting out of band (if you care about window dressing), fund development of anti-fingerprinting technologies, fund Tor, run exit nodes in a transparent and publicly auditable fashion, etc.
It's not hard to make privacy work when you are the government rather than working against a hostile one.
I think it's because every single website breaks if you don't allow cookies at the browser level. Some knowledge of what the specific cookie does was necessary.
Exactly. Nobody wants to go to a news website/entertainment website/informational website that relies on ad revenue because they will get bombarded by banners and then by a huge number of ads that were increased because those banners slashed their ad revenue.
So instead everyone stays on Facebook, Instagram, Reddit, and Twitter, which ALSO operate on ads and have far more information on their users than any third-party ad tracker could ever have.
None of this has gotten rid of the privacy problems. It just consolidated them into the worst offenders while jeopardizing the plurality of the web. Now instead of people being tracked by Facebook on a website with a third-party cookie in a like button, they are tracked by Facebook on Facebook in a Facebook page because they never leave Facebook.
You mean we had the DNT flag in the browser.