Remix.run Logo
Phemist 4 hours ago

> Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner.

So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...

mike_hock 4 hours ago | parent | next [-]

Don't fall for the "we are just stupid" propaganda, which is used constantly by governments acting in bad faith.

Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS.

This coupled with a law mandating ISPs provide a "change IP on demand" feature would have given users a sort of "Tor light" level of privacy. Strong privacy is trivial to achieve for a government that doesn't have a conflicting goal of total surveillance.

morsch an hour ago | parent | next [-]

But I don't want to delete cookies? I want websites to use cookies that are technically necessary e.g. for keeping me logged in. I just don't want them to use it to track my behavior especially inter-website.

mike_hock an hour ago | parent [-]

Interwebsite is solved by partitioning and login cookies are solved by explicit whitelisting.

inigyou 32 minutes ago | parent [-]

You think the average user is going to explicitly whitelist? The law requires sites to whitelist their own cookies under penalty of law, instead.

mike_hock 13 minutes ago | parent [-]

> You think the average user is going to explicitly whitelist

When prompted by the browser on first login/signup, yes, the same way the password manager works. With stored passwords, keeping the login cookie doesn't even add much value.

IanCal 18 minutes ago | parent | prev | next [-]

It’s not about cookies. It’s about what the site is allowed to do with your data. Cookies are an implementation detail.

It’s baffling we’re having this misunderstanding on this site in 2026 still.

Jtarii 2 hours ago | parent | prev | next [-]

Is there any reason to believe that the current laws being passed by the UK, EU are against the will of the people? Everything I have seen makes the "anti-porn" laws or whatever seem extremely popular.

aspbee555 4 hours ago | parent | prev | next [-]

changing IP is not really enough for privacy, there is many ways to fingerprint your machine/browser and uniquely identify you across networks

https://creepjs.org/checker

mike_hock 22 minutes ago | parent | next [-]

No, but it's the obvious starting point. You can then put additional laws on top banning fingerprinting out of band (if you care about window dressing), fund development of anti-fingerprinting technologies, fund Tor, run exit nodes in a transparent and publicly auditable fashion, etc.

It's not hard to make privacy work when you are the government rather than working against a hostile one.

3 hours ago | parent | prev [-]
[deleted]
inigyou 3 hours ago | parent | prev | next [-]

I think it's because every single website breaks if you don't allow cookies at the browser level. Some knowledge of what the specific cookie does was necessary.

croes 37 minutes ago | parent | prev [-]

You mean we had the DNT flag in the browser.

Levitating an hour ago | parent | prev | next [-]

That's exactly what the California's Digital Age Assurance Act does but that wasn't well-received either.

tgv 4 hours ago | parent | prev | next [-]

The problem there is that parent's won't know how to do it, or won't care. Many can hardly operate the most user-friendly phone, let alone manage accounts.

The online safety acts and its EU counterparts are somewhat risky, but nobody wants the mention the only proper alternative: a total ban on "social media." Not just for kids, but for everyone. Or a ban on smart phones, that would work too, at least short term. But: money.

alt227 4 hours ago | parent | next [-]

> The problem there is that parent's won't know how to do it, or won't care.

This is unfortunately the reality.

The other day a friend asked me to help her make her phone safer for her kids to use. I started by asking if she set permissions on the apps she downloaded. She looked at me blankly, "What permissions?". I proceeded to show her how you can granularly control what you allow each app to do on your phone and what access it is allowed. Her head blew up, she had no idea any of this existed and after gong through a few menus, she didn't care any more. It was all too complicated and too much to think about for a busy mum.

This is why governments unfortunately are having to try to protect people from themselves. As tech competent people it all seems so simple to us, but we need to remember the majority of the population just click 'Allow All' and blow past all permission and security questions as they have no idea what any of it means.

dijit 4 hours ago | parent | next [-]

"is this device for you, or a child" is one of the first options when setting up an iphone.

I haven't set up an Android in a while, but, I doubt it's massively different.

alt227 4 hours ago | parent | next [-]

Yeah but most parents devices are for them, they just let their kid use it too.

dijit 3 hours ago | parent [-]

Ah, I guess it's impossible to have a quick enable kids mode then.

We should just give up and give random individuals access to everyone's camera roll.. no other way.

SiempreViernes 32 minutes ago | parent | next [-]

It is probably technically possible, but as almost twenty years hasn't been enough to implement this feature in either of the big mobile systems, it's obviously a huge practical challenge for Apple and Google.

dijit 4 minutes ago | parent [-]

Yeah, obviously.

Greatest minds of our generation couldn’t possibly invent fast profile switching.

Lost technology.

dwedge 2 hours ago | parent | prev [-]

Is there a term for agreeing with someone's stance but disagreeing with the person because they're so insufferable and sarcastic in the way they present the argument?

dijit an hour ago | parent [-]

“I don’t want to be seen agreeing with someone who combats obvious bad faith arguments with sarcasm - please think of me as being better than that, even though we would end up in a pissing contest about nuance or a digression away from the main point”.

Bit of a mouthful though.

mcfedr an hour ago | parent | prev [-]

it's very simpler, i recently got an android tablet for my child and it would take a lot of effort to miss all the stuff about setting it up for a child

SoftTalker 4 hours ago | parent | prev [-]

Make the default "allow none" or "child-safe" and then if the parent does nothing that's what they get.

vidarh an hour ago | parent | prev | next [-]

UK mobile operators already defaulted to blocking adult sites before OSA, and lets the subscriber turn it off, which seems like a reasonable option.

It'd be even better if there was a way for people to selectively turn it off for specific devices without MITM the connections. It wouldn't be that hard to come up with a mechanism for that.

Kuyawa 4 hours ago | parent | prev | next [-]

When we buy a new phone, the configuration process should ask if the device will be used by a kid. Easy and simple.

When restoring factory defaults, the same question, just in case the phone is sold, gifted, stolen or whatever.

If you are going to give a phone to a minor you should set that option right from the start.

SoftTalker 4 hours ago | parent | prev | next [-]

That's why the setting should be on the device, not the browser or individual apps. One setting that you could even get pre-configured when you buy the phone.

alt227 4 hours ago | parent [-]

It still doesnt solve the problem of the millions of parents that just dont care.

GaryBluto 3 hours ago | parent | next [-]

Why should I care that they don't?

preg_match an hour ago | parent [-]

Right, this is the big picture nobody acknowledges. I'm not paying the price for your kid because I don't know them. I couldn't care about them even if I wanted, because their existence doesn't even intersect with my life.

Yes, as a parent, you are required to put in more effort into parenting your kid than random hypothetical people. That's obvious, and has been the case forever.

I understand the concept of community, but community is not me sacrificing my privacy for someone 1000 miles away.

If parents don't want to do X, Y, and Z to lock down their devices then that is their right. And I support their rights, so the conversation is over right then and there IMO.

SoftTalker 3 hours ago | parent | prev [-]

More parents will care if you make it easier.

broken-kebab 4 hours ago | parent | prev | next [-]

It's ok if parents won't care. It's a choice too.

SoftTalker 3 hours ago | parent [-]

Yes, you can't make parents care, but make it easy for the ones who do, and you'll also pick up some number of those who care but only if it's not too difficult. There's no reason a parent should have to set permissions separately in 10 differents apps on a child's device.

readread 2 hours ago | parent | prev | next [-]

I've build some moderately sophisticated server systems up on "bare metal" (as the kids say), know my way around a shell better than most programmers, understand networking better than most programmers, et c., and I still find restricting and monitoring kids' devices to be a huge pain in the ass. The only places it's not extremely shitty are the Switch (which still isn't great) and Apple devices.

Options between "we don't have tech in the house" and "wide-open tech, we have it all" are all some amount of painful, usually for no good reason.

(I remember once investigating how to do some pretty basic stuff for this in Linux, hoping to find something nicer than manually setting some executable permissions and firewall rules and then having to go back and change them all the time, and the closest thing to a guide I found was an old article from Red Hat that basically lead with "LOL, good luck you poor sap, Linux sucks at this" before going on to explain the various bad ways available to sort-of, but not entirely, accomplish it with a lot of work, and significant ongoing time-burden)

conception 4 hours ago | parent | prev | next [-]

That’s not true. Every TV app has a parent setting. That’s really easy to use browser support profiles just like TV apps do bad. UX doesn’t mean that it can’t be set up easily for parents. Windows itself could have profiles for kids that has all this set automatically. It’s not hard. There’s just no will to do it.

alt227 4 hours ago | parent [-]

> There’s just no will to do it.

Exactly. The problem is its from the parents side.

monkpit 3 hours ago | parent | next [-]

Spoken like someone who has never used parental controls. They’re a shitshow.

3 hours ago | parent | prev [-]
[deleted]
mcfedr an hour ago | parent | prev | next [-]

if parents wont make the slightest bit of effort why should the rest of us pay to keep their children safe?

tgv 12 minutes ago | parent [-]

A bit of empathy goes a long way. That child may be your nurse one day, taking care either of you or candy crush.

BiteCode_dev 3 hours ago | parent | prev [-]

A child can still access knives if the parents don't care.

echelon 4 hours ago | parent | prev [-]

>>>>>>> now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense...

THIS

Holy shit. This is such an obvious fix. And it shuts up those surveillance state goons immediately.

My God, why have we tried to summon up the ghost of 1984 when such a simple fix as this will do.

Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.

The blast radius is zero.

Good God, we need to fast track this into browsers right now. If we hurry we might be able to point to this as the technical fix.

Once some of the infrastructure exists, OS vendors can hook into it.

Firefox devs - please do this right now. Please spearhead this.

I might have to vibe code an advocacy site for the spec and set up a GitHub / RFC process.

tangotaylor 2 hours ago | parent | next [-]

> Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.

CA tried this with AB 1856. I wasn't a fan of this (neither was EFF) because of the privacy and tracking concerns of blasting the fact that the user is a child to all websites.

https://www.eff.org/deeplinks/2026/05/one-step-forward-two-s...

It would better for the block to happen at the device level. That is, the browser knows it's on a child's device and has a whitelist of allowed sites.

There is already an RTA (Restriced to Adults) header where the website self-labels that it's for adults only and the browser can block it while protecting the user's privacy. I'd prefer expanding the use of RTA.

dageshi an hour ago | parent [-]

No offense but if you're proposing a solution that involves whitelists... that solution has already failed.

The web is too big and changes too much and that's before we get to the issue of applying laws to a whitelist based on different juristictions worldwide.

And I have to question, who would administer it? The parents? They won't. Google or Apple? Why do they want to deal with irate parents or culture wars around what is or is not on the list?

There is obvious increasing demand for this from parents, politicians are going to act on it, I think a "this is a child" header is the only one that actually really works. It works for the parents because it's easy to setup. It works for websites because they can cleanly identify a child and filter content if appropriate.

It seems to me that every other solution than a "this is a child" header is either impractical or way worse.

bonoboTP 36 minutes ago | parent | prev | next [-]

This will work... if you think this is their true motivation, and the panopticon itself isn't the true end goal.

dijit 3 hours ago | parent | prev | next [-]

I agree, and I agree with the enthusiasm on which you bring in.

I've long since considered that the efforts for online child safety should be pointed at educating parents and spearheading some kind of certification of compliance for child safety of software and websites.

[this product is certified to adhere to EU:CSA]

Then you can block everything not certified, and the software that does the blocking would also be certified, the two major prongs you need (endpoints and sites working together: else they're blocked). The rest of the money goes to education for parents about this fact, and the dangers of not doing it, and how to do it.

This is super "easy" (when comparing to the effort it would take for putting backdoors in everything).

Which is why I think that the reason is definitely not child safety, and more about crime control.

Me talking about UK blocking people unless they ID themselves in 2013: https://news.ycombinator.com/item?id=6979295

Me talking about how its disingenuous because we have superior technical solutions to this particular issue last year: https://news.ycombinator.com/item?id=45010902

alexandre_m 2 hours ago | parent | prev | next [-]

That works well for controlled devices like phones, tablets, and TVs, but it’s much harder on desktops unless you expect parents to become IT administrators.

Paracompact 2 hours ago | parent [-]

What's wrong with asking the user on account creation and OS install?

inigyou 3 hours ago | parent | prev | next [-]

California AB1043, in other words

spiderfarmer 4 hours ago | parent | prev [-]

Make a website about that. I’ll spread it.