Over at Pluralistic, Cory Doctorow has a righteous diatribe about dickovers. If you’re not familiar with the term, dickover was coined by John Gruber to describe those super annoying popups that cover the text you’re trying to read. They’re bad enough for those of us in the U.S. but Doctorow says they’re even worse in the UK and EU where they’re used as a sort of malicious compliance with the GDPR.
The thing is, those popups asking if we consent to the use of cookies are completely unnecessary. The law says that sites must presume that users do not want to be spied on and the popups are simply a way of tricking users into giving that consent. It appears to work. According to the Kill The Cookie Banner site, 90% of people agree to the spying by simply clicking through so they can get on with reading whatever they came to see.
A lot of Doctorow’s post describes ways of dealing dickovers but the salient point for me is the “Global Privacy Control” (GPC) signal. That’s an indication that browsers can send to websites saying that the user does not give permission for their spying. The surveillance industry hates this, of course, and largely ignores it. There are efforts in the EU to make compliance mandatory and a couple of states in the U.S. have already done so. The advertisers are, naturally, against this and have pulled out all stops to scuttle the legislation.
It’s fine to deploy stopgap measures—such as those recommended by Doctorow—to fight surveillance advertising but the real solution is to make the advertisers follow the law and stop offering specious reasons why they can’t or won’t obey it. A good first step is to make honoring the GPC mandatory.