No endless scroll? What the hell am I supposed do I do with my mouse wheel?? Useless!
hectdev•Aug 14, 2026
Needs a scroll that becomes a full page ad that when you scroll pass becomes the same ad but 1/3rd the page
freudia•Aug 14, 2026
Don't give them ideas... LoL
NetMageSCW•Aug 14, 2026
That is already deployed to real web sites.
bigbuppo•Aug 14, 2026
And if you scroll back up the content above is completely changed to something else.
frollogaston•Aug 14, 2026
If the website is for some product that's trying to look fancy, the scroll doesn't actually scroll but moves through some insanely laggy animation
programmarchy•Aug 14, 2026
Really needs a 20MB video playing in the background of the hero.
tacodestroyer•Aug 14, 2026
with an ad overlayed that won't go away
sidrag22•Aug 14, 2026
the main thing its missing is random notification bloops to go with that obnoxious chat box in the bottom right.
rc_kas•Aug 14, 2026
Damn, yeah this is exactly how I make my websites look.
peesem•Aug 14, 2026
inaccurate, i don't have to go three screens deep into a modal to choose only necessary cookies
nerdawson•Aug 14, 2026
The best one now is “Read for free” (give me all the trackers) or join a subscription and you can opt out. Pretty much every news / media site now
orthoxerox•Aug 14, 2026
That one is honest at least, makes you aware that you're the product.
inigyou•Aug 15, 2026
I respect it, even though courts keep ruling that it's illegal (because it's not freely given consent if you are giving something in return for it)
polishdude20•Aug 14, 2026
Even my back button was hijacked for a second. Nice attention to detail!
s08148692•Aug 14, 2026
It's a bit 2025. Needs a scroll hijack background animation and cursor effects to be up to date for 2026
andai•Aug 14, 2026
Trump 2020! I hate puppies!
cg5280•Aug 14, 2026
So many websites do popups and it feels so anti-user. Maybe I get unusually annoyed, but I do not need a Gemini popup ad in Google Docs. Just let me do what I came to the website to do!
dylan604•Aug 14, 2026
But you could obviously be doing it faster/smarter by using Gemini /s
SamBam•Aug 14, 2026
If they make it hard enough to interact with the actual website, we'll have to use AI!
dylan604•Aug 14, 2026
See, there you go thinking being able to use a website is a right
andy99•Aug 14, 2026
Needs to autoplay a video which when dismissed just moves to another window and continues playing. With sound.
tamimio•Aug 14, 2026
And you can’t dismiss it because the X is somehow hidden behind another popup
six_seven•Aug 14, 2026
and hijack your clipboard and back button
RivieraKid•Aug 14, 2026
The cookie thing, I assume it's EU-only, is an example of the EU policy making process being fundamentally broken in some way. If you create a flawed policy and don't fix it many years after it's very visibly obvious that it's a bad policy, something is really wrong.
sghiassy•Aug 14, 2026
It’s an EU law, but it impacts us all in America as well… because you know, every fucking website
mnewme•Aug 14, 2026
It is not an EU law. Nowhere in GDPR are cookie banners mandated.
we could have settled on privacy compliant tracking without cookies, which is possible or use browser preferences and respect those (which would be perfectly legal)
dijit•Aug 14, 2026
it's an example of malicious compliance by some, and herd mentality by others.
I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.
Achterlangs•Aug 14, 2026
I have had the same discussion multiple times at multiple companies. Luckily most of them were fine with dismissing the popup with a timer.
bonoboTP•Aug 14, 2026
That reasoning isn't wrong, though it seems ridiculous when looked at with techie-brain. But if there is a standard expectation of what serious company websites are like, it makes business sense to look like that too. It's like dressing up appropriately to cultural expectations. You can deviate somewhat but you have to strategically spend your weirdness points.
naravara•Aug 14, 2026
How nice of the EU to have determined for the rest of the world that the “cultural expectation” should be that every business do the design equivalent of wearing clown makeup.
bonoboTP•Aug 14, 2026
I don't care about this. I explained why for an individual business trying to project seriousness, it makes sense to adopt a banner in the current environment. I didn't say it's nice of the EU or anything of the sort. It's an incentive pressure that exists on an individual company in the current situation. That's all I said.
Arainach•Aug 14, 2026
The EU doesn't require banners.
Companies could stop selling and storing your data. They could only use cookies when absolutely essential. They could use lots of kinds of UX.
This is the equivalent of businesses who put a big visible "20% the state says we have to give our employees healthcare" fee on their bill to throw a hissy fit and hope customers get angry at the government for protecting them instead of the business for exploiting them.
nonethewiser•Aug 14, 2026
Banners exist to eliminate EU regulatory risk. You can try to convince people they aren’t required but its not going to remove any banners.
Insimwytim•Aug 14, 2026
This is misinformed.
As many have said before:
it's basically malicious compliance. They're supposed to be super annoying ... Instead of complying, they choose this obnoxious practice so they could continue ... monitoring every action a visitor does.
You don't need a cookie banner to be allowed to create Cookies. You only need them if you're using them for something like tracking. [1]
Regulators didn't enforce cookie banners. Cookie banners are a form of malicious compliance. When you complain about them, you are doing the lobbying work of ad companies for free. The correct solution is to just not spy on people, and the problem is that the EU didn't go far enough and just ban the behavior altogether. [2]
Cookie pops are malicious compliance to regulations that legitimately protect consumers. You’ve cherry picked one bad side effect to throw out all the ways the EU is way ahead of anyone else in protecting consumers [3]
Why does static site of Europe's parliament need big cookie banner? Or is that the parliament which created this law doesn't know what you know or they are doing "malicious compliance".
Clearly they are just trying to rile up users against the EU.
dijit•Aug 14, 2026
Because they want to track people and they need consent for that.
YetAnotherNick•Aug 15, 2026
I know the technical reason. I was contesting the GP's comment that most site display banner "Instead of complying". Most website needs basic tracking and there is nothing wrong in it.
We are just conditioned to see it without difference in basic tracking and tracking all your clicks across site and selling it to advertisers.
bulder•Aug 14, 2026
Because they use a commercial service (AT Internet) for analytics and visitor tracking as stated in their cookies policy and cookie inventory. This information is readily available through the cookie banner.
Shuang1•Aug 14, 2026
If properly following a law is malicious, then it's a bad law.
There's a reason you don't hear about people "maliciously complying" with HIPAA or PCI laws. Because that's just called compliance.
No excuses for poorly done EU regulations.
Arainach•Aug 14, 2026
You can comply with the law without banners and dark pattern defaults. These businesses are maliciously complying by making things more obnoxious and painful than they need to be.
A comparison would be a store who was angry the law says you have to be 21 to buy alcohol and starts requesting everyone, even people not buying alcohol, to show ID or be kicked out. That's not a bad law, that's a bad business maliciously complying.
inigyou•Aug 15, 2026
They certainly don't eliminate regulatory risk, since most of them don't actually comply with the law at all.
Am4TIfIsER0ppos•Aug 14, 2026
The EU didn't have to do anything. The User Agent can already handle everything from denying cookies to blocking requests for certain resources.
wizzwizz4•Aug 14, 2026
The user agent can refuse to store cookies, but it can't do much against supercookies (cookie-like features not knowingly implemented by the user agent programmers) or fingerprinting: you need something like legislation to curb practices like that.
inigyou•Aug 15, 2026
Let me know when you find a User Agent that can smack a CEO over the head with a virtual cluebat whenever he sells a list of email addresses that signed up to his site, because that's what the regulation is about and I certainly don't see how a UA could enforce it.
danillonunes•Aug 14, 2026
It's more like a cultural expectation that business do shady things and the "clown makeup" is a compromise that government found between making those shady things illegal (utopia) and don't intervene at all and let the corporations set their rules (dystopia).
It's like those warnings in cigarettes packages saying they will kill you. I know cigarettes are bad, but the warnings also make me believe there's at least "some" control in how bad they are. Now if I buy one without the warnings, I will worry those in particular are extra-shady and likely to kill me even faster.
encom•Aug 14, 2026
>warnings in cigarettes packages
Oh how I miss those warnings. Nowadays the packages are covered in graphic body horror pictures. And there's no branding on them any more, just white text on a black background, so I have to carefully check that the illiterate teenagers at the store gives me the correct ones.
Do anyone else hear circus music?
inigyou•Aug 15, 2026
I think the point is to make you stop smoking, without actually making it illegal to smoke. Have you considered stopping smoking?
alexpotato•Aug 14, 2026
Reminds me of the early days of the CANSPAM act.
One of the best indicators that something was not spam was the unsubscribe button.
quruquru•Aug 14, 2026
Many years ago, I used to make informational websites for small, local businesses and they all wanted the cookie banner "just to be safe", even after explaining they didn't need it.
Xirdus•Aug 14, 2026
This website contains chemicals known to the State of California to cause cookies.
zippyman55•Aug 14, 2026
The Irish Republican Army, even at the height of their conflict, would never have stooped to such a website.
forgotaccount3•Aug 14, 2026
But are you a software developer or a lawyer? Do they 'not need it' because the government provided a way to ensure it's not needed or because your interpretation of the law indicates it's unnecessary? Are you willing to indemnify them for legal costs if your guidance was wrong?
Most small business owner's I've spoken to are keenly aware they are only one bad lawsuit away of closing down. Almost no one care's about the cookie banner. Most just mindlessly click to allow cookies and go on with their life. There's almost no cost to having it.
mrandish•Aug 14, 2026
The 'better safe than sorry' calculation of small businesses skews almost 100% toward 'safe' because almost all govt regulations contain no reasonable size scaling cap on penalties. Any penalties on a website that are per-occurance could be almost infinite.
inigyou•Aug 15, 2026
GDPR actually has one. It's 3% of global revenue.
pbhjpbhj•Aug 14, 2026
You could have a 'no cookies' badge that links to your cookie policy - 'we use no tracking cookies and so are compliant with EU law ... then list any cookies/local-storage used and explain what they're for.
tempest_•Aug 14, 2026
Best we can do is a full screen model or annoying toast telling users we dont use cookies and click 4 to 7 check boxes to agree.
Xirdus•Aug 14, 2026
But then you can't have tracking cookies.
bborud•Aug 14, 2026
That would make you sound a lot more professional too. And trustworthy. (As long as that's actually what happens).
When I see these dialogs listing they have 1289723 gazillion vendors they share data with, I know that whoever is in charge of analytics, privacy or both at the company is incompetent.
bborud•Aug 14, 2026
I'd say just remove it. Don't ask people who don't actually understand the cost of having it there because you will get the wrong answers. Sometimes people just have to do the right thing, take some heat and then everyone can move on. If it has severe consequences then that's probably a good reason to leave anyway.
Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they couldn't deny that it cost a fraction of what we were paying our supplier and that things took minutes to set up rather than weeks. And that they worked a lot better.
Yes, there was shouting in meeting rooms. And yes, people said "you can't do this". Turns out they were wrong. A few years later I mentioned this to Werner Vogels. During a meeting. Where my CEO and CTO were present. And where everyone was feeling very good about us being one of AWS' biggest customers in our region.
So when someone says "you can't do that", sometimes you should make them prove it.
(At the time AWS was a good idea. Today dependence on a US service provider is a harder sell in Europe. The _first_ question you get today is if we can host it ourselves if we need to or if we can use a local service provider.)
docjay•Aug 14, 2026
I have the same mindset and often did the same thing, but then I thought about my doctor sneaking into my house while I’m sleeping and injecting me with the “good medicine” I had refused in their office.
bborud•Aug 14, 2026
I did not anticipate where that sentence ended up :-).
inigyou•Aug 15, 2026
Do you ask your manager whether to indent your code? Of course not, you just do it. Because it's your job and not theirs.
inigyou•Aug 15, 2026
holy shit - if AWS cost you a fraction of your other supplier, you were getting really ripped off.
vovavili•Aug 14, 2026
>it's an example of malicious compliance
So how would you do ePrivacy Directive compliance/risk avoidance in a non-obnoxious way?
dghlsakjg•Aug 14, 2026
Don’t use a bunch of unnecessary tracking cookies?
Completely eliminates the need for a cookie permission bar.
pie_flavor•Aug 14, 2026
The law does not say 'tracking'. It says 'strictly necessary'. If you remember the user's light/dark theme preference in a cookie, that requires notification. (Or rather, what it requires in practice is that you hire a Highly Paid Consultant.)
dghlsakjg•Aug 14, 2026
Okay, but it doesn’t require notification for every user that hits your landing page.
If you want to remember dark mode with a cookie, then you can just gate that setting behind a “allow functional cookies” toggle.
Getting consent for functional cookies doesn’t have to be done with an intrusive cookie bar on landing. You can request consent as it becomes needed. There’s other ways of complying that aren’t dark patterns.
inigyou•Aug 15, 2026
Can you please tell me what part of this law requires any sort of notification or toggle whatsoever for remembering your dark mode setting: https://gdpr-info.eu/art-6-gdpr/
dghlsakjg•Aug 15, 2026
You're replying to me, but I'm not the one asserting it. The GDPR law doesn't require it specifically, but the earlier ePrivacy regulation does and it is considered to be the guide for GDPR on this specific issue. Lex Specialis is the term for one regulation being applied within a different one.
"Strictly necessary cookies — These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookies. While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user.
Preferences cookies — Also known as “functionality cookies,” these cookies allow a website to remember choices you have made in the past, like what language you prefer, what region you would like weather reports for, or what your user name and password are so you can automatically log in."
Farther down:
"To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must:
Receive users’ consent before you use any cookies except strictly necessary cookies. ..."
So a preference cookie is categorized differently than "strictly necessary" by the ePrivacy rules predating, but now part of, GDPR. But elsewhere in this thread someone asserted that a cookie that is placed and the data never sent back to the server is exempt, so if you handle dark mode entirely client side you might be ok?
I'm beginning to understand why the lawyers in the EU just say "fuck it, put a banner up"
clan•Aug 14, 2026
Nonsense.
You are correct that people keep stating such things. But it is incorrect.
That example would be an essential cookie, also known as a strictly necessary cookie.
A shame this FUD is still being spread.
pie_flavor•Aug 14, 2026
That's not what various references (and AIs) say. Strictly necessary means strictly necessary. They didn't bother defining it in the law. However, user preferences were called out specifically in the WP29 opinion as something that wouldn't count as strictly necessary if scoped any wider than the browser session. So if the plain English meaning and the drafters' opinion contradicts your opinion, why should I risk significant fines to trust it?
inigyou•Aug 15, 2026
Yeah well most references on this are wrong, and AIs are doubly wrong since they ingest those references and also since they are AIs.
I suggest actually reading the GDPR if you think it applies to you. The EU put it up on a website for everyone to see. Here's the most relevant section: https://gdpr-info.eu/art-6-gdpr/
Notice how cookies are not mentioned, popups are not mentioned, and strictly necessary is not mentioned. Those are requirements the data harvesting industry invented out of whole cloth. They are not the actual requirements.
I'll just repeat that one more time: the GDPR does not mention cookies or popups. Let that sink in. It's all cargo-cult.
The GDPR also doesn't give a shit about dark mode preference. Literally nothing in it has any relevance to a dark mode preference, even (and especially) if you store it in a cookie.
dghlsakjg•Aug 15, 2026
See my other response with citations.
In short: the GDPR doesn't mention it but it is covered by the ePrivacy directive/regulations which does cover cookies very specifically, and which is enforced through GDPR.
rcxdude•Aug 14, 2026
No, it doesn't. If it's reasonably expected as part of the service, you don't need to gather consent. It's not even personal data.
pie_flavor•Aug 14, 2026
The law does not say 'reasonably expected', it says 'strictly necessary'.
rcxdude•Aug 14, 2026
Sorry, getting my GDPR and e-privacy terms mixed up. The cookie is strictly necessary for the setting to be saved. The user has specifically requested that the setting be saved by changing it. The opinion suggests this should be a session cookie unless you indicate somewhere prominently next to the setting that it uses cookies to store it for longer. This still doesn't require a cookie banner.
What's more, if the 'cookie' is entirely local (i.e. it's never sent back to your own server, e.g. you're using the local storage API and the javascript on your page never puts that information into a request), like how this would normally be implemented nowadays, then these requirements don't apply at all (because a cookie according to the law is just something your server gives to the user's device and then the device gives back later).
wat10000•Aug 14, 2026
OK, so don't do that. Web sites work fine without remembering anonymous users' preferences across sessions.
inigyou•Aug 15, 2026
Can you point to the law in question?
vovavili•Aug 14, 2026
I am obviously referring to a scenario where tracking cookies would be highly beneficial to expanding the business, e.g. e-commerce.
ranger207•Aug 14, 2026
tracking cookies are so obviously beneficial to e-commerce that they passed an entire law to disclose them because people... liked them so much?
vovavili•Aug 14, 2026
I don't exactly see how these two statements are contradictory. Policy is about conflicting interests.
dijit•Aug 14, 2026
Don't set a tracking cookie, use of IP addresses is allowed for legitimate purposes (Art 6(1)(f)) as long as they're not stored.
At least for GDPR...
The only ways to actually track without a consent pop-up are:
(1) stay off the device entirely and process server-transmitted data under legitimate interests with a privacy notice, or
(2) confine any device storage to what's strictly necessary for the service the user requested
vovavili•Aug 14, 2026
This goes to show that the assertion that cookie banners are just "malicious compliance" isn't quite correct. These are significant trade-offs here.
dijit•Aug 14, 2026
you don’t need to track users by giving them an ID they send with every request.
in fact. you probably don’t need to track users.
dghlsakjg•Aug 14, 2026
Something being beneficial to a business does not make it broadly necessary, desirable, or - in many cases - legal.
It would be extremely beneficial to businesses to put a clause in their terms and conditions that limit damages to 1 cent in the event of any dispute. For obvious reasons we don't allow anything like that to be enforced.
I'm not saying whether tracking should or shouldn't exist, but "the business can make more money" is not a valid argument in my book.
inigyou•Aug 15, 2026
Don't, since ePD got replaced by GDPR.
Aurornis•Aug 14, 2026
> and he said "yeah, but it makes the site seem less legitimate.
He may be right, sadly. I’ve seen the lack of a cookie banner used to suggest that a site was doing something shady or not complying with the law.
Most people don’t have knowledge about the finer details of cookie laws. They’ve been trained to believe that legitimate sites who comply with the laws will implement the cookie banner, and not seeing it feels suspiciously unprofessional.
inigyou•Aug 15, 2026
Who suggests that? I've never seen it. I've never seen anyone who would even notice if there wasn't a cookie banner. They'd just think they'd been there before, and already accepted it.
kermatt•Aug 14, 2026
> but it makes the site seem less legitimate
I have yet to head that cookie prompts are a sign of legitimacy. What business has customers that would think that way?
TheOtherHobbes•Aug 14, 2026
Not customers. Owners.
Although if you've ever worked retail, you'll know that plenty of customers are idiots.
Whatever "Surely no one is that stupid!" assumptions you make will be proven wrong no matter what you do.
patwolf•Aug 14, 2026
I built an ecommerce site long ago, and even though the UI was fairly modern for the time, they insisted we use antiquated styling on the billing forms of the checkout page to help exude trust. As a developer it bugged me because I knew it was just styling, but they probably weren't wrong.
0xbadcafebee•Aug 14, 2026
Good point. The page should have 200MB of assets so that it loads slowly, making it look like there's serious engineering going on.
nonethewiser•Aug 14, 2026
No one is tanking UX to stick it to the EU. It would be better for them to simply not piss off their users. They are covering their ass.
The obvious conclusion is that when you try to regulate something like this you arent going to get the behavior you want.
wat10000•Aug 14, 2026
They're not covering their ass, they're making a deliberate tradeoff.
It's trivial to make a site that doesn't need a cookie banner: don't set any cookies. Modern web devs have probably forgotten, but this is actually the default behavior. Cookies don't get set unless you do something to make it happen.
And cookies that you actually need for functionality don't need a banner either. If you're setting a session cookie for logged in users so they stay logged in when navigating between pages, you don't need one.
Why, then, does practically every site in existence now have one? Because they set unnecessary cookies. Because they choose to set unnecessary cookies in order to track you for purposes that are not necessary to the actual functionality of the site.
Every single cookie banner you see is a big sign that says, "We value our ability to track you for marketing purposes more than we value your time."
Apparently they're willing to say that. I still see it as a win. No tracking and no banners would be ideal, but at least the regulation forces them to be honest and up front about what they're doing. I'd rather have tracking and cookie banners announcing it than tracking with zero indication of tracking.
aquentinn•Aug 14, 2026
Every site needs analytics no, unless you're going to walk in the dark, and they need payment processors. If it was just about ads, they could have limited it to ads, like 'tracking for the purpose of advertising,' though even then is a press release advertising, and every serious company is going to have press releases.
They could have instead targeted it, and applied it, to third party ad providers only, like Google. And, btw, Google is big enough they could have just outright named it. They're worth as much as the GDP of Germany. Why not just make a Google law?
So yeah, maybe good intentions but it clearly shows the EU parliament is still too young and inexperienced.
inigyou•Aug 15, 2026
Consult a lawyer - anonymous analytics for a good reason are legal, with no banner.
wat10000•Aug 15, 2026
Nope, you don't need analytics. You might want analytics, and you might want them enough to bother every single visitor with a popup so you can have them, but you don't need them.
And if you decide you need them, you can do them server side. That's not as good? Oh well. See above about want vs need.
Why not just make a Google law? Because Google is far from the only abuser. Using a VPN that routes through Europe is a real eye-opener. At least whatever country I got routed through apparently required that cookie banners include a list of every single partner who got your data. Pretty much every site had hundreds of them. One was literally over a thousand. No, the entire industry is rotten. And the epidemic of cookie banners just shows how rotten it is. They can't even be shamed into behaving.
inigyou•Aug 15, 2026
Why don't they just not comply with the law then? HN doesn't, and gets away with it just fine.
dijit•Aug 15, 2026
HN does comply with the law, theres no tracking cookies set.
The only cookie is a functional one.
Mistletoe•Aug 14, 2026
CFO should be fired immediately.
bigbuppo•Aug 14, 2026
In my experience, most people come in two camps: 1) they just click to make it go away because they click everything and would agree to sell their own mother to organ scrappers just to get past the annoyance, and 2) they understand what it's asking and are immediately suspicious.
Insimwytim•Aug 14, 2026
You may float an idea to describe what you've just said in the banner, and have just a "close" button.
E.g. "we don't set any tracking cookies, so we're already compliant with the law even without banner, so there's nothing to decline or agree to".
bot403•Aug 14, 2026
I would hate that more than an actual cookie banner. You didn't have to popup but you chose to anyway just so I could give you a pat on the back?
SilasX•Aug 14, 2026
It's not malicious compliance when the very governing authorities for this in the EU do the same thing.
inigyou•Aug 15, 2026
To whom??? Literally nobody thinks that way. You should convince him to let you do an A/B test.
skrebbel•Aug 14, 2026
Bullshit. There’s no need to track every visitor. Just stop tracking and you don’t need a cookie banner.
The only mistake EU policymakers made was underestimating how willing companies were to deface their websites.
zigzag312•Aug 14, 2026
The policy is both, good, but also flawed. For example, you cannot persist settings, because one policy says that website settings should be ephemeral unless user agrees to persist them.
dgellow•Aug 14, 2026
That’s not true, it’s even explicitly called out by the EU guidelines.
Copy pasting an older comment because it’s really coming up all the time…
That's not true and is a very common misinformation people repeat online. You can save user preferences in cookies without any consent banner, if the cookie isn't used for tracking.
See here[0], page 6:
> As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’
0: https://www.edpb.europa.eu/system/files/documents/2024-10/ed...
As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen
zigzag312•Aug 14, 2026
The guidelines you linked state: "These Guidelines do not address the circumstances under which a processing operation may fall within the exemptions from the consent requirement provided for by the ePD".
Let's check what "Opinion 04/2012 on Cookie Consent Exemption" [0] says under section 3.6:
"""
3.6 UI customization cookies
User interface customization cookies are used to store a user’s preference regarding a service across web pages and not linked to other persistent identifiers such as a username. They are only set if the user has explicitly requested the service to remember a certain piece of information, for example, by clicking on a button or ticking a box.
...
These customization functionalities are thus explicitly enabled by the user of an information society service (e.g. by clicking on button or ticking a box) although in the absence of additional information the intention of the user could not be interpreted as a preference to remember that choice for longer than a browser session (or no more than a few additional hours). As such only session (or short term) cookies storing such information are exempted under CRITERION B. The addition of additional information in a prominent location (e.g. “uses cookies” written next to the flag) would constitute sufficient information for valid consent to remember the user’s preference for a longer duration, negating the requirement to apply an exemption in this case.
"""
See that you need to provide provide "information in a prominent location (e.g. “uses cookies” written next to the flag)" to be able to store user preferences in persistent cookies. You don't need consent banner for that (which I didn't say you need), but you need to clearly inform the user. The act of setting a preference together with clear information about persistence counts as a valid consent.
So much for "it's corps doing malicious compliance"
inigyou•Aug 15, 2026
The Commission represents big business, not the people, but I assume the same is on the European Parliament which does.
ryanfreeborn•Aug 14, 2026
>The only mistake EU policymakers made was underestimating how willing companies were to deface their websites.
Yes and that is a MASSIVE mistake for a policymaker to commit. They should absolutely be pilloried for their incredible lack of foresight and understanding of how internet companies handle compliance. The policy has set back humanity by further desensitizing internet users around the world to the terrible, endemic use of cookies by most websites.
inigyou•Aug 15, 2026
idk, I think it's actually really funny when you phrase it as Google defaced their own website.
ganzsz•Aug 14, 2026
The most used banners at least have a quick way of dismissing without opting in. When the cases against too obvious dark patterns started that fixed itself at least.
gdcbe•Aug 14, 2026
I have yet to see an actual part of that policy which requires a cookie banner though. Seems more to me that it's a combination of (a) websites allowing all kind of fcked up use cases of cookies on their site (most sites do not even need cookies for real) and (b) not respecting http headers that ask to not be tracked... They much rather have a very confusing popup that kinda forces you to accept all :) How convenient.
Just like websites also give zero fcks about accept-language header... sure do geoip lookup, so much easier... not
devmor•Aug 14, 2026
I have always seen the cookie banner as a sort of punishment to the public for daring to have demanded better treatment.
“Oh you want consent involved in this interaction? Then we’ll annoy you about it constantly instead of respecting the intent of the regulation.”
dd8601fn•Aug 14, 2026
I’m certain it’s often just the California “literally everything is known to cause cancer” problem.
It’s simplest just to put the bullshit everywhere and the dipshit bureaucrats will leave everyone alone.
zetanor•Aug 14, 2026
The EU said "you have to ask for permission before forcefully sodomizing your users", and webdevs thought "let's ask for permission" rather than "let's not forcefully sodomize our users". Of course, the law could have said "don't forcefully sodomize users", but it seems the west is still under the impression that some people will do the right thing, just because, sometimes. (maybe 20 years ago they would have, just because, sometimes, but they won't now)
nirava•Aug 14, 2026
Not web devs per se, I’d be hard pressed to find a serious web dev who wanted to “forcefully sodomize users”. Thats a management thing
zetanor•Aug 14, 2026
"No."
If every webdev who would say no can be trivially replaced by webdevs who won't say no, then yes, it is webdevs.
edoceo•Aug 14, 2026
It's silly to blame the individual who doesn't have the authority or power at the business making these choices.
clan•Aug 14, 2026
Unsure if you are saying there is no collective responsibility or think it is time to bring out the pitchforks?
edoceo•Aug 14, 2026
I'm firmly in the blame-management camp, especially for these user-hostile business choices.
bonoboTP•Aug 14, 2026
You can try to put the blame on the grunts, like trying to focus on the engineers in the VW Dieselgate, etc, but that is very weak leverage. You have to intervene at the root cause of the incentive. But of course the higher you go, the more there is a blur between legislators and business owners and they won't be harsh to themselves.
clan•Aug 14, 2026
So morals are good at a certain pay level?
Thank god I am just a minion who now can go home worry free. Yay!
inigyou•Aug 15, 2026
As long as I just follow orders.
zamadatix•Aug 14, 2026
You don't really need a web dev to add a cookie banner these days, but you probably still want one to build the actual site (unless it's simple enough to be fully site-as-a-service, in which case there is really no webdev at all).
Be it the EU for regulating disclosure and consent requirements, users for being "lazy" and usually just accepting all, or the webdev for not staking their livelihood on denying the banner - I'm sure they'll all get blamed before someone sees the ones actually demanding it be done can be the problem.
StableAlkyne•Aug 14, 2026
"Damn, I'm being asked to put a cookie into this site that will maybe result in some guy seeing an ad about a toothpaste he might buy at some point in the future.
I'm going to risk months of unemployment and explain to my family why this is more important than eating when I get home. The internet is serious business, they'll understand."
-- the hypothetical webdev in that scenario, I guess?
zetanor•Aug 14, 2026
If you can get replaced over something so minor, it means there's dozens of capable bootlickers lined up and ready to do it as soon as you're gone, so yes, there is a webdev problem.
StableAlkyne•Aug 14, 2026
> bootlickers
Mate, it's just a cookie on a site.
clan•Aug 14, 2026
Not quite. That would just be boiling the frog.
It is an important fight for our future with our tech overlords. But sure - some will be happy owning nothing.
This is really one of those "First They Came" moments.
Unfortunately convenience trumps all. So for many "its just a cookie".
bborud•Aug 14, 2026
Many of them can't help themselves.
I used to have long conversations with frontend developers that "no, when I log on I don't want to be forced through a look-at-the-new-feature-we-made" sequences. And then they went ahead and did it anyway. And usually whatever flag they tried to set to make sure you only saw it once would malfunction, so next time you'd get to click through it all over again.
(If you want to tell users about new features, show a unread flag on a notification icon and make it a one-click affair to make it go away. Don't get in users' face with stuff they don't want)
mingus88•Aug 14, 2026
Most US sites are giving the cookie bag to US users. It may simply be easier for leadership to say add the widget than it is to say we won’t accept traffic from the EU or risk the consequences
It feels similar to how CA environmental regs become the national standard simply because the market is so large it’s not worth splitting on it. So they just slap a cancer warning on everything
qurren•Aug 14, 2026
1. It's also a piece of cake to just not display the cookie banner for non-EU IPs
2. If you are a purely US entity with no actual business presence in the EU, you only need to comply with US laws and nothing else. If the EU doesn't like a purely-foreign website, it's on them to set up a national firewall and block it.
Case in point 1: It's not on you to comply with China's laws, it's on them to block it if they want to
Case in point 2: China's local businesses with no EU presence do not follow GDPR and do not display cookie banners even if accessed from the EU
dgellow•Aug 14, 2026
GDPR applies to EU citizens data. It doesn’t matter where your business is located in the world, if you process European personal data you’re on the hook. Of course you can decide to ignore and argue the EU doesn’t have jurisdiction
qurren•Aug 14, 2026
Exactly, they don't have jurisdiction outside their borders. If you don't have a presence there, they cannot subject you to their laws.
1. When is the last time you saw China enforcing its laws outside their borders? Why would EU be any different?
2. China has laws that are directly contradictory to GDPR laws; you may be required to retain data regardless of consent; if your website is based in China you have to follow local laws first before you follow contradictory foreign laws that have no jurisdiction over you.
frollogaston•Aug 14, 2026
If you have any presence in the EU, you can be on the hook for EU customers visiting your non-bannered US site.
mnewme•Aug 14, 2026
Actually cookies are not mandated by the EU, but this was the solution the big companies agreed on and now Google and Co try to lobby against better solutions.
Do Not Track was the right implementation (browser-based, activate only once) and it was sabotaged by ad peddlers. It is bad policy that has been reached after every better alternative was rejected.
dgellow•Aug 14, 2026
Do not track has been used by ad companies to track users, it’s one of the datapoints that can be used to identify your fingerprint
frollogaston•Aug 14, 2026
The idea is that it'd be illegal to do so. Same as how with GDPR it's illegal to track users who denied tracking, even though the "don't track me" setting is a cookie and nothing technical stops them from doing fingerprinting.
Havoc•Aug 14, 2026
Policy making assumed good faith actors - specifically that tracking outside of necessary for website to function to be minimal. Because like…not necessary.
It’s only broken to the extent that it collided with a messed up world where websites track even when they don’t need to and then send that to 2000 partners for more profit extraction on top of what the website does commercially.
Something is deeply fucked up there and it’s not the EU part. They just make a good scapegoat because the banner is what users see
f6v•Aug 14, 2026
> Policy making assumed good faith actors
Let's not paint the policymakers naïve when they're in fact incompetent.
mnewme•Aug 14, 2026
They are not incompetent in general. Most stuff works pretty well in Europe and better than in most of the world. We just focus on the bad regulations
vovavili•Aug 14, 2026
>Most stuff works pretty well in Europe
Bold thing to say.
t. European
mnewme•Aug 14, 2026
Not really Bold, yes GDP per capita is lower in many countries than the US, but top tier in almost every other index: low crime rates, clean cities, high quality of living, childfriendliness, longevity, access to healthcare, liveable cities, culture, etc.
Havoc•Aug 14, 2026
Let’s not paint the policymakers incompetent when they’re in fact naive
f6v•Aug 14, 2026
If you think about it, a naïve policy maker isn't competent.
dragonwriter•Aug 14, 2026
So, let’s not paint them as <term meaning lacking the combination of knowledge and skill to do a job effectively> when they are in fact <term meaning particularly lacking wisdom, experience, and/or judgement>
Are you sure?
Xirdus•Aug 14, 2026
The biggest positive outcome of the whole GDPR affair is that people finally believe me when I say that yes, they are selling your data to thousands of 3rd parties, and no, I'm not making these numbers up or exagerrating at all.
ryanfreeborn•Aug 14, 2026
Policy should never assume good faith actors. There wouldn't need to be policy if an assumption of good faith was a valid substrate for the policy. The policy is bad because its authors built it in a vacuum, without any thought or care put towards how its compliance would actually instatiate. This is a consistent problem with EU regulators. The 'tax' the policy levies on invasive cookie use (which I agree is broken and horrific) is forwarded to the user, via this terrible, omnipresent popup. The policy has made the problem worse, by further densensitizing humanity at large to this terrible practice. Shameful behavior by EU regulators and they should absolutely be pilloried for the present state.
mmillin•Aug 14, 2026
I see a lot of people below arguing that this isn’t the fault of the EU policy but the companies. I think that’s being overly charitable to the policy. While you can be rightly upset with the companies behavior, ultimately policy has to work with the incentives it creates. The policy in its current form allows for meeting requirements with annoying cookie banner opt-outs while keeping the lucrative business of tracking. If we don’t want that, the policy should be changed. Don’t expect companies to go against their interests here, even if some will actually be thoughtful and find a way to do so. The “Purpose Of a System Is What It Does” principle applies, and the purpose of the EU policy seems to be cookie banners for most sites.
naravara•Aug 14, 2026
I’ve long believed that making companies liable for paying damages if PII is leaked in a data breach would be the best way to stop excessive tracking. If you force them to have to manage user data like they’re handling radioactive waste then the expense and overhead involved is a natural drag on the business logic that drives the bottomless appetite for data collection. They’ll collect it if they actually need it, and they’ll take great pains to secure it.
mnewme•Aug 14, 2026
Actually having worked in big companies,many of them just track everything, but don’t actually use the data, which is even worse.
Aurornis•Aug 14, 2026
The most valuable data breach content isn’t your advertising tracking data, though.
It would be your payment information, which is orthogonal to most of the tracking data.
The black market demand for leaked advertising-related tracking data is basically nil, except maybe in cases where it’s related to something else exploitable or usable for blackmail like if someone frequents cryptocurrency exchanges or porn sites. Nobody cares to pay for black market data about you shopping for towels on Amazon or things like that.
inigyou•Aug 15, 2026
Payment data doesn't live in a vacuum though. Every payment is authorised by your bank, who runs an AI looking for "suspicious transactions" and has a legal obligation to refund you if you lose money because any part of their payment network got hacked.
dgellow•Aug 14, 2026
That’s already part of the EU regulations people in the comments complain about
99% percent of them intentionally turn the "decline" choice into a 5 - 10 step game of dark patterns even though the EU policy says it should be equally easy to decline. They know its bullshit but they also know the chance that someone will drag them through court is low.
nonethewiser•Aug 14, 2026
Classic over-regulation producing unintended side effects
clan•Aug 14, 2026
Really?
Because the industry really respected DNT[0]?
Regulations are needed when the kids cannot play nice in the school yard.
GDPR is actually not that bad if you read it rather than subscribing to much of the malicious compliance we see.
No one is frustrating users to stick it to the EU. They are doing it to cover their ass.
inigyou•Aug 15, 2026
If that's the case, they're not even doing it right. It's well established by now that reject all has to be equally easy to accept all.
4ndrewl•Aug 14, 2026
It's not a cookies banner. It's a request to harvest your data and share it with third parties for purposes that are not required for the service you're offering.
No harvest data to 936 partners? No need for a banner!
4ndrewl•Aug 14, 2026
Downvote all you like, if you're just using purely functional cookies, you don't need a banner.
inigyou•Aug 15, 2026
People all over this thread are just making up wildly speculative guesses about what the law says.
No it’s not, it’s a testimony to how broken the Internet is.
There’s a perfectly valid and simple way to comply with the EU policies, including GDPR, and not impose annoying popups on your users: just don’t set cookies (if you need to have a login, you can ask for permissions at login time) and don’t collect personal data. That a lot of sites elect not to do that is an indication of how they treat the user, not of the brokenness of EU law.
6510•Aug 14, 2026
You are free to set cookies if you need them for site functionality.
charles_f•Aug 14, 2026
Once again, as everytime I see this, the policy only dictates that you ask for consent to track personal information from people. The problem is not the cookie banner, it's that every fucking website extracts your pants size to sell it to Facebook.
TZubiri•Aug 14, 2026
What is the consequence of not complying with the cookie thing? Assuming you sell out of a jurisdiction outside of the EU
inigyou•Aug 15, 2026
None, it's the same as calling the Kim dynasty a bunch of poopyheads and never travelling to North Korea.
You could still travel to the EU though. Only your business would have to comply before doing business there.
buildsjets•Aug 14, 2026
WARNING: Reading his post can expose you to photons, which are known to the State of California to cause cancer. For more information go to www.P65Warnings.ca.gov
LastTrain•Aug 14, 2026
The banners force sites to divulge that they are tracking you in a very obvious way. It’s fucking great and site owners can make it go away any time they want by choosing not to tack their users.
frollogaston•Aug 14, 2026
Safari + Firefox ignoring 3P cookies did more for privacy than GDPR ever will, and with fewer side effects. It didn't go very far, but it was evidently a threat to Google because they refused to do it in Chrome.
(AIUI "I agree" gets people to give explicit consent with good success and the subscribe modals are quite effective too)
pbhjpbhj•Aug 14, 2026
There was a piece of caselaw about a company having an "agree" but a million tick-boxes to disagree. A lot of sites added a "disagree" button then.
gib444•Aug 14, 2026
That doesn't take away from the fact "I agree" etc can be displayed prominently and often is. "I agree" isn't outlawed
WarmWash•Aug 14, 2026
Loaded way too fast and is way too responsive.
Also when I checked NoScript, it's only loading js from lxe.github.io
I expect there to be at minimum 8 domains, but often 12-18.
anygivnthursday•Aug 14, 2026
And needs some kind of loop that retries endlessly to make the AdBlock counter go brrr
boomlinde•Aug 14, 2026
All buttons and links need to shift around for a good 10 seconds before the page settles.
ModernMech•Aug 14, 2026
I was waiting for the overlay that hides the content until you turn off your ad blocker. Which of course is a trap because as soon as you do it covers the content in ads.
amarant•Aug 14, 2026
..... In such a way that most commonly used button is replaced by an ad 0.001 seconds before you click it
peterleiser•Aug 14, 2026
This. My favorite is when I search for products on a website or app and the results appear in batches, with subsequent results interleaving with the previous results. So when you want to select a particular result and start to move your mouse and click, or move your finger and press, you often end up selecting something unintended because a later result pops into the location.
andypants•Aug 14, 2026
I do this in the gmail mobile app all the time thanks to their ads injecting themselves in between the emails several seconds late. They must love me, their most engaged ad consumer.
coldpie•Aug 14, 2026
Handy tip: If you disable all the tab category things in settings and go down to a single category (Primary), it will stop showing you ads entirely.
peterleiser•Aug 14, 2026
<sarc/> A website can track where your mouse pointer is, but surely they wouldn't do this on purpose just to get ad revenue.
inigyou•Aug 14, 2026
a self-closing sarcasm tag with no content? surely the sarcasm tag itself can't be sarcastic? This is too meta.
Sardtok•Aug 14, 2026
It's important to have the accept cookies button pop up on top of something you are almost guaranteed to click at just the right moment.
jabroni_salad•Aug 14, 2026
Yes, and put a search bar that loses focus to some piece of crap I dont care about after I enter 3 characters, and some hotkeys that navigate me to a different page when I accidentally activate them because I thought I was going to put text in the search field.
youtube people I know you are in here. Fix your stupid PIP thing.
breuleux•Aug 14, 2026
I wish we had a UI paradigm where whatever is underneath your cursor is not allowed to change. If you hover a button, that button must remain right there for you to click, if you hover some text, it must remain there for you to select. Browser and OS-enforced, ideally.
We can debate the specifics, maybe it's only in effect for X seconds after you stop moving the cursor, maybe it creates a 100px diameter disk of stability, I don't know. Just let me interact with the stuff I see.
diegocg•Aug 14, 2026
Oh, that UI paradigm already exist. It's just that browser makers are too busy with things like webasm, webgpu, or allowing pages to launch location/notification popups at users, so they don't have time to fix fundamental flaws.
breuleux•Aug 14, 2026
I don't think it does? Popups are one thing, but the very possibility of dynamic content entails that stuff will shift on the page. Sometimes it's just the nature of the thing, like a chatroom or a notification stream -- it'll shift as new content arrives, which is what I want most of the time, but if I'm interacting with a message, that message shouldn't shift. I'd like a general solution to this. Does that exist?
cobbzilla•Aug 14, 2026
Devil's advocate, the worst-case scenario is really bad, and would probably be common: A random button your pointer is unintentionally hovering on stays put while the rest of the page wildly formats around it, super-janky UX.
breuleux•Aug 14, 2026
Yeah, it would need to be designed and tested carefully. Rather than formatting around things, I would probably be fine with something simple like overlaying the previous layout in a small disk area under the cursor. So if a button shifts down, you'd see it shift down, but there would be a copy of it still under your cursor, which would fade on its own after a short period.
Alternatively, we could disable clicking/selecting anything that wasn't visible for at least 200 or 300 ms at that location. So if you try to click on a button and it's shifted down or something pops up in front, and you end up clicking on that instead, your cursor would just blink red.
cobbzilla•Aug 14, 2026
As someone similarly frustrated by these UI shenanigans, I’m impressed with how well thought-through your idea is. It sounds reasonable! Probably not that hard to implement either. Could it be a mere vibe-coding session away from existence?
Telaneo•Aug 15, 2026
While this may look like shit, I don't actually think this is all that bad a scenario. It's a better worst-case scenario than the 'button moved right into/away from my cursor' scenario.
_kst_•Aug 14, 2026
And if a button has appeared on the screen in the last half second or so, assume that any attempt to click it was unintentional (unless it appeared due to an explicit action by the user).
Similarly, if a button has recently moved, wait a little while before activating it. (Better yet, arrange for things not to move around as the page is loading.)
jiggawatts•Aug 14, 2026
Similarly, the UI must not interrupt me when I’m typing into a text field!
I’ve lost count of the number of modal dialogs I’ve “accepted” because they popped up out of nowhere milliseconds before I pressed enter coincidentally.
stackghost•Aug 14, 2026
js eventListener that intercepts the click/tap event, moves the button somewhere else, and clicks the ad underneath.
imagent•Aug 14, 2026
Better yet, detect mouse clicks and display a popup right where you clicked that says something you didn't want, and show a busy indicator to make sure the user understands that they just agreed to something important.
Freak_NL•Aug 14, 2026
The page of my bank's website (ABN AMRO) which shows an account's transactions does this in the worst way. It all loads perfectly, it shows the transactions, I move to click on one or the button for a new transfer, and boom a message gets loaded in at the top which shifts every fucking item on the page down 20 pixels or so.
The message is always something inane like 'markets go brrr¹', and it's never something I need at the moment on that page (or anywhere else). I can dismiss the message (hooray?) but it always comes back the next time, so that isn't actually helpful at all.
1: Obviously they use carefully blandified corporate bank language for those messages.
wasmperson•Aug 14, 2026
Adding to the list of random examples: DuckDuckGo's AI answer box shifts the entire page down once the text is done generating, which happens some unpredictable time after the page has finished loading. The size of the downward shift is somehow exactly enough to shift all results down by one, making me accidentally click on the link just above the one I wanted to click.
inigyou•Aug 14, 2026
Just what you'd expect from a shady Bing frontend who advertised themselves as not having AI
Gualdrapo•Aug 14, 2026
It also loaded too fast because it has no (ai-generated/3d/high color contrast) 10MB background image in the hero section
psychoslave•Aug 14, 2026
And the legitimate mass spying with multi thousand other organizations, of course.
john_strinlai•Aug 14, 2026
>I expect there to be at minimum 8 domains, but often 12-18.
news sites are the worst for this. bloomberg, nbc, etc. have 20+ domains, and as you click "temporarily allow" on one, it loads in a few more.
foxnews loads 36 domains before temporarily allowing any, which probably approaches 50 once you start allowing.
lxe•Aug 14, 2026
I'm sorry
tmtvl•Aug 14, 2026
Also it shows something when you open it without enabling its JavaScript instead of a normal website which won't show anything without JS... even if the page only has to show text (HTML? I hardly know her).
inigyou•Aug 14, 2026
10 of them should be cloudfront domains that change every day.
reality_inspctr•Aug 14, 2026
No agents.md?
Havoc•Aug 14, 2026
Also on iPhones Twitter appears to have aligned their privacy reject button with where their open in app overlay appears just a second later so that you hit that instead.
Too many people working on evil dark pattern bullshit
ratelimitsteve•Aug 14, 2026
I wasn't asked for my location, notifications, camera permissions or to log in. This is, regrettably, still better than most recipe websites I visit.
Needs a Google login popup, required for any site that there is no reason at all to have an account with.
robertjwebb•Aug 14, 2026
It should appear a second after the page seems to have finished loading, so that it hijacks the input if the user is navigating with the keyboard or typing something into a form.
unselect5917•Aug 14, 2026
This post made me irrationally angry.
Man, I need to unplug.
m3047•Aug 14, 2026
LinkedIn today is so serious about its cookies it can't do proper logout. As long as there's a cookie, I don't know if it's random or what's going on, but if you log out... there's a > 20% chance if you leave for a while and then go back to LI... you're still logged in!
If you log out, and then (in Firefox) close the window... oh wait, you're not really logged out. Try again.
If you log out in Firefox, wait until the window is quiet, then delete the cookie... LinkedIn creates a new cookie... which still sometimes logs you back in but not as often.
Opening a new window, deleting the LinkedIn window (fuck watever it's doing), and THEN delete the cookie in the NEW window... then it seems to stay gone at least as of today.
Dwedit•Aug 14, 2026
Or even better, something that pretends to be a real "Sign in with Google" button but instead phishes your username and password.
JKCalhoun•Aug 14, 2026
Notifications?
How about an email popup. My browser will happily auto-populate it.
malfist•Aug 14, 2026
It also needs to ask the browser for your location and to send you notifications.
dorianpruski•Aug 14, 2026
missing carousel
heyitsmedotjayb•Aug 14, 2026
It needs to present a happy moose to you if you don't use an adblocker
martythemaniak•Aug 14, 2026
For my current project, I tried going with a non-traditional style I personally liked, I call it "Soft Neo Brutalism". You can see it at: http://www.frost-e.com
I generally wanted web 1.0 simplicity, lots of contrast, but also a soft gentle colours and modern vibe. I also have a general design for use in dashboards/apps etc: https://frost-e.com/design-system/
dangjustintime•Aug 14, 2026
This is actually good boilerplate. lol
wxw•Aug 14, 2026
I kinda miss the CSS bootstrap aesthetic.
lifestyleguru•Aug 14, 2026
Cookie banners are malicious compliance. There are only 1-2 EU countries with quarrelsome predatory lawyers proactively scanning the web.
The positives about covid and AI is that we don't hear anymore about blockchain and crypto (well, except one boomer oligarch holding onto it). Just please make the next two big things happen already for God's sake.
RattlesnakeJake•Aug 14, 2026
That "In case you're not aware, there's COVID-19 happening" banner isn't nearly tall nor yellow enough. Given a 6-inch-tall screen, the proper layout would be:
+-----------------+
|2" of vestigial |
|COVID messaging |
+-----------------+
|1.5" of actual |
| content |
+-----------------+
|2.5 of EU |
| cookie banner |
+-----------------+
A local utility took it even further during COVID:
+---------------------+
|2" of COVID messaging|
+---------------------+
|1" of undismissable |
| "our app is gone; |
| use the mobile site |
| that you're on now" |
+---------------------+
|0.5" of content |
+---------------------+
|2.5" of EU cookie |
| banner, despite |
| being a US-only corp|
+---------------------+
jasonjayr•Aug 14, 2026
It also needs to scroll in after a second or two, and shift the page content down, so you mis-click the wrong link, and end up loading something that takes forever to load and somehow manages to cause the back button to misbehave.
pbhjpbhj•Aug 14, 2026
Clever people with no morals use that to load ads under your finger, timed to create an inadvertent click.
I swear NYT do this in their games app, the play button gets replaced with a subscribe as the late loaded subscribe element shifts the page exactly the amount to put subscribe under your finger. I wonder how well it worked?
bartread•Aug 14, 2026
Nothing clever about it: it’s a simple and unethical parlour trick.
Every news website does it and, in the UK, the local news outlets are amongst the worst.
The thing I don’t get: many of these sites are running Google Adsense, amongst other ad networks. Adsense Ts & Cs specifically forbid site behaviour that deliberately causes users to misclick on ads.
So why aren’t these sites being banned by Adsense?
The answer, I suspect, is follow the money: it seems likely that they bring in too much money for Google to ban them even though they’re overtly and outrageously breaking the rules.
inigyou•Aug 15, 2026
Programmers tend to think rules are actually rules, because if you don't follow the rules on a computer then it won't work. But rules in politics and capitalism are primarily a manipulation technique. They state as a fact what they want you to think is fact, not what is actually a fact.
monknomo•Aug 14, 2026
manually scrolling before every widget loads should cause a full page refresh.
zooming in should cause a full page refresh
MBCook•Aug 14, 2026
Every paragraph (maybe sentence) needs to fade in as I attempt to scroll. If I can read the first paragraph easily when the page loads (ignoring the pop-ups) then the website is too well designed.
jedbrooke•Aug 14, 2026
it’s missing spinners for 5-10 seconds while it loads endless megabytes of javascript doing who knows what.
Seriously how did we get to this point? I remember growing up in the 2000’s and all the marketing about computers was “it’s fast!” and “get results instantly!” that kind of thing. Now everything it gated by multiple spinners, then it loads a skeleton, then it partially loads your actual content, then, when you go to click on something, more content loads and the existing content jumps to a new place and you end up clicking on something else, meaning now you have to go back (if they haven’t hijacked the back button), wait for it all to load again, wait for the second “real” load, and then click on what you actually meant to click on in the first place.
frail_figure•Aug 14, 2026
Just a quick reminder that you don't need to put up any cookie banners at all if you simply don't track your users in a privacy-invading way.
_superposition_•Aug 14, 2026
This is perfect.
tedggh•Aug 14, 2026
As feedback, you made that popup way too clean and easy to close. That’s not how it works in reality. You need to make the background transparent and the X so small it’s technically impossible to hit. Also think about adding an ad and a timer and move the popup slightly after N ms so that the user always hits the ad.
lxe•Aug 15, 2026
Noted. Will make it worse. Thanks.
Retr0id•Aug 14, 2026
Bootstrap, what a blast from the past! They just don't make bad websites like they used to.
wktmeow•Aug 14, 2026
Yea but do you guys remember when we actually needed pop up blockers to avoid having a site spawn like 10 new windows behind the current one, and tabs didn’t really exist yet, and the popups had adult content and sometimes they autoplayed sound/video? Like, internet explorer 6 era? Sometimes I miss those days
SamBam•Aug 14, 2026
You knew you done goofed when the adult site you opened on your family computer was opening new windows faster than you could close them...
0xbadcafebee•Aug 14, 2026
Not a problem; you were on a 28.8k, so the adult banner images would take forever to load, so you could close the pop-ups before they got you in trouble
monxer•Aug 14, 2026
Every Fucking Website not created by Claude. Otherwise it would have a dark gray background with transparant rounded buttons with a neon border.
lxe•Aug 14, 2026
This is from pre-ai era
morkalork•Aug 14, 2026
Needs the floating video thumbnail with auto-play and sound. Also the requests for location and permission to send notifications dialogs in chrome!
alpha_trion•Aug 14, 2026
Needs more jank from a bajillion ads loading. :D
Kidding aside, this is hilarious and made my morning
jonplackett•Aug 14, 2026
I made a game about this. You can play it if you want to feel annoyed.
Also, where is the unrelated autoplaying video that will unmute if you actually click it, that follows your scrolling and only becomes smaller when you dismiss it? Plus, it should probably have text that cuts off letting you know you can have access for just $10/month.
Plus, isn't this website undissmissably "better in the app" after a few minutes of attempting to use it on a phone? Where's that at?
edit: Oh shoot! I forgot, too. This modal needs to also ensure there is absolutely no way to scroll. If you could scroll you might be able to accidentally get to the address bar of your browser to fix the URL to xcancel or even close the page, which isn't using the app as you are intended to do.
Also, it doesn't attempt to hijack the back button to give me stuff I clearly wanted to see before I leave the page.
A lot of work left to do here before it's a "real" website. Although, it has about as much substance as the average website so far, so good work on that.
bee_rider•Aug 14, 2026
> Plus, isn't this website undissmissably "better in the app" after a few minutes of attempting to use it on a phone? Where's that at?
This is the most annoying thing on the internet. There’s a site I’d like to use, but “try the app” takes up the entire page (and appears to be impossible to dismiss?). Actually, is there a way to permanently request the desktop site for all future visits to a domain on iOS? There is no reason to visit this full-page app advertisement.
quercusa•Aug 14, 2026
If the site happens to be a discussion site that starts with 'R', clearing cookies will let you through for a while. In Brave, there's a setting to do so when you leave the page.
yojo•Aug 14, 2026
They still haven’t removed “old.reddit.com”. Replace “www” with “old” on any reddit URL and enjoy a relic from when the internet was less ruined.
inventor7777•Aug 14, 2026
Yes, but it now requires you to have an account.
inigyou•Aug 14, 2026
And sometimes even to verify with Persona.
RattlesnakeJake•Aug 14, 2026
The issue is that they just started forcing sign-ins on Old Reddit, allegedly because it's easier for bots to scrape. The ability to casually/anonymously peek at a post that answers your question is getting more rare.
Nah, it isn’t Reddit. I actually removed Reddit from my search results once they stopped allowing me to use the old interface.
It’s just some random job board that happens to be popular in my niche for whatever reason.
jchw•Aug 14, 2026
I'd recommend using Libredirect if you're on a Firefox-based mobile browser. It can configure redirects to alternate "frontends" that will serve you much more agreeable HTML (though because we live in hell, it will usually still involve antibotting out of sheer necessity. But I accept this.)
For Reddit, my choice for now is safereddit. If I need to view a Reddit link on mobile and old Reddit is blocked as it sometimes is, I just swap the domain to safereddit.com.
For Twitter, my choice has been xcancel for ages. I have no idea how that manages to stay up in spite of Twitter's hostility but it is a Nitter instance that seems to just work.
You can also run these frontends yourself, too, but I assume it requires accounts.
(edit: Also I hope it goes without saying that I don't really have any specific trust that my activity is necessarily more "private" with these frontends, although honestly if I was forced to bet I would have to bet that they are much more respectful to my privacy than Twitter or Reddit are. I just use them for functionality.)
Good luck fellow traveler. If there was more to do in real life, I'd probably had thrown my phone into the ocean by now. I'm about halfway there in spite of the lack of many appealing third spaces.
mey•Aug 14, 2026
I have Firefox setup to not launch apps on android with permission. I don't have Instagram/Facebook/etc installed. Attempting to view a Instagram link on mobile is the most hostile thing in existence. You essentially can't, but it so aggressively routes you to the website based Google play store it's horrifying.
FridgeSeal•Aug 14, 2026
Whichever devs implemented the Instagram behaviour ought to have their computer taken off them.
100% the worst experience.
“Oh you don’t have the app? No big deal, let’s (maybe) play the video anyway but remove the audio, obscure half the screen, and make any interaction redirect and then bounce to the App Store. Why won’t you download our app already????”
Sanzig•Aug 14, 2026
They have to be pushy, it's how they install spyware which use tracking methods that would be a CFAA violation and prison time for anyone else: https://localmess.github.io/
alex1138•Aug 14, 2026
I've been told Zuckerberg - as opposed to murdering competition in the crib, despite him being ON RECORD IN EMAILS as saying 'they can hurt us' - bought a company that was barely anything. It "had 12 employees" or whatever. How they've "grown it" or whatever. Not what I see. I see it as competition killing. People really liked IG... in 2012. Now it's a poster child (or is that Whatsapp?) for antitrust
sfn42•Aug 15, 2026
I don't use IG but my girl does and she likes to show me things. She does use the app and it drives me absolutely nuts how she tries to show me a video or image and I can't actually see/read the main point of it because there's a million gizmos (buttons etc) in the way that seem like they can't be hidden. Like actually 30% of the video is obscured by this pointless crap.
dpkirchner•Aug 15, 2026
I figure if they can't make a functioning website, the odds they can make an app are basically zero.
pino83•Aug 14, 2026
You can have Firefox and struggle with apps BUT you visit Instagram? This is actually possible both in one person? Wow.
mey•Aug 15, 2026
People share links to Instagram with me. It isn't something I seek out myself.
inventor7777•Aug 14, 2026
On iOS Safari, tap the three stacked lines on the URL bar (depending on which Safari view you use), tap Website Settings, then you'll see a Request Desktop Website switch, which should persist for that domain.
bee_rider•Aug 14, 2026
I don’t know if this site did something tricky or if it is something about how I access it, but the switch doesn’t persist.
moritzwarhier•Aug 15, 2026
There a two dropdown menu options for "request desktop" in my Safari, in that menu. Translations might be imprecise because I use German locale.
But one is in a section called "Website actions", then there's another one in a section named "Website settings".
I didn't even notice it myself until now.
In earlier versions (before Liquid glass redesign I guess, which enlarged all dropdown paddings), the latter was called "always request Desktop site for xyz".
getpokedagain•Aug 14, 2026
Its always confusing to me since I'm already accesing it through an app.
hinkley•Aug 14, 2026
And don’t ever save the user’s “no” for next time. We need to needle them to use the app EVERY SINGLE TIME the visitor the website.
I wonder sometimes how the team doing the website feels about being treated as second class. Or if it’s the same team and they have to hold their noses to work on it.
The third dumbest smart person I had to work with obviously hated HTML and kept trying to get us to use a DSL instead. At least it wasn’t an in house one, but he had a couple other devs interested in his madness as well. But the two of us who were doing the bulk of the performance work and tricky bug fixes would have been absolutely sunk if we’d allowed that to happen. One of the worst things about React is trying to track back an HTML bug in someone else’s complex React project to the templates that are misbehaving together. The Grafana UI code is madness to debug.We would have been there very quickly and without the dev toolbox to help.
jchw•Aug 14, 2026
YouTube does something that makes me irate: it saves the abusive autoplay settings only locally per device. There is no way to set it in your account, so every time I log back in I have to disable autoplaying thumbnails and autoplay next video. Every. Single. Time.
I think a lot of people get progressively worn down by things like this, but for me I actually get angrier each time it happens. It's probably good I no longer work at Google because I would probably feel genuinely enticed to find whoever is most responsible for this and engage in psychological warfare.
hinkley•Aug 14, 2026
Yeah it’s definitely passive aggressive and those people must be stopped.
But I think it’s sometimes by management design. Scrum makes it pretty easy to keep devs permanently off balance so they can’t think about how wrong what we are building is. Maybe that person really is a piece of work, but maybe they just have never had time to think about how dumb that decision was and go fix it. Similar to you, I’m glad I don’t know where Ken Schwaber lives or when he’s presenting because I’d probably call him a traitor to his stupid face.
Paracompact•Aug 14, 2026
I am now very interested in the second and first dumbest smart people you have worked with. You can't keep us hanging!
f17428d27584•Aug 14, 2026
National cinema chain has a banner on their web site that says something like “film lovers prefer our app” so they manage to employ a little guilt / social proof as well.
It’s such a small thing in the grand scheme of things but it’s just that final straw for me, someone made the decision to be this shitty to their users because they want to employ extra tracking/data collection / advertising in their app.
dcminter•Aug 14, 2026
eBay stops me from typing in the thing I want to search for so they can try to persuade me to use the app that I have expressed zero interest in for a decade or so. Guys, I'm trying to press money into your thieving little hands - why are you trying to stop me?
summarybot•Aug 14, 2026
Reminds me of Austin Powers:
21! Blackjack,
"Hit me!"
"...but Austin!"
"I also like to live, dangerously."
kmoser•Aug 14, 2026
They see it as a win because you've still been using their site for a decade now, and every time they advertise their app there's still a non-zero chance you'll relent, but if they stop pushing their app, that chance drops to zero.
The only winning move is not to play.
smaudet•Aug 14, 2026
And then uninstall the app...
dcminter•Aug 14, 2026
Ah yes, I shall use that other auction site. Which was it again?
bozhark•Aug 14, 2026
whitehouse.gov
yunnpp•Aug 14, 2026
These little easter eggs are why I read the comment section down to the Nth level of nesting.
inigyou•Aug 14, 2026
Make your own. You could even scrape auctions from eBay. You might think it's impossible but every other country seems to have a homegrown one, and not many people habitually go to eBay.
port11•Aug 15, 2026
Many per-country ‘competitors’ are actually owned by eBay.
heathrow83829•Aug 14, 2026
Wells Fargo went so far as to remove their best feature from their website: the Spending breakdown page! they now say go to the app but the app is far worse than the browser version was before they removed it. i might even stop using them just for this mess.
philistine•Aug 14, 2026
DO IT! They probably do not even consider the idea that they would lose customers due to UX. Lower rates, promotions, change of circumstances, but there probably isn't a checkmark in their loss of customer forms that include we made our user interface worse.
dessimus•Aug 14, 2026
Meh, WF already has their info, they just create 3 more accounts for every one that is closed.
delecti•Aug 14, 2026
Opening accounts like that might benefit the associate who gets credit for them, but money is the metric that actually counts.
And if nothing else, leaving a company whose service sucks doesn't need to send a message, it's just moving so the service you receive improves.
stickfigure•Aug 14, 2026
You should stop using Wells Fargo anyway. It's been what, nine months since their last national scandal? They're overdue.
malfist•Aug 14, 2026
You can try to stop using Wells Fargo, but they won't let you. They'll just open more accounts for you
mynameisash•Aug 15, 2026
When my wife and I finally got rid of our Wells Fargo accounts -- having sold our house and thus eliminated that mortgage, and having already moved our personal banking to a credit union -- we legitimately celebrated by going out to dinner.
mjhay•Aug 14, 2026
Sounds like that feature would really cut into their overdraft fees.
IAmBroom•Aug 14, 2026
Some Fucking MBA (SFMBA) heard that apps build customer loyalty and increase eyeball time on their sites, so now their company needs an app.
Repeat (without rinsing).
abustamam•Aug 14, 2026
How is the Reddit mobile site worse than this obvious satirical site? I ended up using ublock to zap the annoying Reddit thing because it was annoying to keep going to old.reddit when people sent me links.
unselect5917•Aug 14, 2026
I know the Brave browser can be set to always request the desktop version of the site. Whether or not the website respects that or not may vary. And yes, on iOS.
It's also effectively youtube premium for free as in beer. Lovely browser.
wombat-man•Aug 14, 2026
Wild that it is somehow worth it to stream video to every visitor on the hopes that it'll get them to stick around longer or see an ad in the video. That conversion number has to be crazy low.
wlesieutre•Aug 14, 2026
"We value your privacy! We and our 892 legitimate business partners use cookies to improve your experience."
_trampeltier•Aug 14, 2026
The record I saw is more like 1892 partner
alex1138•Aug 14, 2026
"They're enforcing GDPR so here's malicious compliance and our own little template verbiage about how much we do actually 'care' about your privacy. Now click me to deny or blindly accept like you have with EVERY OTHER SITE you've visited since this morning"
lxe•Aug 14, 2026
Feedback taken. Will ask ai agents to make improvements.
alsetmusic•Aug 14, 2026
Where are the third-party ads that interrupt the content I wasn’t able to read? And the popover telling me about singles on my area? Why haven’t I been offered a subscription to a newsletter so I can receive daily updates and offers to pay for additional services?
You’re right. It’s a good start, but there’s still a lot to do.
sidewndr46•Aug 14, 2026
No, it definitely hijacked the back button
eviks•Aug 14, 2026
> there is absolutely no way to scroll
Or, at the very least, at a widely different speed/acceleration that you're accustomed to
alex1138•Aug 14, 2026
Tribunals at the Hague.
(Not for this website, which is obviously a joke/telling commentary. I mean for real 'fucking websites'.)
I don't think the goal is to capture all of the ways a website can break, but to capture all of the tropes that corporations add to websites in order to check boxes of what they feel a website should be based on imitation.
christophilus•Aug 14, 2026
Yeah. No spinners. No pulsing gray placeholders that sit there for minutes and then shift the content when they load. No 10GB video playing in the background. My laptop didn't even get hot or spin up the fans when I viewed this page.
evandena•Aug 14, 2026
Elements that load slower than the rest of the content, so it bumps the links that you're trying to click down, and you click the wrong thing.
gofreddygo•Aug 14, 2026
Every. SINGLE. Recipe website.
Just search for anything like "egg omelette recipe". Click *any* link for example [1].
to be fair that's the fault of your search engine choice because you are using a search engine that ignores websites that aren't like that.
Perepiska•Aug 14, 2026
You forgot to mention condom^W Cloudflare between you and site. With "please tick checkbox to prove that you are a human" and "we add five minutes delay because you have old browser".
inigyou•Aug 14, 2026
there is code on that page to say you're definitely a bot and send you to https://unbotnet.me/ but I've never seen it triggered.
CodeMage•Aug 14, 2026
Don't forget hijacking Ctrl+K or Ctrl+F to display their own search modal.
aidenn0•Aug 14, 2026
Also needs a carousel that cycles in approximately 2/3 the time it takes me to read the item, with an arrow target small enough that I'm likely to miss the arrow and instead go to a random part of the page that I don't care about.
avdwrks•Aug 14, 2026
To be fair, this website was from 2020... To your point, the web has gotten significantly more annoying to use since then.
cpill•Aug 14, 2026
don't forget subscribe to alerts. my favourite, coz I want some random website to push notify me everyone it does anything
ColdStream•Aug 14, 2026
I was about to say, by today's standards this site is actually fairly usable. That is depressing.
yassa9•Aug 14, 2026
Yea , thank u , I really despite those websites of current web, much JS, colors, much images and animations with mouse, and million fonts , rounded buttons and everything is rounded and "modern" and slow and bloated
why cant have we simple websites, small coherent nice color palette
to just read and know the needed info ?
hackernews is extremely good example
suckless: https://suckless.org/sucks/web/
is another brilliant example
improgrammer007•Aug 14, 2026
I use Brave browser and even that didn’t help.
fuzzy_dunlopp•Aug 14, 2026
SmallWeb ftw!
tonymet•Aug 14, 2026
It’s missing a “we stand with the current thing “ flag and a compliance prompt for community standards.
Also 1.5gb of heap allocated minimum
hbcdbff•Aug 14, 2026
Not enough AI slop
clintmcmahon•Aug 14, 2026
Is the beef with the design or the pop ups, chatbot, banner, etc?
If it's the design, not everyone is a web designer so the bootstrap theme is great to get up off the ground.
If it's the other stuff then, yeah, totally.
rob74•Aug 14, 2026
(2019) *
* according to the copyright notice, although, going by the mention of Covid, it could also be 2020?
croes•Aug 14, 2026
The cookie banner should have the option to change the cookies but you have to deselect the trackers one by one
JKCalhoun•Aug 14, 2026
Yeah, I hand-rolled my site. Not even Google analytics. I have absolutely no idea if anyone even visits my site.
Oh well.
1dom•Aug 14, 2026
No need to worry, I just visited. Now you know.
Seems like the sort of site and person who should have a guestbook - I would have left an appreciative and encouraging comment there, but this will have to do:)
donatj•Aug 14, 2026
We've got the stupid chat bubble at the bottom.
We didn't want it, it's like a megabyte of JavaScript. It's some third party service corporate forced on us.
I have to imagine a lot of websites are in the same boat, where they're just add crap they don't want to add by higher ups.
duxup•Aug 14, 2026
Cookie banners are a great example of regulation gone wrong.
Me having to make a legal agreement with every website is absurd and totally predictable.
amelius•Aug 14, 2026
Apple.com looks ok. It doesn't have the cookie banner.
The confirmation when pressing back was the icing on the cake
maqp•Aug 14, 2026
I can't believe I'm not able to buy Every Fucking Website Premium with business focused ads and native advertising masquerading as quasi-educational infotainment. Also where's the sign-up with Spybook?
freediver•Aug 14, 2026
Answer: ads as the main business model running the web since 25 years ago and us accepting the convenience of 'free'.
It turns out everything has a price, and in more recent times we started noticing that our time, attention and intelligence not being insulted also has value.
jmmv•Aug 14, 2026
Somehow the clicking around reminded me of Windows RG. Go check this old relic if you have never seen it: https://www.jamesweb.co.uk/windowsrg . Turn the volume up!
aavci•Aug 14, 2026
Where is the ‘sign in with google’ pop up?
t1234s•Aug 14, 2026
The worst patterns:
1) scroll hijacking (this should be a felony)
2) stupid cookie popups/banners
3) useless hero images (clients love them, users hate them)
0xbadcafebee•Aug 14, 2026
Needs a shopping cart that when you click submit, does nothing, requiring you to open web dev tools to discover the silent 503 error, with no way to report the error. Bonus points for a bank account, credit card or retirement fund
lxe•Aug 14, 2026
lol
idopmstuff•Aug 14, 2026
I started an e-commerce brand on a Shopify site. I swore to myself I would never put up one of those stupid things that pops up "Someone bought X product an hour ago!" messages in the corner of the screen.
I ended up trying it. Boosted conversion rate meaningfully. Worth the price I pay in mild self-loathing.
Chesterton's popup, I guess.
frantathefranta•Aug 14, 2026
Out of all the annoying website things, always thought that one was pretty tame. Almost feels like a spiritual successor to the visit-o-meter. Obviously as long is it doesn't put a (1) on my tab or makes a noise and doesn't steal mouse focus.
rao-v•Aug 14, 2026
Genuine curiosity - is the pop up vaguely factual or sort of randomly generated?
m4tthumphrey•Aug 14, 2026
Always randomly generated!
rao-v•Aug 14, 2026
I salute your honesty! But [he hastens to add, looking furtively around] I also frown disapprovingly at your choices
phoghed•Aug 14, 2026
You’re saluting the honesty of someone who is not the original person who’s lived experience you were asking for lol
rao-v•Aug 14, 2026
Ha!
xXSLAYERXx•Aug 14, 2026
Gosh, I always assumed they were factual. Now I'm wondering the factualness of the old "15 people have this in their shopping cart" and "This is a popular item - limited stock left".
idopmstuff•Aug 15, 2026
Entirely factual. It's "Someone from <city> bought <product> <period of time since purchase> ago!" with a picture of the product. All purchases are real.
m4tthumphrey•Aug 14, 2026
This is not in the same sport let alone league as the things demoed in OP.
agumonkey•Aug 14, 2026
Is there a law of society / business where everything we hate is on average something that made the society able to function ? it's similar to chesterton but it's not a fence, it's the tree we live on.
LollipopYakuza•Aug 14, 2026
This reminds me the clickbail title and thumbnail on YouTube.
One of my favorite channel apologized for it but explained that the difference compared to NOT doing this is phenomenal and they can't afford stopping.
ivanjermakov•Aug 14, 2026
Don't get me started on "like and subscribe".
inigyou•Aug 14, 2026
Sponsorblock can be configured to skip these.
olyjohn•Aug 14, 2026
If this is the only way to get people to watch your videos, maybe your channel sucks. But glad you are making money tricking people into wasting their time so you can get one more ad impression.
inigyou•Aug 14, 2026
So every channel sucks?
debugnik•Aug 15, 2026
Sounds like you've let your feed fill with shitty channels, but no, not all channels do this. I mostly refuse to watch videos with those cringe clickbait thumbnails, and I've still got more stuff to watch that I've got time for. And it's mostly gaming and variety streamers, or music/animation artists; not serious stuff.
Now, I'll grant you that these may not become as successful as the clickbaity ones. Then again, the latter channels might as well not exist to me and like-minded people.
Just an hour ago I unfollowed a streamer precisely because he's been getting clickbaity. We've got to take some responsibility over the people we choose to watch.
ryandrake•Aug 14, 2026
That's the real problem. Being aggressively annoying works. Dark patterns work. Popups that grab your attention work. Flashing text conveying urgency works. Thumbnails with open-mouth YouTube-face work. Moving buttons around so people mis-click works. Tiny [X] buttons that make people accidentally click an ad work. You're never going to convince someone to stop doing something that is making them money.
gigatree•Aug 14, 2026
Absolutely. Maybe the answer is that everyone should just rank them up to 11 until it stops working and then people have to get creative again.
toyg•Aug 14, 2026
The tech field is increasingly devoid of any resemblance of morality.
I guess it's the inevitable parable of anything started by '70s hippies: sooner or later, we all sell out.
theappsecguy•Aug 14, 2026
I think most fields are like that..?
inigyou•Aug 14, 2026
The entire system of capitalism is like that, and the system is shutting down the parts that aren't like that, and replacing them with ones that are.
vovavili•Aug 14, 2026
Leaving money on the table is never easy.
wakamoleguy•Aug 14, 2026
On the extreme side, things like blackmail and fraud are generally illegal, even if they can make you money. Most of these dark patterns that "work" tend to follow a similar pattern: by taking advantage of the target, one can extract more money from them.
I would possibly be a terrible salesperson, because these all give me the ick. Your product should provide an offer of genuine value.
gtowey•Aug 14, 2026
Yes, but on whom does it work?
Does it work because you're taking advantage of a group of people who are extremely vulnerable to manipulation? People who already struggle with impulse control, who are prone to making bad financial decisions? The elderly, kids?
We have to escape this mentality that anything that makes money is valid, that the money itself is the validation of "rightness".
Some of us, just some think that maybe enterprises that prey on the vulnerable just don't deserve to be in business. Otherwise everything might as well be payday loans and online gambling. I'm not saying OP is definitely in that category, but I would encourage them to think long and hard about weather or not using dark patterns to goose their sales is really the kind of world we want to be fostering.
d3rockk•Aug 14, 2026
>Yes, but on whom does it work?
Hitting the nail on the head here-> know your target audience.
danillonunes•Aug 14, 2026
Well, if you own an online casino, I guess your moral compass is already so skewed that you simple don't care. On the other hand, if you own an online mom & pop store that sells clothes for puppies, you rationalize that the impact of those manipulations is not that big of a deal. You're not ruining anyone's live by the single act of persuading them to purchase $100 worth of apparel for mr. pancake.
sarreph•Aug 14, 2026
> people who are extremely vulnerable to manipulation
I think this is a gross over-exaggeration, otherwise dark patterns wouldn't work at the magnitude (majority of the buying population) they do.
I say this not disagreeing with your point:
> We have to escape this mentality that anything that makes money is valid, that the money itself is the validation of "rightness".
DavidPiper•Aug 15, 2026
I agree with you too, but I don't think it's necessarily a gross over-exaggeration: it's possible that the majority of the buying population are extremely vulnerable to manipulation.
"Average" doesn't necessarily mean half way between two extremes - the average human might actually be all of:
- extremely vulnerable to manipulation
- struggling with impulse control
- prone to making bad financial decisions
- the elderly / kids (<16/>60)
Based on age demographics, rampant consumerism and social media addiction, especially in those age demographics, I'd be more inclined to guess the average human is all of those things.
jen729w•Aug 14, 2026
> We have to escape this mentality that anything that makes money is valid, that the money itself is the validation of "rightness".
I agree. But.
I run an online business. It's tough. I scrape by. GP noted that the skeezy popup "Boosted conversion rate meaningfully". So that's real money in GP's pocket that they presumably use to have a nicer life. At what cost? Some popup? I mean…
Would I take more money in my pocket? Boy, I'd like that. So far I haven't gone the skeezy popup route, but the day I try, and more money ends up in my pocket, it's gonna be hard to turn that thing off.
I'm not judging, is all I'm saying.
idopmstuff•Aug 15, 2026
Yeah, I mean at the end of the day there is clearly a spectrum of conversion rate optimizing stuff you can do, some of which is fine and some of which is unethical. A/B testing the color of your add to cart button and using the one that converts best? I think it'd be a little crazy to argue that's unethical manipulation. Lying to customers about the product to get them to buy? Obviously bad.
Silly obnoxious social proof popup is clearly on the ethical side in my view (my issue was never ethics, just that I personally find them very annoying). I'm not misleading anyone (it does in fact show real purchases) or forcing anyone to do anything. If that's the difference between you buying or not, I still feel perfectly comfortable that you made the choice of your own free will.
RoddaWallPro•Aug 14, 2026
That's the real problem: selling drugs works! Forming a cartel to produce and distribute addictive products, killing anyone who gets in your way? It's effective! You're never going to convince someone to stop killing people and dumping their bodies into culverts when they're making money. It's just not reasonable to expect that, or do anything about it.
TZubiri•Aug 14, 2026
Nuance: if someone actually bought the product 1 hour ago, it's fine. If not, it's fraud.
yencabulator•Aug 14, 2026
And if the drugs do make you feel good, that's not fraud either.
cm11•Aug 14, 2026
Very much agree, but also (not saying you're saying otherwise) stealing, lying, entitlement (which is possibly just stealing and lying), and scamming "work." These are checked in large part by a person's aversion to it not just by its lack of working. Of course dark patterns work. If what one says increasingly inches towards 100% misrepresention (but shy of it), people will "mistake" what's being said. "Mistake" doing a lot of blame shifting.
"You're never going to convince someone to stop doing something that is making them money." Reasonable, but I would soften from "never". There was less of it at one point—and it seems logical to guess we have less today than we'll have tomorrow. The main reason is likely that we simply didn't know about these tricks yet, but somewhere below that on the list of the reasons is that some people dropped off from doing it at lesser forms of misrepresentation. Or they made the case against it at work resulting in them either winning (and their projects perhaps did less well) or them losing and being overrun by those more willing. With losing possible also leading towards leaving, not getting promoted, or getting fired. This is just a way to say that there are people who do forgo money, they just might not be around or visible for various reasons. And, as implied by the difficulty of convincing people to not make money, their (former) coworkers prefer that on some level even if they don't believe they agree with stealing or lying. But losing or earning less money is not the same as having no choice.
inigyou•Aug 14, 2026
There used to be less data to optimise from. Doing ordinary business is a low risk strategy, compared to dark patterns. Now we have data to enable us to do dark patterns without risk.
xtracto•Aug 14, 2026
Spamming image based penny stocks emails also worked; doesn't make it right.
Advertising should.be illegal.
dieselgate•Aug 14, 2026
> Advertising should.be illegal.
I dislike advertising as much as the next guy but wouldn't go so far as making it illegal
xtracto•Aug 14, 2026
I was thinking of this post that made the rounds here some weeks ago:
Thank you for the follow up link, it brings up good points. I think the 1st Amendment angle is too quickly brushed off by the author and not sure how this would be settled in a legal dispute--especially considering the means and depth of advertising and tech companies. The article is worth reading and great food for thought.
Isn't this a part of legally excluding under-18s from using social media?
inigyou•Aug 14, 2026
If giving out anti-draft pamphlets is considered by the courts to be equivalent to shouting fire in a crowded theatre then why couldn't advertising?
moritzwarhier•Aug 14, 2026
(edit; not directly responding only to your comment, also to the parent)
Advertising is shitty but how would you realistically even make it illegal without violating free speech.
Also, advertising does have a good-faith purpose in functioning markets.
Failures in regulation IMO are mostly at entirely different levels.
E.g. monetization of public utilities and public space. Noise, brightness, and of course deceptive tactics could all be better regulated as well.
But advertising, including its diffusion into general pop culture and entertainment, is older than the printing press, and I think for a broad sense of "advertising", even a lot older.
inigyou•Aug 14, 2026
Plenty of countries don't have unlimited free speech. The USA, even, isn't one of the countries with the freest speech.
moritzwarhier•Aug 14, 2026
Sure, but which countries ban all advertising? Is a logo advertising?
Or only advertising in media?
Urban spaces? Sure I'd say, but what about your storefront?
Encouraging word of mouth?
unselect5917•Aug 14, 2026
I hate that you're right. Short term gains for long term suffering, though?
Just another horror beyond our comprehension?
bigbuppo•Aug 14, 2026
I actually kind of like those, though I've always been suspicious that those events are fabricated because that's the sort of thing marketing people would do.
mikestew•Aug 14, 2026
I got one of those on Etsy not long ago: “only one left!” Fuck off with your FOMO, Etsy, there’s plenty left.
Five minutes later, “add to cart”. Etsy: “sold out; we weren’t lying!” So in this particular case it didn’t work. But it will next time.
inigyou•Aug 14, 2026
Clear cookies and try again. But better yet, boycott Etsy.
apple4ever•Aug 14, 2026
Yes but a small popup I. The corner is different than a dickover. I don't think what you did is bad at all.
andrewflnr•Aug 14, 2026
If it's not a lie, then yeah, that's pretty mild.
coldpie•Aug 14, 2026
Yeah. I've written about this a few times, with some suggestions for how to make it marginally less miserable to visit a website:
If the traffic to the site drops dramatically because of the “features”, we would have seen the features removed already.
lxe•Aug 14, 2026
I made this 6 years ago but it still applies today.
josefritzishere•Aug 14, 2026
This is completely accurate. I see it every day.
dstanko•Aug 14, 2026
I may be skeptical, so take this with a grain of salt. The transformation happened when someone decided to stop being UI designer, to become UX designer. That wasn't enough, so they came up with XD - experience design. At every step of the way, they introduced more lofty goals for the design to justify the increased importance of themselves.
gnarlouse•Aug 14, 2026
Why would you make this. I feel traumatized.
lxe•Aug 14, 2026
To spread suffering
imagent•Aug 14, 2026
You're hired
1dom•Aug 14, 2026
This feels about 2 - 5 years out of date now. There isn't enough dark theme with slop-neon accents.
lxe•Aug 14, 2026
I should modernize this?
1dom•Aug 14, 2026
Claude should modernise this. It'll come out looking like all the other results when you search an image engine for "AI landing page": dark, with purple, blue or other neon accents.
2b3a51•Aug 14, 2026
I'm filing a bug report...
Steps to reproduce:
Open terminal emulator and type;
The web is more than blogspam, SaaS, the most desperate cases of ecommerce, and the web versions of legacy newspapers/magazines.
buzzin__•Aug 14, 2026
How hard could it be to write a greasemonkey script that will send the current html/Javascript from hell to a LLM with a prompt that will ask you which of the detected annoying elements you want to remove, and then will create and install another GM script that is removing those elements from this site, and also invent finglonger as a side effect. A man can dream, though. A man can dream.
agumonkey•Aug 14, 2026
it's missing the google sso popup, the close buttons are not anti-pattern enough, and the cookie banner still lets me use the site too much
good job though
dansitu•Aug 14, 2026
Maybe also it could randomly jump to different vertical scroll positions while you are reading an article?
snawazzee•Aug 14, 2026
I knew it wont work but still I tried to enter a message in chat window and click enter. (And it didn't worked)
nphardon•Aug 14, 2026
A while back I realized that it was just the browser keeping me on screen when I didn't want to be. I switched to the purely native Safari app on my phone, from a highly customized ad blocking browser, with lots of content filtering. My screen time dropped from like 2 hours a day to like 10 minutes.
ChipopLeMoral•Aug 14, 2026
Missing some spammy "article" links with AI generated images.
charles_f•Aug 14, 2026
You forgot the sign-up "CTA" button bold and wide, with a microscopic "Sign-in" button somewhere in the footer.
hk1337•Aug 14, 2026
If it works, keep it. If it doesn't work, remove it.
TuxPowered•Aug 14, 2026
Every Fucking Website 2026:
- Paragraphs emerge from the background as you scroll, sometimes only after 3/4 of your screen is empty.
- Some paragraphs are hidden until you expand them. You can’t expand more than one at a time.
- Horizontal scrolling for some items, like e.g. meal categories in a restaurant. The buttons for the scrolling are different on each site, or are dots you must click on.
ajam1507•Aug 14, 2026
Needs an annoying header that changes size as you scroll.
bilekas•Aug 14, 2026
How will the poor analytics companies pay their poor salaries? And how will people be able to know to advertise to me about a pair of shorts I looked up last month??
insane_dreamer•Aug 14, 2026
missing the popup to "SAVE 10% ON YOUR NEXT ORDER" by giving your phone number, with no "No Thanks" button, and the X button to close the popup is almost invisible in the corner so you think there's no way to get rid of it other than entering your number
phoghed•Aug 14, 2026
Should request push notification and local network access lol
chrisjj•Aug 14, 2026
Did I miss "We share your PPI with 1786 partners" ?
VCFundedGenYer•Aug 14, 2026
Some graybeard advice - Any time you need to use a website that doesn't require active cognitive interaction - click the button in your browser that enables Reader View to get the content and strip out everything else. It's not perfect, but it makes the web more usable (especially on mobile, my goodness it's gotten bad).
Firefox also has an extension called "Auto Reader View" in which you can set sites to automatically change to that mode.
bigbuppo•Aug 14, 2026
The interstitial popup needs to be delayed until about 750ms after the first scroll action for that extra insult.
mawadev•Aug 14, 2026
Beautiful engineering, it is modern art. I missed the very slow skeletons in between and the particle webgl stuff
jdthedisciple•Aug 14, 2026
needs more unexpected layout shifts ;)
Cameri•Aug 14, 2026
Not enough ads!
bigbuppo•Aug 14, 2026
also didn't yell at me for using an ad blocker.
donio•Aug 14, 2026
In 2026 instead of "Here's some stuff we wrote that you won't read." it's "Here's some slop we couldn't be bothered to write but why don't you read it."
It needs a feature that disables the whole page and prevents you from using it if it detects you are using Forefox.
jere•Aug 14, 2026
monkey's paw curls
smaudet•Aug 14, 2026
Serious answer:
Bootstrap.
That framework did more damage to web design than any other framework. Yeah, its nice that you can spin up a page in a second that looks like every other page on the internet, wait a minute...
Technical answer:
CSS
It was a nice idea, and it sure beat hand-designing each and every page (wait a second, weren't/aren't we doing that all over again?).
It did/does too much, and was mostly in lieu of a common repository of UI stuff, so people found One Way that it would work reasonably well on most browsers/devices, and so bootstrap was born...
dcminter•Aug 14, 2026
There's some alternate timeline where browsers kept competing on widgets and every website now looks like a native application.
I don't know if it would be better or worse.
trueno•Aug 15, 2026
I was hanging around during the bootstrap era. It was fine, no i think theres some blend of where UI/UX/marketing that were way overblown that really blitzed all sites into looking the same. Every component framework or helper framework under the sun is barely doing anything different. Shadcn, daisyui, tailwind, all of that.. it's all customizable but people aren't interested in making something fresh and new using bootstrap/daisyui/shadcn/whatever, the components aren't the problem. Anyone could if they took the time and effort put together something pretty unique using any of these, but they don't. Outta the box yeah they are particularly bland (flat buttons and rounded everything literally sucks I'm so tired of it), but it's _what_ the page is and how it's arranged that is reeking with sameness / pointlessness / enshittification. And that abomination is... landing pages. These pages are fkn awful. Career UX/UI folks will defend them, and this just feels like they smoked too much of their own shenanigans.
Every SaaS under the sun, hell half the things here that end up with some sort of VC backing... the first thing they do is spin up a nothingburger landing page that says a whole lot of jack diddly squat that all have a familiar feel where everything's centered, there's meaningless bulletpoints and info cards, but no real meat or information that describes what you're after... that feeling = "how do i beat gd level 1 (this landing page) so i can find what im looking for" and yeah. This has bled into documentation spaces as well, somehow rendering documentation (the thing that is supposed to help you get oriented) feel like you can't actually find what you're looking for.
UX/UI in the past decade was blown way out of proportion and I can't help but feel like it's been shaped by way too many imperfect half theories / stupid market research and is way too heavily influenced by marketing and adspace to be taken seriously. In general there is certainly a taste for what makes a good UX and that to me is typically a blend of utility and looks-cool. But without any utility everything feels like a goddamn waste of time & I'm mostly assured that websites that sport pages like this have way too many financial strings attached driving their every move. They all try to drive you towards filling out a sales inquiry form. It's ironic and hilarious that a lot of times if I want to learn about some platform or product, the last place I can reliably go to is their own website. These days you just gotta go digging, ask claude to go collect a bunch of user feedback from around the net or something.
aavci•Aug 14, 2026
I don't see any answers here with a link to best practices or a grading system or something promoting clean websites. What can be done in this space?
You get things rating accessibility, methodologies for building apps but nothing about standards for website quality?
tonymet•Aug 14, 2026
neal.fun did it better
zelphirkalt•Aug 14, 2026
Any web dev reading these comments and understanding what the comments express, should know: If you have built any of these dark patterns and anti-features, the annoyance and loathing expressed here is what you are responsible for, and this is how you made people feel about the website you took part in building. By implementing such stuff, you are personally part of the responsible group of people for making this crap. You personally have managed to make this planet a worse place and make your website shit. Given that these days basically 95% or more of websites push this shit, it is safe to assume, that there are many of such web devs in our midst, who are responsible. Congratulations for ruining the web.
apple4ever•Aug 14, 2026
Fucking dickovers. The modern web sucks.
wseqyrku•Aug 14, 2026
I can ignore all this except for the cookie banner, it is a technical issue and the likes of google in the industry are responsible to solve rather than letting marketing or product get "creative" with it. This is pretty stupid and we all should be embarrassed by the fucking mess that we created for everyone.
simondanerd•Aug 14, 2026
There's a distinct lack of ads, you're not done quite yet.
CM30•Aug 14, 2026
Let's not forget the generic images using either corporate memphis or AI. Or the lazy loading that makes it impossible to reach the footer. Or in some cases, numerous videos and animations that have no purpose other than looking flashy, along with a big slideshow/carousel at the top.
RobLach•Aug 14, 2026
Only gotten worse.
m3047•Aug 14, 2026
Well that's pathetic, only three new FQDNs. Two of them are on CF, one on AWS. Where are the effing CNAME chains?
And this is something which I learned which is surprising to me: github.com resolves to AWS. WTF? GH has its own netname and a /20. It's literally one hop, somehow, from my ISP. WTF? It's not MS and it's this shite? WTF?
aspectmin•Aug 15, 2026
Sigh. A good user experience for the web is just out the door isn't it? Max enshittification. Makes me so sad - it could be so much better.
bookstore-romeo•Aug 15, 2026
very sorry for the joke, but isn’t every regular website also like this?
109 Comments
Actually big tech is to blame: https://killthecookiebanner.eu/
- https://www.edps.europa.eu/data-protection/our-work/subjects...
- https://en.wikipedia.org/wiki/EPrivacy_Directive
I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.
Companies could stop selling and storing your data. They could only use cookies when absolutely essential. They could use lots of kinds of UX.
This is the equivalent of businesses who put a big visible "20% the state says we have to give our employees healthcare" fee on their bill to throw a hissy fit and hope customers get angry at the government for protecting them instead of the business for exploiting them.
As many have said before:
[1] https://news.ycombinator.com/item?id=29529148[2] https://news.ycombinator.com/item?id=38299135
[3] https://news.ycombinator.com/item?id=46552795
[1]: https://www.europarl.europa.eu/portal/en
We are just conditioned to see it without difference in basic tracking and tracking all your clicks across site and selling it to advertisers.
There's a reason you don't hear about people "maliciously complying" with HIPAA or PCI laws. Because that's just called compliance.
No excuses for poorly done EU regulations.
A comparison would be a store who was angry the law says you have to be 21 to buy alcohol and starts requesting everyone, even people not buying alcohol, to show ID or be kicked out. That's not a bad law, that's a bad business maliciously complying.
It's like those warnings in cigarettes packages saying they will kill you. I know cigarettes are bad, but the warnings also make me believe there's at least "some" control in how bad they are. Now if I buy one without the warnings, I will worry those in particular are extra-shady and likely to kill me even faster.
Oh how I miss those warnings. Nowadays the packages are covered in graphic body horror pictures. And there's no branding on them any more, just white text on a black background, so I have to carefully check that the illiterate teenagers at the store gives me the correct ones.
Do anyone else hear circus music?
One of the best indicators that something was not spam was the unsubscribe button.
Most small business owner's I've spoken to are keenly aware they are only one bad lawsuit away of closing down. Almost no one care's about the cookie banner. Most just mindlessly click to allow cookies and go on with their life. There's almost no cost to having it.
When I see these dialogs listing they have 1289723 gazillion vendors they share data with, I know that whoever is in charge of analytics, privacy or both at the company is incompetent.
Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they couldn't deny that it cost a fraction of what we were paying our supplier and that things took minutes to set up rather than weeks. And that they worked a lot better.
Yes, there was shouting in meeting rooms. And yes, people said "you can't do this". Turns out they were wrong. A few years later I mentioned this to Werner Vogels. During a meeting. Where my CEO and CTO were present. And where everyone was feeling very good about us being one of AWS' biggest customers in our region.
So when someone says "you can't do that", sometimes you should make them prove it.
(At the time AWS was a good idea. Today dependence on a US service provider is a harder sell in Europe. The _first_ question you get today is if we can host it ourselves if we need to or if we can use a local service provider.)
So how would you do ePrivacy Directive compliance/risk avoidance in a non-obnoxious way?
Completely eliminates the need for a cookie permission bar.
If you want to remember dark mode with a cookie, then you can just gate that setting behind a “allow functional cookies” toggle.
Getting consent for functional cookies doesn’t have to be done with an intrusive cookie bar on landing. You can request consent as it becomes needed. There’s other ways of complying that aren’t dark patterns.
In any case here is a plain text interpretation from the EU (https://gdpr.eu/cookies/):
"Strictly necessary cookies — These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookies. While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user.
Preferences cookies — Also known as “functionality cookies,” these cookies allow a website to remember choices you have made in the past, like what language you prefer, what region you would like weather reports for, or what your user name and password are so you can automatically log in."
Farther down:
"To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must:
Receive users’ consent before you use any cookies except strictly necessary cookies. ..."
So a preference cookie is categorized differently than "strictly necessary" by the ePrivacy rules predating, but now part of, GDPR. But elsewhere in this thread someone asserted that a cookie that is placed and the data never sent back to the server is exempt, so if you handle dark mode entirely client side you might be ok?
I'm beginning to understand why the lawyers in the EU just say "fuck it, put a banner up"
You are correct that people keep stating such things. But it is incorrect.
That example would be an essential cookie, also known as a strictly necessary cookie.
A shame this FUD is still being spread.
I suggest actually reading the GDPR if you think it applies to you. The EU put it up on a website for everyone to see. Here's the most relevant section: https://gdpr-info.eu/art-6-gdpr/
Notice how cookies are not mentioned, popups are not mentioned, and strictly necessary is not mentioned. Those are requirements the data harvesting industry invented out of whole cloth. They are not the actual requirements.
I'll just repeat that one more time: the GDPR does not mention cookies or popups. Let that sink in. It's all cargo-cult.
The GDPR also doesn't give a shit about dark mode preference. Literally nothing in it has any relevance to a dark mode preference, even (and especially) if you store it in a cookie.
In short: the GDPR doesn't mention it but it is covered by the ePrivacy directive/regulations which does cover cookies very specifically, and which is enforced through GDPR.
What's more, if the 'cookie' is entirely local (i.e. it's never sent back to your own server, e.g. you're using the local storage API and the javascript on your page never puts that information into a request), like how this would normally be implemented nowadays, then these requirements don't apply at all (because a cookie according to the law is just something your server gives to the user's device and then the device gives back later).
At least for GDPR...
The only ways to actually track without a consent pop-up are:
(1) stay off the device entirely and process server-transmitted data under legitimate interests with a privacy notice, or
(2) confine any device storage to what's strictly necessary for the service the user requested
in fact. you probably don’t need to track users.
It would be extremely beneficial to businesses to put a clause in their terms and conditions that limit damages to 1 cent in the event of any dispute. For obvious reasons we don't allow anything like that to be enforced.
I'm not saying whether tracking should or shouldn't exist, but "the business can make more money" is not a valid argument in my book.
He may be right, sadly. I’ve seen the lack of a cookie banner used to suggest that a site was doing something shady or not complying with the law.
Most people don’t have knowledge about the finer details of cookie laws. They’ve been trained to believe that legitimate sites who comply with the laws will implement the cookie banner, and not seeing it feels suspiciously unprofessional.
I have yet to head that cookie prompts are a sign of legitimacy. What business has customers that would think that way?
Although if you've ever worked retail, you'll know that plenty of customers are idiots.
Whatever "Surely no one is that stupid!" assumptions you make will be proven wrong no matter what you do.
The obvious conclusion is that when you try to regulate something like this you arent going to get the behavior you want.
It's trivial to make a site that doesn't need a cookie banner: don't set any cookies. Modern web devs have probably forgotten, but this is actually the default behavior. Cookies don't get set unless you do something to make it happen.
And cookies that you actually need for functionality don't need a banner either. If you're setting a session cookie for logged in users so they stay logged in when navigating between pages, you don't need one.
Why, then, does practically every site in existence now have one? Because they set unnecessary cookies. Because they choose to set unnecessary cookies in order to track you for purposes that are not necessary to the actual functionality of the site.
Every single cookie banner you see is a big sign that says, "We value our ability to track you for marketing purposes more than we value your time."
Apparently they're willing to say that. I still see it as a win. No tracking and no banners would be ideal, but at least the regulation forces them to be honest and up front about what they're doing. I'd rather have tracking and cookie banners announcing it than tracking with zero indication of tracking.
They could have instead targeted it, and applied it, to third party ad providers only, like Google. And, btw, Google is big enough they could have just outright named it. They're worth as much as the GDP of Germany. Why not just make a Google law?
So yeah, maybe good intentions but it clearly shows the EU parliament is still too young and inexperienced.
And if you decide you need them, you can do them server side. That's not as good? Oh well. See above about want vs need.
Why not just make a Google law? Because Google is far from the only abuser. Using a VPN that routes through Europe is a real eye-opener. At least whatever country I got routed through apparently required that cookie banners include a list of every single partner who got your data. Pretty much every site had hundreds of them. One was literally over a thousand. No, the entire industry is rotten. And the epidemic of cookie banners just shows how rotten it is. They can't even be shamed into behaving.
The only cookie is a functional one.
E.g. "we don't set any tracking cookies, so we're already compliant with the law even without banner, so there's nothing to decline or agree to".
The only mistake EU policymakers made was underestimating how willing companies were to deface their websites.
Copy pasting an older comment because it’s really coming up all the time…
https://news.ycombinator.com/item?id=49060456
===
That's not true and is a very common misinformation people repeat online. You can save user preferences in cookies without any consent banner, if the cookie isn't used for tracking. See here[0], page 6: > As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’ 0: https://www.edpb.europa.eu/system/files/documents/2024-10/ed... As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen
Let's check what "Opinion 04/2012 on Cookie Consent Exemption" [0] says under section 3.6:
"""
3.6 UI customization cookies
User interface customization cookies are used to store a user’s preference regarding a service across web pages and not linked to other persistent identifiers such as a username. They are only set if the user has explicitly requested the service to remember a certain piece of information, for example, by clicking on a button or ticking a box.
...
These customization functionalities are thus explicitly enabled by the user of an information society service (e.g. by clicking on button or ticking a box) although in the absence of additional information the intention of the user could not be interpreted as a preference to remember that choice for longer than a browser session (or no more than a few additional hours). As such only session (or short term) cookies storing such information are exempted under CRITERION B. The addition of additional information in a prominent location (e.g. “uses cookies” written next to the flag) would constitute sufficient information for valid consent to remember the user’s preference for a longer duration, negating the requirement to apply an exemption in this case.
"""
See that you need to provide provide "information in a prominent location (e.g. “uses cookies” written next to the flag)" to be able to store user preferences in persistent cookies. You don't need consent banner for that (which I didn't say you need), but you need to clearly inform the user. The act of setting a preference together with clear information about persistence counts as a valid consent.
[0] https://ec.europa.eu/justice/article-29/documentation/opinio...
Settings are not mentioned. Cookies are not mentioned.
Yes and that is a MASSIVE mistake for a policymaker to commit. They should absolutely be pilloried for their incredible lack of foresight and understanding of how internet companies handle compliance. The policy has set back humanity by further desensitizing internet users around the world to the terrible, endemic use of cookies by most websites.
Just like websites also give zero fcks about accept-language header... sure do geoip lookup, so much easier... not
“Oh you want consent involved in this interaction? Then we’ll annoy you about it constantly instead of respecting the intent of the regulation.”
It’s simplest just to put the bullshit everywhere and the dipshit bureaucrats will leave everyone alone.
If every webdev who would say no can be trivially replaced by webdevs who won't say no, then yes, it is webdevs.
Thank god I am just a minion who now can go home worry free. Yay!
Be it the EU for regulating disclosure and consent requirements, users for being "lazy" and usually just accepting all, or the webdev for not staking their livelihood on denying the banner - I'm sure they'll all get blamed before someone sees the ones actually demanding it be done can be the problem.
I'm going to risk months of unemployment and explain to my family why this is more important than eating when I get home. The internet is serious business, they'll understand."
-- the hypothetical webdev in that scenario, I guess?
Mate, it's just a cookie on a site.
It is an important fight for our future with our tech overlords. But sure - some will be happy owning nothing.
This is really one of those "First They Came" moments.
Unfortunately convenience trumps all. So for many "its just a cookie".
I used to have long conversations with frontend developers that "no, when I log on I don't want to be forced through a look-at-the-new-feature-we-made" sequences. And then they went ahead and did it anyway. And usually whatever flag they tried to set to make sure you only saw it once would malfunction, so next time you'd get to click through it all over again.
(If you want to tell users about new features, show a unread flag on a notification icon and make it a one-click affair to make it go away. Don't get in users' face with stuff they don't want)
It feels similar to how CA environmental regs become the national standard simply because the market is so large it’s not worth splitting on it. So they just slap a cancer warning on everything
2. If you are a purely US entity with no actual business presence in the EU, you only need to comply with US laws and nothing else. If the EU doesn't like a purely-foreign website, it's on them to set up a national firewall and block it.
Case in point 1: It's not on you to comply with China's laws, it's on them to block it if they want to
Case in point 2: China's local businesses with no EU presence do not follow GDPR and do not display cookie banners even if accessed from the EU
1. When is the last time you saw China enforcing its laws outside their borders? Why would EU be any different?
2. China has laws that are directly contradictory to GDPR laws; you may be required to retain data regardless of consent; if your website is based in China you have to follow local laws first before you follow contradictory foreign laws that have no jurisdiction over you.
Check out: https://killthecookiebanner.eu/
It’s only broken to the extent that it collided with a messed up world where websites track even when they don’t need to and then send that to 2000 partners for more profit extraction on top of what the website does commercially.
Something is deeply fucked up there and it’s not the EU part. They just make a good scapegoat because the banner is what users see
Let's not paint the policymakers naïve when they're in fact incompetent.
Bold thing to say.
t. European
Are you sure?
It would be your payment information, which is orthogonal to most of the tracking data.
The black market demand for leaked advertising-related tracking data is basically nil, except maybe in cases where it’s related to something else exploitable or usable for blackmail like if someone frequents cryptocurrency exchanges or porn sites. Nobody cares to pay for black market data about you shopping for towels on Amazon or things like that.
99% percent of them intentionally turn the "decline" choice into a 5 - 10 step game of dark patterns even though the EU policy says it should be equally easy to decline. They know its bullshit but they also know the chance that someone will drag them through court is low.
Because the industry really respected DNT[0]?
Regulations are needed when the kids cannot play nice in the school yard.
GDPR is actually not that bad if you read it rather than subscribing to much of the malicious compliance we see.
[0] https://en.wikipedia.org/wiki/Do_Not_Track
No harvest data to 936 partners? No need for a banner!
Here's what it actually says: https://gdpr-info.eu/art-6-gdpr/
Note that cookies aren't even mentioned. (You're in the right)
There’s a perfectly valid and simple way to comply with the EU policies, including GDPR, and not impose annoying popups on your users: just don’t set cookies (if you need to have a login, you can ask for permissions at login time) and don’t collect personal data. That a lot of sites elect not to do that is an indication of how they treat the user, not of the brokenness of EU law.
You could still travel to the EU though. Only your business would have to comply before doing business there.
(AIUI "I agree" gets people to give explicit consent with good success and the subscribe modals are quite effective too)
Also when I checked NoScript, it's only loading js from lxe.github.io
I expect there to be at minimum 8 domains, but often 12-18.
youtube people I know you are in here. Fix your stupid PIP thing.
We can debate the specifics, maybe it's only in effect for X seconds after you stop moving the cursor, maybe it creates a 100px diameter disk of stability, I don't know. Just let me interact with the stuff I see.
Alternatively, we could disable clicking/selecting anything that wasn't visible for at least 200 or 300 ms at that location. So if you try to click on a button and it's shifted down or something pops up in front, and you end up clicking on that instead, your cursor would just blink red.
Similarly, if a button has recently moved, wait a little while before activating it. (Better yet, arrange for things not to move around as the page is loading.)
I’ve lost count of the number of modal dialogs I’ve “accepted” because they popped up out of nowhere milliseconds before I pressed enter coincidentally.
The message is always something inane like 'markets go brrr¹', and it's never something I need at the moment on that page (or anywhere else). I can dismiss the message (hooray?) but it always comes back the next time, so that isn't actually helpful at all.
1: Obviously they use carefully blandified corporate bank language for those messages.
news sites are the worst for this. bloomberg, nbc, etc. have 20+ domains, and as you click "temporarily allow" on one, it loads in a few more.
foxnews loads 36 domains before temporarily allowing any, which probably approaches 50 once you start allowing.
Too many people working on evil dark pattern bullshit
Man, I need to unplug.
If you log out, and then (in Firefox) close the window... oh wait, you're not really logged out. Try again.
If you log out in Firefox, wait until the window is quiet, then delete the cookie... LinkedIn creates a new cookie... which still sometimes logs you back in but not as often.
Opening a new window, deleting the LinkedIn window (fuck watever it's doing), and THEN delete the cookie in the NEW window... then it seems to stay gone at least as of today.
How about an email popup. My browser will happily auto-populate it.
I generally wanted web 1.0 simplicity, lots of contrast, but also a soft gentle colours and modern vibe. I also have a general design for use in dashboards/apps etc: https://frost-e.com/design-system/
The positives about covid and AI is that we don't hear anymore about blockchain and crypto (well, except one boomer oligarch holding onto it). Just please make the next two big things happen already for God's sake.
I swear NYT do this in their games app, the play button gets replaced with a subscribe as the late loaded subscribe element shifts the page exactly the amount to put subscribe under your finger. I wonder how well it worked?
Every news website does it and, in the UK, the local news outlets are amongst the worst.
The thing I don’t get: many of these sites are running Google Adsense, amongst other ad networks. Adsense Ts & Cs specifically forbid site behaviour that deliberately causes users to misclick on ads.
So why aren’t these sites being banned by Adsense?
The answer, I suspect, is follow the money: it seems likely that they bring in too much money for Google to ban them even though they’re overtly and outrageously breaking the rules.
zooming in should cause a full page refresh
Seriously how did we get to this point? I remember growing up in the 2000’s and all the marketing about computers was “it’s fast!” and “get results instantly!” that kind of thing. Now everything it gated by multiple spinners, then it loads a skeleton, then it partially loads your actual content, then, when you go to click on something, more content loads and the existing content jumps to a new place and you end up clicking on something else, meaning now you have to go back (if they haven’t hijacked the back button), wait for it all to load again, wait for the second “real” load, and then click on what you actually meant to click on in the first place.
https://termsandconditions.game
Also, where is the unrelated autoplaying video that will unmute if you actually click it, that follows your scrolling and only becomes smaller when you dismiss it? Plus, it should probably have text that cuts off letting you know you can have access for just $10/month.
Plus, isn't this website undissmissably "better in the app" after a few minutes of attempting to use it on a phone? Where's that at?
edit: Oh shoot! I forgot, too. This modal needs to also ensure there is absolutely no way to scroll. If you could scroll you might be able to accidentally get to the address bar of your browser to fix the URL to xcancel or even close the page, which isn't using the app as you are intended to do.
Also, it doesn't attempt to hijack the back button to give me stuff I clearly wanted to see before I leave the page.
A lot of work left to do here before it's a "real" website. Although, it has about as much substance as the average website so far, so good work on that.
This is the most annoying thing on the internet. There’s a site I’d like to use, but “try the app” takes up the entire page (and appears to be impossible to dismiss?). Actually, is there a way to permanently request the desktop site for all future visits to a domain on iOS? There is no reason to visit this full-page app advertisement.
It’s just some random job board that happens to be popular in my niche for whatever reason.
For Reddit, my choice for now is safereddit. If I need to view a Reddit link on mobile and old Reddit is blocked as it sometimes is, I just swap the domain to safereddit.com.
For Twitter, my choice has been xcancel for ages. I have no idea how that manages to stay up in spite of Twitter's hostility but it is a Nitter instance that seems to just work.
You can also run these frontends yourself, too, but I assume it requires accounts.
(edit: Also I hope it goes without saying that I don't really have any specific trust that my activity is necessarily more "private" with these frontends, although honestly if I was forced to bet I would have to bet that they are much more respectful to my privacy than Twitter or Reddit are. I just use them for functionality.)
Good luck fellow traveler. If there was more to do in real life, I'd probably had thrown my phone into the ocean by now. I'm about halfway there in spite of the lack of many appealing third spaces.
100% the worst experience. “Oh you don’t have the app? No big deal, let’s (maybe) play the video anyway but remove the audio, obscure half the screen, and make any interaction redirect and then bounce to the App Store. Why won’t you download our app already????”
But one is in a section called "Website actions", then there's another one in a section named "Website settings".
I didn't even notice it myself until now.
In earlier versions (before Liquid glass redesign I guess, which enlarged all dropdown paddings), the latter was called "always request Desktop site for xyz".
I wonder sometimes how the team doing the website feels about being treated as second class. Or if it’s the same team and they have to hold their noses to work on it.
The third dumbest smart person I had to work with obviously hated HTML and kept trying to get us to use a DSL instead. At least it wasn’t an in house one, but he had a couple other devs interested in his madness as well. But the two of us who were doing the bulk of the performance work and tricky bug fixes would have been absolutely sunk if we’d allowed that to happen. One of the worst things about React is trying to track back an HTML bug in someone else’s complex React project to the templates that are misbehaving together. The Grafana UI code is madness to debug.We would have been there very quickly and without the dev toolbox to help.
I think a lot of people get progressively worn down by things like this, but for me I actually get angrier each time it happens. It's probably good I no longer work at Google because I would probably feel genuinely enticed to find whoever is most responsible for this and engage in psychological warfare.
But I think it’s sometimes by management design. Scrum makes it pretty easy to keep devs permanently off balance so they can’t think about how wrong what we are building is. Maybe that person really is a piece of work, but maybe they just have never had time to think about how dumb that decision was and go fix it. Similar to you, I’m glad I don’t know where Ken Schwaber lives or when he’s presenting because I’d probably call him a traitor to his stupid face.
It’s such a small thing in the grand scheme of things but it’s just that final straw for me, someone made the decision to be this shitty to their users because they want to employ extra tracking/data collection / advertising in their app.
21! Blackjack,
"Hit me!"
"...but Austin!"
"I also like to live, dangerously."
The only winning move is not to play.
And if nothing else, leaving a company whose service sucks doesn't need to send a message, it's just moving so the service you receive improves.
Repeat (without rinsing).
It's also effectively youtube premium for free as in beer. Lovely browser.
You’re right. It’s a good start, but there’s still a lot to do.
Or, at the very least, at a widely different speed/acceleration that you're accustomed to
(Not for this website, which is obviously a joke/telling commentary. I mean for real 'fucking websites'.)
Obligatory xkcd:
https://xkcd.com/1174/
Just search for anything like "egg omelette recipe". Click *any* link for example [1].
[1]: https://www.loveandlemons.com/omelette-recipe/
Also 1.5gb of heap allocated minimum
If it's the design, not everyone is a web designer so the bootstrap theme is great to get up off the ground.
If it's the other stuff then, yeah, totally.
* according to the copyright notice, although, going by the mention of Covid, it could also be 2020?
Oh well.
Seems like the sort of site and person who should have a guestbook - I would have left an appreciative and encouraging comment there, but this will have to do:)
We didn't want it, it's like a megabyte of JavaScript. It's some third party service corporate forced on us.
I have to imagine a lot of websites are in the same boat, where they're just add crap they don't want to add by higher ups.
Me having to make a legal agreement with every website is absurd and totally predictable.
It turns out everything has a price, and in more recent times we started noticing that our time, attention and intelligence not being insulted also has value.
1) scroll hijacking (this should be a felony) 2) stupid cookie popups/banners 3) useless hero images (clients love them, users hate them)
I ended up trying it. Boosted conversion rate meaningfully. Worth the price I pay in mild self-loathing.
Chesterton's popup, I guess.
Now, I'll grant you that these may not become as successful as the clickbaity ones. Then again, the latter channels might as well not exist to me and like-minded people.
Just an hour ago I unfollowed a streamer precisely because he's been getting clickbaity. We've got to take some responsibility over the people we choose to watch.
I guess it's the inevitable parable of anything started by '70s hippies: sooner or later, we all sell out.
I would possibly be a terrible salesperson, because these all give me the ick. Your product should provide an offer of genuine value.
Does it work because you're taking advantage of a group of people who are extremely vulnerable to manipulation? People who already struggle with impulse control, who are prone to making bad financial decisions? The elderly, kids?
We have to escape this mentality that anything that makes money is valid, that the money itself is the validation of "rightness".
Some of us, just some think that maybe enterprises that prey on the vulnerable just don't deserve to be in business. Otherwise everything might as well be payday loans and online gambling. I'm not saying OP is definitely in that category, but I would encourage them to think long and hard about weather or not using dark patterns to goose their sales is really the kind of world we want to be fostering.
Hitting the nail on the head here-> know your target audience.
I think this is a gross over-exaggeration, otherwise dark patterns wouldn't work at the magnitude (majority of the buying population) they do.
I say this not disagreeing with your point:
> We have to escape this mentality that anything that makes money is valid, that the money itself is the validation of "rightness".
"Average" doesn't necessarily mean half way between two extremes - the average human might actually be all of:
- extremely vulnerable to manipulation
- struggling with impulse control
- prone to making bad financial decisions
- the elderly / kids (<16/>60)
Based on age demographics, rampant consumerism and social media addiction, especially in those age demographics, I'd be more inclined to guess the average human is all of those things.
I agree. But.
I run an online business. It's tough. I scrape by. GP noted that the skeezy popup "Boosted conversion rate meaningfully". So that's real money in GP's pocket that they presumably use to have a nicer life. At what cost? Some popup? I mean…
Would I take more money in my pocket? Boy, I'd like that. So far I haven't gone the skeezy popup route, but the day I try, and more money ends up in my pocket, it's gonna be hard to turn that thing off.
I'm not judging, is all I'm saying.
Silly obnoxious social proof popup is clearly on the ethical side in my view (my issue was never ethics, just that I personally find them very annoying). I'm not misleading anyone (it does in fact show real purchases) or forcing anyone to do anything. If that's the difference between you buying or not, I still feel perfectly comfortable that you made the choice of your own free will.
"You're never going to convince someone to stop doing something that is making them money." Reasonable, but I would soften from "never". There was less of it at one point—and it seems logical to guess we have less today than we'll have tomorrow. The main reason is likely that we simply didn't know about these tricks yet, but somewhere below that on the list of the reasons is that some people dropped off from doing it at lesser forms of misrepresentation. Or they made the case against it at work resulting in them either winning (and their projects perhaps did less well) or them losing and being overrun by those more willing. With losing possible also leading towards leaving, not getting promoted, or getting fired. This is just a way to say that there are people who do forgo money, they just might not be around or visible for various reasons. And, as implied by the difficulty of convincing people to not make money, their (former) coworkers prefer that on some level even if they don't believe they agree with stealing or lying. But losing or earning less money is not the same as having no choice.
Advertising should.be illegal.
I dislike advertising as much as the next guy but wouldn't go so far as making it illegal
https://simone.org/advertising/
Advertising is shitty but how would you realistically even make it illegal without violating free speech.
Also, advertising does have a good-faith purpose in functioning markets.
Failures in regulation IMO are mostly at entirely different levels.
E.g. monetization of public utilities and public space. Noise, brightness, and of course deceptive tactics could all be better regulated as well.
But advertising, including its diffusion into general pop culture and entertainment, is older than the printing press, and I think for a broad sense of "advertising", even a lot older.
Or only advertising in media?
Urban spaces? Sure I'd say, but what about your storefront?
Encouraging word of mouth?
Just another horror beyond our comprehension?
Five minutes later, “add to cart”. Etsy: “sold out; we weren’t lying!” So in this particular case it didn’t work. But it will next time.
"Take back your web browser screen space with Kill Sticky" https://www.smokingonabike.com/2024/01/20/take-back-your-web...
"Quick Tips For Making The Internet Suck Less" https://www.smokingonabike.com/2025/08/01/tips-for-making-th...
"Web browsers have stopped blocking pop-ups" https://www.smokingonabike.com/2025/12/31/web-browsers-have-...
Steps to reproduce: Open terminal emulator and type;
$ w3m https://lxe.github.io/everywebsite/
I can read the same content as I can read in Firefox.
What I expected to happen: See content similar to the following;
Update your browser Your browser isn't supported any more. To continue your search, upgrade to a recent version. Learn more
The web is more than blogspam, SaaS, the most desperate cases of ecommerce, and the web versions of legacy newspapers/magazines.
good job though
- Paragraphs emerge from the background as you scroll, sometimes only after 3/4 of your screen is empty.
- Some paragraphs are hidden until you expand them. You can’t expand more than one at a time.
- Horizontal scrolling for some items, like e.g. meal categories in a restaurant. The buttons for the scrolling are different on each site, or are dots you must click on.
Firefox also has an extension called "Auto Reader View" in which you can set sites to automatically change to that mode.
Bootstrap.
That framework did more damage to web design than any other framework. Yeah, its nice that you can spin up a page in a second that looks like every other page on the internet, wait a minute...
Technical answer:
CSS
It was a nice idea, and it sure beat hand-designing each and every page (wait a second, weren't/aren't we doing that all over again?).
It did/does too much, and was mostly in lieu of a common repository of UI stuff, so people found One Way that it would work reasonably well on most browsers/devices, and so bootstrap was born...
I don't know if it would be better or worse.
Every SaaS under the sun, hell half the things here that end up with some sort of VC backing... the first thing they do is spin up a nothingburger landing page that says a whole lot of jack diddly squat that all have a familiar feel where everything's centered, there's meaningless bulletpoints and info cards, but no real meat or information that describes what you're after... that feeling = "how do i beat gd level 1 (this landing page) so i can find what im looking for" and yeah. This has bled into documentation spaces as well, somehow rendering documentation (the thing that is supposed to help you get oriented) feel like you can't actually find what you're looking for.
UX/UI in the past decade was blown way out of proportion and I can't help but feel like it's been shaped by way too many imperfect half theories / stupid market research and is way too heavily influenced by marketing and adspace to be taken seriously. In general there is certainly a taste for what makes a good UX and that to me is typically a blend of utility and looks-cool. But without any utility everything feels like a goddamn waste of time & I'm mostly assured that websites that sport pages like this have way too many financial strings attached driving their every move. They all try to drive you towards filling out a sales inquiry form. It's ironic and hilarious that a lot of times if I want to learn about some platform or product, the last place I can reliably go to is their own website. These days you just gotta go digging, ask claude to go collect a bunch of user feedback from around the net or something.
You get things rating accessibility, methodologies for building apps but nothing about standards for website quality?
And this is something which I learned which is surprising to me: github.com resolves to AWS. WTF? GH has its own netname and a /20. It's literally one hop, somehow, from my ISP. WTF? It's not MS and it's this shite? WTF?
[1] 1: https://xkcd.com/90/
damn