HN Debrief

Kill The Cookie Banner

  • Privacy
  • Regulation
  • Browsers
  • Advertising
  • Web

The post is a campaign for replacing per-site cookie consent popups with a browser or device setting that sends a single privacy preference to websites. The core claim is that EU law already defaults to no tracking, but the current banner regime turned that into endless dark-pattern prompts that train people to click "accept". A lot of the conversation sharpened an important distinction the campaign itself can blur. These are not really "cookie banners". They are tracking consent banners. Session cookies, login state, carts, and explicitly requested preferences usually do not need consent in the first place. What triggers the mess is adtech, third-party embeds, analytics stacks, and broader data processing that companies want but cannot justify as strictly necessary.

Treat cookie banners as a symptom, not the problem. If you run a product or publish content, plan for browser-level consent signals and privacy-safe analytics now, because the direction of travel is toward binding defaults and stricter enforcement of dark patterns.

Discussion mood

Strongly pro getting rid of cookie banners and deeply hostile to adtech. The frustration came less from privacy law itself than from years of dark patterns, weak enforcement, and the sense that websites turned consent into a nuisance designed to wear users down.

Key insights

  1. 01

    Tracking consent is the real target

    What needs fixing is not ordinary browser cookies but the consent machinery around cross-site tracking, third-party processing, and embedded services. That reframing matters because it cuts through a lot of confusion. Sites can keep login cookies, carts, and user-requested preferences without banners, so teams blaming privacy law for every popup are often really defending a tracking stack they chose to install.

    Audit your site by purpose, not by cookie count. Strip out third-party tracking and many consent problems disappear before any browser-level standard arrives.

      Attribution:
    • rtpg #1
    • IanCal #1
    • dgellow #1
  2. 02

    DNT failed because nobody had to honor it

    Do Not Track was not a technical dead end. It was an unenforced suggestion. The important change in the new proposal is legal force. If a browser signal becomes binding, ignoring it stops being a product choice and becomes a straightforward compliance failure that is easy to detect and penalize.

    If you build browser features, ad products, or web tooling, assume the next privacy signal will be enforced rather than advisory. Design for a world where consent state arrives as a machine-readable default and regulators can test it automatically.

      Attribution:
    • MassiveQuasar #1
    • IshKebab #1
    • crote #1
  3. 03

    Most banners are broken by design or by neglect

    The ugly truth is not just dark patterns in the UI. Many sites either make rejection take more clicks, fail to remember a rejection, or fire tracking tags before consent because the consent management platform was never wired into the rest of the page correctly. One commenter running compliance scans claimed about 7 in 10 regulated sites still leaked tracking without proper gating. That makes the current system look performative even when companies say they are trying to comply.

    Do not assume your consent management platform works because legal signed off on the banner. Test what actually loads and fires under each consent state, including tags added later by marketing or vendors.

      Attribution:
    • readread #1
    • jackson1442 #1
    • tremon #1
    • SlightlyLeftPad #1
  4. 04

    Child-mode headers create a new privacy leak

    The side discussion about using the same browser-signal idea for child safety exposed a real tradeoff. Broadcasting a "this user is a child" header to every site solves one policy problem by creating another permanent classification signal. Comments arguing for device-level blocking or site self-labeling were more convincing because they avoid turning age status into yet another tracking attribute.

    Be careful when generalizing the privacy-signal model to age or safety policy. A browser signal that reveals protected status can become a fresh data collection surface even if the original goal is protective.

      Attribution:
    • tangotaylor #1 #2
  5. 05

    Bad privacy UX helps the biggest platforms

    One sharp economic point was that banner spam did not kill surveillance advertising. It pushed users toward logged-in platforms like Facebook, Instagram, Reddit, and YouTube where tracking is first-party and much harder to escape. Smaller publishers get the nuisance and revenue hit, while the largest platforms keep the data advantage. That makes browser-level defaults more than a UX cleanup. It is also a competition issue.

    If you operate outside the big platforms, privacy UX is strategic, not just legal. Cleaner, lower-friction consent and less dependence on third-party trackers can be a competitive advantage instead of a compliance tax.

      Attribution:
    • AlienRobot #1
    • xp84 #1

Against the grain

  1. 01

    The current regime is mostly workable

    The skeptical case is that consent rules already got the web most of the way there. Necessary cookies are exempt, reject options exist, and banners usually show once. From this view the fix is narrower enforcement against dark patterns, not a fresh policy push built around banner hatred. That argument is useful because it warns against overselling UX reform as privacy reform.

    If you advocate for browser-level consent, be precise about what it improves. It removes repetitive prompts, but it still needs enforcement and limits on data uses to change the underlying economics of tracking.

      Attribution:
    • tgma #1
  2. 02

    Third-party embeds still need separate consent

    A hard-nosed legal objection was that even if tracking cookies vanished, prompts would remain for other disclosures and third-party data transfers such as YouTube embeds or externally hosted assets. That pushes against the idea that one browser switch kills every banner. The point is narrower than the broader anti-regulation takes, but it is credible and operationally relevant.

    If you want a banner-free site, reducing trackers is not enough. Also inventory third-party embeds, hosted fonts, maps, and media players that can still trigger consent or data-transfer issues.

      Attribution:
    • jebronie2 #1 #2
  3. 03

    Untargeted ads may not fund the web

    A minority view held that killing targeted tracking will cut publisher revenue and force either more generic ad clutter or more paywalls. That does not rescue dark patterns, but it does highlight the business model gap that privacy advocates often leave vague. Removing surveillance is easier than replacing the money it currently throws off.

    If your business depends on ad revenue, model privacy changes as a monetization problem early. Test contextual ads, subscriptions, sponsorships, or commerce before regulation forces the shift on worse terms.

      Attribution:
    • jebronie2 #1
    • charcircuit #1

In plain english

adtech
Advertising technology companies and tools that target, measure, and automate online ads, often using user tracking.
DNT
Do Not Track, an older browser signal meant to tell websites a user does not want to be tracked.

Reference links

Privacy signals and browser standards

Regulation and legal guidance

Tools and blockers

Industry and advocacy references

Examples discussed in the thread