Also, where is the unrelated autoplaying video that will unmute if you actually click it, that follows your scrolling and only becomes smaller when you dismiss it? Plus, it should probably have text that cuts off letting you know you can have access for just $10/month.
Plus, isn't this website undissmissably "better in the app" after a few minutes of attempting to use it on a phone? Where's that at?
edit: Oh shoot! I forgot, too. This modal needs to also ensure there is absolutely no way to scroll. If you could scroll you might be able to accidentally get to the address bar of your browser to fix the URL to xcancel or even close the page, which isn't using the app as you are intended to do.
Also, it doesn't attempt to hijack the back button to give me stuff I clearly wanted to see before I leave the page.
A lot of work left to do here before it's a "real" website. Although, it has about as much substance as the average website so far, so good work on that.
> Plus, isn't this website undissmissably "better in the app" after a few minutes of attempting to use it on a phone? Where's that at?
This is the most annoying thing on the internet. There’s a site I’d like to use, but “try the app” takes up the entire page (and appears to be impossible to dismiss?). Actually, is there a way to permanently request the desktop site for all future visits to a domain on iOS? There is no reason to visit this full-page app advertisement.
I have Firefox setup to not launch apps on android with permission. I don't have Instagram/Facebook/etc installed. Attempting to view a Instagram link on mobile is the most hostile thing in existence. You essentially can't, but it so aggressively routes you to the website based Google play store it's horrifying.
I'd recommend using Libredirect if you're on a Firefox-based mobile browser. It can configure redirects to alternate "frontends" that will serve you much more agreeable HTML (though because we live in hell, it will usually still involve antibotting out of sheer necessity. But I accept this.)
For Reddit, my choice for now is safereddit. If I need to view a Reddit link on mobile and old Reddit is blocked as it sometimes is, I just swap the domain to safereddit.com.
For Twitter, my choice has been xcancel for ages. I have no idea how that manages to stay up in spite of Twitter's hostility but it is a Nitter instance that seems to just work.
You can also run these frontends yourself, too, but I assume it requires accounts.
(edit: Also I hope it goes without saying that I don't really have any specific trust that my activity is necessarily more "private" with these frontends, although honestly if I was forced to bet I would have to bet that they are much more respectful to my privacy than Twitter or Reddit are. I just use them for functionality.)
Good luck fellow traveler. If there was more to do in real life, I'd probably had thrown my phone into the ocean by now. I'm about halfway there in spite of the lack of many appealing third spaces.
If the site happens to be a discussion site that starts with 'R', clearing cookies will let you through for a while. In Brave, there's a setting to do so when you leave the page.
Wild that it is somehow worth it to stream video to every visitor on the hopes that it'll get them to stick around longer or see an ad in the video. That conversion number has to be crazy low.
I wish we had a UI paradigm where whatever is underneath your cursor is not allowed to change. If you hover a button, that button must remain right there for you to click, if you hover some text, it must remain there for you to select.
We can debate the specifics, maybe it's only in effect for X seconds after you stop moving the cursor, maybe it creates a 100px diameter disk of stability, I don't know. Just let me interact with the stuff I see.
This. My favorite is when I search for products on a website or app and the results appear in batches, with subsequent results interleaving with the previous results. So when you want to select a particular result and start to move your mouse and click, or move your finger and press, you often end up selecting something unintended because a later result pops into the location.
I do this in the gmail mobile app all the time thanks to their ads injecting themselves in between the emails several seconds late. They must love me, their most engaged ad consumer.
Yes, and put a search bar that loses focus to some piece of crap I dont care about after I enter 3 characters, and some hotkeys that navigate me to a different page when I accidentally activate them because I thought I was going to put text in the search field.
youtube people I know you are in here. Fix your stupid PIP thing.
I was waiting for the overlay which hides the content until you turn off your ad blocker. Which of course is a trap because as soon as you do it covers the content in ads.
I started an e-commerce brand on a Shopify site. I swore to myself I would never put up one of those stupid things that pops up "Someone bought X product an hour ago!" messages in the corner of the screen.
I ended up trying it. Boosted conversion rate meaningfully. Worth the price I pay in mild self-loathing.
Out of all the annoying website things, always thought that one was pretty tame. Almost feels like a spiritual successor to the visit-o-meter. Obviously as long is it doesn't put a (1) on my tab or makes a noise and doesn't steal mouse focus.
The cookie thing, I assume it's EU-only, is an example of the EU policy making process being fundamentally broken in some way. If you create a flawed policy and don't fix it many years after it's very visibly obvious that it's a bad policy, something is really wrong.
it's an example of malicious compliance by some, and herd mentality by others.
I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.
You could have a 'no cookies' badge that links to your cookie policy - 'we use no tracking cookies and so are compliant with EU law ... then list any cookies/local-storage used and explain what they're for.
That would make you sound a lot more professional too. And trustworthy. (As long as that's actually what happens).
When I see these dialogs listing they have 1289723 gazillion vendors they share data with, I know that whoever is in charge of analytics, privacy or both at the company is incompetent.
That reasoning isn't wrong, though it seems ridiculous when looked at with techie-brain. But if there is a standard expectation of what serious company websites are like, it makes business sense to look like that too. It's like dressing up appropriately to cultural expectations. You can deviate somewhat but you have to strategically spend your weirdness points.
How nice of the EU to have determined for the rest of the world that the “cultural expectation” should be that every business do the design equivalent of wearing clown makeup.
I don't care about this. I explained why for an individual business trying to project seriousness, it makes sense to adopt a banner in the current environment. I didn't say it's nice of the EU or anything of the sort. It's an incentive pressure that exists on an individual company in the current situation. That's all I said.
I'd say just remove it. Don't ask people who don't actually understand the cost of having it there because you will get the wrong answers. Sometimes people just have to do the right thing, take some heat and then everyone can move on. If it has severe consequences then that's probably a good reason to leave anyway.
Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they couldn't deny that it cost a fraction of what we were paying our supplier and that things took minutes to set up rather than weeks. And that they worked a lot better.
Yes, there was shouting in meeting rooms. And yes, people said "you can't do this". Turns out they were wrong. A few years later I mentioned this to Werner Vogels. During a meeting. Where my CEO and CTO were present. And where everyone was feeling very good about us being one of AWS' biggest customers in our region.
So when someone says "you can't do that", sometimes you should make them prove it.
(At the time AWS was a good idea. Today dependence on a US service provider is a harder sell in Europe. The _first_ question you get today is if we can host it ourselves if we need to or if we can use a local service provider.)
I have the same mindset and often did the same thing, but then I thought about my doctor sneaking into my house while I’m sleeping and injecting me with the “good medicine” I had refused in their office.
Many years ago, I used to make informational websites for small, local businesses and they all wanted the cookie banner "just to be safe", even after explaining they didn't need it.
> and he said "yeah, but it makes the site seem less legitimate.
He may be right, sadly. I’ve seen the lack of a cookie banner used to suggest that a site was doing something shady or not complying with the law.
Most people don’t have knowledge about the finer details of cookie laws. They’ve been trained to believe that legitimate sites who comply with the laws will implement the cookie banner, and not seeing it feels suspiciously unprofessional.
I see a lot of people below arguing that this isn’t the fault of the EU policy but the companies. I think that’s being overly charitable to the policy. While you can be rightly upset with the companies behavior, ultimately policy has to work with the incentives it creates. The policy in its current form allows for meeting requirements with annoying cookie banner opt-outs while keeping the lucrative business of tracking. If we don’t want that, the policy should be changed. Don’t expect companies to go against their interests here, even if some will actually be thoughtful and find a way to do so. The “Purpose Of a System Is What It Does” principle applies, and the purpose of the EU policy seems to be cookie banners for most sites.
I’ve long believed that making companies liable for paying damages if PII is leaked in a data breach would be the best way to stop excessive tracking. If you force them to have to manage user data like they’re handling radioactive waste then the expense and overhead involved is a natural drag on the business logic that drives the bottomless appetite for data collection. They’ll collect it if they actually need it, and they’ll take great pains to secure it.
The most valuable data breach content isn’t your advertising tracking data, though.
It would be your payment information, which is orthogonal to most of the tracking data.
The black market demand for leaked advertising-related tracking data is basically nil, except maybe in cases where it’s related to something else exploitable or usable for blackmail like if someone frequents cryptocurrency exchanges or porn sites. Nobody cares to pay for black market data about you shopping for towels on Amazon or things like that.
99% percent of them intentionally turn the "decline" choice into a 5 - 10 step game of dark patterns even though the EU policy says it should be equally easy to decline. They know its bullshit but they also know the chance that someone will drag them through court is low.
The EU said "you have to ask for permission before forcefully sodomizing your users", and webdevs thought "let's ask for permission" rather than "let's not forcefully sodomize our users". Of course, the law could have said "don't forcefully sodomize users", but it seems the west is still under the impression that some people will do the right thing, just because, sometimes. (maybe 20 years ago they would have, just because, sometimes, but they won't now)
I used to have long conversations with frontend developers that "no, when I log on I don't want to be forced through a look-at-the-new-feature-we-made" sequences. And then they went ahead and did it anyway. And usually whatever flag they tried to set to make sure you only saw it once would malfunction, so next time you'd get to click through it all over again.
(If you want to tell users about new features, show a unread flag on a notification icon and make it a one-click affair to make it go away. Don't get in users' face with stuff they don't want)
"Damn, I'm being asked to put a cookie into this site that will maybe result in some guy seeing an ad about a toothpaste he might buy at some point in the future.
I'm going to risk months of unemployment and explain to my family why this is more important than eating when I get home."
-- the hypothetical webdev in that scenario, I guess?
You don't really need a web dev to add a cookie banner these days, but you probably still want one to build the actual site (unless it's simple enough to be fully site-as-a-service, in which case there is really no webdev at all).
Be it the EU for regulating disclosure and consent requirements, users for being "lazy" and usually just accepting all, or the webdev for not staking their livelihood on denying the banner - I'm sure they'll all get blamed before someone sees the ones actually demanding it be done can be the problem.
You can try to put the blame on the grunts, like trying to focus on the engineers in the VW Dieselgate, etc, but that is very weak leverage. You have to intervene at the root cause of the incentive. But of course the higher you go, the more there is a blur between legislators and business owners and they won't be harsh to themselves.
Actually cookies are not mandated by the EU, but this was the solution the big companies agreed on and now Google and Co try to lobby against better solutions.
Policy making assumed good faith actors - specifically that tracking outside of necessary for website to function to be minimal. Because like…not necessary.
It’s only broken to the extent that it collided with a messed up world where websites track even when they don’t need to and then send that to 2000 partners for more profit extraction on top of what the website does commercially.
Something is deeply fucked up there and it’s not the EU part. They just make a good scapegoat because the banner is what users see
The biggest positive outcome of the whole GDPR affair is that people finally believe me when I say that yes, they are selling your data to thousands of 3rd parties, and no, I'm not making these numbers up or exagerrating at all.
Most US sites are giving the cookie bag to US users. It may simply be easier for leadership to say add the widget than it is to say we won’t accept traffic from the EU or risk the consequences
It feels similar to how CA environmental regs become the national standard simply because the market is so large it’s not worth splitting on it. So they just slap a cancer warning on everything
1. It's also a piece of cake to just not display the cookie banner for non-EU IPs
2. If you are a purely US entity with no actual business presence in the EU, you only need to comply with US laws and nothing else. If the EU doesn't like a purely-foreign website, it's on them to set up a national firewall and block it.
Case in point 1: It's not on you to comply with China's laws, it's on them to block it if they want to
Case in point 2: China's local businesses with no EU presence do not follow GDPR and do not display cookie banners even if accessed from the EU
Do Not Track was the right implementation (browser-based, activate only once) and it was sabotaged by ad peddlers. It is bad policy that has been reached after every better alternative was rejected.
It's not a cookies banner. It's a request to harvest your data and share it with third parties for purposes that are not required for the service you're offering.
No harvest data to 936 partners? No need for a banner!
The most used banners at least have a quick way of dismissing without opting in. When the cases against too obvious dark patterns started that fixed itself at least.
I have yet to see an actual part of that policy which requires a cookie banner though. Seems more to me that it's a combination of (a) websites allowing all kind of fcked up use cases of cookies on their site (most sites do not even need cookies for real) and (b) not respecting http headers that ask to not be tracked... They much rather have a very confusing popup that kinda forces you to accept all :) How convenient.
Just like websites also give zero fcks about accept-language header... sure do geoip lookup, so much easier... not
The policy is both, good, but also flawed. For example, you cannot persist settings, because one policy says that website settings should be ephemeral unless user agrees to persist them.
we could have settled on privacy compliant tracking without cookies, which is possible or use browser preferences and respect those (which would be perfectly legal)
I may be skeptical, so take this with a grain of salt. The transformation happened when someone decided to stop being UI designer, to become UX designer. That wasn't enough, so they came up with XD - experience design. At every step of the way, they introduced more lofty goals for the design to justify the increased importance of themselves.
It should appear a second after the page seems to have finished loading, so that it hijacks the input if the user is navigating with the keyboard or typing something into a form.
So many websites do popups and it feels so anti-user. Maybe I get unusually annoyed, but I do not need a Gemini popup ad in Google Docs. Just let me do what I came to the website to do!
As feedback, you made that popup way too clean and easy to close. That’s not how it works in reality. You need to make the background transparent and the X so small it’s technically impossible to hit. Also think about adding an ad and a timer and move the popup slightly after N ms so that the user always hits the ad.
That "In case you're not aware, there's COVID-19 happening" banner isn't nearly tall nor yellow enough. Given a 6-inch-tall screen, the proper layout would be:
+-----------------+
|2" of vestigial |
|COVID messaging |
+-----------------+
|1.5" of actual |
| content |
+-----------------+
|2.5 of EU |
| cookie banner |
+-----------------+
A local utility took it even further during COVID:
+---------------------+
|2" of COVID messaging|
+---------------------+
|1" of undismissable |
| "our app is gone; |
| use the mobile site |
| that you're on now" |
+---------------------+
|0.5" of content |
+---------------------+
|2.5" of EU cookie |
| banner, despite |
| being a US-only corp|
+---------------------+
It also needs to scroll in after a second or two, and shift the page content down, so you mis-click the wrong link, and end up loading something that takes forever to load and somehow manages to cause the back button to misbehave.
Clever people with no morals use that to load ads under your finger, timed to create an inadvertent click.
I swear NYT do this in their games app, the play button gets replaced with a subscribe as the late loaded subscribe element shifts the page exactly the amount to put subscribe under your finger. I wonder how well it worked?
Somehow the clicking around reminded me of Windows RG. Go check this old relic if you have never seen it: https://www.jamesweb.co.uk/windowsrg . Turn the volume up!
Answer: ads as the main business model running the web since 25 years ago and us accepting the convenience 'free'.
It turns out everything has a price, and in more recent we started noticing that our time, attention and intelligence not being insulted also has value.
Yea , thank u , I really despite those websites of current web, much JS, colors, much images and animations with mouse, and million fonts , rounded buttons and everything is rounded and "modern" and slow and bloated
why cant have we simple websites, small coherent nice color palette
to just read and know the needed info ?
hackernews is extremely good example
suckless: https://suckless.org/sucks/web/
is another brilliant example
Yea but do you guys remember when we actually needed pop up blockers to avoid having a site spawn like 10 new windows behind the current one, and tabs didn’t really exist yet, and the popups had adult content and sometimes they autoplayed sound/video? Like, internet explorer 6 era? Sometimes I miss those days
Seems like the sort of site and person who should have a guestbook - I would have left an appreciative and encouraging comment there, but this will have to do:)
Every paragraph (maybe sentence) needs to fade in as I attempt to scroll. If I can read the first paragraph easily when the page loads (ignoring the pop-ups) then the website is too well designed.
I can't believe I'm not able to buy Every Fucking Website Premium with business focused ads and native advertising masquerading as quasi-educational infotainment. Also where's the sign-up with Spybook?
Also on iPhones Twitter appears to have aligned their privacy reject button with where their open in app overlay appears just a second later so that you hit that instead.
Too many people working on evil dark pattern bullshit
it’s missing spinners for 5-10 seconds while it loads endless megabytes of javascript doing who knows what.
Seriously how did we get to this point? I remember growing up in the 2000’s and all the marketing about computers was “it’s fast!” and “get results instantly!” that kind of thing. Now everything it gated by multiple spinners, then it loads a skeleton, then it partially loads your actual content, then, when you go to click on something, more content loads and the existing content jumps to a new place and you end up clicking on something else, meaning now you have to go back (if they haven’t hijacked the back button), wait for it all to load again, wait for the second “real” load, and then click on what you actually meant to click on in the first place.
For my current project, I tried going with a non-traditional style I personally liked, I call it "Soft Neo Brutalism". You can see it at: http://www.frost-e.com
I generally wanted web 1.0 simplicity, lots of contrast, but also a soft gentle colours and modern vibe. I also have a general design for use in dashboards/apps etc: https://frost-e.com/design-system/
Cookie banners are malicious compliance. There are only 1-2 EU countries with quarrelsome predatory lawyers proactively scanning the web.
The positives about covid and AI is that we don't hear anymore about blockchain and crypto (well, except one boomer oligarch holding onto it). Just please make the next two big things happen already for God's sake.
Should load much slower.
Also, where is the unrelated autoplaying video that will unmute if you actually click it, that follows your scrolling and only becomes smaller when you dismiss it? Plus, it should probably have text that cuts off letting you know you can have access for just $10/month.
Plus, isn't this website undissmissably "better in the app" after a few minutes of attempting to use it on a phone? Where's that at?
edit: Oh shoot! I forgot, too. This modal needs to also ensure there is absolutely no way to scroll. If you could scroll you might be able to accidentally get to the address bar of your browser to fix the URL to xcancel or even close the page, which isn't using the app as you are intended to do.
Also, it doesn't attempt to hijack the back button to give me stuff I clearly wanted to see before I leave the page.
A lot of work left to do here before it's a "real" website. Although, it has about as much substance as the average website so far, so good work on that.
> Plus, isn't this website undissmissably "better in the app" after a few minutes of attempting to use it on a phone? Where's that at?
This is the most annoying thing on the internet. There’s a site I’d like to use, but “try the app” takes up the entire page (and appears to be impossible to dismiss?). Actually, is there a way to permanently request the desktop site for all future visits to a domain on iOS? There is no reason to visit this full-page app advertisement.
I have Firefox setup to not launch apps on android with permission. I don't have Instagram/Facebook/etc installed. Attempting to view a Instagram link on mobile is the most hostile thing in existence. You essentially can't, but it so aggressively routes you to the website based Google play store it's horrifying.
I'd recommend using Libredirect if you're on a Firefox-based mobile browser. It can configure redirects to alternate "frontends" that will serve you much more agreeable HTML (though because we live in hell, it will usually still involve antibotting out of sheer necessity. But I accept this.)
For Reddit, my choice for now is safereddit. If I need to view a Reddit link on mobile and old Reddit is blocked as it sometimes is, I just swap the domain to safereddit.com.
For Twitter, my choice has been xcancel for ages. I have no idea how that manages to stay up in spite of Twitter's hostility but it is a Nitter instance that seems to just work.
You can also run these frontends yourself, too, but I assume it requires accounts.
(edit: Also I hope it goes without saying that I don't really have any specific trust that my activity is necessarily more "private" with these frontends, although honestly if I was forced to bet I would have to bet that they are much more respectful to my privacy than Twitter or Reddit are. I just use them for functionality.)
Good luck fellow traveler. If there was more to do in real life, I'd probably had thrown my phone into the ocean by now. I'm about halfway there in spite of the lack of many appealing third spaces.
If the site happens to be a discussion site that starts with 'R', clearing cookies will let you through for a while. In Brave, there's a setting to do so when you leave the page.
Feedback taken. Will ask ai agents to make improvements.
Wild that it is somehow worth it to stream video to every visitor on the hopes that it'll get them to stick around longer or see an ad in the video. That conversion number has to be crazy low.
"We value your privacy! We and our 892 legitimate business partners use cookies to improve your experience."
Loaded way too fast and is way to responsive.
Also when I checked NoScript, it's only loading js from lxe.github.io
I expect there to be at minimum 8 domains, but often 12-18.
All buttons and links need to shift around for a good 10 seconds before the page settles.
I wish we had a UI paradigm where whatever is underneath your cursor is not allowed to change. If you hover a button, that button must remain right there for you to click, if you hover some text, it must remain there for you to select.
We can debate the specifics, maybe it's only in effect for X seconds after you stop moving the cursor, maybe it creates a 100px diameter disk of stability, I don't know. Just let me interact with the stuff I see.
It's important to have the accept cookies button pop up on top of something you are almost guaranteed to click at just the right moment.
This. My favorite is when I search for products on a website or app and the results appear in batches, with subsequent results interleaving with the previous results. So when you want to select a particular result and start to move your mouse and click, or move your finger and press, you often end up selecting something unintended because a later result pops into the location.
I do this in the gmail mobile app all the time thanks to their ads injecting themselves in between the emails several seconds late. They must love me, their most engaged ad consumer.
Yes, and put a search bar that loses focus to some piece of crap I dont care about after I enter 3 characters, and some hotkeys that navigate me to a different page when I accidentally activate them because I thought I was going to put text in the search field.
youtube people I know you are in here. Fix your stupid PIP thing.
js eventListener that intercepts the click/tap event, moves the button somewhere else, and clicks the ad underneath.
I was waiting for the overlay which hides the content until you turn off your ad blocker. Which of course is a trap because as soon as you do it covers the content in ads.
..... In such a way that most commonly used button is replaced by an ad 0.001 seconds before you click it
>I expect there to be at minimum 8 domains, but often 12-18.
news sites are the worst for this. bloomberg, nbc, etc. have 20+ domains, and as you click "temporarily allow" on one, it loads in a few more.
foxnews loads 36 domains before temporarily allowing any, which probably approaches 50 once you start allowing.
And needs some kind of loop that retries endlessly to make the AdBlock counter go brrr
I'm sorry
It also loaded too fast because it has no (ai-generated/3d/high color contrast) 10MB background image in the hero section
And the legitimate mass spying with multi thousand other organizations, of course.
I started an e-commerce brand on a Shopify site. I swore to myself I would never put up one of those stupid things that pops up "Someone bought X product an hour ago!" messages in the corner of the screen.
I ended up trying it. Boosted conversion rate meaningfully. Worth the price I pay in mild self-loathing.
Chesterton's popup, I guess.
Out of all the annoying website things, always thought that one was pretty tame. Almost feels like a spiritual successor to the visit-o-meter. Obviously as long is it doesn't put a (1) on my tab or makes a noise and doesn't steal mouse focus.
Yeah. I've written about this a few times, with some suggestions for how to make it marginally less miserable to visit a website:
"Take back your web browser screen space with Kill Sticky" https://www.smokingonabike.com/2024/01/20/take-back-your-web...
"Quick Tips For Making The Internet Suck Less" https://www.smokingonabike.com/2025/08/01/tips-for-making-th...
"Web browsers have stopped blocking pop-ups" https://www.smokingonabike.com/2025/12/31/web-browsers-have-...
The cookie thing, I assume it's EU-only, is an example of the EU policy making process being fundamentally broken in some way. If you create a flawed policy and don't fix it many years after it's very visibly obvious that it's a bad policy, something is really wrong.
it's an example of malicious compliance by some, and herd mentality by others.
I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.
You could have a 'no cookies' badge that links to your cookie policy - 'we use no tracking cookies and so are compliant with EU law ... then list any cookies/local-storage used and explain what they're for.
That would make you sound a lot more professional too. And trustworthy. (As long as that's actually what happens).
When I see these dialogs listing they have 1289723 gazillion vendors they share data with, I know that whoever is in charge of analytics, privacy or both at the company is incompetent.
Best we can do is a full screen model or annoying toast telling users we dont use cookies and click 4 to 7 check boxes to agree.
But then you can't have tracking cookies.
> but it makes the site seem less legitimate
I have yet to head that cookie prompts are a sign of legitimacy. What business has customers that would think that way?
That reasoning isn't wrong, though it seems ridiculous when looked at with techie-brain. But if there is a standard expectation of what serious company websites are like, it makes business sense to look like that too. It's like dressing up appropriately to cultural expectations. You can deviate somewhat but you have to strategically spend your weirdness points.
How nice of the EU to have determined for the rest of the world that the “cultural expectation” should be that every business do the design equivalent of wearing clown makeup.
I don't care about this. I explained why for an individual business trying to project seriousness, it makes sense to adopt a banner in the current environment. I didn't say it's nice of the EU or anything of the sort. It's an incentive pressure that exists on an individual company in the current situation. That's all I said.
I'd say just remove it. Don't ask people who don't actually understand the cost of having it there because you will get the wrong answers. Sometimes people just have to do the right thing, take some heat and then everyone can move on. If it has severe consequences then that's probably a good reason to leave anyway.
Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they couldn't deny that it cost a fraction of what we were paying our supplier and that things took minutes to set up rather than weeks. And that they worked a lot better.
Yes, there was shouting in meeting rooms. And yes, people said "you can't do this". Turns out they were wrong. A few years later I mentioned this to Werner Vogels. During a meeting. Where my CEO and CTO were present. And where everyone was feeling very good about us being one of AWS' biggest customers in our region.
So when someone says "you can't do that", sometimes you should make them prove it.
(At the time AWS was a good idea. Today dependence on a US service provider is a harder sell in Europe. The _first_ question you get today is if we can host it ourselves if we need to or if we can use a local service provider.)
I have the same mindset and often did the same thing, but then I thought about my doctor sneaking into my house while I’m sleeping and injecting me with the “good medicine” I had refused in their office.
Many years ago, I used to make informational websites for small, local businesses and they all wanted the cookie banner "just to be safe", even after explaining they didn't need it.
This website contains chemicals known to the State of California to cause cookies.
The Irish Republican Army, even at the height of their conflict, would never have stooped to such a website.
> and he said "yeah, but it makes the site seem less legitimate.
He may be right, sadly. I’ve seen the lack of a cookie banner used to suggest that a site was doing something shady or not complying with the law.
Most people don’t have knowledge about the finer details of cookie laws. They’ve been trained to believe that legitimate sites who comply with the laws will implement the cookie banner, and not seeing it feels suspiciously unprofessional.
I have had the same discussion multiple times at multiple companies. Luckily most of them were fine with dismissing the popup with a timer.
>it's an example of malicious compliance
So how would you do ePrivacy Directive compliance/risk avoidance in a non-obnoxious way?
Don’t use a bunch of unnecessary tracking cookies?
Completely eliminates the need for a cookie permission bar.
Reminds me of the early days of the CANSPAM act.
One of the best indicators that something was not spam was the unsubscribe button.
I see a lot of people below arguing that this isn’t the fault of the EU policy but the companies. I think that’s being overly charitable to the policy. While you can be rightly upset with the companies behavior, ultimately policy has to work with the incentives it creates. The policy in its current form allows for meeting requirements with annoying cookie banner opt-outs while keeping the lucrative business of tracking. If we don’t want that, the policy should be changed. Don’t expect companies to go against their interests here, even if some will actually be thoughtful and find a way to do so. The “Purpose Of a System Is What It Does” principle applies, and the purpose of the EU policy seems to be cookie banners for most sites.
Actually the purpose was not to invade our privacy as much, which we do and there is active lobbying (for example by Google) against any better solution: https://noyb.eu/en/eu-member-states-and-google-suddenly-want...
I’ve long believed that making companies liable for paying damages if PII is leaked in a data breach would be the best way to stop excessive tracking. If you force them to have to manage user data like they’re handling radioactive waste then the expense and overhead involved is a natural drag on the business logic that drives the bottomless appetite for data collection. They’ll collect it if they actually need it, and they’ll take great pains to secure it.
That’s already part of the EU regulations people in the comments complain about
Actually having worked in big companies,many of them just track everything, but don’t actually use the data, which is even worse.
The most valuable data breach content isn’t your advertising tracking data, though.
It would be your payment information, which is orthogonal to most of the tracking data.
The black market demand for leaked advertising-related tracking data is basically nil, except maybe in cases where it’s related to something else exploitable or usable for blackmail like if someone frequents cryptocurrency exchanges or porn sites. Nobody cares to pay for black market data about you shopping for towels on Amazon or things like that.
Nah fuck the companies and their horse shit.
99% percent of them intentionally turn the "decline" choice into a 5 - 10 step game of dark patterns even though the EU policy says it should be equally easy to decline. They know its bullshit but they also know the chance that someone will drag them through court is low.
The EU said "you have to ask for permission before forcefully sodomizing your users", and webdevs thought "let's ask for permission" rather than "let's not forcefully sodomize our users". Of course, the law could have said "don't forcefully sodomize users", but it seems the west is still under the impression that some people will do the right thing, just because, sometimes. (maybe 20 years ago they would have, just because, sometimes, but they won't now)
Not web devs per se, I’d be hard pressed to find a serious web dev who wanted to “forcefully sodomize users”. Thats a management thing
Many of them can't help themselves.
I used to have long conversations with frontend developers that "no, when I log on I don't want to be forced through a look-at-the-new-feature-we-made" sequences. And then they went ahead and did it anyway. And usually whatever flag they tried to set to make sure you only saw it once would malfunction, so next time you'd get to click through it all over again.
(If you want to tell users about new features, show a unread flag on a notification icon and make it a one-click affair to make it go away. Don't get in users' face with stuff they don't want)
"No."
If every webdev who would say no can be trivially replaced by webdevs who won't say no, then yes, it is webdevs.
"Damn, I'm being asked to put a cookie into this site that will maybe result in some guy seeing an ad about a toothpaste he might buy at some point in the future.
I'm going to risk months of unemployment and explain to my family why this is more important than eating when I get home."
-- the hypothetical webdev in that scenario, I guess?
You don't really need a web dev to add a cookie banner these days, but you probably still want one to build the actual site (unless it's simple enough to be fully site-as-a-service, in which case there is really no webdev at all).
Be it the EU for regulating disclosure and consent requirements, users for being "lazy" and usually just accepting all, or the webdev for not staking their livelihood on denying the banner - I'm sure they'll all get blamed before someone sees the ones actually demanding it be done can be the problem.
You can try to put the blame on the grunts, like trying to focus on the engineers in the VW Dieselgate, etc, but that is very weak leverage. You have to intervene at the root cause of the incentive. But of course the higher you go, the more there is a blur between legislators and business owners and they won't be harsh to themselves.
It's silly to blame the individual who doesn't have the authority or power at the business making these choices.
Actually cookies are not mandated by the EU, but this was the solution the big companies agreed on and now Google and Co try to lobby against better solutions.
Check out: https://killthecookiebanner.eu/
Policy making assumed good faith actors - specifically that tracking outside of necessary for website to function to be minimal. Because like…not necessary.
It’s only broken to the extent that it collided with a messed up world where websites track even when they don’t need to and then send that to 2000 partners for more profit extraction on top of what the website does commercially.
Something is deeply fucked up there and it’s not the EU part. They just make a good scapegoat because the banner is what users see
> Policy making assumed good faith actors
Let's not paint the policymakers naïve when they're in fact incompetent.
They are not incompetent in general. Most stuff works pretty well in Europe and better than in most of the world. We just focus on the bad regulations
The biggest positive outcome of the whole GDPR affair is that people finally believe me when I say that yes, they are selling your data to thousands of 3rd parties, and no, I'm not making these numbers up or exagerrating at all.
Most US sites are giving the cookie bag to US users. It may simply be easier for leadership to say add the widget than it is to say we won’t accept traffic from the EU or risk the consequences
It feels similar to how CA environmental regs become the national standard simply because the market is so large it’s not worth splitting on it. So they just slap a cancer warning on everything
1. It's also a piece of cake to just not display the cookie banner for non-EU IPs
2. If you are a purely US entity with no actual business presence in the EU, you only need to comply with US laws and nothing else. If the EU doesn't like a purely-foreign website, it's on them to set up a national firewall and block it.
Case in point 1: It's not on you to comply with China's laws, it's on them to block it if they want to
Case in point 2: China's local businesses with no EU presence do not follow GDPR and do not display cookie banners even if accessed from the EU
Do Not Track was the right implementation (browser-based, activate only once) and it was sabotaged by ad peddlers. It is bad policy that has been reached after every better alternative was rejected.
It's not a cookies banner. It's a request to harvest your data and share it with third parties for purposes that are not required for the service you're offering.
No harvest data to 936 partners? No need for a banner!
The most used banners at least have a quick way of dismissing without opting in. When the cases against too obvious dark patterns started that fixed itself at least.
I have yet to see an actual part of that policy which requires a cookie banner though. Seems more to me that it's a combination of (a) websites allowing all kind of fcked up use cases of cookies on their site (most sites do not even need cookies for real) and (b) not respecting http headers that ask to not be tracked... They much rather have a very confusing popup that kinda forces you to accept all :) How convenient.
Just like websites also give zero fcks about accept-language header... sure do geoip lookup, so much easier... not
I have always seen the cookie banner as a sort of punishment to the public for daring to have demanded better treatment.
“Oh you want consent involved in this interaction? Then we’ll annoy you about it constantly instead of respecting the intent of the regulation.”
Bullshit. There’s no need to track every visitor. Just stop tracking and you don’t need a cookie banner.
The only mistake EU policymakers made was underestimating how willing companies were to deface their websites.
"Every time you visit the websites managed by the European Commission, you will be prompted to accept or refuse cookies." https://european-union.europa.eu/cookies_en
The policy is both, good, but also flawed. For example, you cannot persist settings, because one policy says that website settings should be ephemeral unless user agrees to persist them.
That shows the same fundamental misunderstanding of the modern web that led to the ignorance of EU regulations.
It’s an EU law, but it impacts us all in America as well… because you know, every fucking website
It is not an EU law. Nowhere in GDPR are cookie banners mandated.
Actually big tech is to blame: https://killthecookiebanner.eu/
The cookie disaster is thanks to the ePrivacy Directive, which came before GDPR:
- https://www.edps.europa.eu/data-protection/our-work/subjects...
- https://en.wikipedia.org/wiki/EPrivacy_Directive
we could have settled on privacy compliant tracking without cookies, which is possible or use browser preferences and respect those (which would be perfectly legal)
I may be skeptical, so take this with a grain of salt. The transformation happened when someone decided to stop being UI designer, to become UX designer. That wasn't enough, so they came up with XD - experience design. At every step of the way, they introduced more lofty goals for the design to justify the increased importance of themselves.
Needs a Google login popup, required for any site that there is no reason at all to have an account with.
It also needs to ask the browser for your location and to send you notifications.
It should appear a second after the page seems to have finished loading, so that it hijacks the input if the user is navigating with the keyboard or typing something into a form.
Or even better, something that pretends to be a real "Sign in with Google" button but instead phishes your username and password.
Notifications?
How about an email popup. My browser will happily auto-populate it.
So many websites do popups and it feels so anti-user. Maybe I get unusually annoyed, but I do not need a Gemini popup ad in Google Docs. Just let me do what I came to the website to do!
But you could obviously be doing it faster/smarter by using Gemini /s
If they make it hard enough to interact with the actual website, we'll have to use AI!
See, there you go thinking being able to use a website is a right
Needs to autoplay a video which when dismissed just moves to another window and continues playing. With sound.
and hijack your clipboard and back button
And you can’t dismiss it because the X is somehow hidden behind another popup
I made this 6 years ago but it still applies today.
As feedback, you made that popup way too clean and easy to close. That’s not how it works in reality. You need to make the background transparent and the X so small it’s technically impossible to hit. Also think about adding an ad and a timer and move the popup slightly after N ms so that the user always hits the ad.
That "In case you're not aware, there's COVID-19 happening" banner isn't nearly tall nor yellow enough. Given a 6-inch-tall screen, the proper layout would be:
A local utility took it even further during COVID:It also needs to scroll in after a second or two, and shift the page content down, so you mis-click the wrong link, and end up loading something that takes forever to load and somehow manages to cause the back button to misbehave.
Clever people with no morals use that to load ads under your finger, timed to create an inadvertent click.
I swear NYT do this in their games app, the play button gets replaced with a subscribe as the late loaded subscribe element shifts the page exactly the amount to put subscribe under your finger. I wonder how well it worked?
manually scrolling before every widget loads should cause a full page refresh.
zooming in should cause a full page refresh
Why would you make this. I feel traumatized.
If the traffic to the site drops dramatically because of the “features”, we would have seen the features removed already.
I like it. Reminds me of this: https://how-i-experience-web-today.com/
Oh I love that!
inaccurate, i don't have to go three screens deep into a modal to choose only necessary cookies
The best one now is “Read for free” (give me all the trackers) or join a subscription and you can opt out. Pretty much every news / media site now
That one is honest at least, makes you aware that you're the product.
It's a bit 2025. Needs a scroll hijack background animation and cursor effects to be up to date for 2026
Somehow the clicking around reminded me of Windows RG. Go check this old relic if you have never seen it: https://www.jamesweb.co.uk/windowsrg . Turn the volume up!
it's funny sometimes there will be an archived espn.com (like this https://proxy.espn.com/espn/page2/story?page=simmons/030418) and it's hard to argue the web was not better like this, i.e. readable
Answer: ads as the main business model running the web since 25 years ago and us accepting the convenience 'free'.
It turns out everything has a price, and in more recent we started noticing that our time, attention and intelligence not being insulted also has value.
The worst patterns:
1) scroll hijacking (this should be a felony) 2) stupid cookie popups/banners 3) useless hero images (clients love them, users hate them)
Yea , thank u , I really despite those websites of current web, much JS, colors, much images and animations with mouse, and million fonts , rounded buttons and everything is rounded and "modern" and slow and bloated why cant have we simple websites, small coherent nice color palette to just read and know the needed info ? hackernews is extremely good example suckless: https://suckless.org/sucks/web/ is another brilliant example
We've got the stupid chat bubble at the bottom.
We didn't want it, it's like a megabyte of JavaScript. It's some third party service corporate forced on us.
I have to imagine a lot of websites are in the same boat, where they're just add crap they don't want to add by higher ups.
I made a game about this. You can play it if you want to feel annoyed.
https://termsandconditions.game
Is the beef with the design or the pop ups, chatbot, banner, etc?
If it's the design, not everyone is a web designer so the bootstrap theme is great to get up off the ground.
If it's the other stuff then, yeah, totally.
Yea but do you guys remember when we actually needed pop up blockers to avoid having a site spawn like 10 new windows behind the current one, and tabs didn’t really exist yet, and the popups had adult content and sometimes they autoplayed sound/video? Like, internet explorer 6 era? Sometimes I miss those days
You knew you done goofed when the adult site you opened on your family computer was opening new windows faster than you could close them...
[delayed]
Cookie banners are a great example of regulation gone wrong.
Me having to make a legal agreement with every website is absurd and totally predictable.
Even my back button was hijacked for a second. Nice attention to detail!
Yeah, I hand-rolled my site. Not even Google analytics. I have absolutely no idea if anyone even visits my site.
Oh well.
No need to worry, I just visited. Now you know.
Seems like the sort of site and person who should have a guestbook - I would have left an appreciative and encouraging comment there, but this will have to do:)
If it's going to be every website, it might as well be about pipes.
(shameless plug)
https://www.howgoodisyourpipe.com/
No endless scroll? What the hell am I supposed do I do with my mouse wheel?? Useless!
Needs a scroll that becomes a full page ad that when you scroll pass becomes the same ad but 1/3rd the page
Don't give them ideas... LoL
That is already deployed to real web sites.
(2019) *
* according to the copyright notice, although, going by the mention of Covid, it could also be 2020?
Where is the ‘sign in with google’ pop up?
Every paragraph (maybe sentence) needs to fade in as I attempt to scroll. If I can read the first paragraph easily when the page loads (ignoring the pop-ups) then the website is too well designed.
This is completely accurate. I see it every day.
Apple.com looks ok. It doesn't have the cookie banner.
We need a special version mocking recipe websites
Needs more jank from a bajillion ads loading. :D Kidding aside, this is hilarious and made my morning
It should also detect the ad blocker
Bootstrap, what a blast from the past! They just don't make bad websites like they used to.
There are more creative ones. Check out https://shellbox.dev
I kinda miss the CSS bootstrap aesthetic.
Damn, yeah this is exactly how I make my websites look.
I use Brave browser and even that didn’t help.
[delayed]
It needs to present a happy moose to you if you don't use an adblocker
I can't believe I'm not able to buy Every Fucking Website Premium with business focused ads and native advertising masquerading as quasi-educational infotainment. Also where's the sign-up with Spybook?
I wasn't asked for my location, notifications, camera permissions or to log in. This is, regrettably, still better than most recipe websites I visit.
SmallWeb ftw!
Also on iPhones Twitter appears to have aligned their privacy reject button with where their open in app overlay appears just a second later so that you hit that instead.
Too many people working on evil dark pattern bullshit
The cookie banner should have the option to change the cookies but you have to deselect the trackers one by one
It’s missing a “we stand with the current thing “ flag and a compliance prompt for community standards.
Also 1.5gb of heap allocated minimum
it’s missing spinners for 5-10 seconds while it loads endless megabytes of javascript doing who knows what.
Seriously how did we get to this point? I remember growing up in the 2000’s and all the marketing about computers was “it’s fast!” and “get results instantly!” that kind of thing. Now everything it gated by multiple spinners, then it loads a skeleton, then it partially loads your actual content, then, when you go to click on something, more content loads and the existing content jumps to a new place and you end up clicking on something else, meaning now you have to go back (if they haven’t hijacked the back button), wait for it all to load again, wait for the second “real” load, and then click on what you actually meant to click on in the first place.
This is perfect.
Really needs a 20MB video playing in the background of the hero.
with an ad overlayed that won't go away
Needs the floating video thumbnail with auto-play and sound. Also the requests for location and permission to send notifications dialogs in chrome!
Every Fucking Website not created by Claude. Otherwise it would have a dark gray background with transparant rounded buttons with a neon border.
No agents.md?
For my current project, I tried going with a non-traditional style I personally liked, I call it "Soft Neo Brutalism". You can see it at: http://www.frost-e.com
I generally wanted web 1.0 simplicity, lots of contrast, but also a soft gentle colours and modern vibe. I also have a general design for use in dashboards/apps etc: https://frost-e.com/design-system/
missing carousel
Not enough AI slop
lol
This is actually good boilerplate. lol
Trump 2020! I hate puppies!
Cookie banners are malicious compliance. There are only 1-2 EU countries with quarrelsome predatory lawyers proactively scanning the web.
The positives about covid and AI is that we don't hear anymore about blockchain and crypto (well, except one boomer oligarch holding onto it). Just please make the next two big things happen already for God's sake.
Because it fucking works
(AIUI "I agree" gets people to give explicit consent with good success and the subscribe modals are quite effective too)
There was a piece of caselaw about a company having an "agree" but a million tick-boxes to disagree. A lot of sites added a "disagree" button then.
Just a quick reminder that you don't need to put up any cookie banners at all if you simply don't track your users in a privacy-invading way.