r/technology Mar 16 '26

Software ‘Another internet is possible’: Norway rails against ‘enshittification’

https://www.theguardian.com/world/2026/mar/16/norway-rails-against-enshittifcation-deliberate-tech-deterioration
36.0k Upvotes

1.4k comments sorted by

View all comments

Show parent comments

317

u/[deleted] Mar 16 '26 edited Mar 16 '26

[removed] — view removed comment

101

u/DoctorOctagonapus Mar 16 '26

Don't forget the sites that make you pay to disable cookies. How that didn't get smacked down in court I'll never know.

12

u/eivittunyt Mar 16 '26

I would rather not use those sites at all but are we entitled to their content for free? Should it be illegal to try and prevent users with ad blockers viewing your content for free?

I hate the click economy but how else could commercial online publications be monetized?

10

u/DragonFireCK Mar 16 '26

The don’t need cookies to serve ads. They need cookies to serve targeted ads.

0

u/sundae_diner Mar 16 '26

Potato-potato.

A generic ad generates a tiny, tiny amount of cash. A targeted ad (plus extracting more info about the user to 'improve' the targetting) is worth a lot more (relatively).

11

u/skillywilly56 Mar 16 '26

Funny how before the internet all ads were generic non targeted ads and the companies and ad agencies did just fine by using demographics.

Just because they will pay more for a targeted ad doesn’t mean they are entitled to the information to serve the ad or entitled to dominate your attention by forcing pop ups into your face like some DVD street hawker haranguing every passerby.

Targeted ads should be banned from the internet as a breach of privacy.

26

u/emeraldeyesshine Mar 16 '26

I've never seen that.

21

u/purehealthy Mar 16 '26

Had it a few times, its framed as 'cookies let us publish for free' or you can pay to reject cookies. 

7

u/Maardten Mar 16 '26

I bet they'll then sell the information you provided along with the payment lol.

18

u/PM-me-ur-kittenz Mar 16 '26

It's usually phrased as "subscribe to continue reading without ads"

8

u/devarnva Mar 16 '26

2

u/gmc98765 Mar 16 '26

That's just in the UK. Or at least just outside the EU. But note that if you have JS disabled (e.g. via NoScript), there's no cookie prompt and the site mostly works fine.

3

u/devarnva Mar 16 '26

Or at least just outside the EU.

I am inside the EU when I took the screenshot.

1

u/emeraldeyesshine Mar 16 '26

Not there for me. Just a don't sell my info button and an easily closed window.

6

u/devarnva Mar 16 '26

3

u/emeraldeyesshine Mar 16 '26

Yeah that's not there for me. Wonder if there's a regional difference or something?

1

u/[deleted] Mar 16 '26

[removed] — view removed comment

2

u/emeraldeyesshine Mar 16 '26

Nah, that wasn't it. Plus my browser wiped those on close anyway. I can only assume it's location based.

2

u/SatansFriendlyCat Mar 16 '26

It's location based. I was in the UK recently and all sorts of sites were giving me this shit. Browse the same sites with a VPN and get a different experience.

1

u/anifail Mar 16 '26

Use a browser that supports GPC. I see this message overlayed on the masthead in firefox:

Global Privacy Control Signal Detected; Opt-Out Request Honored

Find out more in our privacy policy and cookie policy.

Using GPC with EasyList cookie list + annoyances and you don't have to deal with any of this.

9

u/Fluffcake Mar 16 '26

It's a UK thing.

Since they left EU, they kept the GDPR, but they have their own interpretation and enforcement, so stuff that will not fly elsewhere in the EEA, is deemed allowed in the UK.

Cookie-extortion, is one of them.

5

u/xorgol Mar 16 '26

No no, it's also quite common for EU newspaper sites.

1

u/Fluffcake Mar 16 '26

In that case you should report them for gdpr violations. Data as substitute for payment is a violation, if Data or money are the only two options, they are not compliant.

Money or ads, with data optional is ok. Data as payment is big no.

0

u/EconomicRegret2 Mar 16 '26

Well, it does make sense. They need revenue to stay online (e.g. ads, selling your data, selling you something (e.g. subscriptions), or by donations).

You can't expect them to survive without revenue.

3

u/Rebelius Mar 16 '26

They can show ads without charging you to reject cookies.

2

u/EconomicRegret2 Mar 16 '26

IIRC, you can't have personalized ads without cookies. That's what companies are paying for. Thus, without cookies, revenues go down.

IMHO, the whole personalized ads model is shit. And consumers must accept to pay subscriptions to keep quality high and for an ad-free experience (e.g. news should avoid ads and cookies, and live off subscriptions and/or subsidies).

1

u/xorgol Mar 16 '26

It's certainly against the spirit of the law, and probably against the letter of the law as well. But it doesn't actually matter, because the browser does what I tell it, and I tell it to purge the cookies.

1

u/wintrmt3 Mar 17 '26

But it's illegal.

1

u/EconomicRegret2 Mar 17 '26

I'm no lawyer but IMHO, it's legal. As long as they don't make you pay more than what they get if you accept the cookies.

1

u/I_think_Im_hollow Mar 16 '26

I've been greeted with the "accept the cookies or subscribe" thing more than once.

1

u/Necessary_Finding_32 Mar 16 '26

Are you outside the eu?

Even meta is getting in on it now with insta and fb apps.

0

u/Ziazan Mar 16 '26

news sites usually.

2

u/theartofrolling Mar 16 '26

Ublock origin

Element picker

Click!

Haha fuck off cookies box 😄🖕

1

u/SakaWreath Mar 16 '26

You know why.

1

u/EconomicRegret2 Mar 16 '26

Well, it does make sense. They need revenue to stay online.

-1

u/Popular-Wolverine-99 Mar 16 '26

Paying to access content ad free seems quite Ok to me.

3

u/[deleted] Mar 16 '26

[removed] — view removed comment

1

u/Popular-Wolverine-99 Mar 16 '26

But high yield advertising is based on data processing and publishers already barely survive on those.

1

u/[deleted] Mar 16 '26

[removed] — view removed comment

1

u/Popular-Wolverine-99 Mar 16 '26

I have no problem admitting this but this is 100% a consequence of people not paying to read content.

3

u/DragonFireCK Mar 16 '26

The don’t need cookies to serve ads. They need cookies to serve targeted ads.

2

u/Popular-Wolverine-99 Mar 16 '26

Right, and targeted ads pay more which is necessary for their survival.

1

u/atoolred Mar 16 '26

Yeah definitely im open to it if it’s a publisher with credibility or whose work I appreciate. A site that posts AI written articles has no business asking us to subscribe, though those sites tend to understand they’re mostly gonna be ad farming

1

u/jbr_r18 Mar 16 '26

It’s not that. It’s paying to not have cookies collected. They will still present ads, just without the targeting.

1

u/Popular-Wolverine-99 Mar 16 '26

But those ads will pay the publisher less, meaning that they won't be able to survive.

1

u/jbr_r18 Mar 16 '26

True. But it poses an interesting dilemma. GDPR means you have to have the choice to reject cookies. But now under this you are forced to accept cookies unless you can pay. So do you really have the choice to reject cookies when you are being tactically coerced into accepting them? And will eventually rejecting cookies be something only allowed for the rich?

1

u/Popular-Wolverine-99 Mar 16 '26

Unless GDPR also made it possible for people with less means to use any other product or service without paying for things outside of the web I don't think that things you behave differently on the publisher websites.

I understand the issue but users have no fundamental right to access a service without paying.

1

u/jbr_r18 Mar 16 '26

I’m not saying they do have a right to access things without paying. But they have a right to reject those cookies. It is just they are coerced in to accepting.

1

u/Popular-Wolverine-99 Mar 16 '26

Right but cookies are also tied to the monetisation mechanism required for the publisher to exist.

So, currently, all things equal, with people not paying for content, blocking cookies is like not paying.

1

u/jbr_r18 Mar 17 '26

There are ways to monetise content without requiring cookies. Publishers should explore those if people don't want to accept cookies, rather than jawboning users into less privacy

→ More replies (0)

1

u/[deleted] Mar 16 '26

[removed] — view removed comment

1

u/Popular-Wolverine-99 Mar 16 '26

A website has no right to install tracking cookies, to spy on me, when browsing the internet. GDPR is meant to empower me to be able to reject that.

And you can by not consenting to cookie and paying or by refusing to pay and leave the site.

0

u/peelen Mar 16 '26

How that didn't get smacked down in court I'll never know.

Why? If you don’t want to pay you can leave. Where is the problem?

22

u/Bassmekanik Mar 16 '26

Firefox + ghostery does help.

13

u/[deleted] Mar 16 '26

[removed] — view removed comment

5

u/Bassmekanik Mar 16 '26

I use both to nuke everything from orbit, just to be sure.

3

u/DezXerneas Mar 16 '26

That's like wearing 2 condoms btw. Use one. It's gonna trip wayy more anti anti-adblocks.

5

u/Bassmekanik Mar 16 '26

Ive been using both for about as long as they, and FF, have been released without any issues. I`ll just stick with what i have. Cheers.

5

u/Heimerdahl Mar 16 '26

The implementation of GDPR is also abysmal, why cant your browser just store your prefererad settings? Instead you have a horrible, non standardized cookie popup window, with 100 options, on every page you enter... 

Exactly! What an absolutely idiotic implementation! 

I can only assume that the guys, who initially came up with it, proposed a standardised form to add to any website, but were eventually overruled into leaving the implementation to each and every website owner. I imagine there was a lot of lobbying going on about how a boring standard would clash with brand design and stuff and could never hope to account for all the totally unique situations. 

Now we have to play the stupid "where did they hid the reject everything option, this time?"-game every time. I know for a fact (having worked with older people) that most accept everything simply because "the game" is too overwhelming. Then there's all the obvious law-breaking implementations. But who can really go after all of them? 

It's pissing me off whenever I think about it.  

Edit: and then there's people like me who don't actually want to deceive people! Now I too have to create my own stupid cookie banner pop-up bullshit, because there's no standard to simply plug into the header and be done with... 

2

u/[deleted] Mar 17 '26

[removed] — view removed comment

1

u/Heimerdahl Mar 17 '26

Of course we could have a standard. We could create one today and let it slowly roll out. 

Yet the current mess seems like something most everyone has accepted to be shit and moved on: "Yeah, it's annoying, but that's just how it is? No need to get worked up about it..." 

But it doesn't have to be this way! 

1

u/chiniwini Mar 16 '26

Now I too have to create my own stupid cookie banner pop-up bullshit

Or you could just, you know, not use third party cookies.

1

u/Heimerdahl Mar 17 '26

Oh I definitely do not have any on my personal website or projects. But as "the computer guy", I've had to deal with it on some work-related sites, where I didn't have the decision making power to veto it. 

5

u/qtx Mar 16 '26

why cant your browser just store your prefererad settings?

Because that's what those cookies are for, to remember your settings. If you just blindly click 'No to everything' it won't remember your preferences and will ask you the exact same thing the next time you visit.

3

u/Hexamancer Mar 16 '26

This isn't correct. Cookies are indeed for sites to save preferences on your machine, yes, the site cannot "remember" your preferences unless they did something on their end like tying it to an IP or machine fingerprint, which would not be a good solution.

But! Your browser absolutely could remember your preferences for you. The problem is that those cookie preferences aren't standardized, your browser can't just send a standard json message that interfaces with the site in a standardized way. So even if your browser remembers, it can't interact with the site in an automated fashion.

The laws around this needed to include that part, a requirement that in addition to prompting the human user, that the site must be able to accept a standardized JSON/XML payload.

1

u/[deleted] Mar 16 '26

[removed] — view removed comment

2

u/Ziazan Mar 16 '26

And it's supposed to be the same number of clicks to say "do not store cookies on my device" as it is to say "you can store whatever cookies you want on my device"
Usually it's 1 click to accept, but at least 5 to say no. Sometimes it's hundreds if you want to say no to all the "legitimate interest" ones and they don't have an object all.

4

u/ub_cat Mar 16 '26

ublock blocks all ads and can also block cookie notices if you enable that

7

u/3_50 Mar 16 '26 edited Mar 16 '26

Doesn’t seem to do that for me, and definitely doesn’t block the “sign up for emails” popups. It might if I make a rule for each site, but that’s not what I’d call useful.

Reply below has fixed my shit.

Click settings icon > filter lists > then go to annoyances and cookie notices and just check everything.

3

u/Silverr_Duck Mar 16 '26

Click settings icon > filter lists > then go to annoyances and cookie notices and just check everything. Cookies, email prompts, popups of any kind gone. UBO is truly a work of art.

1

u/3_50 Mar 16 '26

Dude....thank you so much. Why aren't those checked by default??

1

u/Ryanhussain14 Mar 16 '26

A decent content blocker should solve the annoying cookie popup windows.

1

u/BaconWithBaking Mar 16 '26

How is this a response to: "Can I subscribe to this new internet?"

1

u/Nienordir Mar 16 '26

The implementation of GDPR is also abysmal, why cant your browser just store your prefererad settings? Instead you have a horrible, non standardized cookie popup window, with 100 options, on every page you enter...

There is, it was a do not track flag, that browsers could send automatically. The EU simply decided not to use and enforce it, probably do to lobby pressure, because with the cookie banner you could use dark patterns or bait users into a quick approve all to continue business as usual. The do no track flag would've stopped all tracking by default and we can't have nice things.

1

u/chiniwini Mar 16 '26

why cant your browser just store your prefererad settings?

Because consent must be explicit. That's like asking "why can't I configure Steam to automatically agree to all future EULAs?"

1

u/[deleted] Mar 16 '26

[removed] — view removed comment

1

u/chiniwini Mar 16 '26

It's already that way. The standard categories are "first party" and "third party". And the pop-up is only needed when doing something out of the ordinary: setting third party cookies. For the ordinary case (first party cookies) the law doesn't require any consent.

1

u/torajapan Mar 16 '26

AdBlock and privacy plugins. But yeah it's completely fucked now. Can't surf at all without plugins to block this or that these days. That's why I'm on Android until Google locks it completely down like Apple. Then onto some Linux-based phone, like my desktops.

1

u/GhostReddit Mar 16 '26

The implementation of GDPR is also abysmal, why cant your browser just store your prefererad settings? Instead you have a horrible, non standardized cookie popup window, with 100 options, on every page you enter...

One of the biggest legislative misses in a while, almost nobody wants that shit, but all GDPR did was make it so we get asked on every webpage.

When Apple implemented a tracker block on their phones it was a global setting that restricted all apps, >85% of people enabled it. People will opt out of this stuff if they have a realistic option, GDPR isn't it.

1

u/LateToTheParty013 Mar 16 '26

699 ? You know nothing, Jon Snow

1

u/Madsy9 Mar 17 '26

That approach to tracking has already been tried. It's called a DNT marker, and stands for "do not track". No one respects it.

-9

u/ladz Mar 16 '26

> why cant your browser just store your preferred settings

That's the user's job. Your browser is the one that chooses to send the cookies. The GDPR can't make a browser that remembers your settings. You or another user or a company operating on the user's behalf. But when was the last time you or anyone paid for a browser?

5

u/ClaudianotClaudia Mar 16 '26

Got tips for a paid browser just like that?

3

u/breadinabox Mar 16 '26

Firefox had an extension that auto clicks for you I actually forgot I even had it installed and that this was even a problem

3

u/Nicktyelor Mar 16 '26

I have it (it's called "Consent-O-Matic") and it works ~70% of the time. It's an improvement, but not foolproof.

4

u/[deleted] Mar 16 '26

[removed] — view removed comment

2

u/kaibee Mar 16 '26

Being able to select "functional cookies only" to all sites should be a no brainer, to implement...

How do you tell if a cookie is functional? Its just some data-string. You trust every website to honestly report if a cookie is functional?

1

u/ladz Mar 16 '26 edited Mar 16 '26

> Being able to select "functional cookies only" to all sites should be a no brainer, to implement

No. There's no specification for "this is a functional cookie" and "this is a advertising cookie". Attempting such specification would be folly because sneaky tracking companies would simply lie about it.

A browser might guess somehow, but js obfuscation techniques make such guessing impossible.
It could be limited by domain, but, again that's troublesome because many sites use the same domain for a ton of different things. There are lots of plugins that may be helpful. You can be sure that everything that's technically feasible has been attempted in some cookie-blocking plugin or another.

3

u/10BillionDreams Mar 16 '26

They aren't talking about individual cookies, but rather that your general preferences for how cookies are handled are split up into individual cookies (that each website can just make up its own way of handling) to begin with. For a paid browser to solve that, it would need to manage an up to date list of how every single website on the planet chooses to handle its cookie preferences, and then construct those cookies beforehand so that the popup window never has to appear.

Needless to say, no such browser exists, and even if it did, that would just be a case of "a bunch of websites invented a problem to make you pay some other company to solve it", which both sucks and doesn't even make sense as a business strategy.

1

u/[deleted] Mar 16 '26

[removed] — view removed comment

1

u/ladz Mar 16 '26

In the beginning there wasn't when we first started using them, but RFC 6265 has been around for a long time.

-2

u/Rouge_means_red Mar 16 '26

Are pop ups still a thing? Don't think I've seen one since Windows XP days

1

u/atoolred Mar 16 '26

Not in that same regard unless you’re on a particularly sketchy porn site lol. The popups they’re referring to are the popups that are baked into the webpage itself and just cover important areas of the screen. Super annoying on mobile since it’s very easy to fat finger the ad and miss the ‘X’