The Cookiepocolypse will end privacy on the web

Cookies days are numbered. Ignored by users, blocked by browsers, disliked by regulators. How will websites track users once the cookie has crumbled?

Almost every website you visit drops cookies onto your device so that your behaviour on the website can be tracked and analysed. Cookies enable the website analytics software to identify you, not by name but by IP address which on the internet is as good (better, in fact) as a name. Which pages you visit, how long you were on them, the buttons you click, all of it is tracked. Those cookies remain on your device after you leave the website so that ads can be served to you on other sites in an attempt to get you to return. Many people consider the way cookies are used to be an invasion of privacy, and this is leading to cookies no longer being a viable option for website analytics.

Under the Privacy and Electronic Communications Regulations, which are enforced by the ICO, websites are supposed to allow users to choose whether they accept cookies or not, and adhere to that choice. In fact, the majority of websites completely ignore the cookie selection made by their users and drop tracking cookies regardless of users clicking the accept button. They do this for a combination of reasons including the ICO not enforcing the regulation, technology from before the law came into force that hasn’t been replaced, and knowing that it’s the only way to track sufficient numbers of visitors.

Website visitors ignore the cookie banner. Only 11% of website visitors accept cookies. This means that any organisation that wishes to comply with the regulations, or treat its visitors with some respect and give them the choice of whether to be tracked, is going to find it impossible to understand user behaviour using cookies. That doesn’t sound like it should be a tough choice; adhering to the regulations and treating users with respect versus being able to report of website metrics, but people have different priorities.

And browsers are blocking cookies. Firefox blocks third-party tracking cookies and cryptomining by default and Google is to ‘phase out’ third-party cookies in Chrome, but not for two years. This move by the browser companies is being talked about as about achieving privacy for users, which might be the case for Firefox, but it isn’t for Google.

Regulators don’t like cookies, website visitors don’t like cookies, tech giants don’t like cookies, and in a sense, I think all for the same reason; they don’t have any control over them. Anyway, all of this means that using cookies as a technology for tracking users on a website doesn’t have a future. If your business relies on cookie technology to serve ads and bring customers to your website, you might be worried. If you are a media buying agency that offers advertising services, you might be worried. If you are a major provider of online ads and make billions of dollars a year from advertising, you might be worried. No longer using cookies to track users is going to have considerable impact on businesses and how every user experiences the web. This is why it has been called the cookiepocolypse.

Of course, humans have ingenuity. They find ways around these kinds of problems. 

Visit the New York Times website in a desktop browser and you’ll be presented with a cookie acceptance banner. Visit the New York Times website in a mobile browser and you’ll be asked to login using your google account. Signing-in to a website replaces the need for anonymous tracking using cookies, now the website knows who you are and can track the usage associated to your account. The signin was so easy, just a click of a button, you barely even noticed doing it. You didn’t set up an account in an explicit and obvious way as you might on other websites, but you now have an account with this website. 

We’re seeing it now, but in the future we will see far more websites force users to sign-in before they can read content on the site. It offers them a solution to be able to track users more than they currently can and without the need for third-party tracking cookies. 

This will have two major impacts on the web as we know it: Google will get more data about what we do on the internet, and websites will have to get much better at providing value. 

Google already knows loads about what you do on the internet and on your mobile if you have an android phone. If you don’t believe me go to My Activity and login to your Google account (of course). The reason Google knows so much about you is because you’re logged into your Google account for so many of the activities you do on the web. As you go from Google search results into a website that isn’t owned by Google, Google hopes that they can continue to track you with Google Analytics, which uses cookies dropped on your device by that website. That’s an imperfect way to track users because cookies are non-proprietary technology, which means other companies can also use cookies to track users, and that’s a problem for Google, no market dominance. 

That’s why Chrome isn’t going to start blocking for cookies for two years (around 2022), to give Google time to build up its capabilities in social login and convince businesses to use it to power Google Analytics. Google is in the business of tracking and understanding users. They don’t want internet usage to be private, they want it only available to them. They are using the end of cookies to drive users to login to websites using their Google account so that they can track their usage in third-party websites on an individual level as they do with their own websites.

Once websites have got used to, and got their users used to, using social logins, those that want to monetise their site will turn that login into a paywall where payment is taken as via the users Google Pay account, which of course Google will take a cut of, creating a new revenue stream for them.

The other impact is going to be on the websites that implement login to their site, whether it is enabled by Google or any other provider. These websites will become subject to the economics of information goods. They’ll need to be able to communicate the value of the content before they reveal it to their users, just as you can’t read an ebook until after you’ve bought it. Once users have accessed the webpage that information will become non-excludable, meaning that even though it’s behind a login or paywall, we should expect that other businesses will offer better ways for users to access it. 

Take my website for example, the one you’re reading this on. If you had to create an account before you could read this, would you really have bothered? All that extra time and effort, and more of your data going who knows where, just so you can read the ramblings of someone who late one night convinced himself he’d reached a sufficiently insightful understanding of how websites will track users when they can’t use cookies that he decided to write a blog post about it. Let’s be honest, we’re both surprised you’ve got this far.

If you run a charity website (which is my particular area of interest) there are some things you could try (I say try because there are no tried-and-tested solutions so these need to be viewed as experiments) as the Cookiepocolyse takes away your ability to track users. 

  1. Stop tracking users – Visitors to your website will have a slightly nicer experience because they won’t have another cookie banner to click, and you might be able to get some good PR from taking a stance of putting your users privacy ahead of the organisations need to track and report. There are lots of other ways to understand the experience visitors have of a website, including user research groups and surveys, which will provide a much deeper understanding than some unreliable analytics data.
  2. Only track those that allow it – If you are still tied to using cookies, and you’re going to adhere to the choices your visitors make, but you want to try to increase the number of people that allow themselves to be tracked on your website, then try turning tracking into a way to support the charity. Change the messaging on the cookie banner to something like, ‘We’d like to track your visit to our website today because it helps us show our funders that people need the work we do” (good luck with the legal team). Push the message that user’s data has value and that they can do good things with it.
  3. Create such high value that users will want to login – Make the login super easy (not a lengthy sign-up form to try to collect lots of information) and have tough discussions about the ethics of using social logins vs a means within your control, and then make it worth their while. Decide whether there are some parts of the site that don’t really need to be tracked and so can be outside the login-wall, and then work really hard to make sure that everything behind the login, whether its content to read or a service to be accessed, is worth so much more to them than having to login (and it won’t be every time they visit because those essential cookies will be used for what they were intended for).

Markets for Information Goods

Much has been written about the difficulties that “information” poses for neoclassical economics. How ironic that ICE–information, communication, and entertainment–now comprises the largest sector in the American economy. If information poses problems for economic theory, so much the worse for economic theory: real markets seem to deal with information rather well.

This paradox is the central theme of this essay: information, that slippery and strange economic good, is, in fact, handled very well by market institutions. The reason is that real markets are much more creative than those simple competitive markets studied in Econ 1. The fact that real-life markets can handle a good as problematic as is a testament to the flexibility and robustness of market institutions.

Weeknotes #206

This week I did:

Writing makes neat boxes

I produced an interesting (only to me) comparison chart of the ways one-to-one, one-to-few and one-to-many communication can take place in Microsoft Teams. The reason I find writing documents like this so interesting isn’t because of the topic so much, but because it forces me to structure and clarify my thinking. It gives my understanding some neat boxes to exist in which I can connect with other neat boxes of knowledge and the messy overflowing boxes which I haven’t yet organised.

I also intend to use writing more to help others structure discussions and decisions about our products. This has started me thinking that quite often we don’t need a strategy, we just need a structure. We don’t need long-term plans, we just need agreed means for tracking the progress of work, communicating with each other, making decisions, etc.

Designing services that support the product to deliver a service

My questions about where the lines between product and service are, or whether there even are lines between them, continues. I’ve been working on designing services that support the product to deliver a service. We’re also thinking about what products we need to introduce to enable the services that support the product that delivers the service our users engage with. Ultimately, all of the products and services fit together into an ecosystem that creates the experience of engaging with our organisation. Doing this without falling foul of Conway’s Law is a interesting challenge to check-in with 

Yesterday, today, tomorrow

I tried another experiment in focusing work. Everyday (and I actually managed to stick with it every day this time) I answered three questions; what did I do yesterday, what am I doing today, what do I want to do tomorrow? I know the experiment was only for a few days, but I’m still not convinced it’s achieving any better focus than not writing what. I did learn one thing about choosing the size of the tasks; make it something you can get done in a day, not something vague that might take a number of days.

You can have a long term strategy or agile delivery but you can’t have both

I wrote about my ideas about why an organisation can’t have a long-term strategy and agile delivery. It seems obvious to me that the two are not compatible but on the same continuum of how organisations plan, manage risks, make decisions, and deliver value.


And I learned:

Focus of innovation

I watched a Wardley mapping video workshop where experienced mappers were working together to map the dependencies and evolution of the elements of a health insurance service to identify where in that service to focus their efforts for innovations. Watching them work through and discuss a real example helped my understanding so much more than watching a prepared video or reading a book. They were clear about however useful a map is or isn’t, it doesn’t have any answers. I took this to be what the phrase, ‘the map is not the terrain’ means. Answers only come by getting out in the real world and experimenting.

Exam time

I had the final exam for the first year of my MSc. I’ve really enjoyed all the thinking and learning I’ve done this year. It has expanded my thinking so much. 


And thought about:

Essay time

I want to write some essays (now that I have more time as I’m not studying). The first one is going to be called something like, ‘The weaponisation of digital technology to scale inequalities in society, and why charities need to up their digital game to fight back’. It’ll be about the effects of digital technologies on the nature of social problems, so not ‘this tech causes that problem’, but how the internet enables problems at a speed and scale that charities are not yet able to cope with, and so to help in the future they’ll have to change their thinking about digital. It’ll be a very different piece of work to my blog posts, which are mostly just me ranting about ideas I have, and instead will be researched and (hopefully) better written and presented. I just need to try not to get distracted with all the smaller blog posts that I also want to write.

Service Vulnerability Testing for Charities

I’ve been thinking quite a lot about how charities build services but probably don’t do vulnerability testing to find out if bad actors could use those services to target vulnerable people. I wonder how easy it is to ring a charity, pretend to be someone who accesses their services, and get information about that person (“I’ve changed my phone number, what number to do have on record? Oh yeah, that’s the right one”). 

Charities are getting better at cyber-security, and many (I’d hope all but I don’t know) have safeguarding processes in place, so they are often able to deal with the issues that come to their attention, but how can they be sure that they aren’t inadvertently contributing to issues outside of their attention because they haven’t secured their services.

Related to this, I found a few websites about social engineering in the not-for-profit space Social Engineer has information about how social engineering is used in attacks on organisations, and the Innocent Lives Foundation is a not-for-profit that promotes safety online and uses social engineering skills to help people.

How to manage and build upon ideas

As part of my ongoing experiments in how to better organise my ideas to make it easier to build on them and connect them, I tried adding lots of my writing to a single document (ideas for essays, notes, blog posts, lecture notes) and tried hyperlinking keywords to headings of other sections. My hypothesis was that if all of my notes were in one place where they could be linked, that it might help create some coherence but I haven’t seen that yet.

I also tried using a Miro board to create an ideas map with four layers of depth (practices, principles, philosophies, paradigm)  and a timeline from now to the future, and then placing postit notes on the map to try to indicate which level the idea is on, and whether its something realisable in the near or distant future. My thought was that being able to see certain relationships between ideas might help create some coherence but I haven’t seen that yet either.

Everyone has a newsletter in 2020

I had an idea for a newsletter. It would be focused around ideas affecting the charity, tech, for-good, innovation space, and might be called something like ‘Past, present and future’. Each episode I would take a current issue or event, look at it’s past, so what thinking has led to it, it’s present, what the current thinking is about it, and what its future might look like. The problem is, I always have more ideas than time. And then I had another idea. Maybe I should do a future.charity newsletter and use it to explore thinking around all the things that make up a charity like governance, HR & marketing, and how they could be made fit for the future.


And read these tweets:

Competing priorities 

Beth Crackles tweeted about the biggest barriers to fundraising priorities with a survey that showed that the main reason is ‘competing priorities’. I find how organisations deal with priorities really interesting. It’s so easy to assume that ‘it’s leadership’s job to set and communicate the priorities, so if we have competing priorities it must be because they aren’t doing it very well’. This ‘us and them’ mindset affects our thinking in so many unhelpful ways. I bet the people in leadership feel just as pulled in many different directions when there are so many things to focus on. 

I think there are much deeper reasons for competing priorities than we realise, and the clue is in the phrase, ‘competing priorities’. When we use a competitive mindset, whether because we recognise some kind of ‘us and them’ power struggle, or because we frame our priorities as ‘either/or’, we limit how we can act within the mental space we’ve created. Competition is a market force. If you assume there is a competition, then you have to accept how the market forces are going to affect the things that go on in that space. Supply and demand, scarcity of resources, advantage over other players in the space, vying for power and influence, etc., are all concepts from competitive markets. Replacing the competitive mindset with something more collaborative isn’t at the top of anyone’s priorities at the moment, but if we don’t do something about the worldviews we hold that affect our thinking so completely, it’s not surprising we’ll continue to be competing.

The future of online education

Kay Sidebottom tweeted, “Unis are focusing a lot on content and delivery models regarding move to online. I’m thinking about that too, but also exploring how to establish meaningful relationships with large numbers of students… which can be even harder in digital spaces.” Lots of people are talking about a revolution in online education (Jason Jacobs and Tiago Forte among others). To be successful, the development of online education needs to avoid trying to deliver offline education online. It needs a complete redesign including pricing, content, delivery, engagement, etc., that is built on understanding how the internet-era changes so much about what is possible.

The weight of a website

Ross tweeted a link to this A List Apart article about how wasteful websites are, especially when they have lots of images. The reason this is interesting is that we conceive of websites as virtually things with no physical existence of impact on the world we also inhabit. Appreciating how our physical and virtual worlds are closely interwoven seems like an important thing as our digital world grows in the future and because our physical world can’t grow.

Blame is easy

Matthew Sherrington, tweeted about his blog post ‘Are managers gaslighting staff over wellbeing? (Spoiler: yes)’. He talks about how “people’s wellbeing has routinely been damaged through work overload, unrealistic expectations, and poor decisions and direction from leadership”. I think blaming managers for the workload and wellbeing problems is too-easy ‘eighties’ thinking and doesn’t consider the structural and systemic context. I’ve no doubt that there are lots of bad managers who don’t have the skills to match their responsibilities, but they are just as affected by the same workload and wellbeing issues. I want to write more about this, not to criticise Matthew’s perspective, but try to unpick it on some deeper levels and offer some thoughts on ways to make it better.