Live data from Hacker News

The GDPR Is a Cookie Monster

emarketer.com

51–60 of 97 posts

Re: The GDPR Is a Cookie Monster

#51
post #43
post #39

Earlier quoted context omitted.

Considering you cannot use cookies for mobile traffic, it's understandable that most firms are moving away from it. Fingerprinting and device IDs have been common for a few years and I don't think it will go away any time soon.

Why can't you use cookies for mobile traffic?

I wasn't clear enough and I apologize. You can use cookies but they will only be within the context of a singular app's browser. For example, suppose that you use two web browsers on your Desktop, Chrome and Firefox. If you visit xyz.com on FF, some cookie information will most likely be stored. However, if at a later time, you visit the domain on Chrome, it will not have access to the same cookie store.

This becomes important in the context of third party cookies that want to track you across apps. Hence why cookies are not a reliable method of identification on mobile.

Hope this clears it up. :)

Re: The GDPR Is a Cookie Monster

#52
post #31

The GDPR made me switch my cookie policy, to using two Chrome extensions in tandem: - I don't care about cookies: auto accepts all cookies - Cookie AutoDelete: auto deletes all cookies So now you can track me all you want... until I leave your website and all the cookies are gone (unless whitelisted).

Chrome and these extensions give you a false sense of privacy. Currently, no extension can remove local storage and tracking information contained within them.

https://bugs.chromium.org/p/chromium/issues/detail?id=78093

You'll either have to clear local storage manually or get a privacy-oriented browser.

Re: The GDPR Is a Cookie Monster

#53
The methodology behind this study looks okay but it isn't necessarily representative of real world use. The study looks at the front page of around 200 news sites in Europe with a browser cleaned of all cookies. However in all cases the IP address belonged to a machine at the university of Oxford so it probably had some history attached to it.

It shows some reduction in cookies served before user interaction but it isn't clear is this is due to GDPR or other changes that have been made over the 3 month period.

My summary is that the data found is not statistically significant given the relatively limited sample size and lack of any control sample to compare against showing usual variation over a 3 month period.

Re: The GDPR Is a Cookie Monster

#54
post #41
post #33

I fucking hate GDPR policy making every website to show "Cookie Policy" ad pop modal. STOP. Every single time after I have accepted it, I come back the next day, I see the same modal again. I just accept it anyway, so stop. Stop this horrible UX. Sorry, but it really annoys the shit out of me. It does and I am pissed off every single time. If I accept, stop asking.

Are you using a browser extension that may be interfering with the website? I haven't had issues with website forgetting my preferences yet. Also being in the EU I'm used to these cookie dialogues, except before GDPR if I wanted to opt-out (assuming that it was even an option) I'd often have to wade through multiple pages, opting-out of the tracking which would take a while, especially since they were usually using e…

At work I don't have any third-party blocking extensions (I use Chrome). At home and on my mobile I do (I use Firefox Focus), but neither let websites to "remember".

Is there something I need to configure?

Re: The GDPR Is a Cookie Monster

#55
post #40
post #33

I fucking hate GDPR policy making every website to show "Cookie Policy" ad pop modal. STOP. Every single time after I have accepted it, I come back the next day, I see the same modal again. I just accept it anyway, so stop. Stop this horrible UX. Sorry, but it really annoys the shit out of me. It does and I am pissed off every single time. If I accept, stop asking.

Are you blocking third party cookies in your browser? If the site uses a third party cookie to store your preference, then it may be unable to recall what you previously entered.

No :/

Re: The GDPR Is a Cookie Monster

#56

The dark patterns in play now to get explicit consent are pretty bad now though. Take Mashable for example. On first visiting the site you are presented with the option to "Consent" or view more Options (where you can Opt Out of all - except you can't really because some require Opting Out on the specific Advertisers site). But if you do choose to Opt Out all, they will then show you the initial Option box on every v…

Article 7 of the GDPR specifically states that "It shall be as easy to withdraw as to give consent."

> And if you ever accidentally click I Consent, then they opt you back in to everything again and then never show you that option box ever again.

If this is accurate, then this is another violation of the same article, which also states that "The data subject shall have the right to withdraw his or her consent at any time."

Re: The GDPR Is a Cookie Monster

#57

I feel like the DNT header could have been made a lot better if it worked alongside GDPR. Like, 0 = haven't chosen/prompt me (I want to pick exactly what cookies I want), 1 = don't care give me everything, 2 = functional, 3 = please don't track me at all. You could then just surface this per-site even in the browser, maybe in a way resembling the IE Security Zone settings with their nice sliders.

I don't think this would work as it makes it too easy to not be fully tracked. There are so many hoops to go through now because companies want to incentivise being tracked and punish those who don't wish to be.

If this was brought in through regulation, that's a different story.

Re: The GDPR Is a Cookie Monster

#58

The dark patterns in play now to get explicit consent are pretty bad now though. Take Mashable for example. On first visiting the site you are presented with the option to "Consent" or view more Options (where you can Opt Out of all - except you can't really because some require Opting Out on the specific Advertisers site). But if you do choose to Opt Out all, they will then show you the initial Option box on every v…

Dark patterns like that are explicitly not allowed and hopefully these sites will learn that if they aren’t going to be compliant then they might as well not show anything and just ignore the GDPR.

Re: The GDPR Is a Cookie Monster

#59
post #25

Earlier quoted context omitted.

I don't know. Why are EU companies paying attention to American laws, again?

Largest economy and military in the world are big reasons to play nice with America

Military doesn't come in to this at all.

And similar arguments could be made for why American companies would play nice to the EU.

Re: The GDPR Is a Cookie Monster

#60
post #38

The dark patterns in play now to get explicit consent are pretty bad now though. Take Mashable for example. On first visiting the site you are presented with the option to "Consent" or view more Options (where you can Opt Out of all - except you can't really because some require Opting Out on the specific Advertisers site). But if you do choose to Opt Out all, they will then show you the initial Option box on every v…

This. I also found the Daily Mail decided that if you ignored the banner asking for consent and scrolled far enough down the page, it assumed consent for everything. Definitely shady, probably illegal.

GDPR requires affirmative action for consent. This was specifically touched upon in the recital 32:

> Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject’s agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject’s acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent.

Post reply on HN