Live data from Hacker News

The GDPR Is a Cookie Monster

emarketer.com

61–70 of 97 posts

Re: The GDPR Is a Cookie Monster

#61
post #27

Earlier quoted context omitted.

I just don't use sites that won't work until you give consent.

That's idealistic. In my country all the news sites, as well as the local commerce sites do it. Where should I get local news from?

It is idealistic. Idealism is how the status quo changes for the better.

The short-term effect of GDPR is ugly interstitial pages and mandatory consent, but that's not the point of GDPR. The point is to make legally collecting user data difficult, annoying, and onerous in the hope that going forward more companies will eventually decide it's more trouble than it's worth. That'll only work if complying actually is a chore.

Call your local news site and complain if they aren't honoring GDPR to the letter. Call your country's ICO and complain to them too. Talk your friends and family into doing the same. Be a pest; the more annoying the better.

Re: The GDPR Is a Cookie Monster

#62
post #54
post #41

Earlier quoted context omitted.

Are you using a browser extension that may be interfering with the website? I haven't had issues with website forgetting my preferences yet. Also being in the EU I'm used to these cookie dialogues, except before GDPR if I wanted to opt-out (assuming that it was even an option) I'd often have to wade through multiple pages, opting-out of the tracking which would take a while, especially since they were usually using e…

At work I don't have any third-party blocking extensions (I use Chrome). At home and on my mobile I do (I use Firefox Focus), but neither let websites to "remember". Is there something I need to configure?

Firefox Focus deletes all data upon closing. That includes cookies where your consent was locally stored. That's why you're seeing it every time.

Re: The GDPR Is a Cookie Monster

#63
The GDPR should get one important update and that’s QUICK:

You shouldn’t be allowed to ask for consent to do tracking or targeting as a pop up. The site must be completely usable using only “required” cookies (to which no consent should be required if it only tracks a limited set of data) and any option to consent to anything outside this must be a hidden option.

That is: sites should have to work 100% without popups and shouldn’t be allowed to use “marketing cookies” (for tracking and ad targeting)

Otherwise we just traded one nuisance for another.

Re: The GDPR Is a Cookie Monster

#64
post #46

Earlier quoted context omitted.

Don't we have a glimpse of (lack of) enforcement based on previous incarnations of laws like this? What about this time is special? And why are laws crafted without ample enforcement mechanisms? At the least that makes them toothless, at the most it gives a piece of legislation that can be pulled out and used only when someone wants a reason to punish a company.

The difference is that GDPR does have effective enforcement mechanisms, precisely unlike previous laws. Now let’s see if they’ll be applied.

Mechanisms in the laws or the institutions? The difference is very important and many people, who agree with the intent of the law, have been pointing out this difference for a while now. Scribbles don't make something so. If the approach of just writing it down didn't work before, why just change words instead of approaches?

Re: The GDPR Is a Cookie Monster

#65

I just HATE all the pop-ups asking for permission to use cookies now. Seriously, having to opt-in on a per-site basis has led me to loathe the GDPR. It's a usability disaster. I never thought I'd hate anything more than the "sign up for our newsletter" pop-ups... but these are even more pervasive. If I'm the kind of person who hates cookies/tracking, I'll just install a blocker and block it everywhere, and then white…

I think we should have a de facto standard element class for legal notices with no required user action, like legal-notice-no-action-required. Webistes use the css class, uBlock Origin makes it a built-in default element filter. Website owners can fulfill their legal obligations and users that proactively shape their browsing experience are all set. Neither side wants these things messing up the browsing experience so, unlike the ad wars, we can work together.

Re: The GDPR Is a Cookie Monster

#66

I just HATE all the pop-ups asking for permission to use cookies now. Seriously, having to opt-in on a per-site basis has led me to loathe the GDPR. It's a usability disaster. I never thought I'd hate anything more than the "sign up for our newsletter" pop-ups... but these are even more pervasive. If I'm the kind of person who hates cookies/tracking, I'll just install a blocker and block it everywhere, and then white…

GDPR gives sites a choice: either stop doing shady stuff, or ruin the UX. If a site's UX has been ruined, that's because the site has specifically chosen to keep doing shady stuff. Blame the site for being shady. GDPR is on the side of the users.

Note that GDPR doesn't say things like "cookies need a consent form"; rather, it requires that data processing is only performed if a certain valid reason is given. One valid reason is that the service offered by the site couldn't be achieved without the processing. That's fine. If something's not required to perform the service (i.e. shady stuff), the only valid reason for doing it is if consent is given; hence the awful forms.

Re: The GDPR Is a Cookie Monster

#67
post #8

Earlier quoted context omitted.

I honestly don't get why so many sites are even paying attention to GDPR. If they don't have a presence in the EU, it is irrelevant.

> If they don't have a presence in the EU Only sites with a presence in the EU are paying attention. The LA Times is a counter-example of a site that hasn't bothered with GDPR because they didn't feel EU users were worthwhile keeping. However, collecting data on the 0.5 billion people in the EU evidently seemed worthwhile for most sites.

It seems strange to me that the LA Times would cut off European users, when they presumably have to comply with the new California Consumer Privacy Act, which is similar, anyway.

Re: The GDPR Is a Cookie Monster

#68

The dark patterns in play now to get explicit consent are pretty bad now though. Take Mashable for example. On first visiting the site you are presented with the option to "Consent" or view more Options (where you can Opt Out of all - except you can't really because some require Opting Out on the specific Advertisers site). But if you do choose to Opt Out all, they will then show you the initial Option box on every v…

Enter Brave. And uBlock Origin. And DuckDuckGo privacy essentials.

Swap DDG Privacy Essentials for uMatrix and you won't get the cookie pop-ups _nor_ the tracker cookies, which is pretty swell in my book.

It breaks some sites, but after saving settings for your more commonly visited ones, you really don't notice it all that much.

Re: The GDPR Is a Cookie Monster

#69
post #33

I fucking hate GDPR policy making every website to show "Cookie Policy" ad pop modal. STOP. Every single time after I have accepted it, I come back the next day, I see the same modal again. I just accept it anyway, so stop. Stop this horrible UX. Sorry, but it really annoys the shit out of me. It does and I am pissed off every single time. If I accept, stop asking.

GDPR doesn't make every site show cookie policies and popups now. It's entirely within a site's power to decide not to collect analyitics on their traffic, in which case they don't have to show or get consent for anything.

I know, that's so glib that it's laughable. That's the point.

We currently have a status quo where user analytics are very valuable while the cost of collecting them is minimal. That strongly incentivizes site owners to collect and store as much data as possible. In this moment we have a business culture and a set of engineering best practices that's grown up around those incentives.

GDPR changes the incentive structure by imposing a cost on the collection end, in the hope that site operators will start being significantly pickier about what analytics they want to collect, when, and from whom. The end goal is a cultural change in how we collectively build websites. But culture doesn't change on a dime. It takes time for the existing actors to accept and adapt to a new normal, especially one that's more hostile to their interests.

Be pissed off. Pissed off is an appropriate response to the horrible UX you're being exposed to. But be pissed off at the people showing you the horrible UX. It's in their power to stop, they just don't want to.

Re: The GDPR Is a Cookie Monster

#70
post #61
post #27

Earlier quoted context omitted.

That's idealistic. In my country all the news sites, as well as the local commerce sites do it. Where should I get local news from?

It is idealistic. Idealism is how the status quo changes for the better. The short-term effect of GDPR is ugly interstitial pages and mandatory consent, but that's not the point of GDPR. The point is to make legally collecting user data difficult, annoying, and onerous in the hope that going forward more companies will eventually decide it's more trouble than it's worth. That'll only work if complying actually is a c…

The reason GDPR exists is to protect people who do not understand the complicated world of online tracking. If GDPR is effective only when said people are on the front line of defense, than the GDPR has failed.

As a matter of fact, I do complain a lot, and I do file complaints about GDPR violations, but convincing my friends and family to even care about this stuff is science fiction (I've tried for over a decade now without success).

Post reply on HN