Live data from Hacker News

The GDPR Is a Cookie Monster

emarketer.com

91–97 of 97 posts

Re: The GDPR Is a Cookie Monster

#91
post #80

The dark patterns in play now to get explicit consent are pretty bad now though. Take Mashable for example. On first visiting the site you are presented with the option to "Consent" or view more Options (where you can Opt Out of all - except you can't really because some require Opting Out on the specific Advertisers site). But if you do choose to Opt Out all, they will then show you the initial Option box on every v…

I had an interesting encounter recently: https://imgur.com/a/i1hm1TQ

I'm not sure what conclusion you're drawing, the final two screenshots didn't have any explanation.

As far as I can tell, you've observed that if you force your browser to stop displaying the cookie preferences overlay, the hidden page becomes visible again.

Does this reveal something controversial that I haven't inferred?

Re: The GDPR Is a Cookie Monster

#92
post #80

The dark patterns in play now to get explicit consent are pretty bad now though. Take Mashable for example. On first visiting the site you are presented with the option to "Consent" or view more Options (where you can Opt Out of all - except you can't really because some require Opting Out on the specific Advertisers site). But if you do choose to Opt Out all, they will then show you the initial Option box on every v…

I had an interesting encounter recently: https://imgur.com/a/i1hm1TQ

The same thing happens on Forbes. Trying to opt out fails after "applying preferences" a few minutes.

It's of course bullshit.

Re: The GDPR Is a Cookie Monster

#93

Earlier quoted context omitted.

Because GDPR includes provisions for handling US GDPR violators, a lot of security vendors were touting up the idea that if a European fills out a form on your site or gets cookied for any reason, you could be sued.

So they'd file suit in the EU and... what would happen? Some sort of judgment that would prevent a company from starting business in the EU at a later date?

Detained during their connection in Frankfurt?

Re: The GDPR Is a Cookie Monster

#94

Earlier quoted context omitted.

I think we should have a de facto standard element class for legal notices with no required user action, like legal-notice-no-action-required. Webistes use the css class, uBlock Origin makes it a built-in default element filter. Website owners can fulfill their legal obligations and users that proactively shape their browsing experience are all set. Neither side wants these things messing up the browsing experience s…

> I think we should have a de facto standard element class for legal notices with no required user action, like legal-notice-no-action-required. Webistes use the css class, uBlock Origin makes it a built-in default element filter. Website owners can fulfill their legal obligations and users that proactively shape their browsing experience are all set. Sounds like P3P ( https://en.wikipedia.org/wiki/P3P ) > Neither si…

> Personally, I absolutely want to know when sites are trying to spy on me and sell the data.

It's best to assume they're all doing that to some degree whether they tell you they are or not. For one, most of the world isn't beholden to EU law. Also, bad players don't play by the rules and by the time you know they're bad, it's too late.

> Despicable crap like that should be forced out into the public, not quietly agreed to by the browser.

But the cookie law doesn't fix that problem, or any problem for that matter. The notifications are 100% pointless and we're stuck with them because of a stupid law. If anything, having a standard way to block the notices might encourage more users towards a real fix for the tracking problems, which is using something like uBlock Origin (just don't tell that to the site owners that don't want users having tracking blockers).

Re: The GDPR Is a Cookie Monster

#95
post #46

Earlier quoted context omitted.

The difference is that GDPR does have effective enforcement mechanisms, precisely unlike previous laws. Now let’s see if they’ll be applied.

Mechanisms in the laws or the institutions? The difference is very important and many people, who agree with the intent of the law, have been pointing out this difference for a while now. Scribbles don't make something so. If the approach of just writing it down didn't work before, why just change words instead of approaches?

Both, if I understood what you mean: The GDPR regulation ((EU) 2016/679) contains provisions for legal enforcement, and describes which process and agencies are responsible for that.

Whether this actually works, only time can tell. But the fact that similar previous legislations went unenforced was a specific concern that the designers of the GDPR intended to address.

Re: The GDPR Is a Cookie Monster

#96
post #81
post #29

Earlier quoted context omitted.

Well, Microsoft kinda dropped the ball on that one by making it the default (although they later changed that).

I don't feel like they did drop the ball there. By default I don't want to be tracked. I think that tracking across the internet should be opt in and users should be made aware of what websites are doing _before_ they start doing it. I also find the idea of secret shadow profiles to slightly immoral for the same reason.

DNT is a flawed idea in the first place. DNT is based on the idea that users can opt out of being tracked by sending that header. But (e.g.) European privacy law requires having users explicitly opt in to being tracked -- the message DNT is meant to assert is the legal default under GDPR.

DNT only works if the assumption is that users who make no choice can be treated as consenting (which is no longer the case under GDPR). But if you set DNT by default you're not asserting "this user doesn't want to be tracked", you're just making it impossible to tell whether the user explicitly opts out or hasn't made a choice (and therefore actually do consent).

If tracking is opt-out rather than opt-in (i.e. if we disregard GDPR and similar privacy laws and go with how US startups have operated so far) that means DNT is no longer a reliable signal for opting out and thus meaningless.

Implications about consent and privacy aside, DNT only works if it is used with intent. In the absence of intent, by making it the default without the user's knowledge, it becomes ambiguous and therefore pointless.

To put it differently: if there had never been any browsers that set DNT by default (except maybe browsers explicitly marketing themselves as "privacy first" like Brave does), you could use DNT as an explicit assertion that you do not consent to being tracked. This means it could actually serve as a technical implementation to opt-out of any "implied consent" allowed by the GDPR and making use of your right to control your data.

But thanks to Microsoft randomly slapping on the header to piss off Google, DNT is now too ambiguous to infer any of that.

Re: The GDPR Is a Cookie Monster

#97
post #25

Earlier quoted context omitted.

I don't know. Why are EU companies paying attention to American laws, again?

Largest economy and military in the world are big reasons to play nice with America

The US is not the largest economy. Whatever gave you that idea?

Except for military force and incarcerations per capita, the US is lagging behind in almost every statistic compared to China or the EU.

Post reply on HN