The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…
> The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. At this point I just want those consent forms to be standardized via ARIA tags or whatever so that some extension can click the "yea, sure, whatever" button for me.
Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
81–90 of 238 posts
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#82The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…
Hopefully you'll choose not to use those sites.
For the first couple of months, I clicked all the "manage my choices" buttons. I felt the pain, but decided it was worth it. Then I discovered that for many sites, I would have had to enable 3rd party cookies in order for the choices to stick. That made me realise that I simply didn't want the marketers to even know that I didn't want them to track me; that I didn't want to enable the malpractice of companies that hadn't offered me the choice to disable their options; that I wasn't prepared to rely on the devs behind those dialogs to implement the design implied.
So now, I just close the tab and read something else. My hope is that others make similar choices.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#83The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#84Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enable c…
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#85Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#86Earlier quoted context omitted.
Your comment is being downvoted because you're just rambling like an old man grumpy about kids on his lawn. Not a single shred of evidence, or even an attempt at making an actual reasoned point. Every time there's comments like this I can't help but think I'd be extremely surprised if the people writing them knew any of the names of the people who worked on the law. I wonder what you even define as "having an idea wh…
And yet the poster is right for the reason mentioned by the first poster. Most people click on the option that gives quick access to the content. If it creates more than 2 seconds of distraction, I might even close the page. There is no reason to trust the EU legislature regarding the internet after something like this: https://juliareda.eu/2018/08/censorship-machines-gonna-censo...
1. It was "poorly drafted legislation"
2. The authors had "no idea what they were doing"
Whether it was poorly drafted legislation remains to be seen. The "unintended consequences" people are talking about here are minor, what matters are the intended consequences such as the augmented rights europeans have over their data, their privacy, etc. I personally don't give a shit about the annoying cookie popups, I'm just glad I can finally delete my account and email address from various websites when I want them gone.
GDPR has given me a ton of rights over my data that I should have, and everybody should have. It has given me access to my own data. It has given me the power to delete it. This shit is important, and now it's law. That there's cookie popups because the companies in question suck? I don't care. If it makes you close the page, that's a positive side effect IMO. This shit must be bad for conversion in order for businesses to start getting a clue. It's a version of the "tax on privacy" that a lot of people on HN like talking about.
Regarding #2, I dispute that for the same reasons. GDPR is achieving its goals of securing user data in europe. Companies are scared straight into following it so far.
There are issues with it (especially a lack of compliance material). None of them point to "the authors had no idea what they were doing".
In other words, no, GP isn't "right" just because you have to click off some annoying popups. That's not the only thing GDPR does.
Edit: Lacking replies, I'm going to assume those downvoting this comment are the usual no-privacy-apologists who are annoyed they now have to put legalese in front of users and don't ask themselves why they have to.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#87The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…
> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…
Actually, I think we should be annoyed at browser vendors for letting the problems with cookies get to this point. They're obsessed with backwards compatibility, but sometimes you need to break things to fix a problem.
This is one of those times. Consider, what is the greatest lever we have in this scenario? There are hundreds of thousands of companies and billions of users. Measures to change the behaviour of this huge set of people are futile.
However, there are only a handful of browsers, and the past few years they're somewhat responsive to user feedback. Browsers are our greatest lever, and the privacy solution will have to come from there. Remove cookies or neuter them significantly, like removing JS access to cookies and/or making cookies opt-in only for sites storing login info.
If necessary, add new types of concepts for gathering anonymous analytics data that's guaranteed to respect privacy, and new concepts to specifically store persistent credentials rather than general data and to which JS again has no access.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#88Somehow, I feel like the old, unregulated internet was better. I wonder if that is just nostalgia or there is something to it. With an unregulated internet, any internet user has to take care of their own privacy and anonymity. Barriers for entry for new websites and services are very low. Data breaches and abuses of data can lead to users being concerned about giving their data to tech monopolies, which can enable c…
Right, but then Eternal September happened.
Nowadays, the vast, vast, vast majority of Internet users don't have the necessary background knowledge to understand how to protect their privacy online, and the people who do have that knowledge tend to concentrate into organizations that have a lot of financial incentive not to respect others' privacy.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#89The practical effect of GDPR seems to me that I have to click away about half a dozen consent popups every day. Sometimes a cookie warning in addition to that. If I use Private Browsing (to protect my privacy) I am punished with more popups. If I open a website within a browser shell on mobile that doesn't have my cookies (some kind of webview of an app), I am punished with more popups. Am I expected to look at every…
Yeah I don't want to sit down with the digital form of someone's lawyers each time I visit a site, and if I have to I imagine I and others all just click away to get the dang content already. The way GDPR works out it sort of expects us to care to follow this annoying process, and I don't think people do / want to and thus ultimately won't make good choices. GDPR demands users engage in the process on the web in a ve…
This is simply false. GDPR only allows opt-in for these choices, companies are just implementing GDPR incorrectly.
Re: Brendan Eich Writes to the US Senate: We Need a GDPR for the United States
#90Earlier quoted context omitted.
> These are very real, very concrete negative effects of GDPR Your annoyance is misplaced. Don't be annoyed at GDPR: be annoyed at all the companies who have spent the last decades building an entire web-infrastructure with zero respect for user privacy. We built massive amounts of technology infrastructure that just assumed that privacy and tracking wasn't an issue. Why do these websites need all these cookies in th…
But is GDPR really making the kind of difference people wanted? What I see, is that mostly companies continue the same behavior, but now with a disclosure you are prompted to accept. I predicted everyone would just accept those terms in exchange for free services they already have invested into. Now we just have an extra annoyance. Has anything substantially changed?
A GDPR in the US should have the power to audit companies and ensure compliance, just like the FDA does with health-tech companies.
On the user side you might only see the effects of GDPR in the form of cookies that were added as a quick-and-dirty solution for companies that have built an infrastructure whose revenue model requires collecting user information. On the other side, law also gives a vector for the government to step in and demand changes to companies that are fast and loose with user data.
If we'd had an effective GDPR in the US, the Equifax breach that lost everyone's social security number may have been prevented and they might have faced some kind of real repercussion when it did happen. Instead, data companies still get to privatize gains and externalize losses.