Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

21–30 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#21
The omnipresent "Please accept our privacy policy (or leave)" is worthless cargo cult GDPR pseudo-compliance. If it's neither freely given nor informed, it's not consent under GDPR.

See Art. 7: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract."

See Recital 32: "Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data ... This could include ticking a box when visiting an internet website ... Silence, pre-ticked boxes or inactivity should not therefore constitute consent."

If you want to use external tracking and be GDPR-compliant, you must offer a clear choice ("yes/no") and you must not use pre-ticked boxes (i.e. an opt-out approach).

Please feel free to downvote this if you don't like it, but I'm merely telling you what the law says. If you disagree factually, I'd appreciate a comment though.

Re: Cookie Warning Shenanigans Have Got to Stop

#22

What people miss about the new GDPR notices, compared to cookie warnings of yore, is that they offer you the choice of opting out. In my experience, the option is usually hidden (look for “options”). But a surprising number of sites do actually comply and make this not prohibitively obscure.

I think Troy's point though is that if you understand the situation. You already have lots of tools at your disposal to opt out. It's not easy, but you know and can to some extent do it.

Meanwhile everyone else doesn't understand these pop ups, doesn't know anything more post GDPR, and they just roll through them and get tracked just the same.

In effect we have big annoying pop ups and little seems to have changed. If we care about the ideas behind GDPR, I think we have to recognize that it may be failing miserably in practice.

Re: Cookie Warning Shenanigans Have Got to Stop

#23
post #12

I feel like GDPR and such had some good spirit to it... but the result isn't what they had in mind and the consumers just click through everything / have no more clue. Piling on or malforming GDPR seems like it would just make the already unworkable situation more of a mess. I like the "ideas" behind GDPR, it's just this isn't the way to do it and really accomplish anything that really helps an individual.

I wonder how often we'll repeat the error of treating user privacy as something the user cares deeply about (against all this observable evidence to the contrary) before we accept that the well-demonstrated-and-documented default is users do not care (and if we want the behavior of websites to change, step 1 is educating users as to why they should care and what the risk models are).

Yeah I fear that is the case.

Unless users really become educated and then care ... this is all for not.

If it ever happens (people caring and informed) maybe we're a generation or two away from it being a thing. :(

Re: Cookie Warning Shenanigans Have Got to Stop

#24
post #5

This is like a case study of well-intentioned, carefully designed regulation doing more harm than good. Honestly, I'd rather just have a browser addin that blocks the cookies I don't want. The market was working fine. Now every new website is a pain, and my organization has hired some amiable lady to be "GDPR expert". She doesn't appear to know anything about anything, but she sure seems nice.

GDPR absolutely does not do "more harm than good". It extends well, well beyond these dumb cookie warnings. GDPR puts the citizen/customer in power of their own data. They can ask for their data, they can ask for it to be deleted, they have (however shitty the UX) control over where it goes. They can contact large corporations and request these things and be heard out . I don't know how to explain it any other way: T…

> I don't know how to explain it any other way: These things are fucking important.

I believe that thought is treated as an axiom by some and an under-tested hypothesis by others.

Re: Cookie Warning Shenanigans Have Got to Stop

#25
As a web developer I gotta say the only true solution to this is to stop using the internet altogether. Might as well shut the internet down.

We can't authenticate you without cookies or some other form of identification, so that throws out any site with an account.

Even if I am not even remotely interested in tracking what pages you view on my website if I need to have you login and authenticate I need some form of cookie / session ID.

If you need to be anonymous use a browser like Firefox Focus or similar but understand that you won't be able to log in for longer than a single session, if at all.

Cancel GDPR and similar privacy laws before we outlaw the [useful] internet completely. These laws are a mess written by people who honestly are not remotely qualified to make these kinds of decisions.

I'm all for the option of privacy but it's your own responsibility -- stop using the internet leave all your electronics at home and go ride your horse into the wilderness and breathe some fresh air if you want privacy.

Re: Cookie Warning Shenanigans Have Got to Stop

#26
post #19

I'm sure there's some good reason not do it, so I'll ask if anyone here knows: why doesn't the law just require some technical implementation that can be automated? Why can't the law just specify something similar to the DNT header (finer grained) and require compliance with that?

The GDPR offers a general privacy framework. Technological specifics may (or may not) become part of the upcoming, heavily embattled "ePrivacy regulation", which was intended to come in effect simultaneously with the GDPR. Right now, we have a somewhat unfortunate limbo.

Re: Cookie Warning Shenanigans Have Got to Stop

#27

Earlier quoted context omitted.

GDPR absolutely does not do "more harm than good". It extends well, well beyond these dumb cookie warnings. GDPR puts the citizen/customer in power of their own data. They can ask for their data, they can ask for it to be deleted, they have (however shitty the UX) control over where it goes. They can contact large corporations and request these things and be heard out . I don't know how to explain it any other way: T…

> I don't know how to explain it any other way: These things are fucking important. I believe that thought is treated as an axiom by some and an under-tested hypothesis by others.

That they're not important to everyone doesn't make them unimportant for everyone.

It's kinda like other rights such as free speech. Some people don't need/use it. Some specific people might arguably be better off without it. But Everyone needs it; as in, it needs to be available to everyone for it to work.

Re: Cookie Warning Shenanigans Have Got to Stop

#28
post #12

I feel like GDPR and such had some good spirit to it... but the result isn't what they had in mind and the consumers just click through everything / have no more clue. Piling on or malforming GDPR seems like it would just make the already unworkable situation more of a mess. I like the "ideas" behind GDPR, it's just this isn't the way to do it and really accomplish anything that really helps an individual.

The reason it hasn't been super successful is that there haven't been big punishments.

Re: Cookie Warning Shenanigans Have Got to Stop

#30

Earlier quoted context omitted.

> I don't know how to explain it any other way: These things are fucking important. I believe that thought is treated as an axiom by some and an under-tested hypothesis by others.

That they're not important to everyone doesn't make them unimportant for everyone. It's kinda like other rights such as free speech. Some people don't need/use it. Some specific people might arguably be better off without it. But Everyone needs it; as in, it needs to be available to everyone for it to work.

It's worth noting that the United States considers a right to keep and bear arms as important as a right to free speech.

Internationally, reasonable disagreement on rights seen by some as fundamental is to be expected.

Post reply on HN