Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

81–90 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#81

Earlier quoted context omitted.

From my understanding if the cookie is for an account on a website (which usually is only required to store private information such as name, email, address, etc) you would need to display the cookie warning.

Cookies are only affected if they are not a core and essential part of the product's functionality, and can identify the user. You could also argue that authentication may not be an essential part of an app's functionality, but you would not be successful; it's well-established by now.

According to the following you still are required to display the cookie warning/banner, but without the consent requirement.

https://www.iubenda.com/en/help/5525-cookies-and-eu-data-law...

Exemptions to the consent requirement Some cookies are exempt from the consent requirement and therefore are not subject to preventive blocking (though you’re still required to have the banner and cookie policy in place). The exemptions are as follows:

Technical cookies strictly necessary for the provision of the service. These include preference cookies, session cookies, load balancing, etc. Statistical cookies managed directly by you (not third-parties), providing that the data is not used for profiling Statistical (anonymized) third-party cookies (e.g. Google Analytics)* *This exemption is may not be applicable for all regions and is therefore subject to specific local regulations.

Re: Cookie Warning Shenanigans Have Got to Stop

#82

To add insult to injury the big players with most trackers just refuse to show the cookie warnings at all. At least that's the situation Germany where most major news outlets are full of ads and trackers and handle all of it via opt-out(!) in the privacy policy. For a example see spiegel.de, the most widely read German-language news website. It's mostly small and medium sized firms that show the cookie warning out of…

There is a window now when players can argue that the regulation text isn't clear (it is). Let's hope regulators pick a few high-profile targets that are in violations and hit them with massive fines.

Re: Cookie Warning Shenanigans Have Got to Stop

#83

Earlier quoted context omitted.

You beg the question by saying it's "their own data" in the first place. The idea that, because it's about you it's therefore yours, is wrong.

The famous difference between citizen-first EU and corporation-first US. Over here, we do believe that our data is ours. This is reflected in our legislation and regulation. You don't want these rights and protections in the US? Well good news, you don't have them. They still apply to us however.

What you believe "over there" is wrong; data about you isn't yours. You can pass all the laws you like, that doesn't change the moral fact of the matter.

Re: Cookie Warning Shenanigans Have Got to Stop

#84
post #69

Its too bad nobody invented a browser header to be sent with HTTP requests for Allow-Cookies: SURE_YES_WHATEVER_OMG_STOP_ASKING_PLZ

There are browsers addons for removing these annoying notifications, most popular is named "I don't care about cookies"

uBlock cookie annoyance list works too

Re: Cookie Warning Shenanigans Have Got to Stop

#85
post #64
post #47

Earlier quoted context omitted.

Tracking cookies, pixels, etc., are implemented by server-side software; perhaps the matter you would like to contend is what the meaning of the word "placed" is.

Cookies are data that is placed on the visitor's computer. Tracking pixels are software instructions placed on the visitor's computer. The tracking that is akin "remembering a face" is user agent and ip address tracking. In my mind, a store that uses facial recognition software to track my movement within the store and purchasing habbits is still incredibly creepy and highly invasive of my privacy.

The government has automated license plate readers that do much the same thing. Their justification is, you're in a public place, you have no expectation of privacy. I'm a little more concerned about that.

If I don't want to be tracked, I can choose to shop at a different store. But I can't live in a system of underground tunnels.

Re: Cookie Warning Shenanigans Have Got to Stop

#86

Earlier quoted context omitted.

You make a fair point, but the right to bear arms is mainly controversial for safety reasons. What safety issues are there with providing customers control (or at least visibility) over their data? It's also worth pointing out that the right to bear arms, by its origin, should probably be called the "right to revolt". While this is still a controversial issue for governments (governments don't want revolt), it's less…

I think the safety issues with GDPR compliance are minimal (there's a weak argument to be made for inefficiency introduction and contributing to warning blindness, but it is a weak argument). Larger arguments are in the space of tradeoffs. What could companies be doing with the engineering resources devoted to GDPR compliance (including compliance with the consumer-frustrating applications of the law, like the cookie…

I agree with you that the whole thing is inefficient. I think every GDPR advocate, much like me, will agree that it still needs to be improved and worked on. We're nowhere done.

Re: Cookie Warning Shenanigans Have Got to Stop

#87
internet visitors must be asked for permission in advance for any tracking software to be placed — such as third-party tracking cookies; tracking pixels; and browser fingerprinting tech — and that that permission must be freely obtained... Is this really what we want?

Yes. I'm not even European, and I'm perfectly fine with this.

Ask me to track me. If I like you, your web site, or your content, then sure. I'll give you a little personal data.

Re: Cookie Warning Shenanigans Have Got to Stop

#88
post #5

This is like a case study of well-intentioned, carefully designed regulation doing more harm than good. Honestly, I'd rather just have a browser addin that blocks the cookies I don't want. The market was working fine. Now every new website is a pain, and my organization has hired some amiable lady to be "GDPR expert". She doesn't appear to know anything about anything, but she sure seems nice.

GDPR absolutely does not do "more harm than good". It extends well, well beyond these dumb cookie warnings. GDPR puts the citizen/customer in power of their own data. They can ask for their data, they can ask for it to be deleted, they have (however shitty the UX) control over where it goes. They can contact large corporations and request these things and be heard out . I don't know how to explain it any other way: T…

> I don't know how to explain it any other way: These things are fucking important.

I think many people specially on HN understand the implications of using cookies and also understand the privacy concerns by 3rd parties taking their data. What I don't understand is why there are people who assume almost everyone has absolutely no idea or concern about any of these things and therefore advocate for pushing horrible and half-baked regulations like GDPR unto the dumb masses.

Re: Cookie Warning Shenanigans Have Got to Stop

#89

Earlier quoted context omitted.

The famous difference between citizen-first EU and corporation-first US. Over here, we do believe that our data is ours. This is reflected in our legislation and regulation. You don't want these rights and protections in the US? Well good news, you don't have them. They still apply to us however.

What you believe "over there" is wrong; data about you isn't yours. You can pass all the laws you like, that doesn't change the moral fact of the matter.

I hope one day you get to reflect on that sentence you just wrote.

Re: Cookie Warning Shenanigans Have Got to Stop

#90
post #9
post #5

This is like a case study of well-intentioned, carefully designed regulation doing more harm than good. Honestly, I'd rather just have a browser addin that blocks the cookies I don't want. The market was working fine. Now every new website is a pain, and my organization has hired some amiable lady to be "GDPR expert". She doesn't appear to know anything about anything, but she sure seems nice.

I wouldn't call GDPR "carefully designed" at all. It is ridiculously broad and vague, and so far all implementations (including the cookie warnings all over the internet) are best guesses.

Most of the cookie warnings are clearly against guidance which says that consent must not be a condition of service to be considered freely given, must be opt in not opt out and that even with consent the use of pii must be in the user's interests.

Almost no cookie warnings meet the law and many of the ones that do could use a different lawful basis and not show a dialog at all.

Post reply on HN