Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

91–100 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#91

To add insult to injury the big players with most trackers just refuse to show the cookie warnings at all. At least that's the situation Germany where most major news outlets are full of ads and trackers and handle all of it via opt-out(!) in the privacy policy. For a example see spiegel.de, the most widely read German-language news website. It's mostly small and medium sized firms that show the cookie warning out of…

Anyone who didn't see this as the predictable end-result of requiring cookie awareness and consent was hopelessly naive about how large vs. small organizations respond to unfunded government mandates. The money and time could have been a lot better spent on international awareness campaigns arming consumers with more privacy knowledge instead of expecting website owners to shoulder the informational burden (because t…

These organizations do have such an incentive. The very essence of GDPR is to create these incentives. The EU's goal with GDPR was to make user data a liability, and to encourage organizations to reconsider their need to hoover and hoard it.

The GDPR is unlikely to be overturned, and there are plenty in the EU who are eager to enforce it. Just because it's not being enforced right this second doesn't mean the law won't catch up to offenders.

Especially if Margrethe Vestager replaces Jean-Claude Juncker as president of the European Commission, you can expect a ton of action on this front.

Re: Cookie Warning Shenanigans Have Got to Stop

#92

The omnipresent "Please accept our privacy policy (or leave)" is worthless cargo cult GDPR pseudo-compliance. If it's neither freely given nor informed, it's not consent under GDPR. See Art. 7: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of persona…

> If you want to use external tracking and be GDPR-compliant, you must offer a clear choice ("yes/no") and you must not use pre-ticked boxes (i.e. an opt-out approach)

Exactly this. Basically what the GDPR says is: if your business doesn't require the data, you cant use it without the user's consent. And data used for better advertising is NOT essential to e.g. a news site.

What's more, the regulation syas that you can NOT simply say "accept or leave" in that case. You then have to provide the service to the user without storing that non essential data. You can't provide a service, even for free, that you condition on storing data not essential for that service. There is no "if you don't like it, leave" clause.

Basically: spiegel.de has to be prepared to show their news to anyone, including those that do not wish to be tracked by their ads. Right now we are in a period of denial where site owners believe they can have these "By entering you agree to..." banners. Once the first large fines are handed out, It'll be fun to watch.

Re: Cookie Warning Shenanigans Have Got to Stop

#93

Its too bad nobody invented a browser header to be sent with HTTP requests for Allow-Cookies: SURE_YES_WHATEVER_OMG_STOP_ASKING_PLZ

It's too bad nobody came up with the simple idea of forcing browsers to ask permission before sending personally identifying information everywhere.

Re: Cookie Warning Shenanigans Have Got to Stop

#94
post #5

This is like a case study of well-intentioned, carefully designed regulation doing more harm than good. Honestly, I'd rather just have a browser addin that blocks the cookies I don't want. The market was working fine. Now every new website is a pain, and my organization has hired some amiable lady to be "GDPR expert". She doesn't appear to know anything about anything, but she sure seems nice.

   The market was working fine.
At the very least, this is up for debate.

Re: Cookie Warning Shenanigans Have Got to Stop

#95
post #5

This is like a case study of well-intentioned, carefully designed regulation doing more harm than good. Honestly, I'd rather just have a browser addin that blocks the cookies I don't want. The market was working fine. Now every new website is a pain, and my organization has hired some amiable lady to be "GDPR expert". She doesn't appear to know anything about anything, but she sure seems nice.

GDPR absolutely does not do "more harm than good". It extends well, well beyond these dumb cookie warnings. GDPR puts the citizen/customer in power of their own data. They can ask for their data, they can ask for it to be deleted, they have (however shitty the UX) control over where it goes. They can contact large corporations and request these things and be heard out . I don't know how to explain it any other way: T…

People believe the GDPR is about cookie warnings. That's the problem. The GDPR is great and the annoying cookie warnings is about 1% of GDPR.

You can't say "I liked it better before GDPR because cookie warnings".

Re: Cookie Warning Shenanigans Have Got to Stop

#96
post #36

Earlier quoted context omitted.

... and users appear to disagree on whether there's a wound to seal.

It's difficult for the average person to understand the long term implications of this sort of data collection. They don't realize how powerful all these little details can be when put together.

And there's another category of people that understand but don't care.

Re: Cookie Warning Shenanigans Have Got to Stop

#98

What I don't understand is why websites hosted outside the EU, for non-EU users have the cookie banners. At least keep it in Europe, use the IP to geolocate, let the EU users deal it. Some companies have outright banned EU traffic, sounds like only showing the banners for EU IPs seems ok.

The law doesn't just apply to pages being served to the EU, it applies to pages being served to EU citizens, wherever they happen to be at the moment. So geolocation is not a satisfactory option.

The EU are a bunch of unelected parasites. Perpetuating the delusion that they have any power by obeying their imaginary laws is cowardly and immoral.

Re: Cookie Warning Shenanigans Have Got to Stop

#99

To add insult to injury the big players with most trackers just refuse to show the cookie warnings at all. At least that's the situation Germany where most major news outlets are full of ads and trackers and handle all of it via opt-out(!) in the privacy policy. For a example see spiegel.de, the most widely read German-language news website. It's mostly small and medium sized firms that show the cookie warning out of…

>players with most trackers just refuse to show the cookie warnings at all

The results of the legislation -in regard to cookies- are inconsistent, annoying, unevenly enforced, create a moral hazard and two-tier system, and I presume have negative overall utility.

This is why I do not consider the law to have been written with good intentions. The intentions were claimed to be good, but I don't see the lawmakers having had put in the necessary effort to ensure privacy improvement. Nor admit there are shortcomings to the legislation that need either fixing, or perhaps scrapping the legislation. Did they really intent on exerting enough effort to write the legislation well? To shoulder blame if it does not work out? To take the responsibility? Or to shore it up as situation develops?

Right now I perceive the cookie warnings to be merely EU's advertising banners - "Heeey, this is EU taking care of you!" - plastered all around the web just like banner ads used to be plastered all over the web. Morally the same - pompous self promotion, except paid for with legal rubberstamp rather than money.

Re: Cookie Warning Shenanigans Have Got to Stop

#100

The omnipresent "Please accept our privacy policy (or leave)" is worthless cargo cult GDPR pseudo-compliance. If it's neither freely given nor informed, it's not consent under GDPR. See Art. 7: "When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of persona…

> If you want to use external tracking and be GDPR-compliant, you must offer a clear choice ("yes/no") and you must not use pre-ticked boxes (i.e. an opt-out approach).

You can use absolutely no external tracking and be GDPR-noncompliant. In fact, an Apache web server running the default test page is technically noncompliant. Everyone loves to jump to the tracking ads and data selling, since they are easy targets, but the scope of the law is much broader than that.

Post reply on HN