Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

101–110 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#101

FTA he's quoting: > And the Dutch DPA’s guidance makes it clear internet visitors must be asked for permission in advance for any tracking software to be placed — such as third-party tracking cookies; tracking pixels; and browser fingerprinting tech — and that that permission must be freely obtained. Ergo, a free choice must be offered. Neither cookies, nor tracking pixels, nor browser fingerprinting are software. Yo…

>> And the Dutch DPA’s guidance makes it clear internet visitors must be asked for permission in advance for any tracking software to be placed — such as third-party tracking cookies; tracking pixels; and browser fingerprinting tech — and that that permission must be freely obtained. Ergo, a free choice must be offered.

> Neither cookies, nor tracking pixels, nor browser fingerprinting are software. Your web browser is software. The server side runs software. These are data.

> It seems pedantic, but I think it shows that the lawmakers have an underlying misunderstanding of how tech (and the world) works.

No, that's just TechCruch's summary. This is the Dutch DPA's actual guidance: https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

It's in Dutch. I would not be surprised if "software" has a slightly different meaning or connotations than in English.

And even if it doesn't you don't need a precise command of technical jargon as a practitioner would use it to have a good understanding of an area. The meaning of TechCruch's translation was perfectly clear to me, and better than alternate formulations I can think of that avoid using "software" to refer to cookies. Maybe they should have just government-jargon and called them "tracking cybers."

Re: Cookie Warning Shenanigans Have Got to Stop

#102
post #16
post #13

Earlier quoted context omitted.

That's how the GDPR works - unless the data being collected is required for the operation of the service, you cannot make data collection a requirement of using the service.

What if the ads are required for the operation of the website, because without them the site has to close? People are rarely willing to pay for big sites, they surely won't pay for many small sites separately. Smaller sites don't have the resources to curate their own ads, that's why they use ad networks. If we are strict about this then this rule will eliminate small sites while tightening the grip of the big sites…

> What if the ads are required for the operation of the website, because without them the site has to close?

That's why you ask people. If enough people agree to paying for your content with their data, your site lives on.

If too many opt to not pay for your content with their data, your site dies unless it can find another way of making money, such as subscriptions.

Yes, it absolutely can mean that the giants will expand and lots of small sites that use ad networks will die.

Re: Cookie Warning Shenanigans Have Got to Stop

#103

It's time GDPR is actually enforced. I tried to get my country's law enforcement on the tail of some violators but they're toothless . I don't understand the downvotes though, are you disagreeing that certain countries do not have the manpower to enforce GDPR to the extent they could? Please.

I think they are currently going after the big ones. Personally, I expect that to change once they are through with them. It simply makes no sense to go after big companies when there is still google and facebook to go after. And well, medium and small? I think those still have another year or 2.

In addition to the practicality of choosing the big, obvious violators first, one or two actions against well-known targets should hopefully convince a lot of the secondary and tertiary potential enforcement targets that the EU is serious about enforcing these regulations. Some[1] companies might even decide that complying with the regulations be a better business plan than abusing their user's ignorance to undermine democracy[2].

[1] Unfortunately, experience suggests many will prefer bullheaded clinging to their surveillance capitalism business models to the bitter end.

[2] http://nymag.com/intelligencer/2019/02/shoshana-zuboff-q-and...

Re: Cookie Warning Shenanigans Have Got to Stop

#104
post #12

I feel like GDPR and such had some good spirit to it... but the result isn't what they had in mind and the consumers just click through everything / have no more clue. Piling on or malforming GDPR seems like it would just make the already unworkable situation more of a mess. I like the "ideas" behind GDPR, it's just this isn't the way to do it and really accomplish anything that really helps an individual.

It kind of feels like Prop 65 here in California. So many things have a 'this could cause cancer' tag that it is ignored 100% of the time, the exact opposite of its intent.

Re: Cookie Warning Shenanigans Have Got to Stop

#105

Its too bad nobody invented a browser header to be sent with HTTP requests for Allow-Cookies: SURE_YES_WHATEVER_OMG_STOP_ASKING_PLZ

It's too bad nobody came up with the simple idea of forcing browsers to ask permission before sending personally identifying information everywhere.

It's amazing what's personally identifiable though. Browser fingerprinting combined with ever present analytics scripts gets you most of the way there.

Re: Cookie Warning Shenanigans Have Got to Stop

#106

Its too bad nobody invented a browser header to be sent with HTTP requests for Allow-Cookies: SURE_YES_WHATEVER_OMG_STOP_ASKING_PLZ

It's too bad nobody came up with the simple idea of forcing browsers to ask permission before sending personally identifying information everywhere.

[deleted]

Re: Cookie Warning Shenanigans Have Got to Stop

#107
post #48
post #40

Earlier quoted context omitted.

Advertisement doesn't require profiling and surveillance. That is what GDPR and other efforts like some ad blockers are trying to protect against. The emerging consensus is surveillance capitalism is unethical and increasingly illegal.

> Advertisement doesn't require profiling and surveillance. Targeted ads pay much more. Eliminating targeted ads can result in a revenue drop of 50% or more, effectively killing small sites which most of the time make not much more money from ads than what is needed for financing themselves.

If a sites business model depends on using their users' data without their consent/knowledge then why would we want regulation to protect it from being eaten and their seat at the table taken by facebook?

Re: Cookie Warning Shenanigans Have Got to Stop

#109
It's not even clear to me how they actually work. Usually what I do when there's no "Deny" button (which is most of the time) is just leave the dialog open in hopes that that qualifies as "not accepting". But then some of them say "by continuing to use this site you agree". But, what does that even mean? Do they wait for a scroll event before setting the cookie, or is it there already before I even click "Agree", and the dialog does nothing whatsoever?

Re: Cookie Warning Shenanigans Have Got to Stop

#110

Its too bad nobody invented a browser header to be sent with HTTP requests for Allow-Cookies: SURE_YES_WHATEVER_OMG_STOP_ASKING_PLZ

Why would you want such a header?

Would be much nicer if the - already existing! - do not track header was interpreted to mean "Allow-Cookies: HELL_NO_WHY_ARE_YOU_EVEN_ASKING_FUCK_OFF".

Thanks to GDPR, the provider does NOT have to ask for consent for necessary cookies - only for the tracking stuff to which you have no incentive to agree. Every time a page pops up one of those "we value your privacy" screens, they're lying in your face - if they did, they wouldn't have to ask.

Post reply on HN