Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

141–150 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#141

Earlier quoted context omitted.

> If you want to use external tracking and be GDPR-compliant, you must offer a clear choice ("yes/no") and you must not use pre-ticked boxes (i.e. an opt-out approach) Exactly this. Basically what the GDPR says is: if your business doesn't require the data, you cant use it without the user's consent. And data used for better advertising is NOT essential to e.g. a news site. What's more, the regulation syas that you c…

This is the view of a US person: These are private owned and operated web sites. The site owner determines what is "essential." If you do not agree to to the terms, do not use the site. If you don't want to be tracked for advertising, that's on you to install ad blockers.

We are all free to disagree with a law of course. It doesn't change it, however (and I like it).

Re: Cookie Warning Shenanigans Have Got to Stop

#142
post #96
post #36

Earlier quoted context omitted.

It's difficult for the average person to understand the long term implications of this sort of data collection. They don't realize how powerful all these little details can be when put together.

And there's another category of people that understand but don't care.

Not proud of it, but I fit somewhere in that bucket. I do consider it and I have made (slightly) inconventient choices in the name of privacy, but when it comes down to it, I typically say "screw it" because I want what I want.

Re: Cookie Warning Shenanigans Have Got to Stop

#143
This shows utter incompetence and detachment from reality by European legislators. Maybe it seemed like good idea in theory but the only practical significant impact is that browsing the web has become more annoying.

Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes?

Re: Cookie Warning Shenanigans Have Got to Stop

#144
post #91

Earlier quoted context omitted.

Anyone who didn't see this as the predictable end-result of requiring cookie awareness and consent was hopelessly naive about how large vs. small organizations respond to unfunded government mandates. The money and time could have been a lot better spent on international awareness campaigns arming consumers with more privacy knowledge instead of expecting website owners to shoulder the informational burden (because t…

These organizations do have such an incentive. The very essence of GDPR is to create these incentives. The EU's goal with GDPR was to make user data a liability , and to encourage organizations to reconsider their need to hoover and hoard it. The GDPR is unlikely to be overturned, and there are plenty in the EU who are eager to enforce it. Just because it's not being enforced right this second doesn't mean the law wo…

> there are plenty in the EU who are eager to enforce it

But we haven't yet seen it enforced, have we?

Re: Cookie Warning Shenanigans Have Got to Stop

#145

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

So websites are supposed to just absorb the cost? That seems like a ridiculous stance.

Re: Cookie Warning Shenanigans Have Got to Stop

#146
post #88

Earlier quoted context omitted.

GDPR absolutely does not do "more harm than good". It extends well, well beyond these dumb cookie warnings. GDPR puts the citizen/customer in power of their own data. They can ask for their data, they can ask for it to be deleted, they have (however shitty the UX) control over where it goes. They can contact large corporations and request these things and be heard out . I don't know how to explain it any other way: T…

> I don't know how to explain it any other way: These things are fucking important. I think many people specially on HN understand the implications of using cookies and also understand the privacy concerns by 3rd parties taking their data. What I don't understand is why there are people who assume almost everyone has absolutely no idea or concern about any of these things and therefore advocate for pushing horrible a…

GDPR is neither horrible nor half baked. The word you're looking for is flawed. I don't know why you expected it to be perfect from the get-go when it's such a complex subject in the first place.

What it is however is a major step up from before. It's an excellent start. You won't do any better by scrapping the whole thing and starting over. You can improve it.

Explain to me why you're better off without it.

Re: Cookie Warning Shenanigans Have Got to Stop

#147

To add insult to injury the big players with most trackers just refuse to show the cookie warnings at all. At least that's the situation Germany where most major news outlets are full of ads and trackers and handle all of it via opt-out(!) in the privacy policy. For a example see spiegel.de, the most widely read German-language news website. It's mostly small and medium sized firms that show the cookie warning out of…

Anyone who didn't see this as the predictable end-result of requiring cookie awareness and consent was hopelessly naive about how large vs. small organizations respond to unfunded government mandates. The money and time could have been a lot better spent on international awareness campaigns arming consumers with more privacy knowledge instead of expecting website owners to shoulder the informational burden (because t…

This is not the end-result at all. It is an intermediate result. European data protection agencies will start handing out fines, then courts will start ruling, and in a few years we will see the end-result.

My prediction is that these Cookie shenanigans will be ruled as illegal according to GDPR, and then they will disappear.

Re: Cookie Warning Shenanigans Have Got to Stop

#148

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

Could say Germany, decide differently?

GDPR seems like it could evolve quite quickly, and sort of fork a bit here...

Also makes me wonder, do they have to have access to the whole site?

This feels like a war on cookies, and there are bad things done with cookies, but I'm not sure if they're fighting on the right front long term here.

If people simply just say yes all the time / don't know, not sure we're making progress.

Re: Cookie Warning Shenanigans Have Got to Stop

#149
post #9

Earlier quoted context omitted.

I wouldn't call GDPR "carefully designed" at all. It is ridiculously broad and vague, and so far all implementations (including the cookie warnings all over the internet) are best guesses.

Most of the cookie warnings are clearly against guidance which says that consent must not be a condition of service to be considered freely given, must be opt in not opt out and that even with consent the use of pii must be in the user's interests. Almost no cookie warnings meet the law and many of the ones that do could use a different lawful basis and not show a dialog at all.

> consent must not be a condition of service

So what do you do if your website literally cannot function without cookies?

Re: Cookie Warning Shenanigans Have Got to Stop

#150
post #109

It's not even clear to me how they actually work. Usually what I do when there's no "Deny" button (which is most of the time) is just leave the dialog open in hopes that that qualifies as "not accepting". But then some of them say "by continuing to use this site you agree". But, what does that even mean? Do they wait for a scroll event before setting the cookie, or is it there already before I even click "Agree", and…

Spin up developer tools and see if the cookie has been set
Post reply on HN