Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

171–180 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#171
post #145

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

So websites are supposed to just absorb the cost? That seems like a ridiculous stance.

>So websites are supposed to just absorb the cost? That seems like a ridiculous stance.

The €0.00002 it took to serve that one page just because the user doesn't want to consent to cookie placement/tracking? Is it really that harmful?

NPR seems to do this just fine for GDPR reasons: Decline and Visit Plain Text Site

Re: Cookie Warning Shenanigans Have Got to Stop

#172
post #119
post #111

Earlier quoted context omitted.

We could further optimize by just assuming that people are OK with it if they didn't send the header, and then have them opt in to sending it. Maybe we could call it something like "DoNotTrack", to get the idea across. DNT was mostly ignored, but if it had the weight of law behind it, it could still be great.

If I remember correctly, one of the reasons for it being ignored was that some browsers (rightly IMO) had the setting enabled by default. Some places still respect the header. Medium does - you'll get the warning for embedded content.

Because rationally, tracking should be opt in, not opt out. Arguing that customers desire, by default, is shockinging disconnected from reality.

Properties should be defaulted to what is most likely user desire, I think. So for DNT this would mean “true.”

It was ignored because companies that make money from tracking also make browsers and web sites.

Re: Cookie Warning Shenanigans Have Got to Stop

#173
post #164

Earlier quoted context omitted.

Well, saying it's ridiculous isn't an argument. it's expensive and maybe non-viable for many websites. But it's not like all websites need to exist? There was a world wide web before cookies.

>There was a world wide web before cookies. I like to think of that time as a great time too, but oh man so much we couldn't do.... I get what you're saying generally, but man I'd hate "before cookies" to be the standard.

[deleted]

Re: Cookie Warning Shenanigans Have Got to Stop

#174
post #48

Earlier quoted context omitted.

> Advertisement doesn't require profiling and surveillance. Targeted ads pay much more. Eliminating targeted ads can result in a revenue drop of 50% or more, effectively killing small sites which most of the time make not much more money from ads than what is needed for financing themselves.

If a sites business model depends on using their users' data without their consent/knowledge then why would we want regulation to protect it from being eaten and their seat at the table taken by facebook?

Because we need independent sites too, so we hear other opinions than just the agenda of big money.

It's not ideal that we need targeted ads for that, but currently there is no viable alternative and untargeted ads don't pay enough.

Re: Cookie Warning Shenanigans Have Got to Stop

#175

Can anyone explain to me why the browser isn't the one asking the user? Since, y'know, the browser is the only thing that actually prevents a cookie from being placed or sent in the first place?

The browser cannot distinguish between cookies that are necessary to support a feature you're using (e.g. a session cookie for a login or shopping cart) and a tracking cookie. The former does not require consent. The latter does.

That's a technical problem, which shouldn't prevent solving the main usability issue.

For example, the CAN-SPAM act requires the words "SEXUALLY EXPLICIT" to accompany messages with sexual/adult content. A tracking cookie's name can simply have the word "tracking" in it, which would trigger a browser to throw up a consent pop-up. A long, useless message from the site about why the user should click it could be provided to the user in a number of ways. The law doesn't even have to specify that

Re: Cookie Warning Shenanigans Have Got to Stop

#176
post #145

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

So websites are supposed to just absorb the cost? That seems like a ridiculous stance.

you can actually have an ad without tracking you know that right?

Re: Cookie Warning Shenanigans Have Got to Stop

#177

What people miss about the new GDPR notices, compared to cookie warnings of yore, is that they offer you the choice of opting out. In my experience, the option is usually hidden (look for “options”). But a surprising number of sites do actually comply and make this not prohibitively obscure.

Some of them make the process as slow and painful as possible (I've seen one where you need to deselect a huge number of pre-checked boxes, and then you need to wait through an excrutiatingly long and artificial 'applying preferences' process bar before you are permitted to continue. The website then forgets this preference the next time you visit it). This is directly against GDPR and I hope that companies engaging in these practices to try and make sure as few users as possible opt out get slapped as hard as they can by the regulators.

Re: Cookie Warning Shenanigans Have Got to Stop

#178

Earlier quoted context omitted.

It's too bad nobody came up with the simple idea of forcing browsers to ask permission before sending personally identifying information everywhere.

It's amazing what's personally identifiable though. Browser fingerprinting combined with ever present analytics scripts gets you most of the way there.

I need a plugin that spoofs my fingerprint as a 74-year-old shut-in with no money, terrible credit, and no social connections.

Basically someone companies have no interest in advertising to or tracking.

Re: Cookie Warning Shenanigans Have Got to Stop

#179
post #152

Earlier quoted context omitted.

You make a fair point, but the right to bear arms is mainly controversial for safety reasons. What safety issues are there with providing customers control (or at least visibility) over their data? It's also worth pointing out that the right to bear arms, by its origin, should probably be called the "right to revolt". While this is still a controversial issue for governments (governments don't want revolt), it's less…

There is a safety issue in that data previously only visible internally is now also exposed to the customer/user and any unauthorized person successfully pretending to be them. The problem of "account compromised" now becomes a bigger (potentially much bigger) problem of "account compromised and juicy data is exfiltrated under a GDPR data dump request (and maybe followed by a request for deletion right after maybe ma…

That seems like a huge reach. Most of the data that affects users can be one way or another acquired if you're logged in. Furthermore GDPR requests are often handled outside the account itself, except by companies that have the resources to automate them (and those companies usually have a lot of security resources).

I'll give you though that the addition of human processes in there present more security risks. I'm doubtful about the addition of safety risks though.

I dunno, this all seems like an extension of the risks we already have. More data, what of it? If an account with sensitive data is compromised, you're most likely fucked regardless of whether the hacker gets a hold of that data.

Re: Cookie Warning Shenanigans Have Got to Stop

#180
post #145

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

So websites are supposed to just absorb the cost? That seems like a ridiculous stance.

Websites are allowed to charge you. They are also allowed to show (non-tracking) ads, and they can also track you if you agree to it.

What is not allowed is to withdraw services to those that want to exercise their right to privacy.

Post reply on HN