Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

221–230 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#221
post #218
post #154

Earlier quoted context omitted.

No, they're supposed to serve generic, non-tracking ads. Non-targeted, or whatever the terminology is. It's hilarious how everyone has just forgotten that used to be a thing. The people on this website are literally the problem, you can't even conceive of a website that doesn't track every click you make across the whole internet, and you guys are the people building the new web.

It’s not possible to do a lot of normal web stuff without session cookies.

The concepts of a session cookie is different then a cookie used for advertisemnet that tracks you across the internet. The problem is tracking and ads, not authentication and authorization for functional purposes. Cookies are just one way to track people and serve ads, there are many others.

Facebook is a great example on keeping diluting these concepts. They ask for your information for function security purposes and then go back and use that same data for ads - that is unethical and has to stop.

Re: Cookie Warning Shenanigans Have Got to Stop

#222
I am not a fan of the cookie banners at all. If anything I feel like browsers should implement it as it already does with other security settings (access to location, camera, etc…) and then people can decide to allow all websites. Blacklist, whitelist whatever. Why are we making every site implement a completely unique interface with different verbiage?

Re: Cookie Warning Shenanigans Have Got to Stop

#223
post #154
post #145

Earlier quoted context omitted.

So websites are supposed to just absorb the cost? That seems like a ridiculous stance.

No, they're supposed to serve generic, non-tracking ads. Non-targeted, or whatever the terminology is. It's hilarious how everyone has just forgotten that used to be a thing. The people on this website are literally the problem, you can't even conceive of a website that doesn't track every click you make across the whole internet, and you guys are the people building the new web.

"It's hilarious how everyone has just forgotten that used to be a thing"

Ads were always a thing, they're just going to be better targeted with more info.

There is no free lunch, so what this means is the 'no cookie' users may be exposed to more ads.

I understand the market dynamics are not working very well, but we have to remember that information provided is not free either.

Re: Cookie Warning Shenanigans Have Got to Stop

#224

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

> Clicking 'no' should still allow people to view the website, but without placing any tracking cookies.

No! It doesn't. Viewing a website isn't anyone's god-given right. The tracking cookies are part of the business model. If you don't agree with how a business makes money, stop patronizing them.

If this is serious, look for companies to just block all traffic from The Netherlands. Why even bother dealing with the hassle.

Re: Cookie Warning Shenanigans Have Got to Stop

#225
post #218
post #154

Earlier quoted context omitted.

No, they're supposed to serve generic, non-tracking ads. Non-targeted, or whatever the terminology is. It's hilarious how everyone has just forgotten that used to be a thing. The people on this website are literally the problem, you can't even conceive of a website that doesn't track every click you make across the whole internet, and you guys are the people building the new web.

It’s not possible to do a lot of normal web stuff without session cookies.

Define "a lot of normal web stuff". How did we ever do normal web stuff before session cookies?

Re: Cookie Warning Shenanigans Have Got to Stop

#226

Earlier quoted context omitted.

The law doesn't just apply to pages being served to the EU, it applies to pages being served to EU citizens, wherever they happen to be at the moment. So geolocation is not a satisfactory option.

EU residents, actually, and yes, geolocation is satisfactory -- you can hit EU residents as long as you're not intending to hit them, and are doing nothing in contradiction to that intention (like translating your content into Polish, for example).

> like translating your content into Polish, for example

There are Polish speakers that aren't Polish citizens. Translating to Polish doesn't prove an intent to sell to Poland any more than having a page in English implies trying to sell to England.

There is nothing in the law that says that translating into Polish or another language common in the EU results in GDPR being applied. The actual law says,

"This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

the monitoring of their behaviour as far as their behaviour takes place within the Union."

That's it. "Offering goods or services" can be interpreted in a variety of ways, but translating into a language doesn't mean anything. People speak German in communities all over the world. Even offering payment in Euros isn't necessarily targeting the EU. Plenty of EU expats have Euro accounts, particularly those based in Africa and Asia. So it's perfectly normal to have a German language site, selling products in Euros, targeting Germans in Shanghai and have that not be in GDPR scope. However, an English language site, selling in US dollars showing Berlin apartment listings targeting American expats in Germany -- that would be in GDPR Scope. The language and currency have nothing to do with it. It's the intended audience that matters and that can be often determined by the product/content being sold/delivered.

The point of my rant is that too many people are reducing GDPR into some ridiculously simplistic terms such as "can't use euros, can't use an EU language" or similar. However, the actual reality isn't so sophomoric.

Re: Cookie Warning Shenanigans Have Got to Stop

#227

Earlier quoted context omitted.

How do you remember that a customer has responded to a popup if you don't give them a cookie? Even a cookie as a session identifier.

"Cookies" are mentioned only once in GDPR, in a long list of examples. They're not targeted specifically. The law talks about information that can be used to identify a person . So a cookie such as "gdpr_response=ok" has ZERO effect on GDPR compliance.

> So a cookie such as "gdpr_response=ok" has ZERO effect on GDPR compliance.

I wouldn't be so certain about that. Before now, most people were pretty certain that an accept/decline warning was enough and that they had the right to refuse service to people who did not click OK on the warning.

Re: Cookie Warning Shenanigans Have Got to Stop

#228

This shows utter incompetence and detachment from reality by European legislators. Maybe it seemed like good idea in theory but the only practical significant impact is that browsing the web has become more annoying. Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes?

How do you remember that a customer has responded to a popup if you don't give them a cookie? Even a cookie as a session identifier.

There should be a header that browsers can send to indicate wether the user does or does not consent to tracking.

Re: Cookie Warning Shenanigans Have Got to Stop

#229

This shows utter incompetence and detachment from reality by European legislators. Maybe it seemed like good idea in theory but the only practical significant impact is that browsing the web has become more annoying. Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes?

How do you remember that a customer has responded to a popup if you don't give them a cookie? Even a cookie as a session identifier.

That's a bit of a chicken/egg thing, but it shouldn't matter if there's no pop-up in the first place right?

I should mention that I essentially browse this way due to a few privacy add-ons I use and it is absolutely infuriating having to deal with these pop-ups even on sites that I've already visited.

Re: Cookie Warning Shenanigans Have Got to Stop

#230

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

Hmm, there are features that one literally can't provide without state (cookies). I think the real problem here is that the technical feature of cookies providing browser state is a poor proxy for what EU/DPA _really_ wants to regulate, which is privacy-related tracking. There are tons of sites I've written which use cookies, but have no ads and perform no user-tracking whatsoever, not even Google Analytics. It is tr…

What features? Is local data storage a possible substitute?
Post reply on HN