Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

311–320 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#311
post #235

Earlier quoted context omitted.

Most discussion about the EU cookie directive doesn't mention it, but not all cookies require consent. From https://privacypolicies.com/blog/eu-cookie-law/#some-cookies... : "This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information socie…

" in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service." If I need to get explicit opt-in for "So, remembering your shopping cart when you come back requires cookies, that okay with you?" I'm not sure how much better that would be. It's still gonna be information overload "false positives". But I think that is what the regulations actually i…

I'm fairly sure I agree with out that the law wouldn't achieve its purpose even if it was implemented "correctly", and it certainly doesn't achieve its purpose with how it's implemented by websites today. I considered adding a short sentence about that, but ended up not doing it. I'm just tired of the vast amount of misinformation out there, and people discussing as if the directive applies to all cookies and only to cookies.

I'm not entirely sure if a user account at an online store would require consent; in my view, cookies would be "strictly necessary" to provide the user experience a user expects which includes being able to create an account to save their shopping cart and view their order history, while using cookies to show tailored product suggestions wouldn't be. However, IANAL and I haven't even read through the text of the directive.

In any case, the vast majority of the times I see the cookie notice are times where there are exactly zero reason to use cookies (or other methods of persistent storage) other than tracking, such as blog posts and news articles. Every single one of those websites would be able to get rid of their annoying pop-ups if they just spied on their users a bit less.

Re: Cookie Warning Shenanigans Have Got to Stop

#312
Most cookie warnings are beyond useless, in that they don't even try to actually comply with the GDPR.

The fact that your site uses cookies is irrelevant, and there's no need to tell anyone. However! If your site stores personal information (directly or via a partner), you need to have a valid reason.

The definitions of "personal information" and "valid reason" are, fortunately, not exhaustively enumerated in the GDRP. I say fortunately, because if they were exhaustively enumerated, Facebook would find a loophole, and the whole law would be worthless.

One of the 'valid reasons' for storing personal information, is a clear, freely given, consent from the user. This is the one that all the tracking companies want to get, because they think it allows them to do shady things if they can trick the user into pressing 'OK'. But if the user was tricked or coerced, the consent was not really clear or freely given. Hence the sort of court rulings that the article mentions.

So, if you store a cookie for your domain saying 'tracking_consent=false', this is probably not personally identifiable, so you can just do it. No reason for any banner.

But if you track the 'browser fingerprint' that Troy Hunt is talking about, without consent, you are probably in violation of the GDPR. Even if it's not a cookie. And you had a cookie banner.

Re: Cookie Warning Shenanigans Have Got to Stop

#313
post #147

Earlier quoted context omitted.

This is not the end-result at all. It is an intermediate result. European data protection agencies will start handing out fines, then courts will start ruling, and in a few years we will see the end-result. My prediction is that these Cookie shenanigans will be ruled as illegal according to GDPR, and then they will disappear.

I’ve been hearing this since 1997 when the first Data Protection directive happened. The enforcement never happens unless it’s serving a political goal, such as singling out a Chinese company or whatever.

GDPR is the result of many lessons learned in prior attempts. The EU Commission put particular attention on not repeating the mistakes being made in the Cookies directive, which rendered it essentially useless and only annoying.

Fines are to be handed out by the national data protection agencies. In Germany, the data protection agency regularly goes after violators since the 1990s. They audit German administrations and companies with respect to data protection, and request changes where necessary. See here for yearly reports of one of the state agencies: https://lfd.niedersachsen.de/startseite/allgemein/taetigkeit....

So at least for Germany there is no foundation for your claim.

Re: Cookie Warning Shenanigans Have Got to Stop

#314

Earlier quoted context omitted.

The WWW before cookies was pretty limited, and didn't last long. I mean, the first web browser was released in 1990, and cookies were introduced in 1995. We didn't have e-commerce before cookies.

There was e-commerce before cookies. The same functionality of correlating multiple requests for a single request (building sessions upon packets) was just more difficult to use by encoding the session ID as a parameter in query string for each request. Many frameworks still support this mode.

Cookies pre-date SSL, so how were they securing that e-commerce that existed before cookies?

Re: Cookie Warning Shenanigans Have Got to Stop

#315
post #218
post #154

Earlier quoted context omitted.

No, they're supposed to serve generic, non-tracking ads. Non-targeted, or whatever the terminology is. It's hilarious how everyone has just forgotten that used to be a thing. The people on this website are literally the problem, you can't even conceive of a website that doesn't track every click you make across the whole internet, and you guys are the people building the new web.

It’s not possible to do a lot of normal web stuff without session cookies.

Cookies are allowed, tracking users without consent is now illegal in EU (regardless which technology is used).

Re: Cookie Warning Shenanigans Have Got to Stop

#316

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

I haven't read the full decision but I'm always surprised at how little regard European courts have for property rights. If it's my website, I should be able to decide who has access and under what terms. Don't like cookies? No one is forcing you to visit a particular website. I also feel like tech companies could adopt an open standard for cookie acceptance preferencesin web browsers, but they're afraid to lest they…

> If it's my website, I should be able to decide

to decide whether to track your users? through third parties? for advertising purposes?

Why? Why do you get to decide and not the users? I'd rather you didn't!

It really honestly does surprise me the amount of crap Americans are willing to swallow when it comes to advertising methods, or even just profit in general. Your whole society is rife with abuse. There's robo-calling, giant billboards, attack ads, pharma ads, ads or contests that are literally scams, just a few from the top of my head. Probably more I don't know about (ads to target children? there is NO good way to argue that children "should" be targeted by ads).

It's a small miracle you managed to push a mandatory "unsubscribe" link underneath mass email lists. I suppose it's mandatory because given the attitude to this kind of abuse I doubt they would put them there voluntarily.

Also, you've seen what happened to the online ad industry without this kind of regulation. If you don't make rules they're going to push it as far as they can. It's gotten to the point where people recommend adblockers for security not getting rid of annoyance. Or for saving about 95% of your mobile data plan surfing sites. Did you ever notice the most profitable ads pay for the shittiest content? The system isn't even working.

Re: Cookie Warning Shenanigans Have Got to Stop

#317

This shows utter incompetence and detachment from reality by European legislators. Maybe it seemed like good idea in theory but the only practical significant impact is that browsing the web has become more annoying. Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes?

The EU has generally been a really positive force when it comes to consumer rights, but I'm not a fan of this either. The question I have is, what did web company do to deserve this kind of regulation? It is quite unusual to see governments enact regulations, without the existence of a measurable harm being caused - but solely on the premise, that the act of collecting data is 'unethical'. I mean this is really not normal, and quite unfair, if you look how regulations worked in the past for other industries, it has always been a response to very clear quantifiable harm being caused.

We have seen nothing of that, contrary, tech companies have improved our life's immensely, for free, and in my opinion, are the one of the biggest driving force towards improving the future. Data is not just being collected for advertisement, tracking, and evil purposes, but is a very important asset in the development of products.

Furthermore, historically it was governments, not companies, that were abusing private data for nefarious purposes. Yet there seems to be no effort to stop it happening from that direction? Well of course not, its way to useful, and you'd be a fool not to use it, but companies are 'bad' trying utilize it...

Re: Cookie Warning Shenanigans Have Got to Stop

#318

Earlier quoted context omitted.

"Hmm, there are features that one literally can't provide without state (cookies)." Silent cookies aren't completely banned by the GDPR/cookie laws, only cookies that aren't necessary to provide the service requested by the user. That's sort of vague, but I think mostly obvious what is intended there. It's pretty easy to operate within the spirit and letter of the law: Shopping baskets, load balancer cookies and logi…

Meanwhile, even though the _only_ user-tracking we do where I work is Google Analytics (no advertising features) (and you say your lawyers say you don't need consent for that) -- the official word on high where I work is all our websites need the stupid "i consent to cookies" banner if we use cookies. So, yeah, it's a mess. These "extra" warnings are contributing to user fatigue, I agree with troy hunt that users are…

[deleted]

Re: Cookie Warning Shenanigans Have Got to Stop

#319

To add insult to injury the big players with most trackers just refuse to show the cookie warnings at all. At least that's the situation Germany where most major news outlets are full of ads and trackers and handle all of it via opt-out(!) in the privacy policy. For a example see spiegel.de, the most widely read German-language news website. It's mostly small and medium sized firms that show the cookie warning out of…

Can somebody explain how Der Spiegal does this legally? If they can do it, maybe others can use the same justification.

Re: Cookie Warning Shenanigans Have Got to Stop

#320
post #296

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

We are now in the middle game of GDPR. Companies whose business model depends on tracking users essentially have now an illegal business model, because practically no user will give informed consent when they are offered the same service without consenting. So what can these - now shady - companies do? They probe the limits of the law, and try to keep their business model alive as long as they can. We need to wait an…

Oh, I so hope you're right!
Post reply on HN