Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

491–500 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#491

The problem isn't dumb ol' grandpa EU's folly lawmaking. The lawmaking is on point and the cookie banners are the problem - not the symptom. EU regulations are trying to eliminate privacy-invasive practices like tracking. It's not about making users aware that they're being tracked. It's about making businesses cut that shit out. Of course, on HN I have to acknowledge that half of the users on this website get their…

It doesn't matter what they're trying to do. What matters is what actually ends up happening. The socialists in the Soviet Union tried to improve things as well. It's also quite ironic that the EU now cares about privacy considering that a decade ago they passed the Data Retention Directive. I guess privacy didn't matter then, huh?

"It's also quite ironic that the EU now cares about privacy considering that a decade ago they passed the Data Retention Directive. I guess privacy didn't matter then, huh?"

This is a very astute observation, and is causing some angst among parts of the European population.

However, this seemingly conflicting behavior has a cultural rationale behind it.

In general, Europeans see government as trying to look out for their best interest, while they view corporate power with large skepticism. "Americans" hold the complete opposite view.

So when the governments in the EU tout sheepish clichés like "think about the children, catch terrorists, pedophiles" etc, by being able to retain data for those purposes, the public falls flat and lets Orwellian laws pass without much fuss. Because ... "the government is our ally, and we trust it, the claims, and that the data will be managed responsibly".

However, when corporations do the same, there's more fuss.

The one european people that is of sane mind here is those of germany, due to their history. Unfortunately germans are also deceived by their government through back-room deals on EU level, and with the national security excuse, when it can be kept out of the public eye; effect same as the other EU nations. The good thing however is that the german people are not as gullible as other parts of europe when it comes to surveilance and tracking, and they do tend to kick up a big fuss when this sh*t goes down. So they act as a sort of moral calibration for the other nations, such as mine.

Understanding this fundamentally different mindsets between US and European citizen will hopefully help explain quite a lot, for those who didn't already know this. This is why "american" views are insane to some europeans, and why EU is naive/retarded in the eyes of the US. (very generalized)

Re: Cookie Warning Shenanigans Have Got to Stop

#492
post #58

Earlier quoted context omitted.

I am befuddled by your befuddlement. Consumer protection laws regularly put limits on the freedom of contracts between companies and consumers. A rental car agency can’t give you a rebate for renting an unsafe car. The fact that no money changes hands doesn’t change this. If you’re offering free taster portions of bread to passer-bys, you can not use lead as an ingredient. Neither being free, nor putting up a sign wi…

Agreed, but these rules are clearly defined, make sense to the common man and actually lead to what they should lead to, namely that I can, with great confidence, eat anywhere without being poisoned. GDPR is terribly vague and creates a barrier-to-entry. Draconian measures may hurt large companies, but they threaten smaller ones. EU is saying they don't like Silicon Valley behemoths' power but they want valley-like c…

I take it you have not read the regulation.

If you had you would know that the regulation isn't there to nail companies from other regions. Anyone doing business with Europeans is subject to the same rules of the game, and that naturally also includes European businesses.

Re: Cookie Warning Shenanigans Have Got to Stop

#493

Standardize it. Policy makers should provide a standard message, or small set of messages websites can reuse and consumers recognize with links to an EU-run informational website easy to understand for consumers. I don't understand why it wasn't implemented this way, maybe to allow for more freedom of implementation, but we have seen that has hurt the policy effort. Just standardize it. Incidentally, with all of the…

There's not a standard copy-paste-ready set of phrases because it would be impossible for the law makers to craft such.

They couldn't possibly know what site A or B respectively does with a user's data. That differs from site to site.

It is therefore of course the obligation of each site that directly or indirectly works with user PII to explain to its users how that specific site is using the data.

Re: Cookie Warning Shenanigans Have Got to Stop

#494

So I have a question regarding GDPR. I've recently done two projects for intergovernmental organizations (like the UN, to give you an example). Both organizations claim that they do not have to comply with GDPR. I kindof doubt that but IANAL. Short of reading the GDPR laws, or contacting an expensive lawyer, what's the best way to find out if they are right? I'd like to find out before I start the next project for su…

Read the document: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...

That's the cheapest. It's not really that hard to understand. I'm not a lawyer, read it and had a GDPR consulting firm review the tweaks we made of our systems. They were happy with it.

But if you're working for a larger company, then consult with their legal department or have the company hire a GDPR consulting firm. They should be able to afford it without a problem, and will likely be happy to support such an action if the non-compliance risk is deemed large enough. A business decision, not a technical one.

Re: Cookie Warning Shenanigans Have Got to Stop

#495
post #487

Earlier quoted context omitted.

I fully agree. But still it makes a difference from a moral analysis point of view, because my aim is to condemn the buyer, and don't judge the seller. So now you have to convince me that buying the right to beat someone to death is a morally justifiable action. It is not sufficient for you to judge selling as justifiable to make your point. I actually agree that selling is morally justifiable, and would never vote t…

Like I mentioned in another branch of this thread, if selling is allowed, then it would be immoral to not allow buying; punishing someone for buying something that's legal to sell would be entrapment. In fact, doing so might even pass that immorality down to the grandfather seeking compensation for his suicide; if he's aware of the illegality of buying his life, and yet exercises his right to sell it anyway, then at…

Let me try to repeat your argument: whenever something is morally allowed for an individual, the moral system must ensure that the individual actually can do it.

This does not stand on its own, you need to provide a good argument why a moral system should be designed such that everything which is allowed can also actually be done. In particular, because our current system is not designed that way.

And even if you find such an argument, we end up with a moral dilemma, as long as you can't argue that buying is morally good in itself.

Re: Cookie Warning Shenanigans Have Got to Stop

#496
post #192

Earlier quoted context omitted.

Websites are allowed to charge you. They are also allowed to show (non-tracking) ads, and they can also track you if you agree to it. What is not allowed is to withdraw services to those that want to exercise their right to privacy.

Thanks, this helps clear up some of my understanding. I still think its ridiculous that websites can't refuse to serve who they want.

They can refuse to serve you, however, they can't then turn around and claim that those who clicked "I consent" actually did freely opt-in to tracking because they genuinely wanted to be tracked - because, obviously, they most likely did not.

In essence, GDPR states that you're not allowed to violate the privacy of people unless they really want to (freely given, informed, narrow/specific opt-in consent) - and this time, all the oft-used loopholes to "extract consent" don't really fulfil the criteria, as forced consent is not considered consent.

Re: Cookie Warning Shenanigans Have Got to Stop

#497

Earlier quoted context omitted.

> If it's my website, I should be able to decide to decide whether to track your users? through third parties? for advertising purposes? Why? Why do you get to decide and not the users? I'd rather you didn't! It really honestly does surprise me the amount of crap Americans are willing to swallow when it comes to advertising methods, or even just profit in general. Your whole society is rife with abuse. There's robo-c…

I'm a big fan of a lot of pro-consumer regulation in EU. For example the right to block junk mailers in Germany with a simple notice on your mailbox is amazing. However I think websites should be able to block access to anyone they want. It doesn't seem fair to force websites to serve an audience if they do not wish to.

They can block access to anyone they want.

However, if they say "press here to forego your privacy or we'll block you", then that's not a freely given consent to forego your privacy, and in this case this "consent" doesn't count as consent. In this case they're not allowed to track people who "consented" because they didn't really consent (both in moral and in legal sense). Consent "counts" only if it's freely given, if people really want you to do that thing; in EU privacy rights are not something that can be sold or bartered away.

It's somewhat comparable to consent to sex - let's imagine that in a place where you can freely fire workers at will, you say "consent to have sex with me, or I'll fire you". You technically can fire them, but that "consent" isn't really consent, and even if they "agree", that's still nonconsensual. Privacy (in EU) is pretty much the same.

Re: Cookie Warning Shenanigans Have Got to Stop

#498
post #354

Earlier quoted context omitted.

There is also this in article Article 7.4 ( https://gdpr-info.eu/art-7-gdpr/ ) > 4 It shall be as easy to withdraw as to give consent. If you prompt me to accept on every page then you must also prompt me to decline on every page, otherwise you fail this test. Hiding the option to withdraw consent in some random settings page is obviously not as easy as clicking yes when prompted. Most sites have already created all…

So you want more pop ups? Because I'm sure they're willing to oblige.

Well, no, if they're required to harass the "consenters" equally to the "nonconsenters", then that (a) removes the motivation for users to fake consent just to get away from the harassment; and (b) motivates the site developer to choose an amount of popups that's actually appropriate for the UX they want, since that'll affect all users all the time.

If a site doesn't wants to cover itself all the time with a popup regarding cookies, then they're not allowed to cover itself all the time for users who never consent to tracking.

Re: Cookie Warning Shenanigans Have Got to Stop

#499
post #495

Earlier quoted context omitted.

Like I mentioned in another branch of this thread, if selling is allowed, then it would be immoral to not allow buying; punishing someone for buying something that's legal to sell would be entrapment. In fact, doing so might even pass that immorality down to the grandfather seeking compensation for his suicide; if he's aware of the illegality of buying his life, and yet exercises his right to sell it anyway, then at…

Let me try to repeat your argument: whenever something is morally allowed for an individual, the moral system must ensure that the individual actually can do it. This does not stand on its own, you need to provide a good argument why a moral system should be designed such that everything which is allowed can also actually be done. In particular, because our current system is not designed that way. And even if you fin…

"whenever something is morally allowed for an individual, the moral system must ensure that the individual actually can do it"

More like "whenever one of an inherently-coupled pair of actions is morally allowed, the other of those actions is morally allowed". A moral system which allows one and not the other is self-contradictory.

In this case, a moral system which permits the right to sell a life but denies the right to buy a life self-contradicts; unless you believe that it's moral to trick someone into committing an immoral act (I do not), any attempt to exercise the right to sell one's own life would be inherently immoral because of the impossibility of doing so without causing someone else to perform an immoral act. The only way for the sale of one's own life to be moral is for the corresponding purchase to also be moral.

"we end up with a moral dilemma"

Only if you insist that buying is wrong while also insisting that selling is not wrong. When both are right or both are wrong, then there is no such self-contradiction.

Re: Cookie Warning Shenanigans Have Got to Stop

#500
post #48
post #40

Earlier quoted context omitted.

Advertisement doesn't require profiling and surveillance. That is what GDPR and other efforts like some ad blockers are trying to protect against. The emerging consensus is surveillance capitalism is unethical and increasingly illegal.

> Advertisement doesn't require profiling and surveillance. Targeted ads pay much more. Eliminating targeted ads can result in a revenue drop of 50% or more, effectively killing small sites which most of the time make not much more money from ads than what is needed for financing themselves.

Again, earning increased revenue doesn't justify supporting unethical and/or illegal behavior from the advertising networks.
Post reply on HN