Live data from Hacker News

Slack stores browser cookies without user consent

twitter.com

11–20 of 118 posts

Re: Slack stores browser cookies without user consent

#11
post #8
post #5

1. Block 3rd party cookies (useless on 99.99% of the sites) 2. Install uBlock Origin ( https://www.ublockorigin.com )

Don't forget step 0: 0. Don't illegally put nonessential cookies in the browser without the user's consent.

I think it's impossible to enforce this worldwide, and any website can be based in any jurisdiction. The consent popups are also super annoying. It's also hard to define what "essential" means.

I'm personally much more in favor of the technological solution: I block all cookies and only explicitly enable them on websites that I need to log in to.

Re: Slack stores browser cookies without user consent

#12
If they're for technical purposes, not tracking purposes you don't need permission under GDPR at least. I'm going to assume they know what they're doing, at least until I see evidence to the contrary. Benefit of the doubt, innocent until proven guilty, and all that.

Re: Slack stores browser cookies without user consent

#13
post #9
post #3

Earlier quoted context omitted.

Care to elaborate on that? I rather like it. As a developer it's a pain, but as a citizen I find it to be a step in the right direction.

I think there's some merit to "this site uses cookies to track you as you visit different sites". There's none whatsoever to "this site uses cookies to remember your login information". The law seems to make no distinction. As a user, I view every cookie notice as pointless and annoying -- obviously you use cookies, and obviously I'm okay with it. If the notice were specifically about cross-site tracking, that would…

Those notices also often say "This site uses cookies to make your experience better", so yes, in this sense it's useless. But that's not all the law is doing. Many websites from US simply stopped serving anything for European IP addresses, responding just with error 451, which I always take as a sign that this site wants to sell my data more than they want to show me ads, so I'm glad I didn't accidentally visit it.

Re: Slack stores browser cookies without user consent

#14
post #11
post #8

Earlier quoted context omitted.

Don't forget step 0: 0. Don't illegally put nonessential cookies in the browser without the user's consent.

I think it's impossible to enforce this worldwide, and any website can be based in any jurisdiction. The consent popups are also super annoying. It's also hard to define what "essential" means. I'm personally much more in favor of the technological solution: I block all cookies and only explicitly enable them on websites that I need to log in to.

I would disagree with the idea that it's hard to define what's essential: whatever is essential for the function of a website/app. This means things like session login cookies but not analytics cookies.

Re: Slack stores browser cookies without user consent

#15
One minute wasted watching this and it doesn't even show the contents of those cookies. Without looking at the contents, it's impossible to tell if they are "necessary for site functionality", for which you do not need consent (as you can see in the video, there is no checkbox for that sort of cookies, they are always active).

Re: Slack stores browser cookies without user consent

#16
post #10
post #9

Earlier quoted context omitted.

I think there's some merit to "this site uses cookies to track you as you visit different sites". There's none whatsoever to "this site uses cookies to remember your login information". The law seems to make no distinction. As a user, I view every cookie notice as pointless and annoying -- obviously you use cookies, and obviously I'm okay with it. If the notice were specifically about cross-site tracking, that would…

> The law seems to make no distinction. What do you mean by this? The law does make a distinction between essential and nonessential cookies (cookies that are necessary for the function of the website/app, i.e. session cookies, and not necessary, i.e. analytics IDs) and requires you to get consent for nonessential cookies, while allowing essential cookies. If a website doesn't set any nonessential cookies then it doe…

Good point. I'm certainly not an expert on the law -- I did some quick googling, but not a lot.

Session cookies, e.g. are fine. As best I can tell, "remember me" / "remember my email" checkboxes still do require a banner, though I'm not sure. Preference cookies in general seem to. That strikes me as silly.

Facebook's tracking me on thousands of unrelated websites; Wikipedia is remembering that I X'd out the donation banner last week and don't want to be shown it again[0]. These are entirely different use-cases with entirely different privacy implications. As far as I can tell, both require a banner, and while the banner allegedly has (or links to) details about which is occurring, I've never, ever paid enough attention to those banners to see those details.

Part of this mess may be due to the fact that our client software is dominated by the largest advertiser, but I'd prefer regulations that address that by demanding privacy-respecting settings and setting defaults, not by showing me banners that I've never found useful.

I use uBlock Origin and Firefox' tracking protection. I don't use the consent banners. I think most people automatically click "yes" on those, yet given the option to block tracking cookies en masse, would enable that option.

[0] Okay, seems as if Wikipedia ISN'T storing that info, but I wish they did.

Re: Slack stores browser cookies without user consent

#17
post #9

Earlier quoted context omitted.

I think there's some merit to "this site uses cookies to track you as you visit different sites". There's none whatsoever to "this site uses cookies to remember your login information". The law seems to make no distinction. As a user, I view every cookie notice as pointless and annoying -- obviously you use cookies, and obviously I'm okay with it. If the notice were specifically about cross-site tracking, that would…

Those notices also often say "This site uses cookies to make your experience better", so yes, in this sense it's useless. But that's not all the law is doing. Many websites from US simply stopped serving anything for European IP addresses, responding just with error 451, which I always take as a sign that this site wants to sell my data more than they want to show me ads, so I'm glad I didn't accidentally visit it.

it’s actually a sign of a fragmented internet, and brings into question the very idea of an open and free internet. but alas, if this is what politicians want, this is what we’re getting.

Re: Slack stores browser cookies without user consent

#18
post #16
post #10

Earlier quoted context omitted.

> The law seems to make no distinction. What do you mean by this? The law does make a distinction between essential and nonessential cookies (cookies that are necessary for the function of the website/app, i.e. session cookies, and not necessary, i.e. analytics IDs) and requires you to get consent for nonessential cookies, while allowing essential cookies. If a website doesn't set any nonessential cookies then it doe…

Good point. I'm certainly not an expert on the law -- I did some quick googling, but not a lot. Session cookies, e.g. are fine. As best I can tell, "remember me" / "remember my email" checkboxes still do require a banner, though I'm not sure. Preference cookies in general seem to. That strikes me as silly. Facebook's tracking me on thousands of unrelated websites; Wikipedia is remembering that I X'd out the donation…

The case you describe for Wikipedia would be a functional cookie, not subject to a banner, while Facebook would use a tracking cookie, subject to a banner.

I think that the fact that a lot of websites nag you with endless lists of cookie consent checkboxes, even for functional cookies, is not entirely innocent, and contributes to the idea that cookie notices are terribly annoying and pointless.

Re: Slack stores browser cookies without user consent

#19
post #14
post #11

Earlier quoted context omitted.

I think it's impossible to enforce this worldwide, and any website can be based in any jurisdiction. The consent popups are also super annoying. It's also hard to define what "essential" means. I'm personally much more in favor of the technological solution: I block all cookies and only explicitly enable them on websites that I need to log in to.

I would disagree with the idea that it's hard to define what's essential: whatever is essential for the function of a website/app. This means things like session login cookies but not analytics cookies.

That is still not clear. Not everyone need to sign in so it could not be essential. It should ask when you want to login if you want to store a cookie or not.

Re: Slack stores browser cookies without user consent

#20
post #8
post #5

1. Block 3rd party cookies (useless on 99.99% of the sites) 2. Install uBlock Origin ( https://www.ublockorigin.com )

Don't forget step 0: 0. Don't illegally put nonessential cookies in the browser without the user's consent.

except that -1: there's nothing illegal about not asking for consent when cookies are not related to, in the cookie itself, personally identifiable information.

You don't need permission to set cookies, every server with session management relies on them. You do need permission to set cookie that may leak PII.

This person should try again, but this time actually look at the content of the cookies to see whether their complaint even makes sense.

Post reply on HN