Live data from Hacker News

Slack stores browser cookies without user consent

twitter.com

31–40 of 118 posts

Re: Slack stores browser cookies without user consent

#31
post #29
post #26

Earlier quoted context omitted.

In my opinion, it’s solving the problem at the wrong level. If you, as a government, want to coerce someone into solving this problem, it should be forcing browser vendors to provide more visibility into and control over (especially third-party) cookies. Instead, we have a banner you have to interact with as the price to visit pretty much any website.

I don’t know, I think the banner is a pain but it is absolutely the responsibility of web developers to allow user choice in tracking. Cookies don’t have to be third-party to be harmful. If the roads are bad, we need to fix the roads, not just tell everyone to drive better cars.

I mean sure, but technically you already have that choice. It's entirely up to you whether to keep, discard or modify cookies. Your user agent is doing a bad job of managing this for you.

Re: Slack stores browser cookies without user consent

#32
post #19
post #14

Earlier quoted context omitted.

I would disagree with the idea that it's hard to define what's essential: whatever is essential for the function of a website/app. This means things like session login cookies but not analytics cookies.

That is still not clear. Not everyone need to sign in so it could not be essential. It should ask when you want to login if you want to store a cookie or not.

Yeah, that's why it depends on the function of the website or app. If you need to sign in to access an app, and the session token is saved using a cookie, then it can be considered an essential cookie. But on a marketing website that doesn't have a login component then yes, you're right, logging in isn't required and so it's arguably a nonessential cookie.

Re: Slack stores browser cookies without user consent

#33
post #25

Who cares? Those damn consent banners are ruining the web.

That's the intention. Malicious compliance.

"Oh, you want us to tell people we're tracking them as a means to stop us tracking them? nah, lets just make the banner as obnoxious as possible so that they hate the banners- if we all do it, people will overturn the regulation"

Re: Slack stores browser cookies without user consent

#34

One minute wasted watching this and it doesn't even show the contents of those cookies. Without looking at the contents, it's impossible to tell if they are "necessary for site functionality", for which you do not need consent (as you can see in the video, there is no checkbox for that sort of cookies, they are always active).

Without looking at the contents, would you argue non-Slack cookies (linkedin.com, techtarget.net, etc.) are essential for site functionality?

Re: Slack stores browser cookies without user consent

#35
post #12

If they're for technical purposes, not tracking purposes you don't need permission under GDPR at least. I'm going to assume they know what they're doing, at least until I see evidence to the contrary. Benefit of the doubt, innocent until proven guilty, and all that.

I still struggle to see how cookies set for spiceworks.com or linkedin.com are for "technical" purposes of just serving a landing page.

Re: Slack stores browser cookies without user consent

#36

One minute wasted watching this and it doesn't even show the contents of those cookies. Without looking at the contents, it's impossible to tell if they are "necessary for site functionality", for which you do not need consent (as you can see in the video, there is no checkbox for that sort of cookies, they are always active).

Without looking at the contents, would you argue non-Slack cookies (linkedin.com, techtarget.net, etc.) are essential for site functionality?

Slack has no control over those cookies - but it is of course questionable at best that those third-party services are allowed to embed their crap by default. That's not a cookie consent issue though, strictly speaking.

Re: Slack stores browser cookies without user consent

#37
post #19
post #14

Earlier quoted context omitted.

I would disagree with the idea that it's hard to define what's essential: whatever is essential for the function of a website/app. This means things like session login cookies but not analytics cookies.

That is still not clear. Not everyone need to sign in so it could not be essential. It should ask when you want to login if you want to store a cookie or not.

I think it goes deeper than this.

An app like Yelp could claim that one of their essential features is to show you restaurants physically close to you, so location information is essential. They could claim that being able to recommend food based on your past searches is part of their core functionality, and that requires saving searches in cookies, or saving them on the server side with a fingerprint on your side.

You could argue that Yelp is only a yellow pages of restaurants and therefore no cookies are essential. Someone else could argue that they are much more than a yellow pages, that if they were only a yellow pages they would not be profitable and cease to exist, and that their core reason of existence is their recommendation engine. To that person, essential functionality would require more things to be stored.

Then there is a regulatory aspect. Some governments may require their companies to install trackers of sorts. Some governments just don't give a damn and let their companies do as they please. GDPR is not a universal law. It's an EU law. Nobody else has to follow it, and there is no way you'll convince every country in especially Asia, Africa, and South America to follow GDPR. A technological solution on the other hand can deal with the entire problem with a single software update, much more effectively than any legal route.

Re: Slack stores browser cookies without user consent

#38

One minute wasted watching this and it doesn't even show the contents of those cookies. Without looking at the contents, it's impossible to tell if they are "necessary for site functionality", for which you do not need consent (as you can see in the video, there is no checkbox for that sort of cookies, they are always active).

Without looking at the contents, would you argue non-Slack cookies (linkedin.com, techtarget.net, etc.) are essential for site functionality?

Google bot protection\re-captcha has cookies in google.com and ARE essential. but in the video you have some other stuff. So, at least for google you can't be sure.

Re: Slack stores browser cookies without user consent

#39
post #8

Earlier quoted context omitted.

Don't forget step 0: 0. Don't illegally put nonessential cookies in the browser without the user's consent.

except that -1: there's nothing illegal about not asking for consent when cookies are not related to, in the cookie itself, personally identifiable information. You don't need permission to set cookies, every server with session management relies on them. You do need permission to set cookie that may leak PII. This person should try again, but this time actually look at the content of the cookies to see whether their…

No, it’s not a PII related issue. You need consent to set nonessential cookies, regardless if they contain PII. An example is Segment, which sets cookies but may not be tied to a particular user. Segment, at least using just for analytics, isn’t necessary for the function of a website or app, so even if the cookies don’t have any PII you still need to get consent.

You’re right that you don’t need permission to set server session cookies, but that is because that cookie is essential for the function of an authenticated app.

Re: Slack stores browser cookies without user consent

#40
post #25

Who cares? Those damn consent banners are ruining the web.

This is on purpose. It's done to be as painful as possible while being legal to make the user hate the experience and blame the law, not the implementation.

I'm hoping the EU cracks down on dark pattern implementations, malicious compliance (as another comment mentioned) very likely goes against the spirit of the law. The ad-tech industry is quite powerful so I think this will drag on for a while.

While it drags out, I've been stubborn. Always refusing all cookies when I can't zap the cookie banner/blocker with uBlock. The most pain I can take is setting about 20 toggles. There are some implementations creating hundreds of lines of opt-outs, some where you have to opt-out vendor by vendor on their own website. Those are the ones where I close the page and forget about the content. It's not worth the hassle and my data.

I wasn't such an advocate for data privacy half a decade ago, I was aware about it and how it could be used, just had never seen it, not necessarily in action at the time, but being debated on corridors.

The unethical proposals I heard in meetings or by the coffee machines on how to extract/transform/identify through amassing data were quite alarming. Not because they were blatant bad but that the collective way of talking about it completely disregarded the end user.

GDPR really changed that talk internally, it's been a massive effort and a pain in the ass sometimes but I do value the spirit of it. Could it be the wrong approach? Or too heavy-handed? Misapplied? And so many other still unknown problems? Yes, I do think there are too much uncertainty in how this pans out on the long term. I do deeply appreciate the effort though from the EP and the EU in putting this into the public eye, we should have been having this discussion quite some years ago...

There are still tons of open questions and discussions to be had on data privacy laws, I feel the pain of having an increased workload because of it but it should become cost of business. Protection of your customers' data, its usage and their privacy should be a cost of business for companies depending on that. Level the game, create some mechanisms to help smaller companies be bootstrapped with this mindset and with guidelines and best practices for a quick ramp up.

It can be a cost of business for large enterprises, smaller companies might need help to not be overburden if these laws get too complex.

I don't think I'm too revolutionary.

Post reply on HN