Live data from Hacker News

Slack stores browser cookies without user consent

twitter.com

41–50 of 118 posts

Re: Slack stores browser cookies without user consent

#41

Earlier quoted context omitted.

Without looking at the contents, would you argue non-Slack cookies (linkedin.com, techtarget.net, etc.) are essential for site functionality?

Slack has no control over those cookies - but it is of course questionable at best that those third-party services are allowed to embed their crap by default. That's not a cookie consent issue though, strictly speaking.

This isn't accurate. Slack has 100% control over the content that goes on their site, and that includes 3rd-party tracking pixels and other mechanisms that lead to these cookies from 3rd parties.

Re: Slack stores browser cookies without user consent

#42
post #12

If they're for technical purposes, not tracking purposes you don't need permission under GDPR at least. I'm going to assume they know what they're doing, at least until I see evidence to the contrary. Benefit of the doubt, innocent until proven guilty, and all that.

I still struggle to see how cookies set for spiceworks.com or linkedin.com are for "technical" purposes of just serving a landing page.

“We need these super high tech cookiemotrons to provide you with the best user experience possible. We consider it a technical necessity to meet your need to have your data harvested. You should be thanking us. We would explain further, but you’re too stupid. What are you gonna do? Have us testify before technologically illiterate politicians and fine us 1% of what we pay our CEO?.”

Re: Slack stores browser cookies without user consent

#43
post #38

Earlier quoted context omitted.

Without looking at the contents, would you argue non-Slack cookies (linkedin.com, techtarget.net, etc.) are essential for site functionality?

Google bot protection\re-captcha has cookies in google.com and ARE essential. but in the video you have some other stuff. So, at least for google you can't be sure.

Unless there's actually a captcha on that page, they aren't essential. Furthermore, you could argue that recaptcha itself is in breach of the GDPR as it collects a lot more data than necessary (captchas have been done just fine for decades without collecting any personal information).

Re: Slack stores browser cookies without user consent

#44
post #25

Who cares? Those damn consent banners are ruining the web.

I'm still hoping we can some day come up with some HTTP header that signals *I know what I'm doing, if you send me cookies I'll keep or discard them as I see fit".

We did, it was called Do-Not-Track. If websites were respecting it we wouldn't have the current situation.

The problem? Websites were not only ignoring it but using it as yet another tracking vector.

Re: Slack stores browser cookies without user consent

#45

Earlier quoted context omitted.

Without looking at the contents, would you argue non-Slack cookies (linkedin.com, techtarget.net, etc.) are essential for site functionality?

Slack has no control over those cookies - but it is of course questionable at best that those third-party services are allowed to embed their crap by default. That's not a cookie consent issue though, strictly speaking.

> Slack has no control over those cookies

Sorry, I fail to see how Slack has "no control" over the usage of ads.linkedin cookies?

Re: Slack stores browser cookies without user consent

#46
post #12

If they're for technical purposes, not tracking purposes you don't need permission under GDPR at least. I'm going to assume they know what they're doing, at least until I see evidence to the contrary. Benefit of the doubt, innocent until proven guilty, and all that.

Is this trend of using specific legal concepts and somehow applying them to public discourse writ large ever going to end?

To me, I fail to see how "ads.linkedin" is possibly for "technical purposes." Pretty basic common sense and I don't need to apply some 'innocent before proven guilty in a court of law' standard to my own opinion.

Re: Slack stores browser cookies without user consent

#47
post #22

Don't know about the actual cookies, but I'm pretty sure the "click a simple button to accept all but go through a long and slow process to reject"-pattern is not compliant with GDPR.

Compliant is anything which government do not fine companies for under GDPR. Non-compliant is anything they do. Any other definition isn't relevant in practice. So far I haven't heard of governments fining over this and so it is effectively compliant. So if you have an issue with this behavior complain to your government representatives.

Re: Slack stores browser cookies without user consent

#48
post #25

Who cares? Those damn consent banners are ruining the web.

Completely agree. So annoying especially when it take half of mobile device screen I think with tracking protection in modern browsers it should be absolutely fine to allow websites to store data in any possible way (cookies, local storage, websql etc)

I think many on this site often neglect the reality that soft barriers (having to figure out how to configure your cookie settings) become hard barriers for huge majorities of people.

Re: Slack stores browser cookies without user consent

#49
post #37
post #19

Earlier quoted context omitted.

That is still not clear. Not everyone need to sign in so it could not be essential. It should ask when you want to login if you want to store a cookie or not.

I think it goes deeper than this. An app like Yelp could claim that one of their essential features is to show you restaurants physically close to you, so location information is essential. They could claim that being able to recommend food based on your past searches is part of their core functionality, and that requires saving searches in cookies, or saving them on the server side with a fingerprint on your side. Y…

The law isn't as fuzzy as you think.

> An app like Yelp could claim that one of their essential features is to show you restaurants physically close to you, so location information is essential.

They could claim that but it would not be relevant in law. The GDPR provides an exception for "strictly necessary" cookies only, as follows:

"This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service."

If I didn't explicitly request for Yelp to show me restaurants physically close to me, or to recommend food based on my past searches, then neither of these things are "strictly necessary" as defined by the GDPR and they can't store personal information about me regardless of what they claim.

Re: Slack stores browser cookies without user consent

#50

One minute wasted watching this and it doesn't even show the contents of those cookies. Without looking at the contents, it's impossible to tell if they are "necessary for site functionality", for which you do not need consent (as you can see in the video, there is no checkbox for that sort of cookies, they are always active).

[deleted]
Post reply on HN