Live data from Hacker News

Slack stores browser cookies without user consent

twitter.com

51–60 of 118 posts

Re: Slack stores browser cookies without user consent

#51

Earlier quoted context omitted.

I still struggle to see how cookies set for spiceworks.com or linkedin.com are for "technical" purposes of just serving a landing page.

“We need these super high tech cookiemotrons to provide you with the best user experience possible. We consider it a technical necessity to meet your need to have your data harvested. You should be thanking us. We would explain further, but you’re too stupid. What are you gonna do? Have us testify before technologically illiterate politicians and fine us 1% of what we pay our CEO?.”

> Have us testify before technologically illiterate politicians and fine us 1% of what we pay our CEO?

Slack operates in the EU and has paying customers in the EU. It also likes to take advantage of anti-competition regulations when convenient: https://slack.com/intl/en-in/blog/news/slack-files-eu-compet...

CEO pay seemed to be $356,952 at time of Slack's IPO.

Maximum fine under GDPR is the greater of 4% annual turnover and $23M. Slack's turnover is too small, which means the maximum fine is $23M, nearly 700% of CEO's basic compensation.

Regulations here have teeth; it's not the United States - and it's a good thing for society that they do.

Re: Slack stores browser cookies without user consent

#52
post #38

Earlier quoted context omitted.

Without looking at the contents, would you argue non-Slack cookies (linkedin.com, techtarget.net, etc.) are essential for site functionality?

Google bot protection\re-captcha has cookies in google.com and ARE essential. but in the video you have some other stuff. So, at least for google you can't be sure.

From my perspective as a user making me click those traffic lights isn't essential functionality.

Re: Slack stores browser cookies without user consent

#53
post #52
post #38

Earlier quoted context omitted.

Google bot protection\re-captcha has cookies in google.com and ARE essential. but in the video you have some other stuff. So, at least for google you can't be sure.

From my perspective as a user making me click those traffic lights isn't essential functionality.

But for the business, bot protection is essential. And GDPR talks about business perspective.

Re: Slack stores browser cookies without user consent

#54

Earlier quoted context omitted.

I'm still hoping we can some day come up with some HTTP header that signals *I know what I'm doing, if you send me cookies I'll keep or discard them as I see fit".

We did, it was called Do-Not-Track. If websites were respecting it we wouldn't have the current situation. The problem? Websites were not only ignoring it but using it as yet another tracking vector.

Couldn't all these 'pick cookies' dashboards be integrated in the browser without running in the same issue ?

Re: Slack stores browser cookies without user consent

#55

Earlier quoted context omitted.

Completely agree. So annoying especially when it take half of mobile device screen I think with tracking protection in modern browsers it should be absolutely fine to allow websites to store data in any possible way (cookies, local storage, websql etc)

I think many on this site often neglect the reality that soft barriers (having to figure out how to configure your cookie settings) become hard barriers for huge majorities of people.

As long as it's opt-out by default (like GDPR mandates it), it should be fine ?

Re: Slack stores browser cookies without user consent

#56
post #40
post #25

Who cares? Those damn consent banners are ruining the web.

This is on purpose. It's done to be as painful as possible while being legal to make the user hate the experience and blame the law, not the implementation. I'm hoping the EU cracks down on dark pattern implementations, malicious compliance (as another comment mentioned) very likely goes against the spirit of the law. The ad-tech industry is quite powerful so I think this will drag on for a while. While it drags out,…

> There are some implementations creating hundreds of lines of opt-outs, some where you have to opt-out vendor by vendor on their own website.

If I'm not mistaken, if there isn't a big 'Refuse All' (non critical) button on the 1rst dashboard 'page', then that implementation is considered to be illegal by the GDPR ?

Re: Slack stores browser cookies without user consent

#57
post #37
post #19

Earlier quoted context omitted.

That is still not clear. Not everyone need to sign in so it could not be essential. It should ask when you want to login if you want to store a cookie or not.

I think it goes deeper than this. An app like Yelp could claim that one of their essential features is to show you restaurants physically close to you, so location information is essential. They could claim that being able to recommend food based on your past searches is part of their core functionality, and that requires saving searches in cookies, or saving them on the server side with a fingerprint on your side. Y…

Note that 'share my location' (or not) is already being perfectly fine handled by the browser.

Re: Slack stores browser cookies without user consent

#58
post #37

Earlier quoted context omitted.

I think it goes deeper than this. An app like Yelp could claim that one of their essential features is to show you restaurants physically close to you, so location information is essential. They could claim that being able to recommend food based on your past searches is part of their core functionality, and that requires saving searches in cookies, or saving them on the server side with a fingerprint on your side. Y…

Note that 'share my location' (or not) is already being perfectly fine handled by the browser.

On a side note I was once able to get a very precise location even with permissions turned off, simply by virtue of 2 devices being on the same Wi-Fi network, the other device having given permissions.

For one they both appear to the outside as the same IPv4 address, and Wi-Fi doesn't travel that far so you can usually presume they are at the same location. There are other ways like having one device hog bandwidth in a slowly modulated fashion, and have the other device pick up on that modulation in streamed data.

This isn't related to the parent comments and I highly doubt any major apps actually implement this but just pointing out that such a side channel attack is possible.

Re: Slack stores browser cookies without user consent

#59
post #22

Don't know about the actual cookies, but I'm pretty sure the "click a simple button to accept all but go through a long and slow process to reject"-pattern is not compliant with GDPR.

Compliant is anything which government do not fine companies for under GDPR. Non-compliant is anything they do. Any other definition isn't relevant in practice. So far I haven't heard of governments fining over this and so it is effectively compliant. So if you have an issue with this behavior complain to your government representatives.

Criminals that did something illegal but weren't caught are compliant with the law then?

Re: Slack stores browser cookies without user consent

#60

Earlier quoted context omitted.

I'm still hoping we can some day come up with some HTTP header that signals *I know what I'm doing, if you send me cookies I'll keep or discard them as I see fit".

We did, it was called Do-Not-Track. If websites were respecting it we wouldn't have the current situation. The problem? Websites were not only ignoring it but using it as yet another tracking vector.

Shocked-pikachu.jpg

Why don't we have any browsers that aggressively deny and block tracking?

Oh right, the ad companies.

Post reply on HN