Live data from Hacker News

Slack stores browser cookies without user consent

twitter.com

61–70 of 118 posts

Re: Slack stores browser cookies without user consent

#61
post #59

Earlier quoted context omitted.

Compliant is anything which government do not fine companies for under GDPR. Non-compliant is anything they do. Any other definition isn't relevant in practice. So far I haven't heard of governments fining over this and so it is effectively compliant. So if you have an issue with this behavior complain to your government representatives.

Criminals that did something illegal but weren't caught are compliant with the law then?

That's not what I said. I said, a law which is not enforced is not in practice a law. It's just worthless words on a piece of paper.

There's a difference between a law which is not enforced and a law which a particular entity (but not others) manage to evade.

I merely pointed out that the entity to blame isn't the corporations who follow the law as it is applied but the government who enforces it that way.

Re: Slack stores browser cookies without user consent

#62

Earlier quoted context omitted.

We did, it was called Do-Not-Track. If websites were respecting it we wouldn't have the current situation. The problem? Websites were not only ignoring it but using it as yet another tracking vector.

Shocked-pikachu.jpg Why don't we have any browsers that aggressively deny and block tracking? Oh right, the ad companies.

Isn't that Brave? Granted, they have their wierd crypto crap, but the big selling point is adblocking by default.

Re: Slack stores browser cookies without user consent

#63

One minute wasted watching this and it doesn't even show the contents of those cookies. Without looking at the contents, it's impossible to tell if they are "necessary for site functionality", for which you do not need consent (as you can see in the video, there is no checkbox for that sort of cookies, they are always active).

No cookies are 'necessary' for site functionality, unless there is a login needed.

No cookies are 'necessary' to just display information, pics and videos.

Re: Slack stores browser cookies without user consent

#64

Earlier quoted context omitted.

I'm still hoping we can some day come up with some HTTP header that signals *I know what I'm doing, if you send me cookies I'll keep or discard them as I see fit".

We did, it was called Do-Not-Track. If websites were respecting it we wouldn't have the current situation. The problem? Websites were not only ignoring it but using it as yet another tracking vector.

Do-Not-Track is the opposite. Do-Not-Track is a request not to send cookies.

This would be like Go-Ahead-And-Try-Track-Me-I-Dare-You.

Re: Slack stores browser cookies without user consent

#65

One minute wasted watching this and it doesn't even show the contents of those cookies. Without looking at the contents, it's impossible to tell if they are "necessary for site functionality", for which you do not need consent (as you can see in the video, there is no checkbox for that sort of cookies, they are always active).

No cookies are 'necessary' for site functionality, unless there is a login needed. No cookies are 'necessary' to just display information, pics and videos.

From GDPR.eu:

> Strictly necessary cookies — These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookies. While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user.

Seems like you can in fact set first-party session tokens without consent. Does not seem like you need a specific reason to do so.

Re: Slack stores browser cookies without user consent

#66
post #33
post #25

Who cares? Those damn consent banners are ruining the web.

That's the intention. Malicious compliance. "Oh, you want us to tell people we're tracking them as a means to stop us tracking them? nah, lets just make the banner as obnoxious as possible so that they hate the banners- if we all do it, people will overturn the regulation"

Hopefully, people will just start to use site that comply without being malicious. I just close more and more often the page when I see this. The reality is that they need readers/users more than we need them.

Re: Slack stores browser cookies without user consent

#67

One minute wasted watching this and it doesn't even show the contents of those cookies. Without looking at the contents, it's impossible to tell if they are "necessary for site functionality", for which you do not need consent (as you can see in the video, there is no checkbox for that sort of cookies, they are always active).

No cookies are 'necessary' for site functionality, unless there is a login needed. No cookies are 'necessary' to just display information, pics and videos.

bullshit. any site with a form needs a cookie, unless the site is stupid. any site that tries to use post requests might need some.

heck even the confirmation or storing which cookies should be saved needs a fucking cookie.

Re: Slack stores browser cookies without user consent

#68
post #38

Earlier quoted context omitted.

Google bot protection\re-captcha has cookies in google.com and ARE essential. but in the video you have some other stuff. So, at least for google you can't be sure.

Unless there's actually a captcha on that page, they aren't essential. Furthermore, you could argue that recaptcha itself is in breach of the GDPR as it collects a lot more data than necessary (captchas have been done just fine for decades without collecting any personal information).

That isn't how reCaptcha works though. v3 doesn't even show challenges anymore. It wouldn't work at all without analyzing user metrics.

Re: Slack stores browser cookies without user consent

#69

Earlier quoted context omitted.

I'm still hoping we can some day come up with some HTTP header that signals *I know what I'm doing, if you send me cookies I'll keep or discard them as I see fit".

We did, it was called Do-Not-Track. If websites were respecting it we wouldn't have the current situation. The problem? Websites were not only ignoring it but using it as yet another tracking vector.

if gdpr would have used a framework like do-not-track it would have not happend. but as always in the eu. NIH syndrome. also they did not cared besides multiple people telling the rulemakers that this will happen.

Re: Slack stores browser cookies without user consent

#70
post #3
post #2

I find it hard to care about violations of the worst law that ever happened to the internet.

Care to elaborate on that? I rather like it. As a developer it's a pain, but as a citizen I find it to be a step in the right direction.

Back in the 90s we had cookie confirmation things. A browser called konqueror even had it on by default. Every time a server tried to set a cookie you got a chance to say no, etc…

For users it was as awful then as the experience is now.

The people who made this law seemed to be under the impression that sites would react by removing cookies. This is naive or plain stupid. Instead what we have now is that every single site has a popup saying "Lorem ipsum" (nobody reads this), and you have to click "fuck off" to get to the content.

I would LIKE to say that all this law does is annoy people. I would like that, but no. Instead what it does is train literally billions of people to click "fuck off" (actual text is usually something like "I agree", but what the user means is "fuck off, I'm trying to read the article"), without reading what the box says.

ACTUAL security problems now, or ACTUAL choices, now cannot be warned about. Because if users were not good at reading actual meaningful warnings before, they sure as hell don't read them now.

So not only is this law (1) not helping, people still have cookies. It's also (2) annoying absolutely everyone every day, with up to four "fuck off" buttons users need to click per page load, and (3) actively hurting via huge externalities, as described above.

Oh, and for extra bonus on a weekly basis I run into websites that chose to simply block users from EU IPs, presumably after a ROI calculation. Thanks, EU.

Are you in Europe?

Post reply on HN