Live data from Hacker News

No Cookie for You

github.blog

151–160 of 634 posts

Re: No Cookie for You

#151
post #19

Can anyone familiar with the topic explain what distinguishes essential from non-essential cookies? GitHub gives the example of "those used by third-party analytics, tracking, and advertising services", but curious if the law defines some sort of bright line here.

- Security stuff (auth tokens and similar) are generally essential (if only used for that purpose).

- Any form of tracking people is generally non-essential.

What you can and can't do is not based on technical implementation details but practical usage of the information!!

The tricky part if when both overlap, i.e. if you track people but only for assuring a secure operation, i.e. you don't use the tracking information for anything besides their main purpose of assuring secure operation.

A lot (all?) of systems which provide such security specific tracking do not strictly limit their usage, access and collection of information and as such are also used for non-essential purposes and in turn need opt-in.

But then sometimes companies try to abuse it and will do do until taken to court.

For example Facebook argued that people use Facebook with the (main) intend to get customized ads and as such tracking them is essential for Facebooks service. As you can guess this argument is completely ridiculous especially given that they also track users which don't use Facebook, but if you are the size of Facebook you can try to bring that to court and maybe gain a bit more time before you need to comply.

Re: No Cookie for You

#152

Earlier quoted context omitted.

This is (mostly) based on EU law; entities that set cookies and track user data are required to get opt-in permission from users before doing so, and if the user declines, the entity cannot offer a degraded service. At least that's the idea. In practice, almost everyone just throws up a banner that says "fuck you, we're selling your data as hard and as fast as we can," with no opt-out available, but they pretend that…

The new one I'm seening is you opt out easily enough, but there's a subtly hidden tab called 'legitimate interest' and every ad network claims to have a legitimate interest in harvesting your data, even though you've got no business relationship with them. What should be happening is every company that's done that should be getting massive fines, but instead all the enforcement agencies are doing nothing.

If a company is going to lie or skirt the law about their cookie use, why show the banner at all? It's almost worse to show a decline option that does nothing.

Re: No Cookie for You

#153

I wish there was a browser option "I don't care about being tracked" and that would get rid of all cookie banners (and, more often than not, full page popups). This EU law comes from a good idea, but it's terribly implemented - it implies that everybody out there is a lawyer and can make sense and agree on multiple pages of confusing legalese, and this every time they open a new website. This is so absurd, and the re…

Or blanket non-consent of course.

I too find it quite annoying. The other issue is that sometimes the banners do not properly work with various aids for disability and keyboard-operated browsers.

Re: No Cookie for You

#154

Earlier quoted context omitted.

So what happens if one consent to it, but also have third party cookies disabled in one's browser settings? Is disabling it there globally æquivalent to not accepting on such banners?

Consent often involves more than just cookies. Consenting essentially allows them to use other tracking technologies beyond cookies such as IP addresses or browser fingerprinting. This is also why the GDPR requires consent forms instead of relying on browser cookie settings, as it covers the intent of tracking itself as opposed to any technical means by which it is achieved (and this is why functional cookies such as…

The wording of these banners rarely suggests as much.

They talk about cookies, and little more.

Re: No Cookie for You

#155

This is great. My experience is that many people claim to want analytics for their website but end up looking at it a couple of times and then never using it again. Meanwhile they're sponsoring and bolstering the position of internet tracking giants who - despite their claims - have no regard for user privacy. Just sell your product instead of wasting time and money on bike shedding your website with whatever you bel…

I'd go a step further, and say that most sites don't need cookies either. I wrote about it elsewhere a few days ago:

> Avoid having to put annoying EU cookie consent dialogs on your website with one weird trick: > Don't use cookies on your website.

> If you want users to be able to sign in to access your premium paywalled/onlyfans content, put that on a subdomain that has cookies and requires login.

> (yes this isn't applicable to all websites with cookies; it's just a nice idea worth considering)

=> https://pleroma.envs.net/notice/A1sZxGnSQ2Oi0oWMy0 originally written here

Re: No Cookie for You

#156
post #72
post #33

Earlier quoted context omitted.

Also, it only applies in the EU. You don't need to display any banners outside the EU. Not that I am pro-privacy invasion, I'm not, but I'm definitely anti-annoying-popups.

I really wonder genuinely if the regulation has improved anything at all. I just click through the banners without even thinking. It has become so annoying. The value I get is below zero. I wonder if the majority is like me.

The regulation explicitly forbids annoying banners, the problem is that there’s currently zero enforcement of it so websites continue breaching it and lying to themselves (and others) by thinking their consent banners are compliant.

Re: No Cookie for You

#157

I literally proposed this solution in a previous HN thread, discussing the cookie situation. I'm glad a large business such as GH is able to take the _extremely_ painless route of just outright removing them entirely.

Well a large business such as GH also has the resources to build their own in-house tracking solution, which can piggyback off of the first-party auth cookie without requiring any cookie pop-ups.

Re: No Cookie for You

#158
post #118

Earlier quoted context omitted.

I take the time to check what I'm agreeing to. By law it's default opt out for non-essential usages specifically to deal with people who are annoyed, but not everyone plays by the rules.

Yeah, maybe. But not by clever design. The opt-out boxes are usually designed as secondary buttons. The opt-in is designed as primary button. So if you want to change something you have to really think and make a deliberate choice, whereas most people in that moment just want to see the damn content of the site.

That's because the website operators deliberately design the experience to be obnoxious and frustrating.

They want you to have a bad experience if you decide to opt-out of detailed behavioural tracking, so that you'll feel pressured to "consent" to detailed behavioural tracking, and so you'll feel like the GDPR is to blame, even though it isn't.

I've put "consent" in quotes because it's not freely given consent if you are heavily pressured into it, and it's not consent at all if you end up believing you don't really have a choice.

These banners/dialogs do not even comply with the GDPR (despite saying the GDPR requires them), as GDPR says consent to non-essential personal data collection about you must be as easy to withdraw as it is to give, and the service you get must be the same if you don't consent as if you do.

I wrote a bit more about this here: https://news.ycombinator.com/item?id=25441131

Re: No Cookie for You

#159

I wish there was a browser option "I don't care about being tracked" and that would get rid of all cookie banners (and, more often than not, full page popups). This EU law comes from a good idea, but it's terribly implemented - it implies that everybody out there is a lawyer and can make sense and agree on multiple pages of confusing legalese, and this every time they open a new website. This is so absurd, and the re…

Don't you think, that the implementation of the opt out process is what is actually flawed? The law doesn't require you to throw this popup at your users. You can just set the cookies that are techincally required and explain their function in you statement about data usage. If you want to track people, you can then ask for their consent in some nice, locally served banners, where normally you privacy intruding ad networks would put their third party javascript.

Re: No Cookie for You

#160
post #135

I hate the standard wording on Cookie banners. Most of them should read: "The site uses cookies. Actually it doesn't - you are not logged on and we don't need to maintain state. But our advertising partners, their partners, and their partner's partners all love to set tracking cookies. Click here to consent to three dozen cookies from around the globe."

well most sites still generate at least some kind of csrf cookie. multi language site sometimes even have tz/lang

TZ/lang preferences do not require consent, a CSRF token for a logged in user seems to me to be legitimate interest too, but I suppose you could see it as an identifier that can be linked back to the user. I still think if you're using it just for security purposes it counts, but the fact that the same identifier could be used for tracking based on differences on the backend is one of the reasons why this isn't just based on browser cookie settings.
Post reply on HN