Live data from Hacker News

ICO.gov (click on continue without agreeing to cookies)

ico.gov.uk

41–50 of 56 posts

Re: ICO.gov (click on continue without agreeing to cookies)

#41
post #22

Argh! 99% of people have no clue what a "cookie" is used for and just hear that it is "evil" and such. At the same time, these same people have no problem exhibiting themselves of Facebook or tracking their positions on Foursquare. @gov: Just make something like this ( http://www.networkadvertising.org/ > "Conumer opt-out") legally binding for tracking networks (not for individual web sites!) and the whole "Cookie" p…

> 99% of people have no clue what a "cookie" is used for and just hear that it is "evil" and such.

99% of people also don't know how to evaluate the safety of a food additive.

Most don't even know proper food handling procedures and couldn't even evaluate the food safety procedures of their favorite restaurant's kitchen (assuming they even had the time to do so).

Hence, governmental regulatory bodies. You might not agree with the regulatory environment, or with the outcomes, but the regulatory position is logically consistent.

> At the same time, these same people have no problem exhibiting themselves of Facebook or tracking their positions on Foursquare.

Ignorance aside, people are quite often circumspect with what they share on social networking sites; they, honestly have no idea the level of tracking and data sharing that occurs.

Even still, your statement is an unfounded generalization; there are clearly plenty of people that don't use Facebook (or Foursquare) and do have a problem "exhibiting" themselves.

> @gov: Just make something like this (http://www.networkadvertising.org/ > "Conumer opt-out") legally binding for tracking networks (not for individual web sites!) and the whole "Cookie" paranoia is solved.

As a consumer, I prefer opt-in for analytics, user tracking, and unsolicited spam.

Re: ICO.gov (click on continue without agreeing to cookies)

#42
post #18

"unless the cookie is strictly necessary to provide a service requested by the user" Isn't this open to some interpretation? Seems like a pretty wide loop hole. Seems that this will allow a site to set/read it's own cookies no problem. Third-party ad-networks and trackers though, yeah, they would not fall within this definition I think. And isn't that a good thing?

IMO, the 'service requested by the user' is to deliver the website, and all that the 'website' entails.

One might also say that cookies are never strictly necessary. We can always just put tracking IDs in the URL. And when browsers get rid of URL bars, it'll be harder for people to copy/paste the URL (with session ID) so the 'security' aspect against that argument will fall on deaf ears ("I can't see the problem you're talking about, so it's not real").

Re: ICO.gov (click on continue without agreeing to cookies)

#43
post #22

Argh! 99% of people have no clue what a "cookie" is used for and just hear that it is "evil" and such. At the same time, these same people have no problem exhibiting themselves of Facebook or tracking their positions on Foursquare. @gov: Just make something like this ( http://www.networkadvertising.org/ > "Conumer opt-out") legally binding for tracking networks (not for individual web sites!) and the whole "Cookie" p…

The previous implementation of the law was opt-out. It didn't work, because most users were completely unaware they were being tracked. The real saviour will likely come in the shape of browser support for Do Not Track [1]. While it's not fine-grained enough to be used as the sole mechanism for gaining user consent for all non-essential cookies, it at least covers the 3rd party tracking cookies that were the motivati…

It didn't work, because most users were completely unaware they were being tracked.

More like, most users just plain don't care. So now, the regulators respond with: "we don't care what your personal priorities are, we're going to force everyone you interact with to conform to our values rather than your own".

Re: ICO.gov (click on continue without agreeing to cookies)

#44

Earlier quoted context omitted.

The previous implementation of the law was opt-out. It didn't work, because most users were completely unaware they were being tracked. The real saviour will likely come in the shape of browser support for Do Not Track [1]. While it's not fine-grained enough to be used as the sole mechanism for gaining user consent for all non-essential cookies, it at least covers the 3rd party tracking cookies that were the motivati…

It didn't work, because most users were completely unaware they were being tracked. More like, most users just plain don't care. So now, the regulators respond with: "we don't care what your personal priorities are, we're going to force everyone you interact with to conform to our values rather than your own".

> More like, most users just plain don't care.

If you are right, then getting their informed consent isn't going to pose an issue at all. So there's no problem here, right?

Re: ICO.gov (click on continue without agreeing to cookies)

#45
post #36
post #22

Argh! 99% of people have no clue what a "cookie" is used for and just hear that it is "evil" and such. At the same time, these same people have no problem exhibiting themselves of Facebook or tracking their positions on Foursquare. @gov: Just make something like this ( http://www.networkadvertising.org/ > "Conumer opt-out") legally binding for tracking networks (not for individual web sites!) and the whole "Cookie" p…

Facebook tracking my every move is the reason why I don't have a Facebook account. Ditto: I don't use GMail because I don't want Google to have a copy of all my mail. Call me paranoid if you must, but I'm sure I'm not the only one.

Paranoid how? You're basically right: http://edition.cnn.com/2010/OPINION/01/23/schneier.google.ha....

Re: ICO.gov (click on continue without agreeing to cookies)

#46

Earlier quoted context omitted.

It didn't work, because most users were completely unaware they were being tracked. More like, most users just plain don't care. So now, the regulators respond with: "we don't care what your personal priorities are, we're going to force everyone you interact with to conform to our values rather than your own".

> More like, most users just plain don't care. If you are right, then getting their informed consent isn't going to pose an issue at all. So there's no problem here, right?

getting their informed consent isn't going to pose an issue at all. So there's no problem here, right?

Wrong.

First, you're forcing anyone with a web presence that currently has cookies (and that's probably most of us) to spend time and developer resources addressing this -- time that we could spend really servicing our customers.

Second, you're still not going to get their informed consent. What makes you think that somebody's going to actually read the site's warning (assuming that there is one, and that it's written well enough to be comprehensible)? If they don't already care enough about web privacy issues, they're not going to take the time to read about them now.

Third, the regulation completely forbids a potential business model built around targeted advertising. There's nothing fundamentally wrong with that business model. It may be distasteful to someone sharing your values, but there are certainly a lot of people who don't care (and there's no fundamental reason that they ought to care). You're preventing people from doing business one way not because it's wrong, but simply because you find it distasteful.

Re: ICO.gov (click on continue without agreeing to cookies)

#47

From the linked page: > Currently our website contains one cookie that we do not use, but is essential for part of the site to operate. At present we have left this in place across the site, as we’re unable to remove it from one part of the site without affecting another. This session cookie is set on a user’s arrival to the site - at which time they’re informed that the cookie has been set - and is deleted when a us…

The important bit is "but is essential for part of the site to operate." To me, that clearly falls under the "strictly necessary" banner, albeit that it probably shouldn't be set until you enter the part of the site that requires it. Government IT moves at a glacial pace, and just like everyone else they're still trying to figure out how this stuff should work. That's why they've deferred enforcement for a year.

> The important bit is "but is essential for part of the site to operate." To me, that clearly falls under the "strictly necessary" banner

They say that, but it is easily demonstrable that running a web site providing static content such as they do does not require the use of any cookies or similar technology at all to provide the service the user is requesting: millions of web sites manage it every day. As you say, if only part of their site requires the cookie for some genuine reason, perhaps they should only set it there. In any case, there is really no excuse for not explaining properly what the cookie is for or for cluttering up the screens of visitors who don't check your "do whatever you want" button just to make the extra panel go away.

Bottom line: the exemption is not for cookies that are required because you hired poorly trained web developers or picked an inconvenient tool somewhere on your hosting platform. It's for cookies that are essential to providing the service that visitors are expecting. The ICO themselves have been very clear on this in the guidance they published in the run up to the handover, and their own site is flagrantly violating at least the spirit of the rule if not the letter of the law -- which AIUI they have responsibility for interpreting in the UK, so if they can't get it right, what hope is there for anyone else?

Re: ICO.gov (click on continue without agreeing to cookies)

#48

Earlier quoted context omitted.

> More like, most users just plain don't care. If you are right, then getting their informed consent isn't going to pose an issue at all. So there's no problem here, right?

getting their informed consent isn't going to pose an issue at all. So there's no problem here, right? Wrong. First, you're forcing anyone with a web presence that currently has cookies (and that's probably most of us) to spend time and developer resources addressing this -- time that we could spend really servicing our customers. Second, you're still not going to get their informed consent. What makes you think that…

> What makes you think that somebody's going to actually read the site's warning (...)? If they don't already care enough about web privacy issues, they're not going to take the time to read about them now.

If what you say is correct (that users don't care), they'll just click on Accept, right? And you have their consent. You've given them the option to make an informed choice. Your duty has been performed.

> Third, the regulation completely forbids a potential business model built around targeted advertising.

It forbids potential business models built around targeted advertising not based on visitor knowledge and consent (so it forbids business models that wilfully violate the privacy of site visitors without their knowledge, and without their consent). Again, if users don't care (as you point out), the gaining of consent isn't going to be an issue, so these business models will retain their viability.

So given your statement that users don't care about third party tracking or profiling, none of what you outline are really issues.

Re: ICO.gov (click on continue without agreeing to cookies)

#49

Earlier quoted context omitted.

> More like, most users just plain don't care. If you are right, then getting their informed consent isn't going to pose an issue at all. So there's no problem here, right?

getting their informed consent isn't going to pose an issue at all. So there's no problem here, right? Wrong. First, you're forcing anyone with a web presence that currently has cookies (and that's probably most of us) to spend time and developer resources addressing this -- time that we could spend really servicing our customers. Second, you're still not going to get their informed consent. What makes you think that…

> First, you're forcing anyone with a web presence that currently has cookies (and that's probably most of us) to spend time and developer resources addressing this -- time that we could spend really servicing our customers.

I don't accept your premise that "most of us" are using cookies.

In any case, many sites don't need cookies or similar technologies at all, and most of those that do only need them for session data like whether a user is logged in or what is in their shopping cart. Such use is exempt from these new regulations anyway.

I find it interesting that you have such a strong view about regulations that require some trivial effort on the part of legitimate businesses, while at the same time having no problem with a business model that is fundamentally built on harassing all users and making their browsing experience worse. How is your position not hypocritical?

> You're preventing people from doing business one way not because it's wrong, but simply because you find it distasteful.

While you, on the other hand, are suggesting there is nothing wrong with a busines model based on practices that consumers widely dislike but currently cannot do anything about.

The reason we have consumer protection laws is precisely so consumers win and abusive businesses lose in this sort of situation, and while I question the details of these new regulations, I see nothing wrong with the principle behind them.

Re: ICO.gov (click on continue without agreeing to cookies)

#50
post #18

"unless the cookie is strictly necessary to provide a service requested by the user" Isn't this open to some interpretation? Seems like a pretty wide loop hole. Seems that this will allow a site to set/read it's own cookies no problem. Third-party ad-networks and trackers though, yeah, they would not fall within this definition I think. And isn't that a good thing?

I don't think it's a good thing. Many websites rely on advertising to allow them to even exist

So? All those websites have to do is ask permission from the site visitor to track them. Rather than tracking them without their consent...

And if people don't want to be tracked, and the site loses out by not tracking them, so be it... That is a better situation than somebody being tracked without their knowledge/consent.

Post reply on HN