Live data from Hacker News

EU privacy agency urges more safeguards to curb U.S. tech giants

reuters.com

21–30 of 171 posts

Re: EU privacy agency urges more safeguards to curb U.S. tech giants

#21
On related news: Just two days ago the EU ePrivacy regulation took the first hurdle in Brussels. This will most likely bring some changes to the whole consent drama. I'm not good at reading legalese and there seem to be no commentary for the current version[1] yet. What I understand is that they "encourage" browsers to implement "whitelists" (their choice of word, not mine) as a solution to "end-users [..] overloaded with requests to provide consent". I'm not sure what is in there regarding first-party analytics cookies which some hoped will be exempted.

[1] https://data.consilium.europa.eu/doc/document/ST-6087-2021-I...

Partly recycled comment from https://news.ycombinator.com/item?id=26103635

Re: EU privacy agency urges more safeguards to curb U.S. tech giants

#22
post #18

People. Just. Delete. Your. Cookies. Regularly. I am baffled about the crazy amount of debate and technical solutions to a problem that was solved the moment Cookies were invented. In the 1990s I suppose.

(Seriously) I don't want to be logged out.

why not, your browser or operating system remembers all your logins for you

Re: EU privacy agency urges more safeguards to curb U.S. tech giants

#23
post #11

Earlier quoted context omitted.

I see the usual OneTrust modal, with a giant, very easy to locate "Reject All" button at the bottom of the modal. https://imgur.com/uZmlGlc

I see the same. Maybe I'm getting confused by the wording and layout. I interpreted the "Reject All"/"Confirm My Choices" buttons at the bottom to belong only to the "Manage Consent Preferences" section. The "Information Our Partners Collect" part above it is a separate section, with a separate "Accept All" button, and an opt-out link in the text, so I figured the final "Reject All" might only reject the second secti…

> Either way, none of this inspires confidence that they have my interests in mind.

Bingo. This is the underlying issue. And indeed this dual opt out is probably intentionally confusing - and I'm never sure either whether 'refuse all' refuses also the partners.

Re: EU privacy agency urges more safeguards to curb U.S. tech giants

#24
post #18

Earlier quoted context omitted.

(Seriously) I don't want to be logged out.

why not, your browser or operating system remembers all your logins for you

2FA slows down the entire log-in process a non-trivial amount - even more so if it's implemented over SMS.

Re: EU privacy agency urges more safeguards to curb U.S. tech giants

#25
post #19

really excited for more popup policies to approve

Maybe it's a cunning ploy to condition people into agreeing to anything if only it means they can see the damn content? I already instantly accept cookies without hesitation.

no doubt that's what 99% of people do. just like terms of service, it's an automatic click through and a waste of everyone's time.

Re: EU privacy agency urges more safeguards to curb U.S. tech giants

#26
post #12

Earlier quoted context omitted.

Already done. It's up to 10% of turnover, not profits. Which the companies would happily go to court over. But how to actually prove in court that company X is tracking users if a leak doesn't occur? Subopenas? They need a court order for that. They need reasonable suspicion to get a court order.

Right now it's very easy to see, the companies are not hiding it at all. They send the data to third-party trackers straight from their website or application.

Disqus loads a million external resources

That’s so stupid, why not just take your OWN cookie and use it in the backend to send to all these resources, proxying through your own server or having a CNAME for theirs under your domain?

Re: EU privacy agency urges more safeguards to curb U.S. tech giants

#27
post #12
post #8

Earlier quoted context omitted.

By setting very high fines for those who don't comply?

Already done. It's up to 10% of turnover, not profits. Which the companies would happily go to court over. But how to actually prove in court that company X is tracking users if a leak doesn't occur? Subopenas? They need a court order for that. They need reasonable suspicion to get a court order.

Those issues aren’t unique to this problem. Courts already try to solve them. It’s the same as how you would find banks denying loan based on race. You find banks by complaints or wide search. You do an initial investigation from the outside with no warrant or subpoena. Like send in a white client and black client (or someone with a search history of fishing versus sewing) and see what happens. Then that’s enough to ask for all the secrets. Of course they could delete them, but that should be a big crime.

I’m not saying this is a perfect system. It’s not. But it’s an attempt the problem you describe.

Re: EU privacy agency urges more safeguards to curb U.S. tech giants

#28

People. Just. Delete. Your. Cookies. Regularly. I am baffled about the crazy amount of debate and technical solutions to a problem that was solved the moment Cookies were invented. In the 1990s I suppose.

Your argument isn't grounded in reason. Let me make another one in kind: let me just take all of the money from everyone's wallets. If anyone notices then they can just get new wallets.
Post reply on HN