[1] https://data.consilium.europa.eu/doc/document/ST-6087-2021-I...
Partly recycled comment from https://news.ycombinator.com/item?id=26103635
21–30 of 171 posts
[1] https://data.consilium.europa.eu/doc/document/ST-6087-2021-I...
Partly recycled comment from https://news.ycombinator.com/item?id=26103635
People. Just. Delete. Your. Cookies. Regularly. I am baffled about the crazy amount of debate and technical solutions to a problem that was solved the moment Cookies were invented. In the 1990s I suppose.
(Seriously) I don't want to be logged out.
Earlier quoted context omitted.
I see the usual OneTrust modal, with a giant, very easy to locate "Reject All" button at the bottom of the modal. https://imgur.com/uZmlGlc
I see the same. Maybe I'm getting confused by the wording and layout. I interpreted the "Reject All"/"Confirm My Choices" buttons at the bottom to belong only to the "Manage Consent Preferences" section. The "Information Our Partners Collect" part above it is a separate section, with a separate "Accept All" button, and an opt-out link in the text, so I figured the final "Reject All" might only reject the second secti…
Bingo. This is the underlying issue. And indeed this dual opt out is probably intentionally confusing - and I'm never sure either whether 'refuse all' refuses also the partners.
really excited for more popup policies to approve
Maybe it's a cunning ploy to condition people into agreeing to anything if only it means they can see the damn content? I already instantly accept cookies without hesitation.
Earlier quoted context omitted.
Already done. It's up to 10% of turnover, not profits. Which the companies would happily go to court over. But how to actually prove in court that company X is tracking users if a leak doesn't occur? Subopenas? They need a court order for that. They need reasonable suspicion to get a court order.
Right now it's very easy to see, the companies are not hiding it at all. They send the data to third-party trackers straight from their website or application.
That’s so stupid, why not just take your OWN cookie and use it in the backend to send to all these resources, proxying through your own server or having a CNAME for theirs under your domain?
Earlier quoted context omitted.
By setting very high fines for those who don't comply?
Already done. It's up to 10% of turnover, not profits. Which the companies would happily go to court over. But how to actually prove in court that company X is tracking users if a leak doesn't occur? Subopenas? They need a court order for that. They need reasonable suspicion to get a court order.
I’m not saying this is a perfect system. It’s not. But it’s an attempt the problem you describe.
People. Just. Delete. Your. Cookies. Regularly. I am baffled about the crazy amount of debate and technical solutions to a problem that was solved the moment Cookies were invented. In the 1990s I suppose.