Live data from Hacker News

Automating cookie consent and GDPR violation detection

usenix.org

111–120 of 252 posts

Re: Automating cookie consent and GDPR violation detection

#111

Earlier quoted context omitted.

What do you mean? Can you give an example?

He's saying to deny access to EU-based users, which will make it very unlikely that any EU-based user will complain, thus (in practice) removing the need for GDPR compliance.

I am not aware of any big publishers doing that. That is why I asked for an example.

Re: Automating cookie consent and GDPR violation detection

#112
post #89

Earlier quoted context omitted.

> Did we consider that if everyone is breaking the law, the law itself might need a rework? Agreed - IMO, make cookie banners illegal and make 'minimum cookies' the default. Done?

Isn't this already the case? Does anyone actually think that you give voluntary informed consent to something by being annoyed into pressing a button? No, if you show a cookie banner your users do not opt-in. So a cookie banner is pointless since it doesn't actually give you permission to store cookies you couldn't store before. So we already have the law, we just don't enforce it.

I agree that a cookie banner is pointless. But they are even on government websites, so obviously something has gone terribly wrong along they way (hint: lobbyism).

My thinking goes like this:

1. The law explicitly talks of requesting consent.

2. Incentives will drive actors to request additional permissions if possible (you always get some legal, can claim ignorance, etc)

3. People get constant intrusions wasting our collective time and attention on an enormous scale.

The current law is encouraging this type of user-hostile behavior. This is stating an objective fact, since the current situation is clearly a result of the current law.

If any type of consent-banner or opt-in method is allowed, industry groups will lobby for loopholes they can use to trick users using whatever mechanism the law leaves at their disposal.

Just outright ban the use of cross-site tracking and user profiling. We don't have a societal need for this to be legal.

Re: Automating cookie consent and GDPR violation detection

#113
post #35

Earlier quoted context omitted.

Necessary site functionality, without the spyware. Unfortunately, most websites sites are funded by spyware, so the minimum cookies to keep the internet economy running would have to include the spyware.

Disagree. Let it burn, it's the only way. (change my mind?) This made me think of the Ukraine war, and how the sanctions may turn out to be a bigger help to climate crisis than any political entity could muster on the basis of the impeding climate snafu. Sometimes radical action is the right course of action; for democracy-(pre)serving reasons our governance systems often inhibit change unless most of the population…

I was just asserting out that a law that banned spyware-based advertising would harm the current website ecomomy which is largely based around spyware. I would like to see an end to mass spying, and therefore the creation of a different kind of funding mechanism. That could indeed be brought about by law, but that seems a bit too violent to me. I think what we're missing is a better alternative.

I read an interesting article (from the mid 2000s? Will update if I can find it) arguing that microtransactions will never work due to the cognitive burden of paying for hundreds (or thousands!) of tiny things a day.

Brave's BAT seems to solve this part of the problem by automating the payments based on how much time the user spends on each site. It would require everyone to switch to Brave and use their crypto thing to make it work, so it's obviously "suboptimal".

Re: Automating cookie consent and GDPR violation detection

#114
post #37

Earlier quoted context omitted.

As close to none as possible.

And, to make it even more precise, I would call cookies, which are for login, also as non-essential, unless a visitor really wants to log in, meaning they navigate to the login page. This means, that be default, I don't need any cookies, because I don't want to log in to most websites I visit. Only if I want to log in, I have need for such cookies.

...hit the nail on the head. By 'as close to none' I pretty much meant "any cookie that isn't about authentication and/or holding state of something as an authenticated user that would matter"

Re: Automating cookie consent and GDPR violation detection

#115

Earlier quoted context omitted.

> completely stupid "cookie law" It doesn't take a genius to figure out: Before GDPR: No cookie banners After GDPR: Cookie banners Who's to blame is irrelevant. Users don't care and the effects are real whether it is put on directly by companies as an indirect result of GDPR.

Cookie banners were a thing before the GDPR - the stupid "cookie law" aka ePrivacy Directive was a thing much earlier on. The main problem however is the lack of enforcement though. None of these "cookie banners" comply with the GDPR, yet are allowed to proliferate because nobody is cracking down on them, so they're a form of pseudo-compliance that is very effective at swaying public opinion against the GDPR.

Good point. If this is not an indictment of the failure of GDPR, I don’t know what is.

Re: Automating cookie consent and GDPR violation detection

#116

Earlier quoted context omitted.

if your site is running on apache with default logging, or a shared host like DreamHost, you are probably not fully in compliance with the letter of the GDPR since you're logging IP addresses and aren't using them for necessary site operations. ... especially if the log just grows and grows and never rotates. The GDPR is a very wide-reaching law. Of course, there's no real need to worry since, practically speaking, i…

The problem is, they can enforce it on you at any time of their choosing should you do something deemed unpopular or troublesome. While the cudgel was intended for FAANG, the dagger still hangs to stab any indie that gets out of line. Why would I rely on the kindness of government not to enforce a poorly written law?

I don't think "enforce" means what you think it means. If you are contacted about a GDPR matter usually you have time to fix it before it's "a violation" that incurs penalties.

Re: Automating cookie consent and GDPR violation detection

#117
post #51
post #8

Oh the irony of this site itself having a "we use cookies, got it?" banner while lamenting this exact perceived lack of choice. I always laugh a little when I see those anyway, knowing that my browser's settings and privacy extensions are blocking the cookies and tracking connections either way. Did we consider that if everyone is breaking the law, the law itself might need a rework?

> Did we consider that if everyone is breaking the law, the law itself might need a rework? I think GDPR assumed companies would like to do right by their visitors. I guess the only way to do that is to increase the severity of the consequences for violating user trust. GDPR itself offers a guideline that many seem to misunderstand... you don't need a popup for every kind of cookie. I'm not against enforcing minimal…

>GDPR itself offers a guideline that many seem to misunderstand... you don't need a popup for every kind of cookie.

Cookie banners predate the GDPR, most of them are from the "cookie law"[1] that predates it. They're two entirely separate laws that don't supercede each other.

[1] https://en.wikipedia.org/wiki/Privacy_and_Electronic_Communi...

Re: Automating cookie consent and GDPR violation detection

#118
post #38

Earlier quoted context omitted.

Sure, but you have to also accept that there are aspects that have made the internet a worse experience without actually improving the situation from a privacy point of view.

To be fair, the GDPR does outlaw all the things we find annoying with the cookie banners (or rather, data processing consent flows, as they cover more than just cookies). The problem is continuous lack of enforcement and distinct lack of billion-dollar fines everyone was fear mongering about, which allows companies to passively-aggressively pretend to comply by making their banners annoying on purpose to mislead peop…

> The problem is continuous lack of enforcement

Yeah, but it's hard to enforce a law at scale when the difference between legal and illegal behavior is not obvious to a layperson. The law is too technical.

It also has shouldn't have options where a user can simply allow further data collection, since this makes it hard clearly say whether a certain practice is legal or not, since it "will depend".

This creates more friction to enforcement. If things were more clear-cut, enforcement could be automated, and you would probably see those fines roll out.

It is harder to say "this software library is illegal to use in the EU" if there are certain circumstances where it's not.

Re: Automating cookie consent and GDPR violation detection

#119

Earlier quoted context omitted.

If the law is right, but not possible to enforce, some fixing may be needed

IMO, the problem with GDPR is the same problem we have with a lot of European laws. There's nobody who's incentivized to enforce compliance. If you were able to sue for GDPR violations, either on your own or in a class lawsuit, you would have an incentive to prove that the violation has indeed occurred. As long as your lawyer was working on commission, they would share that incentive. As it stands, all you can do is…

The ADA is the best example of why you need to actually give a law teeth for it to be enforced, and how well it can work when you do.

Re: Automating cookie consent and GDPR violation detection

#120
post #76

Earlier quoted context omitted.

Why? maybe developers beed some adjusting to make compliance numbers higher.

Because GDPR has been around for a few years and its still unmanageable. Laws need to be realistic to make compliance easy and widespread. Maybe there needs to be resources for training or something. There are lots of things you can tweak while still getting the benefits.

Compliance is easy and manageable, for the most part. It's just that companies want to still do the things the law is trying to disincentivize, and want to put as many dark patterns as they can in the way of users avoiding it. So the "unmanageable" part is trying to figure out how close you can come to breaking the law without being blatant.
Post reply on HN