Live data from Hacker News

Automating cookie consent and GDPR violation detection

usenix.org

121–130 of 252 posts

Re: Automating cookie consent and GDPR violation detection

#121
post #110

Earlier quoted context omitted.

I wonder if it's a really lazy and terrible attempt at accounting for how long the opt-out request would take. Let's imagine it has no way to know (because of cross-domain restrictions?) whether an opt-out request to a third-party succeeds - in which case it simply waits a reasonable amount of time for the request to complete. Of course, a reasonable time should be a handful of seconds, but I guess at least it makes…

It's entirely possible that it is the result of incompetence rather than malice. Either way, it strongly discourages users from rejecting cookies by wasting their time for 20-30 seconds every time. Whatever it's doing can simply be done in the background, it doesn't even require UI.

Very few people actively want to be tracked by 500 different companies. Some don't mind, some consider it the price they have to pay

The whole point of the charade of "asking" is to get people to

1) Just say yes

2) Complain to their government about it

Re: Automating cookie consent and GDPR violation detection

#122
post #39

Earlier quoted context omitted.

The law is fine. Great even. It is just that most websites don’t comply and developers misunderstand it. You can freely use cookies like we used to do, for session id’s, shopping carts etc. Once you add stuff to your shopping cart, you have a business relationship with the site, and they can store cookies necessary basic functionality. You can not use them to track users on third party sites, or store personally iden…

> developers misunderstand it. Then maybe the law needs some adjusting to make compliance more manageable.

If you as a developer are tasked with understanding this, you take the time to read the actual rules and then you misunderstand it, you are incompetent. But this is not what generally happens. Folks don't read, just yolo some terrible explanation off of SO and then complain when someone tells them they are not compliant. That's laziness. Those are the only reasons for noncompliance, outside of actual malice.

Re: Automating cookie consent and GDPR violation detection

#123
post #89

Earlier quoted context omitted.

Isn't this already the case? Does anyone actually think that you give voluntary informed consent to something by being annoyed into pressing a button? No, if you show a cookie banner your users do not opt-in. So a cookie banner is pointless since it doesn't actually give you permission to store cookies you couldn't store before. So we already have the law, we just don't enforce it.

I agree that a cookie banner is pointless. But they are even on government websites, so obviously something has gone terribly wrong along they way (hint: lobbyism). My thinking goes like this: 1. The law explicitly talks of requesting consent. 2. Incentives will drive actors to request additional permissions if possible (you always get some legal, can claim ignorance, etc) 3. People get constant intrusions wasting ou…

The most common use of “tracking” cookies is just to be able to count unique views for your site, which I think is a perfectly reasonable thing to want to do. Knowing the impact of your site is something pretty much every website producer (including governments, individuals, and businesses) wants to do.

Other examples of where cross-site tracking is useful is for preventing online payments fraud. You have a similar IRL version of this where your bank will freeze your card if it sees purchases being made in different countries simultaneously.

Somewhere along the line, counting views or helping reduce fraud for customers turned into “store full demographic information about someone who never signed up for our service”, which is where everything went wrong in my mind. The cookies themselves aren’t the problem, it’s how they’re being used.

Re: Automating cookie consent and GDPR violation detection

#125
post #56

Earlier quoted context omitted.

I don't think you really "sue" anyone for breaching GDPR. I think you report it to the local authorities, and then they pursue a case. Basically I don't think there's any money for the lawyers to pick up here.

> I don't think you really "sue" anyone for breaching GDPR. I think you report it to the local authorities, and then they pursue a case. You can. Article 79 explicitly states that data subjects have a "right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Reg…

As to the theory, I stand corrected!

As to the practicality of suing for violations, how would you quantify "damaged suffered" from saving a cookie in my browser?

Re: Automating cookie consent and GDPR violation detection

#126
post #113

Earlier quoted context omitted.

Disagree. Let it burn, it's the only way. (change my mind?) This made me think of the Ukraine war, and how the sanctions may turn out to be a bigger help to climate crisis than any political entity could muster on the basis of the impeding climate snafu. Sometimes radical action is the right course of action; for democracy-(pre)serving reasons our governance systems often inhibit change unless most of the population…

I was just asserting out that a law that banned spyware-based advertising would harm the current website ecomomy which is largely based around spyware. I would like to see an end to mass spying, and therefore the creation of a different kind of funding mechanism. That could indeed be brought about by law, but that seems a bit too violent to me. I think what we're missing is a better alternative. I read an interesting…

> I was just asserting out that a law that banned spyware-based advertising would harm the current website ecomomy which is largely based around spyware.

I think that largely, the website economy is based around advertising. I honestly doubt the advertising-centered business model would disappear even if large-scale tracking did. Would it be less targeted and less efficient on a micro-level - yes probably.

But less abusive advertising would also have upsides for website owners: Privacy conscious people are increasingly blocking all ads, losing them eyeballs. Privacy friendly ads may be given a pass.

Right now it's mostly impossible for privacy-conscious people to support a website the like by looking at their ads. The adtech industry is to blame for this for data-raping people. Website owners would benefit from a sustainable advertising model, where users don't have to make the choice between not contributing financially, vs sacrificing their privacy to data leeches. All the websites crying over ad-blockers would instead be forced to use legal ad networks that don't rely on illegal tracking, and people might again be willing to look at ads for content.

Brave is an interesting take, but I think the more optimal solution is to just ban the practice of tracking and shadow-profile building. Problem solved, and I don't need to encourage people to install ad-blockers anymore.

Re: Automating cookie consent and GDPR violation detection

#127
post #46

Earlier quoted context omitted.

TrustArc's consent popup disappears instantly on Accept All but shows a loading spinner for "up to several minutes" if you reject cookies. I emailed them about this (because in my experience it's only their software that implements such a dark pattern), they replied "customer misconfigured our software, not our fault" lol.

I wonder if it's a really lazy and terrible attempt at accounting for how long the opt-out request would take. Let's imagine it has no way to know (because of cross-domain restrictions?) whether an opt-out request to a third-party succeeds - in which case it simply waits a reasonable amount of time for the request to complete. Of course, a reasonable time should be a handful of seconds, but I guess at least it makes…

My understanding is that the preferences should not be an opt-out of a default setting per the GPDR, they should be preferences that requested and then saved. So surely the opt-in setting would take just as long as the opt-out setting, wouldn't it?

Re: Automating cookie consent and GDPR violation detection

#128

Earlier quoted context omitted.

The problem is, they can enforce it on you at any time of their choosing should you do something deemed unpopular or troublesome. While the cudgel was intended for FAANG, the dagger still hangs to stab any indie that gets out of line. Why would I rely on the kindness of government not to enforce a poorly written law?

I don't think "enforce" means what you think it means. If you are contacted about a GDPR matter usually you have time to fix it before it's "a violation" that incurs penalties.

It's "squishy" terms in law, like "usually" that I find bothersome. Granted, I haven't read the complete specifics of all of the minutia when it comes to the GDPR, I'll admit. I do keep cookies by default though, as a habit, which seems to be in violation of GDPR rules.

Should I start publishing a blog or some such which was antithetical to the prevailing party doctrine, that happened to gain traction with the public, terms like usually tend to go out of the window. Al Capone wasn't indicted on bootlegging after all.

Re: Automating cookie consent and GDPR violation detection

#129
post #89

Earlier quoted context omitted.

Isn't this already the case? Does anyone actually think that you give voluntary informed consent to something by being annoyed into pressing a button? No, if you show a cookie banner your users do not opt-in. So a cookie banner is pointless since it doesn't actually give you permission to store cookies you couldn't store before. So we already have the law, we just don't enforce it.

I agree that a cookie banner is pointless. But they are even on government websites, so obviously something has gone terribly wrong along they way (hint: lobbyism). My thinking goes like this: 1. The law explicitly talks of requesting consent. 2. Incentives will drive actors to request additional permissions if possible (you always get some legal, can claim ignorance, etc) 3. People get constant intrusions wasting ou…

> they are even on government websites

Could you give some examples please? I checked all the government websites I could think of and didn't see any.

Re: Automating cookie consent and GDPR violation detection

#130
post #56

Earlier quoted context omitted.

> I don't think you really "sue" anyone for breaching GDPR. I think you report it to the local authorities, and then they pursue a case. You can. Article 79 explicitly states that data subjects have a "right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Reg…

As to the theory, I stand corrected! As to the practicality of suing for violations, how would you quantify "damaged suffered" from saving a cookie in my browser?

Remember GDPR is a general law about data collection so it could be anything, not necessarily cookies.
Post reply on HN