Live data from Hacker News

Automating cookie consent and GDPR violation detection

usenix.org

141–150 of 252 posts

Re: Automating cookie consent and GDPR violation detection

#141
post #129

Earlier quoted context omitted.

I agree that a cookie banner is pointless. But they are even on government websites, so obviously something has gone terribly wrong along they way (hint: lobbyism). My thinking goes like this: 1. The law explicitly talks of requesting consent. 2. Incentives will drive actors to request additional permissions if possible (you always get some legal, can claim ignorance, etc) 3. People get constant intrusions wasting ou…

> they are even on government websites Could you give some examples please? I checked all the government websites I could think of and didn't see any.

https://gdpr.eu/cookies/ lol ;-)

https://european-union.europa.eu/

https://www.sundhed.dk/

https://www.securite-sociale.fr/

4 out of 4 in my case. May I ask which ones you checked, I'm genuinely curious, cause I really don't remember seeing any official website in the EU without cookie banner in many years.

Re: Automating cookie consent and GDPR violation detection

#142

Earlier quoted context omitted.

In my country, we didn't end that practice without a civil war. I think that story is an excellent example of the limits of the coersive power of law. Even though the goal is righteous, the law may be the wrong tool to achieve it. What alternative tools can be deployed on this topic?

The law has yet to be enforced properly and consistently. Enforcing the law would be a good start before considering alternative options.

Is the issue of consistent and proper enforcement a "Quis custodiet ipsos custodes" issue, or a lack of resources to police / monitor / enforce issue right now? IIUC, enforcement must be "proportionate," but that's a pretty anxiety-inducing word in a law unless there's either solid precedent to establish what that word means or an oversight board.

And if the issue is that they're under-funded, I agree with increasing resources to proportionate to the need to properly enforce the law. Coupled with proper proportionate penalties (including warnings for good-faith efforts to compliance, making the law a bit more like online speeding tickets than the 20-million-euro minimum penalty suggests it should be), it may be able to adjust behavior.

On the other hand, I'd expect the resulting behavior adjustment magnitude to be in the realm of speeding tickets (with the occasional reckless-driving for, say, a FAANG mass-harvesting data). Maybe that's good enough for the goals though.

Re: Automating cookie consent and GDPR violation detection

#143

It's pretty well known that cookie-walls are rife with anti-consumer patterns. Going to something like formula1.com requires me to click more than a 100 times to object to the 'legitimate interests' of as many companies. Which is a pretty terrible anti-pattern when I don't want to be tracked at all... After reading the abstract, it seems the authors try to classify cookies using a special browser extension called "Co…

> Going to something like formula1.com r Not sure if this is because i'm in the states, but 'manage settings' has a 'reject all' button for me[0] and it seems to work. 0: https://i.judge.sh/0vCJB/q_nQ34wtjO.png

But does that button also reject "legitimate" interests?

Re: Automating cookie consent and GDPR violation detection

#144
post #129

Earlier quoted context omitted.

> they are even on government websites Could you give some examples please? I checked all the government websites I could think of and didn't see any.

https://gdpr.eu/cookies/ lol ;-) https://european-union.europa.eu/ https://www.sundhed.dk/ https://www.securite-sociale.fr/ 4 out of 4 in my case. May I ask which ones you checked, I'm genuinely curious, cause I really don't remember seeing any official website in the EU without cookie banner in many years.

Okay, the first two are pretty hilarious, but as far as I can tell, the first one doesn't actually set any cookies if you don't react to the banner, and the second one sets just this: "{"cm":false,"all1st":false,"closed":false}", which seems acceptable.

The other two are trickier to judge, but contain (user?) identifiers, which could certainly be used for tracking, so I'll have to concede your point.

Edit: I had to recheck some of the sites I'd previously checked, as your examples helped me realize that my browser does a lot of blocking. It turns out that just one of my examples was actually a good one: https://finlex.fi/en/

Edit2: Found others: https://www.suomi.fi/frontpage and https://vnk.fi/en/frontpage

Both actually do set cookies, but apparently nothing requiring consent.

Re: Automating cookie consent and GDPR violation detection

#145

Earlier quoted context omitted.

> completely stupid "cookie law" It doesn't take a genius to figure out: Before GDPR: No cookie banners After GDPR: Cookie banners Who's to blame is irrelevant. Users don't care and the effects are real whether it is put on directly by companies as an indirect result of GDPR.

Cookie banners were a thing before the GDPR - the stupid "cookie law" aka ePrivacy Directive was a thing much earlier on. The main problem however is the lack of enforcement though. None of these "cookie banners" comply with the GDPR, yet are allowed to proliferate because nobody is cracking down on them, so they're a form of pseudo-compliance that is very effective at swaying public opinion against the GDPR.

Hot take: Only way to undo past damage is to now make the cookie/consent banner illegal.

Re: Automating cookie consent and GDPR violation detection

#146

That's the end result of extremely complicated legislation. Everyone breaks it, but you only get caught if you stick out enough. Uncharitably, it's a way for the government to arbitrarily prosecute anyone they please.

More charitably and historically accurate, it's the result of hardcore political negotiations with the originally proposed legislation watered down due to pressure from politicians and governments influenced by lobbyists.

But yeah, the result is too complicated to be effectively enforced, sadly. So further reform is needed.

Re: Automating cookie consent and GDPR violation detection

#147
post #56

Earlier quoted context omitted.

> I don't think you really "sue" anyone for breaching GDPR. I think you report it to the local authorities, and then they pursue a case. You can. Article 79 explicitly states that data subjects have a "right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Reg…

As to the theory, I stand corrected! As to the practicality of suing for violations, how would you quantify "damaged suffered" from saving a cookie in my browser?

It would probably be some very large number backed by a theory like "this violation has deprived the plaintiff of their ability to fully control the disposition of their private information and activities, thereby creating permanent direct and indirect risks whose damages to the plaintiff's income, income potential, business, reputation, and family are limited only by the malevolent collective imagination of an unbounded pool of individual, institutional, or governmental adversaries."

Re: Automating cookie consent and GDPR violation detection

#148

Given the amount of confusion and conflicting interpretations of GDPR we get on HN, I'm not really surprised. Then there's always the vocal minority that is fully convinced that GDPR is very simple and clear.

There's a huge amount of misinformation spread around it, and not to mention existing online information about the earlier and completely stupid "cookie law" is sometimes mistaken for the GDPR. It doesn't help that the GDPR is only really simple if you don't abuse personal data. It will obviously become very complex when you're hoping to find loopholes do something that the GDPR was fundamentally designed to outlaw,…

> It doesn't help that the GDPR is only really simple if you don't abuse personal data.

I'm not sure how helpful this criterion is; there exists a large gray area in what people consider to be "abuse". For instance, suppose that an EU-based business hotlinks an image from a U.S.-based website (or a website hosted on a U.S. CDN, or a website operated by a business owned by a U.S. corporation). Then that business is at risk of being fined, since it has no way of proving that the target website does not log IP addresses (e.g., for some DoS-protection suite), and if it does, the U.S. government could gain access to those IP addresses, which are defined as protected personal information.

In this scenario, the EU-based business isn't necessarily doing anything nefarious like selling data to advertisers, and it could even be refraining from storing any data at all. Likewise, a U.S.-based website that stores only connection logs isn't necessarily doing nefarious things with those. But the former business is still at risk of being fined, since IP addresses have been placed under the umbrella of protected personal information.

In the discussion a while back of the Google IP-address fine, I saw two talking points come up repeatedly: that there would have been no issue if Google weren't doing nefarious tracking of IP addresses, and that the EU operator must have known that IP addresses are radioactive to store or transmit but chose to do so anyway. AFAICT, the first is inaccurate, since any persistent storage of IP addresses by U.S. operators is problematic. And the second, I think, illustrates the real tension here: between privacy maximalists who prefer the least possible amount of data to be stored in all circumstances, regardless of the cost, and everyday server operators who fear that using the default settings on their software or using seemingly-trivial functionality could be introducing legal liability.

I'm still not sure myself about the relative merits of the two viewpoints, but much more could be done to assist the latter group in following best practices, instead of immediately demonizing them as nefarious loophole finders. (Not to say that nefarious operators don't exist, of course, but I suspect that their prevelance is very easily overstated.)

Re: Automating cookie consent and GDPR violation detection

#149

Earlier quoted context omitted.

I wonder what is the GDP cost of millions if not billions of people flushing the toilet every day, often multiple times a day. We can all make silly arguments, just because something requires you to take action, and it might cost money, doesn't mean we therefore have to just let late stage capitalism run wild.

If we didn't flush toilets but all of a sudden because of some law (directly or indirectly), we started flushing toilets; we should be concerned about it. But that's clearly not the case here and your analogy doesn't hold up.

A better analogy was if you were forced to use the toilet every time you entered a store you haven't been to previously... Just why in the world would I need to take part in such a wasteful charade.

Re: Automating cookie consent and GDPR violation detection

#150
Part of my job is to maintain GDPR compliance for corporate websites. Even for companies that legitimately want to exceed compliance, you would not believe how much of a pain in the ass it is.

The first company wanted to do it "right". So we enabled opt-out by default for all cookies. Which requires setting an anonymized master cookie to check everytime we load a webpage to see if we are allowed to set other cookies. And since IP-detection was not allowed, we did it for all website visitors. And because we have to remember your settings, we had to create a seperate anonymized database outside of our normal website.

And the website broke ALL THE TIME. Product configurators, shopping carts, forms, downtime detection - all this stuff relied on cookies. And for several months the web team had a constant nightmare of customer complaints about broken stuff.

In the first year we ended up spending close to $250k on legal advice from European lawyers, and most of the advice boiled down to "you're not going to get in trouble if you just do what everyone else is doing". Seriously.

Since then it's gotten better - most third party vendors have done a better job of offering anonymized cookie versions of their products. Or there is just more industry guidance available on what kind of cookies can be considered sufficiently anonymous.

For people who claim GDPR compliance is clear and straightforward - I can't believe they actually have much experience working in Privacy. Actual implementation gets... very opaque. Especially when the law says it's illegal to deny service based on their cookie preference, but some services are literally impossible to provide without a cookie of some form.

Post reply on HN