Live data from Hacker News

People who press on cookie banners anything except “agree” – why do you do that?

news.ycombinator.com

211–220 of 265 posts

Re: People who press on cookie banners anything except “agree” – why do you do that?

#211

Earlier quoted context omitted.

Well, yes, law enforcement in general is a cat-and-mouse game. That doesn't mean we shouldn't have any laws.

I 100% agree, but I feel like the proliferation of consent banners was predictable and if people didn't want it, the law should have initially accounted for it. Assuming people would just log less was hopelessly naive (especially given that apache defaults already do enough logging to run afoul of the GDPR).

A lot of GDPR is (intentionally) misrepresented.

Apache logs for example do not run afoul of GDPR unless you:

A) process them. (Correlate them with further identification)

B) sell them.

C) do nothing to secure them.

Regardless. The law does have conditions for these cookie banners. Namely that if you do not present an easy 2 click opt out then you’re in violation. Many people are in violation in what I feel is an attempt at a sort of civil disobedience. “They can’t prosecute us if we all do it” mentality.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#212
I block the banners outright without interacting with them with uBlock Origin usually, unless that causes site breakage. Usually doesn’t.

TechCrunch doesn’t like this. They have some kind of Yahoo cookie consent thing you have to interact with. You can deny everything though.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#213

Earlier quoted context omitted.

Most ads have no content that can be subjected to critical assessment. Geico's terrible comedy sketches are not designed to convince you that they have a good product – they're designed to rattle around in your mind and influence you subconsciously. To the extent that they succeed in that, they make people behave less rationally, and are of negative social utility. And if they don't succeed, then they're just a point…

I certainly can critically assess Geico's ads - just like you did in your analysis above So your real issue is that people are spending their time and energy on something you don't like

You can assess their comedic and social value, but you can't assess their argument about car insurance, because there isn't one. They're trying to manipulate how you feel, not convince you of some point. It's like if, rather than making an argument in this comment to convince people of my point, I just said "Lol, imagine being such a corporate beta cuck." Some not-particularly-mature people might be influenced by that statement, perhaps more than by an actual argument, but it would be an inappropriate and underhanded tactic.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#214

Earlier quoted context omitted.

> The easiest way to avoid having a banner on your site is to... just not have an analytics package on your site. What if there's back-end only analytics? Does that require a banner?

If you're storing personal data, you need consent. A banner would be the least intrusive way to do that. (If your backend analytics don't store a cookie and don't store IPs, you may not be storing personal data to begin with.)

> If you're storing personal data, you need consent.

Could you explain this claim? I'm seeing it more often and I wonder if there's something I'm missing.

GDPR Article 6 gives five other legal bases for processing. From my reading, consent is just another basis you can use if the others don't work.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#215
post #214

Earlier quoted context omitted.

If you're storing personal data, you need consent. A banner would be the least intrusive way to do that. (If your backend analytics don't store a cookie and don't store IPs, you may not be storing personal data to begin with.)

> If you're storing personal data, you need consent. Could you explain this claim? I'm seeing it more often and I wonder if there's something I'm missing. GDPR Article 6 gives five other legal bases for processing. From my reading, consent is just another basis you can use if the others don't work.

In the context of backend analytics, it is difficult-to-impossible for any of those others to apply. The point is that FE vs. BE, cookie vs. no cookie isn’t really what matters. What data you collect and why is what matters.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#216
post #185
post #145

Earlier quoted context omitted.

At this point, I'd be happy with a service that has my browser send a "do not track" header on each request, and also open a proxy connection to a black hat server each time the page decided to make a request to a known tracking domain.

A "black hat server"?

Someone is trying to convey that a plugin should report sites that are detected ignoring DNT to ne'er'do'wells to invite horrible things to happen to them.

It's a newbie, be nice. They don't get how it works yet.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#217

Meta: why is that post's text gray and hard to read? This is how HN punishes low-voted comments, right? Yet it seems counterproductive to do so for submissions.

That's just the formatting for this type of article. It isn't connected to any type of upvote or downvote in this case.

You are correct in that downvoted pists are made harder to read, and eventually end up dead or invisible.

In fact, those posts can be forced to render by activating show_dead in your profile if you're feeling adventurous.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#218
post #211

Earlier quoted context omitted.

I 100% agree, but I feel like the proliferation of consent banners was predictable and if people didn't want it, the law should have initially accounted for it. Assuming people would just log less was hopelessly naive (especially given that apache defaults already do enough logging to run afoul of the GDPR).

A lot of GDPR is (intentionally) misrepresented. Apache logs for example do not run afoul of GDPR unless you: A) process them. (Correlate them with further identification) B) sell them. C) do nothing to secure them. Regardless. The law does have conditions for these cookie banners. Namely that if you do not present an easy 2 click opt out then you’re in violation. Many people are in violation in what I feel is an att…

I'm not sure a lawyer would agree with your assessment of the Apache logs. If they aren't actively being used to maintain site health, the mere collection of private IPs is enough to make them unnecessary private information.

And that's the default for collection of Apache logs.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#219
post #185

Earlier quoted context omitted.

A "black hat server"?

Someone is trying to convey that a plugin should report sites that are detected ignoring DNT to ne'er'do'wells to invite horrible things to happen to them. It's a newbie, be nice. They don't get how it works yet.

Not a newbie. Let 'em use a MiB or so from my legimate browsing session with legitimate IP to perpetrate click fraud or auction fraud or whatever.

That'll make it harder for fraud detection to work (the traffic is legitimate, organic traffic after all). If enough people do it, tracking firms that ignore DNT will have garbage datasets or worse.

I've worked on systems for detecting this sort of fraud. Systematically injecting malicious traffic into legitimate click streams would defeat most anti-abuse measures that I've seen.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#220
post #190

Earlier quoted context omitted.

People see "targeted advertising" as "I was thinking about buying a bike and it shows me ads for bikes", ie. it's showing me what I want to see . That is not targeted advertising. Targeted advertising is showing you what they want you to see when they want you to see it, or showing you the same products in a light that makes you more likely to buy them. For example, showing you unlikely or imagined bike-related probl…

you have quite a low view of people's ability to make decisions for themselves if you think being shown ads is manipulation. And I struggle to see how targeted ads are somehow worse than the same sort of 'manipulation' inherent in using an algorithmic feed like HackerNews or Twitter. Both are exposing you to things they want you to see. Yet you don't seem to have such strong opposition to those as you do targeted ads…

> you have quite a low view of people's ability to make decisions for themselves if you think being shown ads is manipulation.

The ENTIRE POINT of an ad is manipulation. Advertisers wouldn't bother if people always ignored ads.

Post reply on HN