Live data from Hacker News

People who press on cookie banners anything except “agree” – why do you do that?

news.ycombinator.com

251–260 of 265 posts

Re: People who press on cookie banners anything except “agree” – why do you do that?

#251

Earlier quoted context omitted.

Their sheer volume. Drive into a major city in some country where ads are entirely unregulated. There will be billboards everywhere, impossible to take it all in or critically assess it.

as opposed to the internet, where the content is bounded and manageable? I fail to see how you can square such disdain for ads while taking part in an online forum like hackernews

My head has limited capacity. I'm happy to filter out ads. Thankfully, HN doesn't need the filter.

I also think constant lies on TV is a problem. I of course believe somewhat in my own ability to filter through, but at the end of the day, it is reality-distorting when it goes on in large scale and a societal problem!

Re: People who press on cookie banners anything except “agree” – why do you do that?

#252
post #142

I still remember the day, when the browser would show you a pop-up "Allow somesite.com to set a cookie? Yes - No"... Something like that (with a "remember this choice" checkbox) would be so much more economical, than making every single website implement it individually. When the browser does it, then websites also can't ignore it, cheat it, or use dark patterns to avoid it.

I don't remember this and probably should. Did this have a name? What browsers had this behavior?

Netscape. Well, at least some versions of it.

In the browser settings you could switch the "accept cookies" behavior between "never" - "ask" - "always". I believe it was set to "always" by default? It's been a long time ago, so I'm bit fuzzy on the details.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#253
post #142

I still remember the day, when the browser would show you a pop-up "Allow somesite.com to set a cookie? Yes - No"... Something like that (with a "remember this choice" checkbox) would be so much more economical, than making every single website implement it individually. When the browser does it, then websites also can't ignore it, cheat it, or use dark patterns to avoid it.

The big misconception is that the consent forms are only about cookies. They aren't - they are about data collection and processing in general, no matter the technical means. It could be cookies, but it could be IP addresses, browser fingerprinting, or information you manually entered for a specific purpose (delivery address to receive a package) and don't want to be reused for other purposes such as marketing or tra…

You are right about consent forms - but pure cookie banners: "this site uses cookies - OK" do exist as well - or at least did exist for a time, mandated by a law predating the GDPR.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#254
post #211

Earlier quoted context omitted.

A lot of GDPR is (intentionally) misrepresented. Apache logs for example do not run afoul of GDPR unless you: A) process them. (Correlate them with further identification) B) sell them. C) do nothing to secure them. Regardless. The law does have conditions for these cookie banners. Namely that if you do not present an easy 2 click opt out then you’re in violation. Many people are in violation in what I feel is an att…

I'm not sure a lawyer would agree with your assessment of the Apache logs. If they aren't actively being used to maintain site health, the mere collection of private IPs is enough to make them unnecessary private information. And that's the default for collection of Apache logs.

I guess it varies depending on the lawyer, mine agrees with my interpretation.

Law depending on the opinion of lawyers is “useful”.

If anyone wants to attempt to prosecute me for storing Apache logs then I’m happy to defend it in court. GDPR isn’t the boogeyman unless you’re selling data. I’m quite certain there are sympathetic judges to that end. Logs are necessary and even in some cases legally mandatory.

I would talk to your lawyer.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#255

Earlier quoted context omitted.

> Advertisers were very clear that they would only honor DNT if it people were tracked by default. It's ridiculous that Microsoft's response wasn't to just nuke trackers from space with some kind of adware blocker integration in Edge. This is the equivalent of a mugger saying he'll only honour your "do no mug" sign if the sign defaults to "mug me please" and has to be explicitly changed.

Microsoft is part of "them" now though given their direction since Windows 10, so I find that very unlikely.

While you are right that Microsoft loosened their stance with privacy, let's not conflate data collection purposes:

1. telemetry, for diagnostics and health monitoring

2. usage analysis, for program improvement and personalization

3. content analysis, for advertising and marketing purposes

Windows requires kind 1 and encourages kind 2*. Type 3 does not really apply, though, as I don't see Windows sniffing what I write in my text files so that I'm shown relevant ads later.

It's all explained here: https://privacy.microsoft.com/en-us/data-collection-windows

* Also note that the Customer Experience Improvement Program has been with us since Windows 7. Same thing, just not perceived as badly as Windows 10.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#256

Meta: why is that post's text gray and hard to read? This is how HN punishes low-voted comments, right? Yet it seems counterproductive to do so for submissions.

That's just the formatting for this type of article. It isn't connected to any type of upvote or downvote in this case. You are correct in that downvoted pists are made harder to read, and eventually end up dead or invisible. In fact, those posts can be forced to render by activating show_dead in your profile if you're feeling adventurous.

The formatting of this type of article is counterproductive, it's hard to read and the emotional conditioning from using HN is that gray text = questionable comment.

@dang: why? :)

Re: People who press on cookie banners anything except “agree” – why do you do that?

#257
post #252

Earlier quoted context omitted.

I don't remember this and probably should. Did this have a name? What browsers had this behavior?

Netscape. Well, at least some versions of it. In the browser settings you could switch the "accept cookies" behavior between "never" - "ask" - "always". I believe it was set to "always" by default? It's been a long time ago, so I'm bit fuzzy on the details.

Found it - it actually was an extra checkbox.

see: https://www.fabrica.cz/fabrica/img/netscape.jpg

Re: People who press on cookie banners anything except “agree” – why do you do that?

#258
post #254

Earlier quoted context omitted.

I'm not sure a lawyer would agree with your assessment of the Apache logs. If they aren't actively being used to maintain site health, the mere collection of private IPs is enough to make them unnecessary private information. And that's the default for collection of Apache logs.

I guess it varies depending on the lawyer, mine agrees with my interpretation. Law depending on the opinion of lawyers is “useful”. If anyone wants to attempt to prosecute me for storing Apache logs then I’m happy to defend it in court. GDPR isn’t the boogeyman unless you’re selling data. I’m quite certain there are sympathetic judges to that end. Logs are necessary and even in some cases legally mandatory. I would t…

With a 20 million euro minimum fine on the table, I don't think I'll feel comfortable on this topic until either the law is clarified or someone sets precedent.

My lawyer's great, but he won't be paying the fine if he's wrong.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#259

1. Sure. Though in my case this applies to both options, I'm not storing cookies for webpages I don't deliberately want to be remembered by. 2. If present I'll click 'Deny', but I'm not hunting it down. Blocking the prompt with an adblocker is my preferred option. 3. Cookie Autodelete is the only sensible way to manage cookies IMHO. Store cookies for webpages you trust, delete all others. Annoyingly there's no offici…

> Cookie banners are entirely pointless since I'm fully in control of which cookies I am sharing. The GDPR covers the intent and processing of the data rather than any specific technical means - it's not limited to cookies. Please see my other comment: https://news.ycombinator.com/item?id=30964163

I don't think the GDPR mandates cookie banners at all, but somehow I'm still subjected to them. Most of them don't (explicitly) ask to collect my data, they just ask if they can use cookies.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#260
post #211

Earlier quoted context omitted.

A lot of GDPR is (intentionally) misrepresented. Apache logs for example do not run afoul of GDPR unless you: A) process them. (Correlate them with further identification) B) sell them. C) do nothing to secure them. Regardless. The law does have conditions for these cookie banners. Namely that if you do not present an easy 2 click opt out then you’re in violation. Many people are in violation in what I feel is an att…

I'm not sure a lawyer would agree with your assessment of the Apache logs. If they aren't actively being used to maintain site health, the mere collection of private IPs is enough to make them unnecessary private information. And that's the default for collection of Apache logs.

You would be 100% in the clear on that as long as you apply a reasonable retention policy to your logs. Keeping them forever isn't reasonable. Keeping them for a year almost certainly is.

You would be 99% in the clear if you do nothing. The worst that's likely to happen is that you're forced to adopt a retention policy and delete old logs, and even that is extremely unlikely unless you are Google/Facebook scale or are doing something significantly worse than industry standards.

Post reply on HN