Live data from Hacker News

People who press on cookie banners anything except “agree” – why do you do that?

news.ycombinator.com

261–265 of 265 posts

Re: People who press on cookie banners anything except “agree” – why do you do that?

#261
post #254

Earlier quoted context omitted.

I guess it varies depending on the lawyer, mine agrees with my interpretation. Law depending on the opinion of lawyers is “useful”. If anyone wants to attempt to prosecute me for storing Apache logs then I’m happy to defend it in court. GDPR isn’t the boogeyman unless you’re selling data. I’m quite certain there are sympathetic judges to that end. Logs are necessary and even in some cases legally mandatory. I would t…

With a 20 million euro minimum fine on the table, I don't think I'll feel comfortable on this topic until either the law is clarified or someone sets precedent. My lawyer's great, but he won't be paying the fine if he's wrong.

$20 million isn't the minimum fine. That's the maximum fine for companies with under $500 million in annual turnover.

You aren't going to get the maximum fine unless you are doing something egregious. Collecting the default Apache logs and not using them for anything malicious isn't going to get you the maximum fine or likely any fine at all.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#262
post #225
post #219

Earlier quoted context omitted.

Not a newbie. Let 'em use a MiB or so from my legimate browsing session with legitimate IP to perpetrate click fraud or auction fraud or whatever. That'll make it harder for fraud detection to work (the traffic is legitimate, organic traffic after all). If enough people do it, tracking firms that ignore DNT will have garbage datasets or worse. I've worked on systems for detecting this sort of fraud. Systematically in…

You want to let people commit whatever fraud they want using your computer? Knowingly? How will you defend yourself in court? "I didn't do it, I just let somebody else use my machine, yes I knew they were up to no good that was the point, but to my defense I was shown an ad"?

The tracking servers are using my computer without authorization. (The "do not track" header specifically told them so.)

So, their complaint is what, exactly? They tried to run unauthorized code on my machine, it noticed, and forwarded the unauthorized logic/connection/nonce/etc to a honeypot?

This isn't an actual service I plan to build. If someone else does, and prevails in court, rest assured I'll be cheering them on.

Re: People who press on cookie banners anything except “agree” – why do you do that?

#263

Earlier quoted context omitted.

Microsoft is part of "them" now though given their direction since Windows 10, so I find that very unlikely.

While you are right that Microsoft loosened their stance with privacy, let's not conflate data collection purposes: 1. telemetry, for diagnostics and health monitoring 2. usage analysis, for program improvement and personalization 3. content analysis, for advertising and marketing purposes Windows requires kind 1 and encourages kind 2*. Type 3 does not really apply, though, as I don't see Windows sniffing what I writ…

Without a law like the GDPR, nothing stops them from using data collected for 1) and 2) for 3). Which they will do once some PM realizes it's worth something.

(There's even 0), data collected for functional purposes like 2FA. Multiple companies have taken data straight from 0 to 3 once they see the possible revenue.)

Re: People who press on cookie banners anything except “agree” – why do you do that?

#264
I just use Brave, that blocks most tracking, and click whatever, for the majority o sites those banners in the "real" world, mostly likely dont't change anything behind the curtains anyways.

Most sites probably just put it as a cosmetic to adhere to policy laws.

I can trust much more my browser to block the tracking or data collection, than a"don't agree" button on any site".

Re: People who press on cookie banners anything except “agree” – why do you do that?

#265
I only surf the web with my browser in private mode, using a virtual machine that boots a live Linux distribution and through a mainstream VPN service.

Any banner that pops up to my face, I click "agree"and don't look backwards.

I understand I can still be identified using some browser fingerprinting tricks, but I have absolutely zero trust in any of these privacy notices/policies.

Disclaimer: part of my actual job is to assess whether my clients' systems/applications effectively comply with privacy laws and the policy shown to users/customers. I have never seen a company that does what it promises to its users and I've been doing this job since 2015.

Post reply on HN