Live data from Hacker News

Where did all the “reject” buttons come from?

noyb.eu

41–50 of 127 posts

Re: Where did all the “reject” buttons come from?

#41
post #5

I wish cookie settings were part of the browser (e.g. I want to reject all marketing cookies but not essential ones), have a way in JS/HTTP to indicate the type of the cookie, and never see those cookie popups again.

It's not just cookies, it affects all client-side storage that can be used to track people. This means that this kind of API would also be needed for localStorage etc. This is where it things will get complicated. I don't know if it exists, but it would probably be a good thing to have aria labels for those common buttons on these popups. It would benefit a11y and pave the way for a better automatic approve/reject by…

It is not just client storage either, it could also be ephemereal computed fingerprinting with server side tracking.

Re: Where did all the “reject” buttons come from?

#42
post #15
post #4

The EU cookie legislation was a mistake made by tech-illiterate bureaucrats that ruined the Web to a large degree. It's something that could've been built in to the browser. I have a hard time understanding why one would dedicate their time to this.

You are confusing the law with the intentionally bad implementation. And it was implemented in the browser as Do Not Track but websites ignored it https://en.m.wikipedia.org/wiki/Do_Not_Track

The problem with DNT is that no one wants tracking, and trackers still want to track. So browsers and users have every reason to always have it set. And trackers have no incentive to acknowledge that and shut their business down.

Re: Where did all the “reject” buttons come from?

#43
post #4

The EU cookie legislation was a mistake made by tech-illiterate bureaucrats that ruined the Web to a large degree. It's something that could've been built in to the browser. I have a hard time understanding why one would dedicate their time to this.

The part I find funny about people calling the bureaucrats tech illiterate, is so many users on tech forums are illiterate on the topic themseleves, e.g., believing deleting cookies is a solution to tracking.

Re: Where did all the “reject” buttons come from?

#44
post #10

Just remove cookie banners unless you’re using an ad network (this includes keeping them if you’re using google products). Users want to use your website rather than look it through a porthole, understand that websites remember you, and cookie banners are killing the web in favour of closed app stores.

>Just remove cookie banners unless you’re using an ad network You also need a cookie banner in EU in case your website uses any cookies that are not necessary to serve the content. This includes analytics, telemetry, and so on. It's not only ads. You can remove the cookie banner if your website uses cookies only for required functionality like log-on.

> You also need a cookie banner in EU in case your website uses any cookies that are not necessary to serve the content.

Not quite, for two reasons:

- The law doesn't care about cookies, it cares about personal data, which includes any data which can individually identify someone (like a cookie associating them with a user account). If you're collecting or processing any personal data, that requires consent; even if you have no cookies.

- The law doesn't care about serving-as-in-content; it cares about providing a service, which could be showing content on a Web site, or could be dispatching orders from a warehouse, or whatever. If someone's personal data is required to provide a service for them, then their consent is implied.

The reason analytics, tracking, ad networks, etc. do not have implied consent, is because the people receiving the service (e.g. those buying ad space) are not the people who the personal data is about (i.e. ad companies cannot consent on my behalf!)

Re: Where did all the “reject” buttons come from?

#45

The button is more prominent, yes. And it's still useless. Most tracking now comes from the "legitimate interest" purposes that you need to actively object to, which is buried in a tertiary hidden panel or not available at all, or even forces you to object to several dozens of trackers one by one.

> Most tracking now comes from the "legitimate interest" purposes that you need to actively object to

This is briefly touched on in the article: in the first graph you can see that the "Legitimate interest claimed" violations they detected dropped by 57% after they filed their complaints.

Re: Where did all the “reject” buttons come from?

#46
post #19
post #4

The EU cookie legislation was a mistake made by tech-illiterate bureaucrats that ruined the Web to a large degree. It's something that could've been built in to the browser. I have a hard time understanding why one would dedicate their time to this.

100% I think the underlying reason is that most people don’t consider trade-offs. “Yes, great let’s do the cookie banner thing. But before, let’s also consider how this could be a bad idea?” “Yes, great let’s ban plastic straws. But also let’s consider what we get instead and if that alternative is really better.” These conversations rarely take place in my experience. You can still decide to do it, but at least you…

In this case, the 'dystopian' situation is not bad, if you consider tracking a bad (lets say 'evil' for exagerated effect) thing.

It means that companies that want to do 'evil' are forced to ask their customers. For now most customers find the question annoying, and some go for the easy option of 'fine do some evil to me' out of convenience. But in the meantime, people are slowly building an awareness of this evil happening to them.

For now the evil is profitable enough with the few people that click agree to evil out of convenience. But people are now being faced with these decisions and will slowly turn against this evil. As this awareness builds, people will start disliking the companies. And as the law gets enforced better, people will find it easier to say 'no' to evil. At some point, this will make the extra friction of cookie acceptance screens no longer worth it, and we will be in a better place.

(Droping the 'evil' shtick here) All the law says is 'if you want to do this generally bad thing, you gotta ask people and you can't trick or coerce them'. This is slowly going to stop the generally bad thing from happening. The alternative "don't do this bad thing" would have a less annoying transition. But that would have been an over-reaching law that doesn't leave space for the few times where the thing is actually not bad.

A more interesting question is 'without surveillance supported adds, how will the internet actually work'. Especially given that the EU laws are aimed at effectively killing the surveillance supported add industry. This is not something the EU laws have an answer to. I find this the most worrying question, though I see little room for a new way to finance the internet that is worse then surveillance supported adds.

Re: Where did all the “reject” buttons come from?

#47
post #31

I've set my browser to delete cookies at close. You can accept all cookies without problem, and after lunch everything is forgotten. A few websites that I go to often get special treatment (Hacker News!), because I'm to lazy to press ok each time.

That would mean they get deleted every few months when an OS update forces me to reboot only. Why would I ever close my browser?

I reboot my browser weekly to service browser security patches.

Re: Where did all the “reject” buttons come from?

#48
post #37

The button is more prominent, yes. And it's still useless. Most tracking now comes from the "legitimate interest" purposes that you need to actively object to, which is buried in a tertiary hidden panel or not available at all, or even forces you to object to several dozens of trackers one by one.

What are these 'legitimate interest' things, and is it even possible to object to them, legally speaking? I have never seen these I believe, unless you mean 'analytics cookies' and 'functional cookies', which I never saw hidden. I did presume that a 'reject all' included rejecting these cookies, if not it would be great to know.

There's some weird thing in the law. You can accept or reject data collection, but they can collect data for which a legitimate business interest exists unless you object - so if the law makes it default to no, you reject, but if it's default yes, you have to object. As far as I know, you have a right to object, so yes, legally speaking, it is possible to object to them. This means that there's frequently a second page of third-party/'legitimate interest' cookies, which might have an additional "Object all" button, or it might be that you have to click object one by one.

One example is https://www.bbc.com. Open it in a private window and you should see the invasion-of-privacy popup. You have a "Consent" and "Do not consent" button, but underneath there's also "Manage options". Click and and now you can see that there's a bunch of enabled toggles mixed in with the disabled ones, each of them headed "Legitimate interest" and the help text warns "Some vendors are not asking for your consent, but are using your personal data on the basis of their legitimate interest". So notice the text says that if you do not consent it is not relevant: they're going to do use your data on the basis of their legitimate interest. You must object to these in order to counter their right.

This is because the BBC hates you and wants you to be unhappy.

Re: Where did all the “reject” buttons come from?

#49
post #15

Earlier quoted context omitted.

You are confusing the law with the intentionally bad implementation. And it was implemented in the browser as Do Not Track but websites ignored it https://en.m.wikipedia.org/wiki/Do_Not_Track

No he isn't. The law is precisely what allows the intentionally bad implementations. Anyone could have foreseen this. Hell we already knew this would happen based on the earlier cookie laws. The EU should have mandated an interaction-free solution like Do Not Track. They could have.

1. GDPR isn't just about cookies. It's about your data in general. So it covers even offline interactions.

2. Governments shouldn't mandate solutions. Instead, EU stipulated a requirement. And industry as a whole decided that they will break the law for as long as possible until the governments chase after them. In the process the industry has convinced gullible developers that it is the law that it is bad, and not the greedy leeches who flaunt it.

Re: Where did all the “reject” buttons come from?

#50
post #15
post #4

The EU cookie legislation was a mistake made by tech-illiterate bureaucrats that ruined the Web to a large degree. It's something that could've been built in to the browser. I have a hard time understanding why one would dedicate their time to this.

You are confusing the law with the intentionally bad implementation. And it was implemented in the browser as Do Not Track but websites ignored it https://en.m.wikipedia.org/wiki/Do_Not_Track

>And it was implemented in the browser as Do Not Track but websites ignored it

Implemented in the browser AND mandated by law to be respected - in other words, similar enforcement as the current cookie notice, but with a uniform interface and central control.

Post reply on HN