Live data from Hacker News

Where did all the “reject” buttons come from?

noyb.eu

51–60 of 127 posts

Re: Where did all the “reject” buttons come from?

#51

Earlier quoted context omitted.

No he isn't. The law is precisely what allows the intentionally bad implementations. Anyone could have foreseen this. Hell we already knew this would happen based on the earlier cookie laws. The EU should have mandated an interaction-free solution like Do Not Track. They could have.

There is an interaction-free solution; it's called 'do not track' (as in, not tracking users). The EU don't mandate it, since that would probably be considered over-reach: if Web sites want to break their UI and annoy their users, they're free to do so. Consent for personal data is implied when performing services for a user (e.g. logging in, shopping carts, remembering high-scores, etc.). Interactions are only neede…

>There is an interaction-free solution; it's called 'do not track' (as in, not tracking users). The EU don't mandate it

If it's not mandated it's not a solution, it's more like a pacifist asking for peace in the middle of WWII

>The EU don't mandate it, since that would probably be considered over-reach

I don't think that's the reason, as it wouldn't be any more overeach than mandating the current cookie notice (or, in another domain, USB-C for mobile phones).

Re: Where did all the “reject” buttons come from?

#52

Earlier quoted context omitted.

No he isn't. The law is precisely what allows the intentionally bad implementations. Anyone could have foreseen this. Hell we already knew this would happen based on the earlier cookie laws. The EU should have mandated an interaction-free solution like Do Not Track. They could have.

1. GDPR isn't just about cookies. It's about your data in general . So it covers even offline interactions. 2. Governments shouldn't mandate solutions . Instead, EU stipulated a requirement . And industry as a whole decided that they will break the law for as long as possible until the governments chase after them. In the process the industry has convinced gullible developers that it is the law that it is bad, and no…

>Governments shouldn't mandate solutions

Huh? That's what we have governments for.

Re: Where did all the “reject” buttons come from?

#53
Cookie pop-ups are incredibly annoying and greatly harm the usability of the web.

Either GDPR should be updated to ban consent pop-ups and simply make “REJECT” the default everywhere, or the consent UI should be moved to the browser where defaults (accept/reject/ask) can be set for all websites.

Re: Where did all the “reject” buttons come from?

#54

The button is more prominent, yes. And it's still useless. Most tracking now comes from the "legitimate interest" purposes that you need to actively object to, which is buried in a tertiary hidden panel or not available at all, or even forces you to object to several dozens of trackers one by one.

My layman's understanding of the GDPR was that it was the primary website (i.e. the website you are actually and intentionally visiting) that could store your data on the basis of a legitimate business interest -- for example because they need that information to deliver some stuff you ordered from them.

However someone seems to have found a legal loophole whereby third parties ostensibly are able to track you on the grounds that their business is tracking, and they therefore have a legitimate interest in tracking you.

Hopefully this loophole is eventually struck down in some French or German court, and the GDPR will one day be applied as intended. Tracking is not, and will never be, a legitimate business.

Re: Where did all the “reject” buttons come from?

#55
post #37

The button is more prominent, yes. And it's still useless. Most tracking now comes from the "legitimate interest" purposes that you need to actively object to, which is buried in a tertiary hidden panel or not available at all, or even forces you to object to several dozens of trackers one by one.

What are these 'legitimate interest' things, and is it even possible to object to them, legally speaking? I have never seen these I believe, unless you mean 'analytics cookies' and 'functional cookies', which I never saw hidden. I did presume that a 'reject all' included rejecting these cookies, if not it would be great to know.

IANAL and all that.

This is the most vague part of the law because the law couldn't just forbid everything and then run into issues.

For example, to run a business a merchant doesn't need anything more from you beside you name and address (and login info if they need to show you your order history). They don't need to ask you for your consent to collect this info because this info is required for their service to operate.

However, they also want to run fraud protection. So they need to collect more data (e.g. your birth date, your IP address, perhaps other data). They have a legitimate reason to collect this data even if this data is not strictly required.

As with any vague parts this "legitimate" part is now abused by the ad industry.

Re: Where did all the “reject” buttons come from?

#56

Cookie pop-ups are incredibly annoying and greatly harm the usability of the web. Either GDPR should be updated to ban consent pop-ups and simply make “REJECT” the default everywhere, or the consent UI should be moved to the browser where defaults (accept/reject/ask) can be set for all websites.

The nightly build of Brave will automatically manage the banners for you.

Re: Where did all the “reject” buttons come from?

#57

I've set my browser to delete cookies at close. You can accept all cookies without problem, and after lunch everything is forgotten. A few websites that I go to often get special treatment (Hacker News!), because I'm to lazy to press ok each time.

I close my browser regularly to delete cookies on close, but i also run ccleaner regularly. Nothing worse than being logged into gmail...open youtube...already logged in. Not cool if i want to check put a video anonymously (ie not linked to my login). I also change my spoof user aget and change vpn exit, too. Regularly annoying, but i do enjoy the thought that somebody is not getting from me what they thought they might.

Re: Where did all the “reject” buttons come from?

#58
This cookie malarkey is about a breakdown of protocol. If two entities no longer intend to cooperate and honour each others signals, all bets are off for building reliable economies on that technology. What's holding "web" together right now is the monopoly of a few browsers that more or less force users to accept insecure settings against their interests in order to keep them talking to hostile services.

Re: Where did all the “reject” buttons come from?

#59
post #54

The button is more prominent, yes. And it's still useless. Most tracking now comes from the "legitimate interest" purposes that you need to actively object to, which is buried in a tertiary hidden panel or not available at all, or even forces you to object to several dozens of trackers one by one.

My layman's understanding of the GDPR was that it was the primary website (i.e. the website you are actually and intentionally visiting) that could store your data on the basis of a legitimate business interest -- for example because they need that information to deliver some stuff you ordered from them. However someone seems to have found a legal loophole whereby third parties ostensibly are able to track you on the…

> Tracking is not, and will never be, a legitimate business.

The problem is, the way the Internet and its services are financed, it is pretty much a requirement.

A lot of services absolutely depend on advertising revenue because affordable micro-transactions still are not a thing, not to mention 20 years of cultural ingrainment that services on the Internet have to be free when they are aimed at the general public. The alternative is philantropy aka rich billionaires footing the bill - we're seeing with the Washington Post (Bezos), Twitter (Musk) or Austrian newspapers just how problematic that is. The only relevant project surviving off of individual donations is Wikipedia and even that has issues (see e.g. the endowment debate that regularly pops up here), Mozilla depends on Google's money. Another alternative that regularly pops up, especially in Europe, is having the government fund services - but let's be real, who wants to use a messenger where the government has any sort of involvement? China shows why this is a very bad idea.

So basically, now that we have established that currently advertising is required, another can of worms opens up: ad fraud, which is incredibly widespread. Everyone but the advertiser clients has a massive financial interest in manipulations:

- ad networks want to claim "x millions of sites use our services to show ads", so they have an incentive to create fake sites that no one ever looks at

- ad agencies want to claim reachout capacity (to their clients) and maximize ad eyeballs because often they're paid as a percentage of ad spend

- content creators want to have as much income as they possibly can get. Click fraud and SEO spam fake sites/content mills come to mind here.

Advertisers, in turn, want to minimize their ad spend and maximize the ROI. That means they need a way to target ads to specific demographic groups, they need a way to weed out fraudulent spending and they need a way to weed out undesirable context (i.e. no popular brand wants to show a pre-roll ad to Alex Jones claiming crisis actors). And that is where tracking and other "middlemen" companies come in - they serve to protect advertisers from overspending and bullshit, and provide the actual data required for targeting.

The only groups that could get away without tracking and countless middlemen services are "household brands" that simply book ads at massive TV and radio stations and niche magazines and their advertising clients (say, a magazine about farming naturally yields itself to equipment manufacturers, pesticide and other farm suppliers) - but even there, media has an incentive to over-inflate their reader/viewer/listener counts to demand more money from advertisers, so they need third parties like Nielsen Ratings as independent "arbiters".

Re: Where did all the “reject” buttons come from?

#60
post #10

Just remove cookie banners unless you’re using an ad network (this includes keeping them if you’re using google products). Users want to use your website rather than look it through a porthole, understand that websites remember you, and cookie banners are killing the web in favour of closed app stores.

>Just remove cookie banners unless you’re using an ad network You also need a cookie banner in EU in case your website uses any cookies that are not necessary to serve the content. This includes analytics, telemetry, and so on. It's not only ads. You can remove the cookie banner if your website uses cookies only for required functionality like log-on.

You can have all those things without cookies.

And you will need consent, because it has nothing to do with cookies. You need a telemetry banner.

Post reply on HN