Live data from Hacker News

Where did all the “reject” buttons come from?

noyb.eu

111–120 of 127 posts

Re: Where did all the “reject” buttons come from?

#111
post #82

Earlier quoted context omitted.

Reject is the default! That's the point of the law in the first place. If you, for example, blocked every consent dialog from appearing, no website would have legal grounds to track you (except for legitime purposes yada-yada).

> "Reject is the default!" I wish that was true. > "If you, for example, blocked every consent dialog from appearing, no website would have legal grounds to track you (except for legitime purposes yada-yada)." Sounds good to me!

> I wish that was true.

Is it? He just said it was and he's right.

Re: Where did all the “reject” buttons come from?

#112

Earlier quoted context omitted.

> ”They cannot ban people from asking users for consent to collect data.” Why not? This is exactly what needs to happen. Either that, or allow cookie consent to be granted/declined globally in the browser settings, not with a bespoke, intrusive UI on every. single. damn. website. Let’s ban cookie pop ups!

> Why not? This is exactly what needs to happen. No, it's not. Because there are actual legitimate reasons for organisations and businesses to ask for user's consent. > Either that, or allow cookie consent You keep missing the simple fact that GDPR is not about cookie consents . How many times do I have to repeat this? > not with a bespoke, intrusive UI on every. single. damn. website. Again. In as simple terms as I…

> "You keep missing the simple fact that GDPR is not about cookie consents. How many times do I have to repeat this?"

Fine. That's great: if GDPR is not about cookie consents then let's get rid of the damned pop-ups! If that means no more tracking cookies, then so be it. That's a good thing!

This is no different to the behaviour when a user clicks "reject non essential cookies" and also no different to what Apple already did with apps that accessed advertising tracking IDs on iOS. Facebook complained and lost a little money, but the world didn't end and the sky didn't fall. (iOS users can still choose to let apps track, but that UI is provided by the OS, not the app, and can be set globally).

> "makes legitimate cases for asking for user consent illegal"

I'm not at all suggesting that consent shouldn't still be asked for in situations where it's legitimate, like storing actual user personal data that they provide when signing up for an account, for example.

But simply visiting a website should not be considered a legitimate reason to obtain or store a user's data. Therefore there is no reason to ask for consent, and the practice should be banned.

Re: Where did all the “reject” buttons come from?

#113

Earlier quoted context omitted.

> Why not? This is exactly what needs to happen. No, it's not. Because there are actual legitimate reasons for organisations and businesses to ask for user's consent. > Either that, or allow cookie consent You keep missing the simple fact that GDPR is not about cookie consents . How many times do I have to repeat this? > not with a bespoke, intrusive UI on every. single. damn. website. Again. In as simple terms as I…

> "You keep missing the simple fact that GDPR is not about cookie consents. How many times do I have to repeat this?" Fine. That's great: if GDPR is not about cookie consents then let's get rid of the damned pop-ups! If that means no more tracking cookies, then so be it. That's a good thing! This is no different to the behaviour when a user clicks "reject non essential cookies" and also no different to what Apple alr…

> I'm not suggesting that consent shouldn't still be asked for in cases where it's legitimate, like storing actual user personal data that they provide when signing up for an account, for example.

Guess what. In this case the you don't have to ask for user consent. Because this data is strictly essential to site functionality.

> But simply visiting a website should not be considered a legitimate reason to obtain or store a user's data.

Guess what. It's exactly what GDPR is saying.

Re: Where did all the “reject” buttons come from?

#114

Earlier quoted context omitted.

> "You keep missing the simple fact that GDPR is not about cookie consents. How many times do I have to repeat this?" Fine. That's great: if GDPR is not about cookie consents then let's get rid of the damned pop-ups! If that means no more tracking cookies, then so be it. That's a good thing! This is no different to the behaviour when a user clicks "reject non essential cookies" and also no different to what Apple alr…

> I'm not suggesting that consent shouldn't still be asked for in cases where it's legitimate, like storing actual user personal data that they provide when signing up for an account, for example. Guess what. In this case the you don't have to ask for user consent. Because this data is strictly essential to site functionality. > But simply visiting a website should not be considered a legitimate reason to obtain or s…

> "Guess what. It's exactly what GDPR is saying."

But that is not how it is being interpreted in practice.

Clearly we just need to go one step further and explicitly say "it is not permitted for consent for tracking cookies to be obtained by the use of a pop-up UI that appears when a user visits a website". Problem solved.

Re: Where did all the “reject” buttons come from?

#115
post #111

Earlier quoted context omitted.

> "Reject is the default!" I wish that was true. > "If you, for example, blocked every consent dialog from appearing, no website would have legal grounds to track you (except for legitime purposes yada-yada)." Sounds good to me!

> I wish that was true. Is it? He just said it was and he's right.

If reject was the default (or it could be set globally, in the browser) then we wouldn't need pop-ups.

Re: Where did all the “reject” buttons come from?

#116

Earlier quoted context omitted.

> I'm not suggesting that consent shouldn't still be asked for in cases where it's legitimate, like storing actual user personal data that they provide when signing up for an account, for example. Guess what. In this case the you don't have to ask for user consent. Because this data is strictly essential to site functionality. > But simply visiting a website should not be considered a legitimate reason to obtain or s…

> "Guess what. It's exactly what GDPR is saying." But that is not how it is being interpreted in practice. Clearly we just need to go one step further and explicitly say "it is not permitted for consent for tracking cookies to be obtained by the use of a pop-up UI that appears when a user visits a website". Problem solved.

> But that is not how it is being interpreted in practice.

No. In practice it's actually being interpreted correctly. What is being willfully misinterpreted is how easily a user can opt-out. Because the industry wants to remain exactly the same: it wants to siphon user data and sell it en masse.

The existing pop ups that use dark patterns to make the user click "accept" are already illegal.

> it is not permitted for consent for tracking cookies to be obtained by the use of a pop-up UI that appears when a user visits a website

So it won't be a pop-up. It will be an interstitial page. You keep focusing in the entirely wrong issue and blaming the law for it.

So, we've banned pop ups. Now what? Now every time you visit a web site, you get a full page asking for your consent.

Then you'll blame the law and ask to ban interstitials.

Ok. We'll ban interstitials. Now it will be banners. Or every second paragraph in text. Videos. Images.

Where the law just says: do not collect user data without user's consent, and the user isn't obliged to give you that consent.

And the industry replies: screw this, we demand this data and make users' life hell for it.

Somehow gullible devs are now fully convinced that the law requires all this.

Re: Where did all the “reject” buttons come from?

#117

Earlier quoted context omitted.

> "Guess what. It's exactly what GDPR is saying." But that is not how it is being interpreted in practice. Clearly we just need to go one step further and explicitly say "it is not permitted for consent for tracking cookies to be obtained by the use of a pop-up UI that appears when a user visits a website". Problem solved.

> But that is not how it is being interpreted in practice. No. In practice it's actually being interpreted correctly. What is being willfully misinterpreted is how easily a user can opt-out. Because the industry wants to remain exactly the same: it wants to siphon user data and sell it en masse. The existing pop ups that use dark patterns to make the user click "accept" are already illegal. > it is not permitted for…

I’m not necessarily blaming the law, but saying that a new law (or change to the existing one) is needed to ban cookie pop-ups.

It’s clear at this point that the problem is not going to go away without intervention. The industry isn’t going to fix itself.

Also, it’s unfair to blame developers here. Devs don’t have some perverse desire to create annoying pop-ups. They’re being told to do it by management and legal teams, because that’s how the GDPR has been interpreted.

> ”So it won't be a pop-up. It will be an interstitial page.”

Ok, so you phrase it more generally: “it is not permitted for consent for tracking cookies to be obtained when a user visits a website”

Re: Where did all the “reject” buttons come from?

#118
post #102

Earlier quoted context omitted.

Some sites certainly do present the only options "accept or go away", it slightly more subtle "by continuing..."¹. IIRC this is against both the meaning and the letter of the law, but that is not practical to properly enforce so they get away with it.

the worst are accept or pay. i found it especially annoying to see that on a site like heise.de who should really know better.

There is at least some honesty in pay one way or another. The ad industry is so very rarely even that honest, that it is almost refreshing.

Re: Where did all the “reject” buttons come from?

#119
post #98
post #47

Earlier quoted context omitted.

I reboot my browser weekly to service browser security patches.

What browser has weeks security holes?

Firefox fixes security 1-2x per month [0]. Chrome's security page is more difficult to grep since it includes multiple software types, but I see 1-2x per month as well [1].

[0] - https://www.mozilla.org/en-US/security/advisories/ [1] - https://chromereleases.googleblog.com/search/label/Stable%20...

Re: Where did all the “reject” buttons come from?

#120

Earlier quoted context omitted.

> But that is not how it is being interpreted in practice. No. In practice it's actually being interpreted correctly. What is being willfully misinterpreted is how easily a user can opt-out. Because the industry wants to remain exactly the same: it wants to siphon user data and sell it en masse. The existing pop ups that use dark patterns to make the user click "accept" are already illegal. > it is not permitted for…

I’m not necessarily blaming the law, but saying that a new law (or change to the existing one) is needed to ban cookie pop-ups. It’s clear at this point that the problem is not going to go away without intervention. The industry isn’t going to fix itself. Also, it’s unfair to blame developers here. Devs don’t have some perverse desire to create annoying pop-ups. They’re being told to do it by management and legal tea…

> It’s clear at this point that the problem is not going to go away without intervention. The industry isn’t going to fix itself.

Indeed. The main problem with GDPR is that enforcement has been slow. And that the industry has blamed its own behavior on the law.

As the article shows, the tide is ever so slowly turning.

> Ok, so you phrase it more generally: “it is not permitted for consent for tracking cookies to be obtained when a user visits a website”

And how, in this case, do you ask for consent for legitimate reasons?

Post reply on HN