Live data from Hacker News

Stop whining about “The EU Cookie Policy” and improve your ways

social.wildeboer.net

131–140 of 272 posts

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#131
The problem with the GDPR is that it is a monster of a legalese text:

https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...

Which nobody understands.

Which, depending on how you read it, might make participating on the internet practically impossible. An IP is considered personal data, so in theory you cannot use foreign infrastructure like a CDN.

Which certainly makes the internet as we know it impossoble. An internet where everybody builds tools on their site that everybody else can embed on their site. Because that would mean IPs flowing around between sites.

Which gives a huge disadvantage to Euroeans. Because Europreans have to show cookie banners and stuff to everybody around the world. While the rest of the world has to only show them to Europeans. Look at your favorite website through a proxy inside/outside the EU. It starts with an annoying popup only in the EU.

Which cements the stronghold of Google and Co, who 1) only have to bug their European users and 2) have the legal resources to cope with this insanity. Startups and indiemakers don't. So there will be even less of them in the EU. And the ones who exist will have to waste their time on this instead of building their products.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#132

>So stop blaming "the EU" and ask yourself if this is the internet we want. ...Yes, thats exactly the internet "we" want. I don't get why it so hard to accept that people simply dgaf about privacy, and much prefer free products online paid for by ads. And there is nothing wrong with that, because for those that actually care about privacy, there are plenty of tools.

> thats exactly the internet "we" want

This is not how civilized society works. Taken individually, people don't care about a million things, yet regulators have to take care of those things on behalf of everybody else.

Just because you don't understand the ramifications of something it does not mean nobody else understands it.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#133
post #35
post #31

Earlier quoted context omitted.

Not without breaking the law.

Which is why it's a stupid law that has made everybody's lives worse, both the businesses and the users.

Why is it a stupid law? Why should businesses be free to look up the IP and figure out who is looking at their page? An IP can reveal a lot of information, especially if there's servers hanging off of it.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#134

Earlier quoted context omitted.

To anyone that doesn't agree with me, please show me your rooted android phone that has no popular apps installed that collect any data, and doesn't use a sim card. Because if you say you give a fuck about privacy, and use a modern android phone with OEM rom or an iPhone, you either don't understand what privacy is and shouldn't be talking about it in the first place, or you are a hypocrite.

I don't live in a heavily fortified home only accessible through a drawbridge but still give a fuck about the privacy of my little city flat that you could probably enter with a heavy kick. Modern society enables miracles.

A more applicable analogy is that you want to have locks on your door to prevent unwanted visitors, but the people that built the building have a master key that they can come in whenever they want, take pictures, install cameras/microphones. But thats ok, because they are the only ones that are collecting data, and they say they are "privacy-first".

But thanks for proving the part of "not understanding what privacy is" part of my post.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#135

> "To make this very clear: user/visitor consent is only needed for data going to 3rd parties." I think this statement is categorically false. Art. 6 GDPR ( https://gdpr-info.eu/art-6-gdpr/ ) lists exhausively the reasons for lawful processing of personal data which applies not only to cookies, but also IP addresses etc. The "cookie consent" addresses Art. 6 Point 1(a). Whether third-parties (data processors) are inv…

Toot author here. Yes, the complexities are tough to explain in a few toots. Bit as an abstraction it is valid IMHO. As per the GDPR and ePrivacy Directive, a website must ask its users’ consent to use cookies that are not necessary for accessing the website’s functionality. All third party cookies typically fall under this rule. 1st party cookies that do not collect PII (Personally Identifiable Information) like simple session cookies ar exempted from consent.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#136

This is correct. Bad UX with modal popups and very ambiguous/deliberately vague verbose language designed to make you click some ok button are a choice not a legal requirement. Being deliberately obnoxious is of course a weird choice if you are trying to actually get people to engage with your website. The more obnoxious the UX, the less you should trust websites to do the right things when it comes to your privacy a…

> The harder websites try to hide that button, the harder I try to find it and click it. It's usually there.

These days, if I can't find it within a few seconds, I just bounce and find some other less obnoxious site to use instead.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#137
post #88

>So stop blaming "the EU" and ask yourself if this is the internet we want. ...Yes, thats exactly the internet "we" want. I don't get why it so hard to accept that people simply dgaf about privacy, and much prefer free products online paid for by ads. And there is nothing wrong with that, because for those that actually care about privacy, there are plenty of tools.

I don't understand why it isn't solved in this way: You get a banner on your first visit, with a list "here are all the cookies and ways how we use your data, if you are not fine with it, please leave this website" This should be an option for small private websites (different rules for FB, Google and alike), because no one forces you to use a site, same as "my house, my rules"

> "my house, my rules"

A website is in no way "your house".

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#138

Earlier quoted context omitted.

To anyone that doesn't agree with me, please show me your rooted android phone that has no popular apps installed that collect any data, and doesn't use a sim card. Because if you say you give a fuck about privacy, and use a modern android phone with OEM rom or an iPhone, you either don't understand what privacy is and shouldn't be talking about it in the first place, or you are a hypocrite.

Someone can give a fuck about privacy in the areas they can, while not going overboard or trying too hard, you know. what you are describing is no true Scotsman nonsense. “You dgaf about privacy unless you wear a balaclava all the time”. It’s also possible they understand the trade off with privacy wrt, say, google and their isps/mobile providers, versus the trade off with random websites on the internet.

There is no "areas" here. What you do online is tracked if you use windows, mac os on laptop or phone, or android. Who is tracking that is irrelevant. Claiming that its ok that Apple gets your data, a company who literally allowed the iCloud photo hacks to happen, but not 3d party advertisers is like olympic level mental gymnastics.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#139
post #88

Earlier quoted context omitted.

I don't understand why it isn't solved in this way: You get a banner on your first visit, with a list "here are all the cookies and ways how we use your data, if you are not fine with it, please leave this website" This should be an option for small private websites (different rules for FB, Google and alike), because no one forces you to use a site, same as "my house, my rules"

The issue is that there is too much money to be left on the table advertising wise, so instead you are going to see every way to get around anything GDPR that is going to progressively shit up the internet. In the end, you can be tracked without cookies using fingerprinting, and AI will make this job easier and easier. So the banner is pretty much irrelevant technologically. You will also see companies that make popu…

> get around anything GDPR

Nitpick: none of those dark patterns "get around" the GDPR - they merely get away with it due to a (hopefully temporary) lack of enforcement. GDPR explicitly disallows annoying the user into accepting and tricks such as hiding the decline button, etc.

> So the banner is pretty much irrelevant technologically

That's why the GDPR doesn't explicitly target cookies or a specific means of tracking but rather the collection and processing of personal data, regardless of technical means (a hypothetical crystal ball that actually worked would also fall in scope).

> Between things like VPN and all the privacy tweaking you can do in Firefox, if someone wants privacy they can have it.

Even if let's assume there was a way to truly be anonymous and defeat all fingerprinting, how are you going to do business on the internet? At some point you will need to enter personal data, whether it's to buy something, sign up for real-world thing, etc. No amount of VPNs or plugins will save you if you enter your delivery address because you bought something.

GDPR or similar legislation is the only way around it - you should be able to enter your delivery address without consenting to it being used for malicious purposes such as advertising.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#140
post #131

The problem with the GDPR is that it is a monster of a legalese text: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE... Which nobody understands. Which, depending on how you read it, might make participating on the internet practically impossible. An IP is considered personal data, so in theory you cannot use foreign infrastructure like a CDN. Which certainly makes the internet as we know it impossoble.…

This is way off base. Using PI to fulfill a request someone has made of you is the happy path of GDPR, you just can't retain or reuse that information more than you have

1) a contract or

2) permission or

3) a lawful task

For.

Having other parties process PI for you is fine as long as it's done under an agreement that binds them to the same terms.

Post reply on HN