Live data from Hacker News

Stop whining about “The EU Cookie Policy” and improve your ways

social.wildeboer.net

151–160 of 272 posts

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#151

>So stop blaming "the EU" and ask yourself if this is the internet we want. ...Yes, thats exactly the internet "we" want. I don't get why it so hard to accept that people simply dgaf about privacy, and much prefer free products online paid for by ads. And there is nothing wrong with that, because for those that actually care about privacy, there are plenty of tools.

It's not the internet I want. I don't want surveillance capitalism manipulating society so they buy more shit. I'm part of the EU electorate. Are you?

>I don't want surveillance capitalism manipulating society so they buy more shit.

Neither do I, but prove to me that this actually happens. Namely the surveillance part with online trackers.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#152
post #83

Earlier quoted context omitted.

My guess is they are a native speaker of some Romance language, and that is the acronym in their native language, perhaps French based on username and what little I know of French.

Ah the French. In the great words of Samuel L Jackson "English motherfucker do you speak it".

It's not only the French, would be the same for the Portuguese, for example. English is an official language of only two EU countries, if I'm not mistaken.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#153
Ideally browsers would have an API to handle GDPR requests natively, the way they do for hardware access, and users would be able to set the default level of access, as well as lists of exceptions for some domains. Of course, Google will never provide such API in Chrome as it would be bad for their core business of spying on people in order to sell them more stuff.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#154

Earlier quoted context omitted.

Toot/thread author here. You are of course right. I couldn't pack all details in those toots. I had to break it down to the absolute basics that are often misunderstood: Not every cookie needs consent. The way this is presented nowadays in these popups is deliberately misleading and trying to move the blame to some anonymous political entity when in reality it simply isn't that way.

Aren't you failing to account for the following? In theory, website owners could do as GitHub did and remove inessential cookies and get rid of annoying banners: https://github.blog/2020-12-17-no-cookie-for-you/ But in practice, website owners are worried about breaking laws and aren't experts and just follow what they see everyone else doing, and so put up banners. So in practice, the regulations are indeed the ulti…

Yes, there's a cargo cult mentality (encouraged by the big players who would like everyone to believe they are just doing the same as the average wordpress blog), but one way of counteracting that is to educate website owners like the above posts aim to. It's important to realise this isn't just a consequence of the laws being passed but poor understanding of them, which is in part deliberately propagated by those who object to the law.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#155

>So stop blaming "the EU" and ask yourself if this is the internet we want. ...Yes, thats exactly the internet "we" want. I don't get why it so hard to accept that people simply dgaf about privacy, and much prefer free products online paid for by ads. And there is nothing wrong with that, because for those that actually care about privacy, there are plenty of tools.

It's hard to accept because many, many people won't agree with you and do give a fuck.

When you say "many, many" I take that to mean "a substantial proportion" and I think you may be making the mistake of estimating your proportions from the population of people in tech forums, rather than from the global population of internet users.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#156

Earlier quoted context omitted.

Toot/thread author here. You are of course right. I couldn't pack all details in those toots. I had to break it down to the absolute basics that are often misunderstood: Not every cookie needs consent. The way this is presented nowadays in these popups is deliberately misleading and trying to move the blame to some anonymous political entity when in reality it simply isn't that way.

Aren't you failing to account for the following? In theory, website owners could do as GitHub did and remove inessential cookies and get rid of annoying banners: https://github.blog/2020-12-17-no-cookie-for-you/ But in practice, website owners are worried about breaking laws and aren't experts and just follow what they see everyone else doing, and so put up banners. So in practice, the regulations are indeed the ulti…

I would argue that's the entire point of the OP.

It's not the EU that's causing the fear of breaking laws. It's the ad tech industry that is instilling that fear by fostering the "you need a cookie banner on your site now" FUD. If Joe Schmoe thinks he needs a cookie banner for doing nothing and puts one up, then from a user's perspective, all sites are equally bad.

Compare with "Ask App Not to Track" in iOS, which is enforced by the OS and actually means something. The tracking industry hates that one because it shows them for what they are (not all apps need to throw up that screen) and they don't get to blame the EU for it.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#157
post #148

Both CloudFlare and Jetpack on WordPress insert a tracking cookie as a part of using their service, right? (I may be wrong, things may have changed) For a lot of folks, that's what they have to use, otherwise delivering the page resource-wise isn't viable. Ergo, they need those banner popups to be in compliance, right?

It depends on what the cookies are being used for. If they're "essential for site functionality" (e.g. fraud prevention) then consent is not necessary.

Well, here's the thing though, it could be argued that they are essential for site functionality (if you conflate functionality with availability for example), however, you are revealing the IP of the user to those third-party services, which is no bueno.

Loading Google Fonts via Google's CDN is non-compliant, ergo why would Jetpack be any different? https://www.theregister.com/2022/01/31/website_fine_google_f...

However, CloudFlare is an odd one. They're also the reverse proxy and DNS for the site, ergo they can collect that IP if they intend to, which they apparently don't.

Where is the line drawn? If an asset loaded via a third-party CDN is "leaking the IP", surely CloudFlare also is? Surely any kind of DNS is?

I'm asking big questions, I know, but have always been curious, and have been waiting for a good opportunity to put them in front of others.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#158

Earlier quoted context omitted.

> thats exactly the internet "we" want This is not how civilized society works. Taken individually, people don't care about a million things, yet regulators have to take care of those things on behalf of everybody else. Just because you don't understand the ramifications of something it does not mean nobody else understands it.

Taking care of those things would involve an actual solution that works, which would require people understanding the technical aspects of the problem, which would require those type of people running for office and getting elected. When that happens, then we can talk about responsible governance in this regard. GDPR was a direct response to Trump campaign shenanigans, as a tool for politicians to capitalize on appea…

The Cambridge Analytica scandal was broken two years after the GDPR passed. It has been in the works long before Trump announced his campaign.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#159

Earlier quoted context omitted.

The issue is that there is too much money to be left on the table advertising wise, so instead you are going to see every way to get around anything GDPR that is going to progressively shit up the internet. In the end, you can be tracked without cookies using fingerprinting, and AI will make this job easier and easier. So the banner is pretty much irrelevant technologically. You will also see companies that make popu…

> get around anything GDPR Nitpick: none of those dark patterns "get around" the GDPR - they merely get away with it due to a (hopefully temporary) lack of enforcement. GDPR explicitly disallows annoying the user into accepting and tricks such as hiding the decline button, etc. > So the banner is pretty much irrelevant technologically That's why the GDPR doesn't explicitly target cookies or a specific means of tracki…

The point is to allow someone the option to defeat all fingerprinting if they want to. The consequences of that are up to the companies - if they don't want to sell you something because you are anonymous, they have the right to reject your browser requests. Thats an important cornerstone of capitalism.

Even with limits on collection/processing of personal data, because the legislation was made by non technical people, there are always ways around it. For example, lets say company has an advertising ml model that they use that essentially identifies visitors by fingerprint and maps them to some advertising targeting. They can train that model and throw away the training data, and then hand that model off to any regulator that is going to have no idea what to do with a bunch of floats in matrices, and claim that there is no user data stored in there, and nobody could prove otherwise.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#160

Earlier quoted context omitted.

It's GDPR as in General Data Protection Regulation.

You're right... I'm french ;-) Sorry about the wrong acronym (RGPD = GDPR)

Isn't it inconvenient and search result partitioning to use this? I haven't come across/noticed it before. In English for example we use the French order acronym UTC, not UCT or CUT. (Though to be fair in the UK outside of a computing context we mostly use GMT.)
Post reply on HN