Live data from Hacker News

Stop whining about “The EU Cookie Policy” and improve your ways

social.wildeboer.net

161–170 of 272 posts

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#161

Actually it's a bit more complex (but not much) than what is described: 1st party may need user consent when they will use personal datas for something that is not the intended service (legitimate use). For example, for a shopping cart: cookies are necessary for the service, so no problem. For fraud detection : no problem because it's a legitimate use. But if you start tracking with a user cookie what pages your user…

Toot/thread author here. You are of course right. I couldn't pack all details in those toots. I had to break it down to the absolute basics that are often misunderstood: Not every cookie needs consent. The way this is presented nowadays in these popups is deliberately misleading and trying to move the blame to some anonymous political entity when in reality it simply isn't that way.

This seems to conflict with the ePrivacy directive:

> Where such devices, for instance cookies, are intended for a legitimate purpose, such as to facilitate the provision of information society services, their use should be allowed on condition that users are provided with clear and precise information in accordance with Directive 95/46/EC about the purposes of cookies or similar devices so as to ensure that users are made aware of information being placed on the terminal equipment they are using. Users should have the opportunity to refuse to have a cookie or similar device stored on their terminal equipment.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#162
post #71
post #43

>Tech bros love to whine about "The EU cookie policy" that simply doesn't exist the way they imagine it. All these popups are the most radical way to interpret the explicit consent demanded by regulations when sending data to a 3rd party. An ongoing provocation by the ad/tracker industry to blame their ruthless data hoarding on the EU. The official EU website has one of these annoying pop-ups. Are they part of the pr…

That one's the pretty much the optimal implementation though. * it's a small bar on the bottom * the site works without clicking on the consent buttons * it has clear "opt-in" or "opt-out" options * no annoying "customize my permissions" sub-menu with tons of enabled switches and dark patterns

> That one's the pretty much the optimal implementation though.

Takes up 40% of my screen on mobile

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#163

Earlier quoted context omitted.

Someone can give a fuck about privacy in the areas they can, while not going overboard or trying too hard, you know. what you are describing is no true Scotsman nonsense. “You dgaf about privacy unless you wear a balaclava all the time”. It’s also possible they understand the trade off with privacy wrt, say, google and their isps/mobile providers, versus the trade off with random websites on the internet.

There is no "areas" here. What you do online is tracked if you use windows, mac os on laptop or phone, or android. Who is tracking that is irrelevant. Claiming that its ok that Apple gets your data, a company who literally allowed the iCloud photo hacks to happen, but not 3d party advertisers is like olympic level mental gymnastics.

> Who is tracking that is irrelevant.

It is absolutely relevant; it is arguably the most relevant question. It lies at the basis of the entire concept of "threat model" in security.

The police wants to track you to investigate you as a suspect in a crime. Facebook wants to track you to know who you are talking to. Amazon wants to track you to learn what you might want to buy. The Chinese government wants to track you to know if you might work for or against it. And so on.

I, like most people, give wildly different amounts of shit about every single one of these agents, and take different levels of precautions as a result.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#164
post #136

This is correct. Bad UX with modal popups and very ambiguous/deliberately vague verbose language designed to make you click some ok button are a choice not a legal requirement. Being deliberately obnoxious is of course a weird choice if you are trying to actually get people to engage with your website. The more obnoxious the UX, the less you should trust websites to do the right things when it comes to your privacy a…

> The harder websites try to hide that button, the harder I try to find it and click it. It's usually there. These days, if I can't find it within a few seconds, I just bounce and find some other less obnoxious site to use instead.

I don’t even get that far. I just close websites with cookie banners if I can help it.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#165

Earlier quoted context omitted.

A more applicable analogy is that you want to have locks on your door to prevent unwanted visitors, but the people that built the building have a master key that they can come in whenever they want, take pictures, install cameras/microphones. But thats ok, because they are the only ones that are collecting data, and they say they are "privacy-first". But thanks for proving the part of "not understanding what privacy…

I have given my landlord a key recently so that he can check the smoke alarm and take the water meter reading while I'm at work. I trust that he didn't install a hidden camera even though nothing could have stopped him apart from "being a decent human being" and "not wanting to commit a crime". Not every protection needs to on a technological level. I'd rather live in a society where we have other tools available tha…

Your analogies are really poor. Not only do you not you understand the level to which Apple or Google or your carrier can read the things you do on your devices, and how little control you have over that, but you are ignoring things like the big celebrity iCloud hacks.

For the sake of not playing an analogy war, let me just say this: if you use a modern device with OS made by Microsoft, Google or Apple (or derivative of), you are implicitly consenting to very large amount of personal data collection, which you have no control over. If you choose to trust those entities for whatever reason, thats totally fine, but your particular selection of trust isn't "correct" in the sense that it should apply to everyone, because it has no concrete objective basis. And therefore, you shouldn't base what you think the law should be on it.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#166

Earlier quoted context omitted.

Toot/thread author here. You are of course right. I couldn't pack all details in those toots. I had to break it down to the absolute basics that are often misunderstood: Not every cookie needs consent. The way this is presented nowadays in these popups is deliberately misleading and trying to move the blame to some anonymous political entity when in reality it simply isn't that way.

This seems to conflict with the ePrivacy directive: > Where such devices, for instance cookies, are intended for a legitimate purpose, such as to facilitate the provision of information society services, their use should be allowed on condition that users are provided with clear and precise information in accordance with Directive 95/46/EC about the purposes of cookies or similar devices so as to ensure that users ar…

It's not in force yet, not even passed.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#167
post #56

Earlier quoted context omitted.

Because Google owns the largest browser. The problem could only be solved politically.

No, that proves the problem could not be solved politically, because regulators lacked the political power needed to regulate google

If they would try to regulate google, that would be a political measure. How would they "regulate google" in a technical way?

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#169

> "To make this very clear: user/visitor consent is only needed for data going to 3rd parties." I think this statement is categorically false. Art. 6 GDPR ( https://gdpr-info.eu/art-6-gdpr/ ) lists exhausively the reasons for lawful processing of personal data which applies not only to cookies, but also IP addresses etc. The "cookie consent" addresses Art. 6 Point 1(a). Whether third-parties (data processors) are inv…

Agreed. It isn't the third party that is the issue - it is the separate purpose. For example, if I access a web page, I'm giving my IP address to the server, so that it knows how to sent the data I just asked for back. That IP address is personal information, but it is necessary for the server to fulfil the purpose of the task I just asked for. That server also gives the IP address to a third party - the router in be…

Wouldn't that depend on perspective? Wouldn't the router e.g. cloudflares purpose be to ensure fast delivery and that it's not an attack.

Both require capturing the ip address and analyzing behavior. A faster road where no one wants to go isn't a faster way, so the router needs to capture it so they know where to build their roads.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#170

Earlier quoted context omitted.

Ah yes, the "internet we want", where Ad geniuses will spam you for the same thing you just bought off Amazon and mobile sites turning your phone into a hand warmer with all the ad crap they have to load and all the 3rd party cookies they add

And yet, before GDPR, when all of this was happening, those sites still saw increase in visitors and still made money, because people learned to ignore the ads since the design of the core website was pretty good and ads were not obtrusive to user experience.

"Hey, people used to put up with that shit" isn't exactly a winning argument.
Post reply on HN