Live data from Hacker News

Stop whining about “The EU Cookie Policy” and improve your ways

social.wildeboer.net

191–200 of 272 posts

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#191

Earlier quoted context omitted.

Is he right though? I work with affiliate people a lot, and they hate cookie-consent popups. Even when you do all your analytics inhouse with self-hosted matomo, if you want to use a cookie, you need consent is what the lawyers say unanimously. And these aren't "we want you to ask for consent because we secretly want more privacy" lawyers, these are "I get paid to find a way for you to do your tracking in the easiest…

> Even when you do all your analytics inhouse with self-hosted matomo, if you want to use a cookie, you need consent is what the lawyers say unanimously If you use a cookie for Matomo tracking than yes, you need consent. You are using a cookie for a non essential service (analytics), so you need to ask consent. But you can use Matomo as cookieless: https://matomo.org/cookie-consent-banners/ If matomo gathers data wit…

But that primarily says that Github doesn't care about cookies (or consent), not that you (not being a multinational corporations with an army of lawyers and millions in lobbying spending) can do the same.

I'm pretty sure those cookies are non-compliant if you look at them closely, because none of them are necessary for the operation of the service. a) a default value doesn't need to be stored in a cookie -- and it has to be a default value, because you haven't selected a color scheme or a timezone b) login-state does not require a cookie: either you're logged in and have a session, or you aren't, and you don't, c) there's no reason for a session on the public facing side that doesn't contain any private/individualized data, unless you want to use these session cookies to track users -- and it's only about users as bots will typically ignore cookies.

My money is on "Microsoft knows that cookie consent is optional if you're not a small European company".

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#192

Earlier quoted context omitted.

Taking care of those things would involve an actual solution that works, which would require people understanding the technical aspects of the problem, which would require those type of people running for office and getting elected. When that happens, then we can talk about responsible governance in this regard. GDPR was a direct response to Trump campaign shenanigans, as a tool for politicians to capitalize on appea…

The Cambridge Analytica scandal was broken two years after the GDPR passed. It has been in the works long before Trump announced his campaign.

I may be wrong on this, but according to wiki, date adopted was 2016, and date implemented was 2018, not sure what those things mean.

I remember it being big news back in 2018, riding off the back of the CA scandal that it could help to prevent in the future.

Regardless, if I am wrong about this, it doesn't change the fact that it doesn't really do anything for the people.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#193
post #160

Earlier quoted context omitted.

You're right... I'm french ;-) Sorry about the wrong acronym (RGPD = GDPR)

Isn't it inconvenient and search result partitioning to use this? I haven't come across/noticed it before. In English for example we use the French order acronym UTC, not UCT or CUT. (Though to be fair in the UK outside of a computing context we mostly use GMT.)

UTC is a hilarious acronym precisely because it is not correct in either French or English.

In French it would be TUC, in English CUT. Both parties agreed on UTC because it doesn’t give either language primacy.

https://en.m.wikipedia.org/wiki/Coordinated_Universal_Time

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#195
Toot/thread author here. I have added more clarifications and explanations, based on the feedback in the comments here. Thank you for that! It was an angry rant written down in a very short burst of productivity ;) I had to simplify a lot if things to get the main point across — that these pop-up banners are NOT what GDPR demands, that they deliberately are designed to exaggerate and intrude on users.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#196

Earlier quoted context omitted.

It's not in force yet, not even passed.

ePrivacy predates GDPR, and is in effect. However, it still doesn't require a banner.

Yes, you are right. I was was confusing it with the ePrivacy regulation which still is in the works. The above text is from the directive though.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#197

Actually it's a bit more complex (but not much) than what is described: 1st party may need user consent when they will use personal datas for something that is not the intended service (legitimate use). For example, for a shopping cart: cookies are necessary for the service, so no problem. For fraud detection : no problem because it's a legitimate use. But if you start tracking with a user cookie what pages your user…

> if you start tracking with a user cookie what pages your users are viewing (statistics collection), then... you need the user consent What about if you're Amazon and you want to show 'people who bought this also bought this' content? Then the tracking is necessary.

Then you ask for consent.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#198

No one likes these consent modals, not the EU, not the companies, not the end users. But they're good. They're making the negative externality visible. We had developed an ecosystem where as soon as you clicked on a webpage it would spaff your personal data to third party brokers and infest you with tracking across the entire internet. All driven by marketing and sales departments. All driven by a capitalist free mar…

No, they are not good in any way. Imagine you have to press buttons whenever you start your car and have to give promises you are not going to go above the speed limit...

It's just plain NONSENSE. This consent madness should be implemented in the browser. You set it once, and then you just forget about it. Poof, problem gone. If

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#199
post #71

Earlier quoted context omitted.

That one's the pretty much the optimal implementation though. * it's a small bar on the bottom * the site works without clicking on the consent buttons * it has clear "opt-in" or "opt-out" options * no annoying "customize my permissions" sub-menu with tons of enabled switches and dark patterns

> That one's the pretty much the optimal implementation though. It's strictly performative, they're setting session and tracking cookies without consent. Whatever you click on their "consent" (or if you click at all) is irrelevant and has no effect on the cookies being set. It's been that way for a long time and nobody cares (I've reported it before and never got a reply). It's a classic "do as I say, not as I do". R…

After navigating for a couple of pages in incognito (without clicking on any option on the banner) I see two cookies set: one which I suspect tracks if I accepted cookies or not, and one that tracks the fact that I closed the EU/European Commission survey. I'm not sure what you're seeing, or if you're thinking that these two are not OK to be set.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#200
post #116
post #30

GitHub got rid of their banners in 2020: https://github.blog/2020-12-17-no-cookie-for-you/ I believe there is also a lot of "cargo culting" where site admins copy what everyone else is doing without understanding the legal background.

That’s what happens when you add regulations to an industry of small players who can’t afford to spend time or money in understanding these things

> small players who can’t afford to spend time or money in understanding these things

Most of them can afford it, since it's part of the cost of doing business. Most European businesses were already regulated by similar rules with the Loi informatique et libertés in France, and the Datenschutzgesetz in Germany. But since the maximum fines were smaller, everybody was breaking the law.

The main issue is not that they can't afford it, the issue is that they don't want to do it.

I've worked for 3 different small businesses which were happy to use free-of-charge AGPL libraries in their main SaaS product. And when I mentioned that we should remove AGPL libraries or release our entire codebase under AGPL, what I got was "we'll look into this later".

This is not "i can't afford it", this is "i'm too lazy/incompetent to make time for it"

Post reply on HN