Live data from Hacker News

Stop whining about “The EU Cookie Policy” and improve your ways

social.wildeboer.net

211–220 of 272 posts

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#211

Earlier quoted context omitted.

Toot/thread author here. You are of course right. I couldn't pack all details in those toots. I had to break it down to the absolute basics that are often misunderstood: Not every cookie needs consent. The way this is presented nowadays in these popups is deliberately misleading and trying to move the blame to some anonymous political entity when in reality it simply isn't that way.

Aren't you failing to account for the following? In theory, website owners could do as GitHub did and remove inessential cookies and get rid of annoying banners: https://github.blog/2020-12-17-no-cookie-for-you/ But in practice, website owners are worried about breaking laws and aren't experts and just follow what they see everyone else doing, and so put up banners. So in practice, the regulations are indeed the ulti…

> But in practice, website owners are worried about breaking laws

That is weird argument. If one genuinely cannot bother to read the law or does not feel capable of fully comprehending the law why don't they simply consult a lawyer? Hiring professional accountants is somehow standard practice.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#212

>So stop blaming "the EU" and ask yourself if this is the internet we want. ...Yes, thats exactly the internet "we" want. I don't get why it so hard to accept that people simply dgaf about privacy, and much prefer free products online paid for by ads. And there is nothing wrong with that, because for those that actually care about privacy, there are plenty of tools.

As long it is an informed consent that people don't care about privacy.

Uninformed consent is the tricky part. Medicine has to constantly deal with that a lot of people that dgaf about what medicine or brand of medicine is given to treat a specific illness. They just want to get better. Is there something wrong with doctors that just don't inform or get consent? Patients that actually care about specific medicines can look it up.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#213

Earlier quoted context omitted.

Because the industry doesn't want to give up on tracking and siphoning user data.

7 years of complaining about it hasn't changed that. Do you think another 7 years will be more effective? Alternatively, the EU could change the laws. Or enforce the existing ones.

> 7 years of complaining about it hasn't changed that.

Funnily how "7 years of complaining" was, and continues to be, only about the EU. Not about the predatory businesses creating these banners (often in direct violation of GDPR).

> Or enforce the existing ones.

That's definitely the biggest criticism you can level at EU: they are too slow in enforcing this.

I think the tide is very slowly changing. First they started showing reject buttons https://noyb.eu/en/where-did-all-reject-buttons-come There's a report on the cookie banners in the works: https://noyb.eu/en/data-protection-authorities-support-noybs... etc.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#214

Earlier quoted context omitted.

Ah yes, the "internet we want", where Ad geniuses will spam you for the same thing you just bought off Amazon and mobile sites turning your phone into a hand warmer with all the ad crap they have to load and all the 3rd party cookies they add

And yet, before GDPR, when all of this was happening, those sites still saw increase in visitors and still made money, because people learned to ignore the ads since the design of the core website was pretty good and ads were not obtrusive to user experience.

And yet, before the FDA was allowed to regulate baby food, baby food producers in the US saw increase in buyers and still made money with their product with arsonic and lead content above dangerous threeshold for adults.

Those new regulation will probably increase the price of baby food, and people obvisouly didn't care about the heavy metal content, so why regulate at all?

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#215
post #160

Earlier quoted context omitted.

You're right... I'm french ;-) Sorry about the wrong acronym (RGPD = GDPR)

Isn't it inconvenient and search result partitioning to use this? I haven't come across/noticed it before. In English for example we use the French order acronym UTC, not UCT or CUT. (Though to be fair in the UK outside of a computing context we mostly use GMT.)

I generally prefer when we agree on a spelling, even if it isn't in English. CERN is a good example of this, no English speaker in their right mind would call it ECNR.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#216

Earlier quoted context omitted.

The incessant "think of the small businesses" is becoming the new "think of the children". It's easier for small businesses to comply with GDPR.

This is hilariously wrong. Small companies have less code and complexity but don't have internal resources specialised in law, security and web development available to fix things. They usually also don't have the money to bring outsiders to do it for them.

> Small companies have less code and complexity but don't have internal resources specialised in law, security and web development available to fix things.

When you clamp all those things together, this sounds like a great burden. Please tell me, how these poor small businesses comply with, you know, actual laws, rules and regulations that they have to comply with? By breaking them?

GDPR for small businesses is much easier because small businesses depend on much less data, and often don't even need to collect any (much less sell it to third parties).

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#217
post #88

Earlier quoted context omitted.

I don't understand why it isn't solved in this way: You get a banner on your first visit, with a list "here are all the cookies and ways how we use your data, if you are not fine with it, please leave this website" This should be an option for small private websites (different rules for FB, Google and alike), because no one forces you to use a site, same as "my house, my rules"

This would be explicitly forbidden by GDPR. You either don’t serve EU customers or allow them to opt out/in. You can’t degrade or deny service based on consent.

So what is the difference between “all cookies” and “essential cookies”?

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#218
post #148

Earlier quoted context omitted.

It depends on what the cookies are being used for. If they're "essential for site functionality" (e.g. fraud prevention) then consent is not necessary.

Well, here's the thing though, it could be argued that they are essential for site functionality (if you conflate functionality with availability for example), however, you are revealing the IP of the user to those third-party services, which is no bueno. Loading Google Fonts via Google's CDN is non-compliant, ergo why would Jetpack be any different? https://www.theregister.com/2022/01/31/website_fine_google_f... How…

What we did was basically ignore GDPR and send a mail to our watchdog about the points we weren't sure would pass as legitimate use.

Basically: if you in good faith think it's legitimate, it's probably legitimate. The watchdog will propose you ways to remove PII from your data if he think you're misguided, and they drafted us an architecture that worked for data protection (like half a day of work for an architect, i think they already have these kind of drafts as our issue was quite common). We spent 20 minutes to write the email and basically earned 500$ (or whatever is the cost of half a day of an architect is). We also had prior contact with the watchdogs for unrelated reasons (trying to get certified to handle sensitive data).

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#219
post #163

Earlier quoted context omitted.

> Who is tracking that is irrelevant. It is absolutely relevant; it is arguably the most relevant question. It lies at the basis of the entire concept of "threat model" in security. The police wants to track you to investigate you as a suspect in a crime. Facebook wants to track you to know who you are talking to. Amazon wants to track you to learn what you might want to buy. The Chinese government wants to track you…

I don't buy the argument that you don't want Amazon or Facebook to track you, but you are ok with Apple or Google tracking you. In case its not clear, because Im really doubting that people have a good grasp of privacy here, when you buy an Iphone, it phones home quite a bit collecting pieces of data about you that Apple can and does use internally for their advertising purposes, and you cannot opt out of it.

You don't have to buy it, I'm gonna give it to you for free: I don't want Facebook tracking me, because I don't like them and don't trust them. OTOH I don't care if Google tracks me because I am an actively paying user of Google on a contract. I also don't care if Apple tracks me because they have a much cleaner track record.

Re: Stop whining about “The EU Cookie Policy” and improve your ways

#220

No one likes these consent modals, not the EU, not the companies, not the end users. But they're good. They're making the negative externality visible. We had developed an ecosystem where as soon as you clicked on a webpage it would spaff your personal data to third party brokers and infest you with tracking across the entire internet. All driven by marketing and sales departments. All driven by a capitalist free mar…

No, they are not good in any way. Imagine you have to press buttons whenever you start your car and have to give promises you are not going to go above the speed limit... It's just plain NONSENSE. This consent madness should be implemented in the browser. You set it once, and then you just forget about it. Poof, problem gone. If

I cannot imagine that the legal systems in question would consider setting a consent setting in your browser, once, to be explicit positive and informed opt-in.
Post reply on HN