Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

121–130 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#121
post #79

Hate this way of thinking where the government (with seemingly good intentions) tries to stop something but leaves a loophole where all our lives are made more tedious and then people defend it saying the companies should just not do it, well we needed the law in the first place so it's a bit silly thinking to suggest they stop doing it after the law, no?. If the cookie law was written properly then it would have jus…

This is 100% what PG means IMO and the most sane take on this. Either write the law correctly so it's not easily bypassed or just don't touch anything because you will only make it worse.

The law is not bypassed, the annoying banners with no simple option to reject are illegal. The issue is that enforcement is slow, not that the law is badly written.

GDPR's Article 7 [0] is very clear:

> 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent. [emphasis mine]

[0] https://gdpr.eu/article-7-how-to-get-consent-to-collect-pers...

Re: Dear Paul Graham, there is no cookie banner law

#122
post #40
post #21

Part of what it means to be "good at regulation" is to anticipate the likely consequences of regulations. So a regulation that says that "businesses must now give away their products for free, unless they honk each customer's nose" will result in a lot of sore noses. Which is basically the case here. Almost all websites make money through ads, or at least keep logs of user activity to help them optimize their website…

> Almost all websites make money through ads The EU regulation does not prevent ads from being shown, it specifically targets tracking. No tracking > no banner > everyone is happier > go ahead and show all the ads that are required.

And all that tracking comes down with inability to take risk on business side. Ad company wants to be 100% sure that ads are shown to humans, and pay only for those shown to humans(going deeper - to specific cohorts of humans, which in the past was approximated by content of the site showing ads). Whereas sites serving ads want to extract as much money as it is possible from advertisers based on their audience count.

The incentives are on both sides to to one-up each other without tracking - hosts by inflating visitor numbers, advertisers by disputing that.

In a perfect world ad(wouldn't exist i know but bear with that) companies would pay X/month for site with Y visitors, where X depends on Y. No need for tracking, and roughly over multiple sites and multiple months it averages out.

Not enough conversion rates(risk for ad company - they could pay less)? offer lower rate per visitor next period. Site gets spike in visitors(risk for host - they could charge more)? report higher estimated Y for next period.

What we got instead is an insane tracking infrastructure that costs way more than any possible profit gained for both sides. It's not even profit - it's avoiding being 'scammed', avoiding risk.

Remember that all that tracking bullshit started before targeted advertising was mainstream and widespread. It all started with bots and inflated click numbers, and inability to accept risk.

Tl;dr banning targeted advertising won't remove all tracking bullshit

Re: Dear Paul Graham, there is no cookie banner law

#123
post #70

>, Paul Graham came up with the thought, that the EU forces companies to have cookie banners. There is no law for cookie banners. [...] Companies could easily avoid any cookie banner. Just don’t track. KingOfCoders/amazingcto, of course you are technically correct but Paul Graham wasn't talking about the letter of the law. Instead, you have to interpret his complaint with the lens of game theory . I.e. The Law of Uni…

I consider it a good outcome when I can clearly identify shitty websites and just click the back button.

Re: Dear Paul Graham, there is no cookie banner law

#124
Having read comments here first, I was surprised when I visited the article and found that while the thrust of the article was that pg was incorrect about the existence of a law about "cookie banners", the tweet referenced in the post -- and screenshot, even -- does not even imply that pg thinks that there is a law specifically mandating cookie banners.

Re: Dear Paul Graham, there is no cookie banner law

#125
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

> On this issue in the group that complain about the cookie law there are some people who are very wrong on purpose because it's in their interest, and some people who are very wrong because they genuinely don't understand the position they're defending, complaining about being made aware of the fee, instead of the fees themselves or the fact that the companies hide them if not forced by law. The reality is that I (a…

> The reality is that I (and others who are complaining, as well as many who have resigned themselves to their fate) are happy to have a website "track me", certainly if the cost of non-tracking are having to click away an annoying popup

The you should doubly blame the companies, because that's what do not track was for, they're the one who decided to make it not work that way and instead being ignored and not considered a valid option for the law.

> think that people who compare a website wanting to know the number of their visitors to "hidden fees" are kind of being ridiculous.

You don't need a cookie for that, and what GDPR has told us is that we're not talking of that but about dozens or hundreds on every major sites so trying to frame it that way is disingenuous.

Re: Dear Paul Graham, there is no cookie banner law

#126
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

Hidden fees are bad because of the specific combination - the hiding, and the fees. Since tracking isn't hidden and isn't a fee, the analogy doesn't help to justify the EUs law.

People should have a default expectation that if they give their personal data to companies then it will be recorded. And if they don't want cookies then they should disable cookies. The EU's regulation hasn't revealed anything that is useful to know about.

Re: Dear Paul Graham, there is no cookie banner law

#127
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

Using your analogy, I think what ends up happening is that even companies that don't collect hidden fees will put up a banner just in case. Not only that, I'm not an EU citizen and I'm not browsing websites based in EU but I'm still bombarded with cookie banners non-stop.

Do you have /any/ examples of websites that don't have a bunch of 3rd party cookies that still have a cookie banner?

Middle managers absolutely love anything with charts and graphs because it makes their decisions feel more scientific. That's why they want tracking software included on their websites. And if the law requires disclosure then a cookie popup is the solution.

Re: Dear Paul Graham, there is no cookie banner law

#128
post #85

Yes there is. More specifically, it’s the Privacy and Electronic Communications Directive 2002/58/EC, which each member state adjusts their own laws to follow. It’s published here: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A... The relevant part: > Article 5 > Confidentiality of the communications > 3. Member States shall ensure that the storing of information, or the gaining of access to information…

You are citing directive that does not apply in all cases. It is amended by Directive 2009/136/EC, which changes especially the cookies part. > (66) Third parties may wish to store information on the equipment of a user, or gain access to information already stored, for a number of purposes, ranging from the legitimate (such as certain types of cookies) to those involving unwarranted intrusion into the private sphere…

That update doesn’t matter because the original has the same exception. I quoted it.

Re: Dear Paul Graham, there is no cookie banner law

#129
post #69

Earlier quoted context omitted.

Your point is well made, and this is an unfortunate consequence of the regulation (and I enjoyed the analogy). But it isn't necessary to have cookie banners on every website. Github is a moderately complex, user-optimised website, right? https://github.blog/2020-12-17-no-cookie-for-you/

I clicked on that link and immediately got a cookie banner. Am I missing something?

Interesting. Clearly I am providing out of date information.

Re: Dear Paul Graham, there is no cookie banner law

#130

Yes there is. More specifically, it’s the Privacy and Electronic Communications Directive 2002/58/EC, which each member state adjusts their own laws to follow. It’s published here: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A... The relevant part: > Article 5 > Confidentiality of the communications > 3. Member States shall ensure that the storing of information, or the gaining of access to information…

hmm I disagree. I found the article, quite an eye opener for me. I also thought that he cookie banners is what the EU forced the web-site owners to show.. but it clearly isn't. It is just about consent. This consent could be given in a non-annoying way, but clearly the involved companies don't want to.
Post reply on HN