Live data from Hacker News

Please stop putting cookie pop-ups on your website (2022)

olivergrimsley.com

81–90 of 211 posts

Re: Please stop putting cookie pop-ups on your website (2022)

#81
So, suppose I run websites. Actually I do and I have cookie banners on all of them - but only for users with EU IP Addresses.

Here's the twist: Good news is (for me), I can[1] track and do whatever I want with any other IP address. You visit my site? Well, thanks to nobody else I care about having GDPR-like regulations in place, I can make sure I'll not only track you down and display ads across all advertiser networks, feed them your visit in all imaginable and unimaginable ways, but I can do it in such a targeted way that it's borderline scary. I can literally use any information you gave me on my websites, like your name, your location, proximity to anything. And if I can't then the advertiser can. And in the case of that particular lawsuit mentioned in the article, collecting all user consents, their IP addresses, and basically which websites they visited, its like a gold mine for advertisiers. If it isn't one yet, it can be turned into one with the click of a button.

It's like that one case a few years back, where a health insurance company bought a bank and started closing bank accounts from people they knew were risk patients.

Simply connect the dots...

GDPRs promise was to make it harder to do so. It wasn't the plan to annoy the hell out of everyone with banners. The whole idea was to not allow tracking unless you opted in, because quite frankly, its scary.

And no, I'm not a fan of GDPR or overregulation. But in reality, there hasn't been any tech I've come across that really protects the non-technical internet users at large. There's uBlock and plugins, but not installed by default or built into standard mobile browsers. Apple might be close for regular consumers to stop the excessive tracking and companies like FB really hates them for it (for good reason, it costs them big $$). Google will never shoot their own foot by integrating non-tracking tech into any of their products.

So, no, my opinion is don't stop that darn annoying cookie pop-ups unless you also stop the tracking. If you stop the tracking, remove the cookie pop-up. As easy as that.

[1] I don't do it, but I could. I'm not a reckless psycho-marketer.

Re: Please stop putting cookie pop-ups on your website (2022)

#82

Earlier quoted context omitted.

GDPR compliance can be implement many ways, starting with not collecting data in the first place. Even if data is collected and sold it is still both possible and arguably even easier to implement GDPR compliance without cookie pop ups. However, we have codecamp graduates gluing left-pad modules together until something works instead of engineers building websites and it shows.

Neither "graduates" nor "engineers" are responsible for any website functionality. They simply do the work that the management requested them to do.

The request from management to engineering was "make us gdpr compatible, show that cookie banner we see on other sites or some shit", implementation details were designed by IT.

Re: Please stop putting cookie pop-ups on your website (2022)

#83

> Enact a law that requires a service to respect the do not track signal from a browser (currently entirely voluntary), and not store any tracking cookies, clear gifs or other trackers – and require that a site not “discriminate” against users who elect no tracking – basically – provide all functions to users whether they consent or do not consent. This is indeed the obvious solution. I don't understand why the EU di…

> I don't understand why the EU didn't mandate the do not track flag to be obeyed.

1. Because the implementation is simply left open?

2. Because it's nearly impossible to verify?

Re: Please stop putting cookie pop-ups on your website (2022)

#84
post #57

The future 2 years down is cookieless anyway.¹ I'm afraid that these banners, because these are called "cookie banners" and not "consent to us using your data and giving it freely to other companies banners", will just go away, people (& companies) will be happy, and the consumer stays a fool. ¹ https://en.wikipedia.org/wiki/Third-party_cookies

The legal requirement behind them is about storing information about a person that isn't strictly necessary for functionality or law. It remains even if "cookies" were replaced with "smart dust tracked into your house by cyber-ants".

Yup, but it will be very hard to see/prove this from the outside.

Unlike cookies.

Re: Please stop putting cookie pop-ups on your website (2022)

#85

Maybe stop doing stupid shit that will legally require you to inform users that you're about to sell/share everything you know about them to 3rd parties? I fail to understand companies that display page after page of cookies and tracking stuff for you to approve don't see the issue with their actions or the insanity of "allow us to share data with our 1500 partners". Does no one in these business look at this and go:…

The vast majority of websites just want to know where their visitors are coming from and, if they are selling a product, some aggregate level of demographic knowledge to tailor their marketing efforts. They really don’t care about an individual or even small cohort and aren’t selling the data on.

Targeting advertising is sooo much more effective for small and medium sized businesses and actually makes many businesses viable in a way they weren’t in the past.

The ideal solution would be to find a way for businesses to get those insights in a way that preserves privacy at the individual level. Something like apples differential privacy system but web wide.

Re: Please stop putting cookie pop-ups on your website (2022)

#86

Earlier quoted context omitted.

Because it is there: don't make them choose; we have x and nothing more so you cannot have more.

Yeah but there's the rub. Asking Google to take analytics away just isn't going to happen. It makes them billions. And marketeers want this data because sales data only tells them where they succeeded. Not where they failed to sell, which is more interesting to them because that's where the growth is found. It'll be really hard to wean them off this.

The EU can simply tell them they can no longer operate Analytics. Too bad if it's hard on Google. They are a preditory company that violates privacy rights. There is clearly competition in the markets they serve. Any threat of complete exit is empty. Those competitors are more than willing to gain any market they exit. These companies need to be put in check by the government or a regulatory body. Marketing and Advertising are toxic to the internet.

Re: Please stop putting cookie pop-ups on your website (2022)

#87

Maybe stop doing stupid shit that will legally require you to inform users that you're about to sell/share everything you know about them to 3rd parties? I fail to understand companies that display page after page of cookies and tracking stuff for you to approve don't see the issue with their actions or the insanity of "allow us to share data with our 1500 partners". Does no one in these business look at this and go:…

The vast majority of websites just want to know where their visitors are coming from and, if they are selling a product, some aggregate level of demographic knowledge to tailor their marketing efforts. They really don’t care about an individual or even small cohort and aren’t selling the data on. Targeting advertising is sooo much more effective for small and medium sized businesses and actually makes many businesses…

> Targeting advertising is sooo much more effective for small and medium sized businesses

I'm starting to question that, but without any proof that just me rambling. Assuming that it works, I'd actually be fine with a site saying "Hey, just letting you know, we use Google Analytics to learn more about you, is that cool?".

The 1500 partners and 50+ trackers aren't numbers I'm making up, those are numbers I frequently see. Sure, you feel you need a tracker, I can easily enough say no to a single tracker. I can also understand a webshop needing to share information with their advertising partner, but not 1500 of them.

The law would never have amounted to anything if the reality was a limited scope of data sharing with a clear obvious purpose. It's the insane amount of tracking and data sharing that triggered all this.

Re: Please stop putting cookie pop-ups on your website (2022)

#88
post #83

> Enact a law that requires a service to respect the do not track signal from a browser (currently entirely voluntary), and not store any tracking cookies, clear gifs or other trackers – and require that a site not “discriminate” against users who elect no tracking – basically – provide all functions to users whether they consent or do not consent. This is indeed the obvious solution. I don't understand why the EU di…

> I don't understand why the EU didn't mandate the do not track flag to be obeyed. 1. Because the implementation is simply left open? 2. Because it's nearly impossible to verify?

How are cookie banners any better in regards to 2? Not sure what you mean by 1.

Re: Please stop putting cookie pop-ups on your website (2022)

#89

Earlier quoted context omitted.

Because it is there: don't make them choose; we have x and nothing more so you cannot have more.

Yeah but there's the rub. Asking Google to take analytics away just isn't going to happen. It makes them billions. And marketeers want this data because sales data only tells them where they succeeded. Not where they failed to sell, which is more interesting to them because that's where the growth is found. It'll be really hard to wean them off this.

This is why the AdNauseam extension is so hated by Google et al. It doesn't eliminate ads but rather fights against them using a different approach: polluting the well. It is built on Ublock Origin so it indeed blocks ads, but aside doing that it also silently clicks on all of them so that data collected by advertising companies suddenly become useless. https://adnauseam.io/

Re: Please stop putting cookie pop-ups on your website (2022)

#90
post #3

Interesting article. This policy has felt like a complete failure, but I didn't know the depths of how badly it has failed. I would really like to see these die. Regulators should just work with browser vendors to make an API that I can set at the browser level, and websites just read that to know my preferences and leave me alone.

The API exists already: the DNT (do not track) header.
Post reply on HN