Live data from Hacker News

Kill The Cookie Banner

killthecookiebanner.eu

71–80 of 621 posts

Re: Kill The Cookie Banner

#71
post #34

I still don't get why every website has a cookie banner by default. I am data controller for several companies and have lots of exposure to GDPR. All my websites have no cookie banner, as they are not required. I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies? Who knows.

Don't underestimate the argument of "just to be on the safe side". Someone running a business who doesn't know a lot about cookies will often just put a banner on as an easy arse covering mechanism even when not required.

Or they had their site developed by an agency and the cookie banner is just part of their standard scaffolding for a new site.

Re: Kill The Cookie Banner

#72
post #34

I still don't get why every website has a cookie banner by default. I am data controller for several companies and have lots of exposure to GDPR. All my websites have no cookie banner, as they are not required. I guess that most companies just chuck it up there as a default so they dont have to read the law, or maybe they are all actually harvesting and selling personal data and therefore require cookies? Who knows.

> I guess that most companies just chuck it up there as a default so they dont have to read the law

I think most companies just don't give a fuck about user privacy and therefor have to show one. There are of course exceptions. But I don't know how many of them have been actual (for-profit) companies.

Re: Kill The Cookie Banner

#73

The other approach to killing the cookie banner is simply to declare that such a thing cannot constitute “informed consent”. (Perhaps: “ticking a checkbox and/or clicking a button cannot constitute informed consent”; and see what they try next.) From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them…

[deleted]

Re: Kill The Cookie Banner

#74
post #57

Earlier quoted context omitted.

That's why the setting should be on the device, not the browser or individual apps. One setting that you could even get pre-configured when you buy the phone.

It still doesnt solve the problem of the millions of parents that just dont care.

More parents will care if you make it easier.

Re: Kill The Cookie Banner

#76

The other approach to killing the cookie banner is simply to declare that such a thing cannot constitute “informed consent”. (Perhaps: “ticking a checkbox and/or clicking a button cannot constitute informed consent”; and see what they try next.) From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them…

> From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way

There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened.

There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.

Re: Kill The Cookie Banner

#77
post #52
post #32

Earlier quoted context omitted.

> but it might also be "you can have this content for free". ads don't require invasve and pervasive tracking

You seem to have missed the point. No ads dont require those things, but companies could start offering content in return for those things instead of ads.

As I understand it, it is the position of several DPAs that denial of access entirely (i.e. "consent or pay") could contravene the "freely given" requirement of GDPR in most cases, though this has thus far not been tested in court.

(see e.g. https://iapp.org/news/a/cjeu-clarifies-cookie-consent-requir... https://www.edpb.europa.eu/news/edpb-consent-or-pay-models-s... )

Re: Kill The Cookie Banner

#79

Earlier quoted context omitted.

Don't fall for the "we are just stupid" propaganda, which is used constantly by governments acting in bad faith. Browsers already had settings for deleting cookies. There was never a reason for banners whose only function was pulling the ladder up from smaller competitors and concentrating power in the hands of an oligopoly that could siphon data directly from the OS. This coupled with a law mandating ISPs provide a…

changing IP is not really enough for privacy, there is many ways to fingerprint your machine/browser and uniquely identify you across networks https://creepjs.org/checker

[deleted]

Re: Kill The Cookie Banner

#80
post #38

Earlier quoted context omitted.

I’ve made a few sites for work that aren’t our primary focus. The sites used cookies for login and for “required purposes” (storing in progress state). We did all the tracking on the backend, no cookies or client side trackers. On our go-live form there’s a question “do you use cookies” and it’s yes/no. If you say yes legal block the site from going live without the pre approved cookie banner…

> We did all the tracking on the backend Just checking, you do know that still counts as tracking and may fall under GDPR rules? GDPR was never just about cookies.

I do but we shouldn’t be talking about cookies in our cookie banner then.
Post reply on HN