Live data from Hacker News

Kill The Cookie Banner

killthecookiebanner.eu

411–420 of 621 posts

Re: Kill The Cookie Banner

#411

Perhaps it would be simpler to make all non-essential cookies illegal. I cannot imagine why any reasonable person would want to accept non-essential cookies, other than in the course of following a path of least resistance.

This is the only way. They'd also have to make all third-party assets illegal as well though and that may break some legit use cases, and make it a lot harder to use CDNs.

Re: Kill The Cookie Banner

#412

I always wondered though why a website in the eu, for the love of their users, won't just drop cookie usage and instrusive third party scripts. Just do analytics on the backend and don't set any cookie, except for tokens in authenticated areas

They don't love you. They want to track you and make a tiny amount of money off that. Also, they want to hire cheap incompetent staff who don't understand what all the analytics shit they are putting on the website even does.

Re: Kill The Cookie Banner

#413
post #362
post #331

Earlier quoted context omitted.

It's wild to me that anyone thinks that would be a reasonable law (whether or not it is law, I have no clue, I don't live in UK or EU). If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to le…

Allowing bad actors to act badly against all but the most sophisticated users is exactly where lawmakers should be stepping in. Sorry you find that controversial.

YouTube is a site that pretty much everyone has an account already for (and therefore have already consented), but say you make YouTube 2, you can only make money if people allow personalized ads (they pay 10-20x untargeted ads). 90% less revenue means your business model doesn't work. The government in the area has decided you can't refuse service to customers that cost you money (people who don't consent).

You simply will have to go out of business.

This is also why you see many large companies fighting for more regulation. It's harder for a competitor to emerge if they have to navigate mountains of red tape.

Re: Kill The Cookie Banner

#414
post #381

Earlier quoted context omitted.

How to know if they actually read it? The signature implies that the contract has been read, understood, and accepted. I see no need for any alternative mechanism.

Well, if you presented them with list of 100 partners each with 20 page of privacy policies and they accept it within 10 seconds it should be tricky to argue that user actually read it all. You could, for example, require that user answers very specific questions regarding 10 randomly selected partners and how exactly they can use the data ("is partner x allowed to build very detailed profile of you and target you wi…

If you did this people would only use the same half dozen sites and competitors would emerge.

We're borderline already there today when the cost of switching is typing a different url at the top of the screen. You add some mandatory 20 minute wait and you'll never see a new site again.

Google and Facebook would love it though.

Re: Kill The Cookie Banner

#415

Earlier quoted context omitted.

My understanding is that any front-end analytics solution will require consent. You're right about explicitly set preferences. I was mixing that up with inferred preferences.

It depends on what is to be analyzed. How many requests per second are being served? How many error codes were delivered to clients? How quickly the service responded? Service logs without PII? All perfectly fine to aggregate and analyze without consent.

How long did it take x user to navigate from x screen to y screen is one of the most valuable metrics for any site, and most people consider this to require consent. Or at least it not being worth the risk to not ask.

Acting dense like this isn't productive... And literally this information would be stores as anonymous user 12345, but that still would require consent (probably, or at least arguably).

Re: Kill The Cookie Banner

#416
post #397

Earlier quoted context omitted.

Not wrong in the EU, you don't need to ask for consent nor notify about cookies which are required to make the site functional. Tracking and ads don't fall under that though, which is why every site these days does need to ask for your consent.

This is actually slightly narrower exception than people (and regulators) think. The exception is: > strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service. One very ignored qualifier here is "information society service". This is defined in Directive 2015/1535 and one of the requirements is that the service is "normally pro…

What I hate about EU laws is they tend to word these things like this.

People act shocked when it leads to unintended side effects, but companies legal teams are just telling them they have no idea how a judge will interpret these broad wordings in regards to their business.

People say this fixes "future loopholes" but as you see with the cookie banner, it just leads to every company assuming the worst case scenario.

Going back years of conversation on cookie banners you'll see a constant argument on when they're required or not precisely because it's not defined explicitly.

Re: Kill The Cookie Banner

#417
post #264

So much legislation about privacy that involves "oh those bad companies" that ends up putting the onus on the individual to manage it all. I'm visiting a website, i don't want to make a legal agreement with every website ... Social media bad for kids? Everyone hand over your ID at the door ...

The companies want to track everything you do on the web. EU passes a law that says they have to ask for permission first. They all comply maliciously because they still just want to track you. Then you blame the government.

The mechanism that I have to make a legal agreement with every site was a government choice, and a poor one.

Re: Kill The Cookie Banner

#418
post #18

Wow, finally. This would be a major quality of life update for browsing the web. As others have stated, not all sites merit the same preferences. Hopefully they can adapt a middleground of default settings with the ability to customize site by site.

under what circumstances as user would I want to explicitly agree to have my browsing history sent to tens or hundreds of third party tracking aggregators?

People want free content online. More than that, they just expect it.

Any future law in regards to this will likely just lead to the companies that already got consent (companies you already have accounts with) becoming even deeper entrenched.

Non targeted ads pay a small percentage of targeted ads.

Re: Kill The Cookie Banner

#419

The other approach to killing the cookie banner is simply to declare that such a thing cannot constitute “informed consent”. (Perhaps: “ticking a checkbox and/or clicking a button cannot constitute informed consent”; and see what they try next.) From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them…

> it’s well-understood that very few people actually read those things, they just want to get them out of the way. This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data…

If only there was a short little text file that websites could use to keep track of the setting...
Post reply on HN