Live data from Hacker News

Kill The Cookie Banner

killthecookiebanner.eu

541–550 of 621 posts

Re: Kill The Cookie Banner

#541
post #459

Earlier quoted context omitted.

The GDPR doesn’t allow opt-out consent to count as consent. The only consent it recognizes as valid consent is opt-in. However, since we are discussing the banner that The Guardian website shows to US viewers, I assume they’re trying to comply with California privacy law, which does allow opt-out regarding the sale of personal information.

> The GDPR doesn’t allow opt-out consent to count as consent. wat GDPR says that opt-out is the default, and if you are asking for consent, it had to be clear, unambiguous, and with both chouces clearly present.

You're both using different meanings of "opt-out"

Not legal: you have to click a button to be opted out, otherwise you're opted in. (Opt-out as a verb)

Legal: you are opted out by default (opt-out as an adjective describing the default situation)

Re: Kill The Cookie Banner

#542

My request to the owner/promoter of the site: provide an email template that we can send to our representatives. I'm willing to send such email, I've the list of the people I want to reach. But what is too complex is to write the appropriate email... Can you help me with this ?

In general, representatives ignore template emails. Their staff throw them in the trash folder before anyone important reads them.

Re: Kill The Cookie Banner

#544
post #477
post #424

Earlier quoted context omitted.

The result is entirely predictable. They picked it.

No, the websites picked it. They consciously made cookie banners as annoying as possible so that you would give up and accept.

You're both right. The government could have just made it illegal.

Re: Kill The Cookie Banner

#545
post #459

Earlier quoted context omitted.

> The GDPR doesn’t allow opt-out consent to count as consent. wat GDPR says that opt-out is the default, and if you are asking for consent, it had to be clear, unambiguous, and with both chouces clearly present.

You're both using different meanings of "opt-out" Not legal: you have to click a button to be opted out, otherwise you're opted in. (Opt-out as a verb) Legal: you are opted out by default (opt-out as an adjective describing the default situation)

https://en.wiktionary.org/wiki/opt-out

https://en.wiktionary.org/wiki/opt-in

You've muddled the definitions again. "opt" signifies an action by the user.

If I am "in a group" by default, then I can take an action to "opt out", requesting to be removed from the list.

If I am not initially joined to the group, then I can take an action to "opt in" and be added to the list.

There is no such thing as "opt by default". That is not a user action. It also makes no sense for the same list or group to be both "opt in" and "opt out" because, as adjectives, they imply the default states and they describe the user action taken to change that default.

opt-in: default state is out

opt-out: default state is in

Re: Kill The Cookie Banner

#546
post #299

Earlier quoted context omitted.

> Don’t force your wordview on people through regulation As opposed to enforcing your worldview with a lack of regulation? Because that's precisely what's happening, with the advertisement industry enforcing their worldview through lack of compliance.

That was suppose to be a reductio ad absurdum, not a genuine argument

Poe's law strikes again! My fault here, sorry for the misunderstanding!

Re: Kill The Cookie Banner

#547

Earlier quoted context omitted.

"necessary only" also tends to have a malicious compliance aspect where they don't store a cookie recording your preference and show the banner on every single page until you click accept.

I don't see that as malicious. Is my consent record "strictly necessary"? No. Don’t get me wrong. I’m sure they love that, but if sites saved that preference when only necessary was selected, I’m sure a bunch of people would be screaming that they weren’t following the law.

The malicious compliance aspect is that they're not offering a choice between "tracking" and "no tracking", but bundling "no tracking" + "painfully degraded functionality" (like repeating the question on every page) = "strictly necessary cookies only"

Re: Kill The Cookie Banner

#549

Earlier quoted context omitted.

if you're talking about cross site cookies, which are the big ones that require consent: no they don't!

Consent has nothing to do with crosssiteness except insofar as that proves it isn't needed for the operation of your own site.

lol sounds like it does then

Re: Kill The Cookie Banner

#550

Earlier quoted context omitted.

Abstract: It's still spying on users. Practical: Supposedly-aggregated stats have a history of actually being perfectly possible to analyze back into individually identifiable information. Also, it's conveniently the same tech stack in a way that makes it easier to make an actual slippery slope.

The practical argument I can understand. From the abstract argument though, it sounds like you'd be opposed even if the anonymization could be guaranteed, which I don't understand. Why is it "spying" to try to understand in aggregate how users are using your website? How are you supposed to eg. identify usability problems without this information? And what is the harm to users? (Again, in the abstract case where we l…

because no one has shown an anonymization guarantee yet
Post reply on HN