Live data from Hacker News

Kill The Cookie Banner

killthecookiebanner.eu

581–590 of 621 posts

Re: Kill The Cookie Banner

#581

Earlier quoted context omitted.

I don't buy it. 70% of the CMPs being "misconfigured" tells us that even if these panels were broken by design, the companies using them must all conveniently not notice this. Strange, given that even a small risk of large fines or prolonged legal process with public entities would warrant someone paying at least a moment of attention to this. I suspect they are, and the choice of leaving things misconfigured is deli…

> I suspect they are, and the choice of leaving things misconfigured is deliberate. That honestly doesn't fit our data or my experience. In our scanning, about 60% of the misconfigured sites had a CMP with blocking active but one or two tags bypassing consent controls Generally those misconfigurations aren't valuable to the business. We don't see for example lots of ad targeting and conversion tracking firing without…

Another tiny data point example: A previous company used Stripe for a very niche feature (most companies who used our product didn't ever enable it) but having the SDK in the bundle drops their "anti-fraud" cookies, whatever they are). That is exactly the kind of thing that a CMP won't be able to fix without deeper engineering work, and which doesn't actually matter anyway because no one is profiting from that -- but that's the kind of thing that a company could be sued or fined for. A complete distraction from what actually matters.

Re: Kill The Cookie Banner

#582

Earlier quoted context omitted.

It can and has been in many cases in many legal systems. For example, let’s say you walk into my store to buy a dish washer. I say ”here is an extended warranty that I will give you. Just sign” you sign it instead of reading 15 pages of boilerplate. In the end of the document it says you now owe me 10 billion dollars. Doubt I will be able to enforce it in most legal systems.

This is bullshit. https://www.nbcnews.com/news/us-news/disney-says-man-cant-su... "Disney is trying to have a widower's wrongful death lawsuit dismissed and sent to arbitration because the man had signed up for a Disney+ account several years ago." Now what happened was that Disney quit fighting over really bad PR. But the court challenge would have liteky succeeded.

You get that US is a tiny part of the worlds entire legal systems right? Just because US is messed up doesn’t mean the rest of the world is. Most people don’t live in US.

Re: Kill The Cookie Banner

#583
post #557

Earlier quoted context omitted.

"legitimate interest" is legal basis in GDPR. ePD (which governs access to cookies) does not have such legal basis, only consent and the two exceptions. Other processing (like after value is read) can happen under GDPR if the data is personal data.

My understanding is that ePD was obsoleted by GDPR. Note that you don't comply with EU directives anyway - you comply with actual laws of actual countries, and the EU process helps them to mostly agree with each other. Did countries replace their ePD-based laws with GDPR-based laws? My understanding is they did.

No, it's not. ePD is lex specialis in relation to original Data Protection Directive (and later GDPR). DPD was replaced by GDPR, ePD was not. There has been talks about ePrivacy Regulation over the years, but it was shelved again in 2025.

ePD is still active and national laws implement it. GDPR itself is not implemented by national laws as it's EU regulation rather than EU directive. Member States primarily repealed their DPD-based laws after GDPR and implemented various things that GDPR allows (like Article 23 restrictions). Some countries may have explicitly imported GDPR into their own law due to how their own legalization works. Like that's why UK DPA was originally pretty much just copy of GDPR.

Re: Kill The Cookie Banner

#584
post #394

Earlier quoted context omitted.

A right to privacy also includes the freedom to forgo privacy in return for other benefits.

"A right to not be raped also includes the right to be raped in exchange for benefits"

It's called consentual sex

Re: Kill The Cookie Banner

#585
post #374
post #321

Earlier quoted context omitted.

> Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you Exactly. I use the "I don't care about cookies" extension, which rejects most cookies automatically without me having to see the popups. But even accepting cookies is fine - I'll be closing my browser soon anyway and they'll be gone.

I'll be closing my browser soon anyway and they'll be gone Sure, your browser cookie will be gone. But you have already allowed the server-side identifiers of your session to be used for whatever purpose, including reconstituting increasingly larger parts of your identity over multiple disconnected sessions. Please don't make the mistake of thinking that clearing your cookies afterwards is the same as rejecting all s…

Sure, but "rejecting all server-side processing" is basically trusting the website to honor my wishes. I don't put much faith in that at all.

They'll have my IP and browser fingerprint. Using Firefox mobile narrows me down to 1-2% of the world, but also lets me run ad blockers and noscript, to block some of the more troublesome trackers.

It's all tradeoffs...

Re: Kill The Cookie Banner

#586

Earlier quoted context omitted.

Actually you can't send any cookie that is not essential to the operation of the website without consent and that would include analytics regardless of PII. same for pixel tracking / fingerprinting, it's all a no-no.

There's "legitimate business interest" which I think is a catch-all for things you want to do as long as they don't invade privacy?

Most of those things involve tracking users I imagine but if there's any that don't, go for it.

Re: Kill The Cookie Banner

#587
post #486

Earlier quoted context omitted.

Spoken like someone who has never used parental controls. They’re a shitshow.

You miss my point. It is that parents dont care. However good the parental controls are, there are millions of parents who just dont and wont ever care.

You replied to a comment saying the companies don’t care to make it easy. Then, you shifted the blame to parents instead of the companies. I got your point just fine.

Re: Kill The Cookie Banner

#588
post #268

Earlier quoted context omitted.

Agreeing to terms and contracts without reading or at least skimming them is not responsible adult behavior and should not be used as a model for legislation, no matter how many people do it. I agree that we do have a culture where private law is not taken very seriously, and that's very unfortunate. People do not have a right (morally speaking, not legally) to access or use a service (or a website) etc without havin…

How much of https://www.ycombinator.com/legal/ have you actually read?

All of it, if it was presented for me to accept when signing up for this account. Don't remember explicitly. As I said to others, most of it is boilerplate, so you just learn to skim and see the stuff that's really different.

Re: Kill The Cookie Banner

#589

Earlier quoted context omitted.

Terms of services and contracts are written for lawyers and not the average people. If your terms require people to get a law degree and take a week to parse the 400 page document, then I would argue that it's a tactic to get people to sign up for the service without fully understanding it. We need legislation that forces companies to communicate the terms in a way that an average person can comprehend.

Terms of service aren't even legally binding!

Wikipedia and a few other sites I saw say otherwise for the US. https://en.wikipedia.org/wiki/Terms_of_service Wouldn't make much sense otherwise.

Re: Kill The Cookie Banner

#590

I never understood why visited websites and all their first and third party cookies are not isolated by default in browsers. There are so few sites where I really need cross-site logins to work that an opt-in would be much more preferable. Have all sites set cookies on whichever third party they want, but don't share those cookies over. Add an explicit "Do you really want foo.com to share data with bar.com?" if you r…

That's how it works on Firefox
Post reply on HN