Live data from Hacker News

Every Fucking Website (2020)

lxe.github.io

181–190 of 529 posts

Re: Every Fucking Website (2020)

#181

Earlier quoted context omitted.

>it's an example of malicious compliance So how would you do ePrivacy Directive compliance/risk avoidance in a non-obnoxious way?

Don’t use a bunch of unnecessary tracking cookies? Completely eliminates the need for a cookie permission bar.

The law does not say 'tracking'. It says 'strictly necessary'. If you remember the user's light/dark theme preference in a cookie, that requires notification. (Or rather, what it requires in practice is that you hire a Highly Paid Consultant.)

Re: Every Fucking Website (2020)

#182
post #140

Earlier quoted context omitted.

1. It's also a piece of cake to just not display the cookie banner for non-EU IPs 2. If you are a purely US entity with no actual business presence in the EU, you only need to comply with US laws and nothing else. If the EU doesn't like a purely-foreign website, it's on them to set up a national firewall and block it. Case in point 1: It's not on you to comply with China's laws, it's on them to block it if they want…

GDPR applies to EU citizens data. It doesn’t matter where your business is located in the world, if you process European personal data you’re on the hook. Of course you can decide to ignore and argue the EU doesn’t have jurisdiction

Exactly, they don't have jurisdiction outside their borders. If you don't have a presence there, they cannot subject you to their laws.

1. When is the last time you saw China enforcing its laws outside their borders? Why would EU be any different?

2. China has laws that are directly contradictory to GDPR laws; you may be required to retain data regardless of consent; if your website is based in China you have to follow local laws first before you follow contradictory foreign laws that have no jurisdiction over you.

Re: Every Fucking Website (2020)

#184

Earlier quoted context omitted.

Bullshit. There’s no need to track every visitor. Just stop tracking and you don’t need a cookie banner. The only mistake EU policymakers made was underestimating how willing companies were to deface their websites.

The policy is both, good, but also flawed. For example, you cannot persist settings, because one policy says that website settings should be ephemeral unless user agrees to persist them.

That’s not true, it’s even explicitly called out by the EU guidelines.

Copy pasting an older comment because it’s really coming up all the time…

https://news.ycombinator.com/item?id=49060456

===

That's not true and is a very common misinformation people repeat online. You can save user preferences in cookies without any consent banner, if the cookie isn't used for tracking. See here[0], page 6: > As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’ 0: https://www.edpb.europa.eu/system/files/documents/2024-10/ed... As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen

Re: Every Fucking Website (2020)

#186
post #18

The cookie thing, I assume it's EU-only, is an example of the EU policy making process being fundamentally broken in some way. If you create a flawed policy and don't fix it many years after it's very visibly obvious that it's a bad policy, something is really wrong.

it's an example of malicious compliance by some, and herd mentality by others. I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.

Good point. The page should have 200MB of assets so that it loads slowly, making it look like there's serious engineering going on.

Re: Every Fucking Website (2020)

#187

Earlier quoted context omitted.

> Plus, isn't this website undissmissably "better in the app" after a few minutes of attempting to use it on a phone? Where's that at? This is the most annoying thing on the internet. There’s a site I’d like to use, but “try the app” takes up the entire page (and appears to be impossible to dismiss?). Actually, is there a way to permanently request the desktop site for all future visits to a domain on iOS? There is n…

If the site happens to be a discussion site that starts with 'R', clearing cookies will let you through for a while. In Brave, there's a setting to do so when you leave the page.

They still haven’t removed “old.reddit.com”. Replace “www” with “old” on any reddit URL and enjoy a relic from when the internet was less ruined.

Re: Every Fucking Website (2020)

#188
post #18

The cookie thing, I assume it's EU-only, is an example of the EU policy making process being fundamentally broken in some way. If you create a flawed policy and don't fix it many years after it's very visibly obvious that it's a bad policy, something is really wrong.

it's an example of malicious compliance by some, and herd mentality by others. I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.

No one is tanking UX to stick it to the EU. It would be better for them to simply not piss off their users. They are covering their ass.

The obvious conclusion is that when you try to regulate something like this you arent going to get the behavior you want.

Post reply on HN