Live data from Hacker News

Every Fucking Website (2020)

lxe.github.io

441–450 of 529 posts

Re: Every Fucking Website (2020)

#441
post #18

Earlier quoted context omitted.

it's an example of malicious compliance by some, and herd mentality by others. I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.

No one is tanking UX to stick it to the EU. It would be better for them to simply not piss off their users. They are covering their ass. The obvious conclusion is that when you try to regulate something like this you arent going to get the behavior you want.

Why don't they just not comply with the law then? HN doesn't, and gets away with it just fine.

Re: Every Fucking Website (2020)

#442

Earlier quoted context omitted.

They're not covering their ass, they're making a deliberate tradeoff. It's trivial to make a site that doesn't need a cookie banner: don't set any cookies. Modern web devs have probably forgotten, but this is actually the default behavior. Cookies don't get set unless you do something to make it happen. And cookies that you actually need for functionality don't need a banner either. If you're setting a session cookie…

Every site needs analytics no, unless you're going to walk in the dark, and they need payment processors. If it was just about ads, they could have limited it to ads, like 'tracking for the purpose of advertising,' though even then is a press release advertising, and every serious company is going to have press releases. They could have instead targeted it, and applied it, to third party ad providers only, like Googl…

Consult a lawyer - anonymous analytics for a good reason are legal, with no banner.

Re: Every Fucking Website (2020)

#443

Earlier quoted context omitted.

But are you a software developer or a lawyer? Do they 'not need it' because the government provided a way to ensure it's not needed or because your interpretation of the law indicates it's unnecessary? Are you willing to indemnify them for legal costs if your guidance was wrong? Most small business owner's I've spoken to are keenly aware they are only one bad lawsuit away of closing down. Almost no one care's about t…

The 'better safe than sorry' calculation of small businesses skews almost 100% toward 'safe' because almost all govt regulations contain no reasonable size scaling cap on penalties. Any penalties on a website that are per-occurance could be almost infinite.

GDPR actually has one. It's 3% of global revenue.

Re: Every Fucking Website (2020)

#444
post #87
post #18

Earlier quoted context omitted.

it's an example of malicious compliance by some, and herd mentality by others. I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.

I'd say just remove it. Don't ask people who don't actually understand the cost of having it there because you will get the wrong answers. Sometimes people just have to do the right thing, take some heat and then everyone can move on. If it has severe consequences then that's probably a good reason to leave anyway. Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they…

holy shit - if AWS cost you a fraction of your other supplier, you were getting really ripped off.

Re: Every Fucking Website (2020)

#445

Earlier quoted context omitted.

On iOS Safari, tap the three stacked lines on the URL bar (depending on which Safari view you use), tap Website Settings, then you'll see a Request Desktop Website switch, which should persist for that domain.

I don’t know if this site did something tricky or if it is something about how I access it, but the switch doesn’t persist.

There a two dropdown menu options for "request desktop" in my Safari, in that menu. Translations might be imprecise because I use German locale.

But one is in a section called "Website actions", then there's another one in a section named "Website settings".

I didn't even notice it myself until now.

In earlier versions (before Liquid glass redesign I guess, which enlarged all dropdown paddings), the latter was called "always request Desktop site for xyz".

Re: Every Fucking Website (2020)

#446
post #135
post #87

Earlier quoted context omitted.

I'd say just remove it. Don't ask people who don't actually understand the cost of having it there because you will get the wrong answers. Sometimes people just have to do the right thing, take some heat and then everyone can move on. If it has severe consequences then that's probably a good reason to leave anyway. Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they…

I have the same mindset and often did the same thing, but then I thought about my doctor sneaking into my house while I’m sleeping and injecting me with the “good medicine” I had refused in their office.

Do you ask your manager whether to indent your code? Of course not, you just do it. Because it's your job and not theirs.

Re: Every Fucking Website (2020)

#447
post #18

Earlier quoted context omitted.

it's an example of malicious compliance by some, and herd mentality by others. I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.

> and he said "yeah, but it makes the site seem less legitimate. He may be right, sadly. I’ve seen the lack of a cookie banner used to suggest that a site was doing something shady or not complying with the law. Most people don’t have knowledge about the finer details of cookie laws. They’ve been trained to believe that legitimate sites who comply with the laws will implement the cookie banner, and not seeing it feel…

Who suggests that? I've never seen it. I've never seen anyone who would even notice if there wasn't a cookie banner. They'd just think they'd been there before, and already accepted it.

Re: Every Fucking Website (2020)

#448
post #18

Earlier quoted context omitted.

it's an example of malicious compliance by some, and herd mentality by others. I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.

>it's an example of malicious compliance So how would you do ePrivacy Directive compliance/risk avoidance in a non-obnoxious way?

Don't, since ePD got replaced by GDPR.

Re: Every Fucking Website (2020)

#449

Earlier quoted context omitted.

Don’t use a bunch of unnecessary tracking cookies? Completely eliminates the need for a cookie permission bar.

The law does not say 'tracking'. It says 'strictly necessary'. If you remember the user's light/dark theme preference in a cookie, that requires notification. (Or rather, what it requires in practice is that you hire a Highly Paid Consultant.)

Can you point to the law in question?

Re: Every Fucking Website (2020)

#450
post #241

Earlier quoted context omitted.

Nonsense. You are correct that people keep stating such things. But it is incorrect. That example would be an essential cookie, also known as a strictly necessary cookie. A shame this FUD is still being spread.

That's not what various references (and AIs) say. Strictly necessary means strictly necessary. They didn't bother defining it in the law. However, user preferences were called out specifically in the WP29 opinion as something that wouldn't count as strictly necessary if scoped any wider than the browser session. So if the plain English meaning and the drafters' opinion contradicts your opinion, why should I risk sign…

Yeah well most references on this are wrong, and AIs are doubly wrong since they ingest those references and also since they are AIs.

I suggest actually reading the GDPR if you think it applies to you. The EU put it up on a website for everyone to see. Here's the most relevant section: https://gdpr-info.eu/art-6-gdpr/

Notice how cookies are not mentioned, popups are not mentioned, and strictly necessary is not mentioned. Those are requirements the data harvesting industry invented out of whole cloth. They are not the actual requirements.

I'll just repeat that one more time: the GDPR does not mention cookies or popups. Let that sink in. It's all cargo-cult.

The GDPR also doesn't give a shit about dark mode preference. Literally nothing in it has any relevance to a dark mode preference, even (and especially) if you store it in a cookie.

Post reply on HN