Live data from Hacker News

Every Fucking Website (2020)

lxe.github.io

451–460 of 529 posts

Re: Every Fucking Website (2020)

#451

Earlier quoted context omitted.

They're not covering their ass, they're making a deliberate tradeoff. It's trivial to make a site that doesn't need a cookie banner: don't set any cookies. Modern web devs have probably forgotten, but this is actually the default behavior. Cookies don't get set unless you do something to make it happen. And cookies that you actually need for functionality don't need a banner either. If you're setting a session cookie…

Every site needs analytics no, unless you're going to walk in the dark, and they need payment processors. If it was just about ads, they could have limited it to ads, like 'tracking for the purpose of advertising,' though even then is a press release advertising, and every serious company is going to have press releases. They could have instead targeted it, and applied it, to third party ad providers only, like Googl…

Nope, you don't need analytics. You might want analytics, and you might want them enough to bother every single visitor with a popup so you can have them, but you don't need them.

And if you decide you need them, you can do them server side. That's not as good? Oh well. See above about want vs need.

Why not just make a Google law? Because Google is far from the only abuser. Using a VPN that routes through Europe is a real eye-opener. At least whatever country I got routed through apparently required that cookie banners include a list of every single partner who got your data. Pretty much every site had hundreds of them. One was literally over a thousand. No, the entire industry is rotten. And the epidemic of cookie banners just shows how rotten it is. They can't even be shamed into behaving.

Re: Every Fucking Website (2020)

#452

Earlier quoted context omitted.

You should stop using Wells Fargo anyway. It's been what, nine months since their last national scandal? They're overdue.

You can try to stop using Wells Fargo, but they won't let you. They'll just open more accounts for you

When my wife and I finally got rid of our Wells Fargo accounts -- having sold our house and thus eliminated that mortgage, and having already moved our personal banking to a credit union -- we legitimately celebrated by going out to dinner.

Re: Every Fucking Website (2020)

#453
post #269

Earlier quoted context omitted.

Yes, but on whom does it work? Does it work because you're taking advantage of a group of people who are extremely vulnerable to manipulation? People who already struggle with impulse control, who are prone to making bad financial decisions? The elderly, kids? We have to escape this mentality that anything that makes money is valid, that the money itself is the validation of "rightness". Some of us, just some think t…

> people who are extremely vulnerable to manipulation I think this is a gross over-exaggeration, otherwise dark patterns wouldn't work at the magnitude (majority of the buying population) they do. I say this not disagreeing with your point: > We have to escape this mentality that anything that makes money is valid, that the money itself is the validation of "rightness".

I agree with you too, but I don't think it's necessarily a gross over-exaggeration: it's possible that the majority of the buying population are extremely vulnerable to manipulation.

"Average" doesn't necessarily mean half way between two extremes - the average human might actually be all of:

- extremely vulnerable to manipulation

- struggling with impulse control

- prone to making bad financial decisions

- the elderly / kids (60)

Based on age demographics, rampant consumerism and social media addiction, especially in those age demographics, I'd be more inclined to guess the average human is all of those things.

Re: Every Fucking Website (2020)

#455

Earlier quoted context omitted.

The law does not say 'tracking'. It says 'strictly necessary'. If you remember the user's light/dark theme preference in a cookie, that requires notification. (Or rather, what it requires in practice is that you hire a Highly Paid Consultant.)

Okay, but it doesn’t require notification for every user that hits your landing page. If you want to remember dark mode with a cookie, then you can just gate that setting behind a “allow functional cookies” toggle. Getting consent for functional cookies doesn’t have to be done with an intrusive cookie bar on landing. You can request consent as it becomes needed. There’s other ways of complying that aren’t dark patter…

Can you please tell me what part of this law requires any sort of notification or toggle whatsoever for remembering your dark mode setting: https://gdpr-info.eu/art-6-gdpr/

Re: Every Fucking Website (2020)

#456
post #277

Earlier quoted context omitted.

You can try to put the blame on the grunts, like trying to focus on the engineers in the VW Dieselgate, etc, but that is very weak leverage. You have to intervene at the root cause of the incentive. But of course the higher you go, the more there is a blur between legislators and business owners and they won't be harsh to themselves.

So morals are good at a certain pay level? Thank god I am just a minion who now can go home worry free. Yay!

As long as I just follow orders.

Re: Every Fucking Website (2020)

#457
post #260

Earlier quoted context omitted.

Really? Because the industry really respected DNT[0]? Regulations are needed when the kids cannot play nice in the school yard. GDPR is actually not that bad if you read it rather than subscribing to much of the malicious compliance we see. [0] https://en.wikipedia.org/wiki/Do_Not_Track

No one is frustrating users to stick it to the EU. They are doing it to cover their ass.

If that's the case, they're not even doing it right. It's well established by now that reject all has to be equally easy to accept all.

Re: Every Fucking Website (2020)

#458

Earlier quoted context omitted.

I’ve long believed that making companies liable for paying damages if PII is leaked in a data breach would be the best way to stop excessive tracking. If you force them to have to manage user data like they’re handling radioactive waste then the expense and overhead involved is a natural drag on the business logic that drives the bottomless appetite for data collection. They’ll collect it if they actually need it, an…

The most valuable data breach content isn’t your advertising tracking data, though. It would be your payment information, which is orthogonal to most of the tracking data. The black market demand for leaked advertising-related tracking data is basically nil, except maybe in cases where it’s related to something else exploitable or usable for blackmail like if someone frequents cryptocurrency exchanges or porn sites.…

Payment data doesn't live in a vacuum though. Every payment is authorised by your bank, who runs an AI looking for "suspicious transactions" and has a legal obligation to refund you if you lose money because any part of their payment network got hacked.

Re: Every Fucking Website (2020)

#459

Earlier quoted context omitted.

It's not a cookies banner. It's a request to harvest your data and share it with third parties for purposes that are not required for the service you're offering. No harvest data to 936 partners? No need for a banner!

Downvote all you like, if you're just using purely functional cookies, you don't need a banner.

People all over this thread are just making up wildly speculative guesses about what the law says.

Here's what it actually says: https://gdpr-info.eu/art-6-gdpr/

Note that cookies aren't even mentioned. (You're in the right)

Re: Every Fucking Website (2020)

#460

The cookie thing, I assume it's EU-only, is an example of the EU policy making process being fundamentally broken in some way. If you create a flawed policy and don't fix it many years after it's very visibly obvious that it's a bad policy, something is really wrong.

What is the consequence of not complying with the cookie thing? Assuming you sell out of a jurisdiction outside of the EU

None, it's the same as calling the Kim dynasty a bunch of poopyheads and never travelling to North Korea.

You could still travel to the EU though. Only your business would have to comply before doing business there.

Post reply on HN