Live data from Hacker News

The stupid cookie law is dead at last

blog.silktide.com

21–30 of 70 posts

Re: The stupid cookie law is dead at last

#21
post #7

I was wondering when another sensationalist blog post would pop-up from Silktide. Last May, the ICO acknowledged that in certain cases, implied consent would be appropriate and this is judged on the basis of the type of cookies that a site is looking to set plus the information that is made available to a user on its site regarding cookies. The ICO considers that due to having had explicit consent on their site for a…

> the type of cookies

The ones with text inside them, or the other ones with text inside them? I don't understand how you decide between good and evil cookies.

> The ICO considers that due to having had explicit consent on their site for a number of months, and due to the information generally available on their site, it was ok to switch to an implied consent approach

Why is there a temporal component ( a couple of months ), surely new visitors come all the time? Why is the content relevant? According to their stats, 10% of the users explicitly consented. Switching to implied consent on that basis makes no sense.

> it is not guaranteed that an implied consent will be appropriate

I'm pretty sure it's not OK to say 'You might be breaking the law, but we'll let you know once we decide to prosecute'. 'Very little information' is a terrible metric; there's an implication that quality is also necessary. If I populate my user-tracking page with mathematical proofs, I've encoded information on that page - potentially a lot. It doesn't mean anything.

> I appreciate that this creates ambiguity

I appreciate that you didn't create this law (I hope). Ambiguity is bad. And expensive. All this backtracking they've been doing, it wastes my time, it wastes some civil servant's time, and it accomplishes nothing. It seems like these policies should be like trademarks; subject to dilution if they aren't suitably enforced. If Disney decided to give everyone two years to use their logo free and clear, or they only prevented 'content-free' uses, they would lose that mark.

Re: The stupid cookie law is dead at last

#22
post #10
post #8

A similar law is still going strong in The Netherlands. As of this year, most Dutch sites greet you with an annoying pop-up.

Annoyance, related to privacy. I vote for being "annoyed".

In the abstract, I agree. Only somebody who does not understand cookies would say such a thing in this context however (like our Dutch politicians).

You, the website visitor, are running a program called a browser. This browser sends and receives data from servers that host the web sites you visit. Some of that data contains a request to store a piece of information on your computer. Your browser stores that piece information, and later when you visit the site again, it sends the same piece of information back to the site.

Note that cookies are not some evil technology created by website owners to track you. It is YOU who is running the software that stores the cookie. If you don't want cookies, DON'T STORE THEM. This is easily done in any competent browser.

By analogy, if you don't want people to store things in your basement, don't give them the keys to your basement! The current Dutch law is: after you already gave them the access to store cookies on your computer, the law forces that person to ask you again if they are allowed to store cookies. Not only does it not keep any bad people out and thus gives a false sense of security, it's also annoying.

The correct action to take is to educate people on the existence of cookies, and how to disable them completely or disable them for specific ranges of sites. This is less annoying for both the users and the site owners, and more importantly it also works for foreign sites that the Dutch law has no power over, like Google analytics & Facebook like buttons that track you all over the internet (which is a much bigger privacy concern than uitzendinggemist.nl or nos.nl). While they're at it they might as well sponsor efforts to make browsers less identifiable through other means than cookies, and support projects like Tor. Of course that's not going to happen, because the current security theater reminds millions of Dutch citizens every day that they are being protected by their politicians through messages in annoying popups.

Re: The stupid cookie law is dead at last

#23

Earlier quoted context omitted.

No, the law also prohibited use (without permission) of such things as flash cookies and cookie-like things stored in HTML5's web storage, HTTP ETags, IE userData storage, Silverlight isolated storage, etc. The browser has no control over these things, only standard HTTP cookies for which it is responsible.

The browser has full control over HTML5 storage.

Yes, but browser's user generally doesn't (in easily accessible way).

Re: The stupid cookie law is dead at last

#24
post #19
post #17

Earlier quoted context omitted.

One thing that is still unclear to me about the Dutch law: Is the Dutch law only for .nl domains? Domains hosted in NL? Sites owned by Dutch companies?

It is nearly always the case that the country the servers are in, and the country the owners (persons/companies) are in is the relevant law. Imagine a dutch company with servers in the netherlands, witha .com address. Why would they be exempt from dutch law?

Why would a Dutch company operating a .com on a US server, or an American company operating a .com (or .nl for that matter) on a Dutch server not be exempt?

I'm not arguing either way, and truthfully I'm not sure how I feel about it, but it gets hard to determine jurisdiction when you're talking about an entity (owner + domain + site files/server) being split across multiple jurisdictions.

Re: The stupid cookie law is dead at last

#25
This is just more disinformation and FUD from the anti-privacy marketing clowns at Silktide. Nothing has changed when it comes to the EU rules on tracking cookies.

Of course it doesn't help that the UK's authority tasked with enforcing the law is utterly incompetent.

Re: The stupid cookie law is dead at last

#26
post #17
post #8

A similar law is still going strong in The Netherlands. As of this year, most Dutch sites greet you with an annoying pop-up.

One thing that is still unclear to me about the Dutch law: Is the Dutch law only for .nl domains? Domains hosted in NL? Sites owned by Dutch companies?

The Dutch law applies to any company doing business in the Netherlands. So it applies to Facebook and Google as well as local Dutch sites, because they have offices here and accept money from Dutch users/advertisers.

It's almost just like in the real world...

(Also, there's plenty of jurisprudence for that when for instance it comes to online gambling.)

Re: The stupid cookie law is dead at last

#27
post #10

Earlier quoted context omitted.

Annoyance, related to privacy. I vote for being "annoyed".

Shame is that at many sites it’s not really opt-in. If you disagree, you get a lecture on why the site is obliged to track you and then you can accept anyway or leave. A cookie wall, if you will. Examples: * http://tweakers.net * http://nos.nl * http://uitzendinggemist.nl NOS (public news broadcaster) and Uitzending Gemist (public television catch up) are interesting cases because apparently they’re actually require…

[deleted]

Re: The stupid cookie law is dead at last

#28
post #8

A similar law is still going strong in The Netherlands. As of this year, most Dutch sites greet you with an annoying pop-up.

The best (worst) thing about this whole law is that these sites used to work fine without cookies, but now no longer do. In effect, while making a sincere (and successful!) attempt making cookie use more transparent, thereby enhancing user privacy, they unintentionally made cookie use more pervasive, thereby hurting user privacy.

I think that's a net negative.

Re: The stupid cookie law is dead at last

#29

Earlier quoted context omitted.

The browser has full control over HTML5 storage.

Yes, but browser's user generally doesn't (in easily accessible way).

No it doesn't.

It's impossible for ordinary users to distinguish between privacy invading tracking cookies and regular functional site cookies.

Also, this doesn't form "informed consent". Users have no idea what the data is used for, and this is the key to this law.

It's not about "cookies", that is just FUD. It's about being able to opt-in to very specific forms of gathering personal data.

Browser functionality is neither opt-in nor informed.

Re: The stupid cookie law is dead at last

#30
post #7

I was wondering when another sensationalist blog post would pop-up from Silktide. Last May, the ICO acknowledged that in certain cases, implied consent would be appropriate and this is judged on the basis of the type of cookies that a site is looking to set plus the information that is made available to a user on its site regarding cookies. The ICO considers that due to having had explicit consent on their site for a…

> the type of cookies The ones with text inside them, or the other ones with text inside them? I don't understand how you decide between good and evil cookies. > The ICO considers that due to having had explicit consent on their site for a number of months, and due to the information generally available on their site, it was ok to switch to an implied consent approach Why is there a temporal component ( a couple of m…

"I don't understand how you decide between good and evil cookies."

It's all in the intended use.

Good cookies: Session cookies for ecommerce and other transactional style web interaction

Bad cookies: Advertisers tracking cookies that track users across multiple sites without their knowledge or consent.

See?

Post reply on HN