Live data from Hacker News

The stupid cookie law is dead at last

blog.silktide.com

31–40 of 70 posts

Re: The stupid cookie law is dead at last

#31
post #22
post #10

Earlier quoted context omitted.

Annoyance, related to privacy. I vote for being "annoyed".

In the abstract, I agree. Only somebody who does not understand cookies would say such a thing in this context however (like our Dutch politicians). You, the website visitor, are running a program called a browser. This browser sends and receives data from servers that host the web sites you visit. Some of that data contains a request to store a piece of information on your computer. Your browser stores that piece in…

The basement analogy is flawed. It's like a proxy holding your keys and giving them to anyone that asks, without your knowledge.

Education wasn't going to happen without notices like these.

Re: The stupid cookie law is dead at last

#32
post #22
post #10

Earlier quoted context omitted.

Annoyance, related to privacy. I vote for being "annoyed".

In the abstract, I agree. Only somebody who does not understand cookies would say such a thing in this context however (like our Dutch politicians). You, the website visitor, are running a program called a browser. This browser sends and receives data from servers that host the web sites you visit. Some of that data contains a request to store a piece of information on your computer. Your browser stores that piece in…

This entire argument boils down to "if you don't want to get raped, don't wear short skirts in public".

People shouldn't have to take protective action in order to not get stalked by advertisers and marketers.

Such activities require opt-in and informed consent, and standard browser functionality doesn't even come close to supporting that.

Oh, I agree that the current law doesn't solve the problem.

But "educating the people" is a completely backward solution. The opaque stalking of people by the likes of Facebook and Google should be outlawed completely, and heavily enforced.

Re: The stupid cookie law is dead at last

#33
post #7

I was wondering when another sensationalist blog post would pop-up from Silktide. Last May, the ICO acknowledged that in certain cases, implied consent would be appropriate and this is judged on the basis of the type of cookies that a site is looking to set plus the information that is made available to a user on its site regarding cookies. The ICO considers that due to having had explicit consent on their site for a…

> the type of cookies The ones with text inside them, or the other ones with text inside them? I don't understand how you decide between good and evil cookies. > The ICO considers that due to having had explicit consent on their site for a number of months, and due to the information generally available on their site, it was ok to switch to an implied consent approach Why is there a temporal component ( a couple of m…

> The ones with text inside them, or the other ones with text inside them? I don't understand how you decide between good and evil cookies.

Yes, of course, on a basic level, there is no difference between cookies but I think it's reasonable to say that they can achieve different purposes, particularly in terms of the information that they can allow third parties to collect on a user.

> Why is there a temporal component ( a couple of months ), surely new visitors come all the time? Why is the content relevant? According to their stats, 10% of the users explicitly consented. Switching to implied consent on that basis makes no sense.

Of course there will be new visitors who will have no idea about the opt-in approach previously taken by the ICO. You are quite right to identify that to those users, the previous opt-in approach was irrelevant. Rather than focusing on individual users, to me, the ICO's approach is to identify what steps a site is taking to educate its users in general.

In reality, I'm sure a large proportion of users will click whatever box they are told to if it means they can access a site or remove a banner but that doesn't mean that a site should be excused of its obligation to at least provide information to those users who may want to learn more about the cookies being set.

In terms of content, I should have been clearer, I meant content providing clear information on the types of cookies being set.

> I'm pretty sure it's not OK to say 'You might be breaking the law, but we'll let you know once we decide to prosecute'. 'Very little information' is a terrible metric; there's an implication that quality is also necessary. If I populate my user-tracking page with mathematical proofs, I've encoded information on that page - potentially a lot. It doesn't mean anything.

Yes, any law should provide clear limits to its effect to people can know when they are breaking it. From what I have read, the ICO is likely to adopt a consultative approach to enforcement in terms of letting a site know that they consider that the site could do more to educate its users as to the cookies that are being set when a user visits. By information, I mean relevant information in the form of a policy clearly explaining to users the cookies that will be set when a user visits the site.

> I appreciate that you didn't create this law (I hope). Ambiguity is bad. And expensive. All this backtracking they've been doing, it wastes my time, it wastes some civil servant's time, and it accomplishes nothing. It seems like these policies should be like trademarks; subject to dilution if they aren't suitably enforced. If Disney decided to give everyone two years to use their logo free and clear, or they only prevented 'content-free' uses, they would lose that mark.

Heh, no, I did not create this law. I agree that ambiguity is bad, and that responsible businesses who sought to implement solutions before the ICO's u-turn on implied consent last May have incurred expenses unnecessarily which is not how laws are meant to operate.

The elephant in the room is that in certain quarters, the UK's approach to interpretation/enforcement falls short of that required to comply with the terms of the Directive. Whilst this may be the case, I'm sure sites would prefer to be subject to the ICO's softer approach at this stage than have to implement a full opt-in and be subject to harsh enforcement.

Your proposal might make a degree of sense - however, a trade mark owner's rights would generally not be revoked for lack of enforcement. A grant of trade mark rights as you mention would be subject to an implied licence which Disney could arguably revoke at any time. At worst, if they did not take action against an unlicensed use, they could be deemed to have acquiesced in the usage, and be prevented from taking enforcement action subsequently. This may be a more appropriate analogy than simply having the underlying rights (mark or legislation) removed.

I'm not particularly positive about the law itself and acknowledge that it is adding confusion and additional costs to businesses in terms of compliance. My only concern is that posts like the Silktide one are unnecessarily bias against the law and are essentially just preaching to the converted (developers/IT professionals etc are aware of how cookies work and what purposes they achieve).

The position I laid out above is only really my interpretation of the ICO's current stance. Although completely anecdotally, only last week, some colleagues who I would consider to be your average internet user were commenting on how weird it was that adverts in relation to sites that they had previously visited were appearing on other sites. If the cookie law means even a small proportion of users are educated about cookies, I think this is a good thing.

Re: The stupid cookie law is dead at last

#34
post #30

Earlier quoted context omitted.

> the type of cookies The ones with text inside them, or the other ones with text inside them? I don't understand how you decide between good and evil cookies. > The ICO considers that due to having had explicit consent on their site for a number of months, and due to the information generally available on their site, it was ok to switch to an implied consent approach Why is there a temporal component ( a couple of m…

"I don't understand how you decide between good and evil cookies." It's all in the intended use. Good cookies: Session cookies for ecommerce and other transactional style web interaction Bad cookies: Advertisers tracking cookies that track users across multiple sites without their knowledge or consent. See?

How about "session cookies for ecommerce and other transactional style web interaction, that track users across multiple sites without their knowledge or consent"? Are these good or bad?

We can decide on a case by case basis whether any particular use of cookies is good or bad, but coming up with a generic rule to do so is fraught with difficulties.

Re: The stupid cookie law is dead at last

#35
post #30

Earlier quoted context omitted.

> the type of cookies The ones with text inside them, or the other ones with text inside them? I don't understand how you decide between good and evil cookies. > The ICO considers that due to having had explicit consent on their site for a number of months, and due to the information generally available on their site, it was ok to switch to an implied consent approach Why is there a temporal component ( a couple of m…

"I don't understand how you decide between good and evil cookies." It's all in the intended use. Good cookies: Session cookies for ecommerce and other transactional style web interaction Bad cookies: Advertisers tracking cookies that track users across multiple sites without their knowledge or consent. See?

[deleted]

Re: The stupid cookie law is dead at last

#36
post #34
post #30

Earlier quoted context omitted.

"I don't understand how you decide between good and evil cookies." It's all in the intended use. Good cookies: Session cookies for ecommerce and other transactional style web interaction Bad cookies: Advertisers tracking cookies that track users across multiple sites without their knowledge or consent. See?

How about "session cookies for ecommerce and other transactional style web interaction, that track users across multiple sites without their knowledge or consent"? Are these good or bad? We can decide on a case by case basis whether any particular use of cookies is good or bad, but coming up with a generic rule to do so is fraught with difficulties.

Well those would be bad, as they've clearly strayed well beyond necessary use of cookies as a mechanic of the website operating and into tracking people without their knowledge or consent.

What about "Tracking people without their knowledge or consent" being A Bad Thing is hard to understand?

The original poster said " in certain cases, implied consent would be appropriate and this is judged on the basis of the type of cookies that a site is looking to set". Your example clearly goes beyond.

Re: The stupid cookie law is dead at last

#37

Earlier quoted context omitted.

The browser has full control over HTML5 storage.

Yes, but browser's user generally doesn't (in easily accessible way).

At least on Chrome, they are displayed precisely in the same manner as cookies.

Re: The stupid cookie law is dead at last

#38
post #33

Earlier quoted context omitted.

> the type of cookies The ones with text inside them, or the other ones with text inside them? I don't understand how you decide between good and evil cookies. > The ICO considers that due to having had explicit consent on their site for a number of months, and due to the information generally available on their site, it was ok to switch to an implied consent approach Why is there a temporal component ( a couple of m…

> The ones with text inside them, or the other ones with text inside them? I don't understand how you decide between good and evil cookies. Yes, of course, on a basic level, there is no difference between cookies but I think it's reasonable to say that they can achieve different purposes, particularly in terms of the information that they can allow third parties to collect on a user. > Why is there a temporal compone…

>>> "Yes, of course, on a basic level, there is no difference between cookies but I think it's reasonable to say that they can achieve different purposes, particularly in terms of the information that they can allow third parties to collect on a user."

And the arbitrator of this decision is: Some lawyer? This is why this entire law is so fantastically absurd.

Re: The stupid cookie law is dead at last

#39
post #33

Earlier quoted context omitted.

> The ones with text inside them, or the other ones with text inside them? I don't understand how you decide between good and evil cookies. Yes, of course, on a basic level, there is no difference between cookies but I think it's reasonable to say that they can achieve different purposes, particularly in terms of the information that they can allow third parties to collect on a user. > Why is there a temporal compone…

>>> "Yes, of course, on a basic level, there is no difference between cookies but I think it's reasonable to say that they can achieve different purposes, particularly in terms of the information that they can allow third parties to collect on a user." And the arbitrator of this decision is: Some lawyer? This is why this entire law is so fantastically absurd.

Technically under the directive, any storage of information on the user's system should have the full consent of the user, with the exception of information which is strictly necessary for the functioning of the service requested by the user (see 2009 amendment to the original directive[1]).

Consequently, it's not necessarily at the determination of a lawyer, but I think the ICO has acknowledged that this is a difficult proposition so is taking a softer approach to enforcement.

At the very least the distinction could very easily be drawn between cookies which facilitate the sharing of information on the user's usage of multiple sites, to cookies which deal solely with the user's usage of the site where the cookie is set.

[1] http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2...

Re: The stupid cookie law is dead at last

#40
post #31
post #22

Earlier quoted context omitted.

In the abstract, I agree. Only somebody who does not understand cookies would say such a thing in this context however (like our Dutch politicians). You, the website visitor, are running a program called a browser. This browser sends and receives data from servers that host the web sites you visit. Some of that data contains a request to store a piece of information on your computer. Your browser stores that piece in…

The basement analogy is flawed. It's like a proxy holding your keys and giving them to anyone that asks, without your knowledge. Education wasn't going to happen without notices like these.

Yes, I wanted to keep it simple. The fact is that that proxy (the browser) is the problem, and is also where the solution lies, not in the subset people that Dutch law happens to apply to who make use of that proxy to obtain your keys.
Post reply on HN