Live data from Hacker News

The stupid cookie law is dead at last

blog.silktide.com

51–60 of 70 posts

Re: The stupid cookie law is dead at last

#51
post #10
post #8

A similar law is still going strong in The Netherlands. As of this year, most Dutch sites greet you with an annoying pop-up.

Annoyance, related to privacy. I vote for being "annoyed".

Be that as it may, you can still be tracked without cookies (HTTP or similar) just by looking at the browser's fingerprint. This method is less reliable which is why it hasn't been used in preference to cookies.

Requiring explicit permission to store cookies on a user's browser is more likely to encourage privacy-invading companies to use the browser's fingerprint instead. This fingerprint can be loosely tied to a real world identity, and across sites too. The user wouldn't have any knowledge of such happening and they also wouldn't have any degree of control over it. At least presently it's trivial to block the most common form of tracking: HTTP cookies.

Re: The stupid cookie law is dead at last

#52
post #9
post #2

Thank goodness for that. Countless hours have been lost debating how best to implement this pointless law, and the amount of business lost due to unsightly and confusing consent banners must have been huge.

yes given that my employer a FTSE 100 publisher must have spent a huge amount time and money on this stupid law - can we claim this back against our tax bill.

Well, yes. Generally and imprecisely speaking, expenses are deducted from revenues and the net is what's taxable. Your employer will end up paying a little less corporation tax because of it. Whether it's a net loss for the government is another matter, as what isn't paid in corporation tax might be paid in national insurance and individual income taxes.

Could your employer sue the government for their compliance costs? Almost certainly not.

Re: The stupid cookie law is dead at last

#53
post #43

Earlier quoted context omitted.

The Dutch law applies to any company doing business in the Netherlands. So it applies to Facebook and Google as well as local Dutch sites, because they have offices here and accept money from Dutch users/advertisers. It's almost just like in the real world... (Also, there's plenty of jurisprudence for that when for instance it comes to online gambling.)

"Doing business" is also complicated. We're a Dutch not-for-profit, running under a US .org domain name, with some servers hosted in Germany, and our visitors come from everywhere. Right now the decision is only to annoy Dutch visitors (based on IP), but I've been waiting to implement it until there is some clarity.

What's the penalty for non-compliance in NL?

Re: The stupid cookie law is dead at last

#54
post #31
post #22

Earlier quoted context omitted.

In the abstract, I agree. Only somebody who does not understand cookies would say such a thing in this context however (like our Dutch politicians). You, the website visitor, are running a program called a browser. This browser sends and receives data from servers that host the web sites you visit. Some of that data contains a request to store a piece of information on your computer. Your browser stores that piece in…

The basement analogy is flawed. It's like a proxy holding your keys and giving them to anyone that asks, without your knowledge. Education wasn't going to happen without notices like these.

All analogies are flawed and quickly break down. They're only designed as a linguistic aid to help explain a concept by likening the unfamiliar to the familiar. They're not designed to describe the concept itself.

Re: The stupid cookie law is dead at last

#55
post #24
post #19

Earlier quoted context omitted.

It is nearly always the case that the country the servers are in, and the country the owners (persons/companies) are in is the relevant law. Imagine a dutch company with servers in the netherlands, witha .com address. Why would they be exempt from dutch law?

Why would a Dutch company operating a .com on a US server, or an American company operating a .com (or .nl for that matter) on a Dutch server not be exempt? I'm not arguing either way, and truthfully I'm not sure how I feel about it, but it gets hard to determine jurisdiction when you're talking about an entity (owner + domain + site files/server) being split across multiple jurisdictions.

Your server don't have to be in the US to operate a .com (or in netherlands to operate a .nl).

Sometimes laws can be written as "a person/company shall not cause personal data to be stored without users consent" (say). So if you, in the Netherlands, programme your server in the US to store personal data without consent, then you might be breaking the law. (Since you have caused a computer to do that.)

Re: The stupid cookie law is dead at last

#56
post #7

I was wondering when another sensationalist blog post would pop-up from Silktide. Last May, the ICO acknowledged that in certain cases, implied consent would be appropriate and this is judged on the basis of the type of cookies that a site is looking to set plus the information that is made available to a user on its site regarding cookies. The ICO considers that due to having had explicit consent on their site for a…

> I still think the overall aim of the policy in terms of educating users as to the nature of cookies is a good one.

If only users could turn off cookies in their web browser and leave the rest of us alone.

Re: The stupid cookie law is dead at last

#57
post #39

Earlier quoted context omitted.

>>> "Yes, of course, on a basic level, there is no difference between cookies but I think it's reasonable to say that they can achieve different purposes, particularly in terms of the information that they can allow third parties to collect on a user." And the arbitrator of this decision is: Some lawyer? This is why this entire law is so fantastically absurd.

Technically under the directive, any storage of information on the user's system should have the full consent of the user, with the exception of information which is strictly necessary for the functioning of the service requested by the user (see 2009 amendment to the original directive[1]). Consequently, it's not necessarily at the determination of a lawyer, but I think the ICO has acknowledged that this is a diffic…

> Technically under the directive, any storage of information on the user's system should have the full consent of the user

Isn't consent assumed by the fact that they've configured their browser to accept cookies?

Re: The stupid cookie law is dead at last

#58
post #39

Earlier quoted context omitted.

Technically under the directive, any storage of information on the user's system should have the full consent of the user, with the exception of information which is strictly necessary for the functioning of the service requested by the user (see 2009 amendment to the original directive[1]). Consequently, it's not necessarily at the determination of a lawyer, but I think the ICO has acknowledged that this is a diffic…

> Technically under the directive, any storage of information on the user's system should have the full consent of the user Isn't consent assumed by the fact that they've configured their browser to accept cookies?

No, consent is not assumed. From my understanding, most browsers are generally set up to accept cookies automatically. If it was the other way round, and users had to physically change their settings, this could be an appropriate opt-in.

The E-Privacy Directive specifically contemplates browser solutions as being a potential solution, however, I understand that at this stage, there isn't an acceptable implementation.

If for example a browser on first load asked what I wanted to do with cookies during that session, that might be acceptable.

I suspect browser makes are hesitant to work towards a solution because it would obviously be a blanket policy when it may be more appropriate for a more nuanced one dependent on each each site's cookie usage.

You can obviously configure cookies in your browser settings but I imagine for most users this option is overly complex for them to understand.

Re: The stupid cookie law is dead at last

#59
post #45
post #42

Earlier quoted context omitted.

"...necessary use of cookies as a mechanic of the website [operation]..." My shopping cart cookie that tracks you across multiple websites is necessary because it keeps my prices lower than my competition giving me the competitive advantage and my customers a better price on the things they want. Your turn.

Nope, you're still tracking someone without their consent, your reason is nothing to do with the technical operation of your website. Keep trying though, this is entertaining.

[deleted]

Re: The stupid cookie law is dead at last

#60
post #45
post #42

Earlier quoted context omitted.

"...necessary use of cookies as a mechanic of the website [operation]..." My shopping cart cookie that tracks you across multiple websites is necessary because it keeps my prices lower than my competition giving me the competitive advantage and my customers a better price on the things they want. Your turn.

Nope, you're still tracking someone without their consent, your reason is nothing to do with the technical operation of your website. Keep trying though, this is entertaining.

By tracking the user across many websites we can give personal recommendations of new products the user might like based on their surfing habits. For instance depression is correlated with erratic surfing behaviour. By making use of these types of relationships we can offer our customers what they need when they need it.

Another good feature is what we call multisite one-click shopping. Having to enter address, credit number, cvc etc on lots of websites is daunting for the customer and can hurt conversions.

/s

Post reply on HN