Live data from Hacker News

The stupid cookie law is dead at last

blog.silktide.com

61–70 of 70 posts

Re: The stupid cookie law is dead at last

#61
post #58

Earlier quoted context omitted.

> Technically under the directive, any storage of information on the user's system should have the full consent of the user Isn't consent assumed by the fact that they've configured their browser to accept cookies?

No, consent is not assumed. From my understanding, most browsers are generally set up to accept cookies automatically. If it was the other way round, and users had to physically change their settings, this could be an appropriate opt-in. The E-Privacy Directive specifically contemplates browser solutions as being a potential solution, however, I understand that at this stage, there isn't an acceptable implementation.…

> You can obviously configure cookies in your browser settings but I imagine for most users this option is overly complex for them to understand.

Can't one argue the same thing for setting up your website to be compliant with this law?

The fact that the easy and free solution is to just tell users to turn off all cookies in their browsers makes any laws of this type a waste.

Re: The stupid cookie law is dead at last

#62
post #43

Earlier quoted context omitted.

"Doing business" is also complicated. We're a Dutch not-for-profit, running under a US .org domain name, with some servers hosted in Germany, and our visitors come from everywhere. Right now the decision is only to annoy Dutch visitors (based on IP), but I've been waiting to implement it until there is some clarity.

What's the penalty for non-compliance in NL?

Maximum penalty is a fine of up to around 450.000 euros.

Re: The stupid cookie law is dead at last

#63
post #60
post #45

Earlier quoted context omitted.

Nope, you're still tracking someone without their consent, your reason is nothing to do with the technical operation of your website. Keep trying though, this is entertaining.

By tracking the user across many websites we can give personal recommendations of new products the user might like based on their surfing habits. For instance depression is correlated with erratic surfing behaviour. By making use of these types of relationships we can offer our customers what they need when they need it. Another good feature is what we call multisite one-click shopping. Having to enter address, credi…

Cool, all sounds useful, so you have no issue asking for the user's permission to do this?

Because it's still not technically necessary for the functioning of whatever it is that the user is trying to do on your particular site.

These are all fine business reasons but (AFAICT) the entire intent of the law is that business reasons are not good enough to track people without their explicit knowledge and permission that that is what you're doing.

(yes of course they fouled up on the coding and execution of the law, bureaucrats were involved)

Re: The stupid cookie law is dead at last

#64
post #63
post #60

Earlier quoted context omitted.

By tracking the user across many websites we can give personal recommendations of new products the user might like based on their surfing habits. For instance depression is correlated with erratic surfing behaviour. By making use of these types of relationships we can offer our customers what they need when they need it. Another good feature is what we call multisite one-click shopping. Having to enter address, credi…

Cool, all sounds useful, so you have no issue asking for the user's permission to do this? Because it's still not technically necessary for the functioning of whatever it is that the user is trying to do on your particular site. These are all fine business reasons but (AFAICT) the entire intent of the law is that business reasons are not good enough to track people without their explicit knowledge and permission that…

Yet again, semantics matter.

You didn't originally say "technically necessary," but my argument is not with you. It's with half-baked legislation. Does the legislation make the distinction? You use the phrase "technically necessary for the functioning of..." and the business guys in the company will continue to argue that yes, this is technically necessary for the functioning of their company/website/business etc.

Ask the engineers whether these things are "technically necessary" to facilitate the business plan, because the business plan is the entire reason the company exists. The answer is yes. I'd suspect the workaround is that you just don't do business with people who don't want to be tracked.

Are we going to start legislating every detail of business?

Re: The stupid cookie law is dead at last

#65
post #9

Earlier quoted context omitted.

yes given that my employer a FTSE 100 publisher must have spent a huge amount time and money on this stupid law - can we claim this back against our tax bill.

Well, yes. Generally and imprecisely speaking, expenses are deducted from revenues and the net is what's taxable. Your employer will end up paying a little less corporation tax because of it. Whether it's a net loss for the government is another matter, as what isn't paid in corporation tax might be paid in national insurance and individual income taxes. Could your employer sue the government for their compliance cos…

Yes very cute but that only gets a $TAXRATE percentage refund on the wasted money. The rest is gone.

Re: The stupid cookie law is dead at last

#66
post #58

Earlier quoted context omitted.

No, consent is not assumed. From my understanding, most browsers are generally set up to accept cookies automatically. If it was the other way round, and users had to physically change their settings, this could be an appropriate opt-in. The E-Privacy Directive specifically contemplates browser solutions as being a potential solution, however, I understand that at this stage, there isn't an acceptable implementation.…

> You can obviously configure cookies in your browser settings but I imagine for most users this option is overly complex for them to understand. Can't one argue the same thing for setting up your website to be compliant with this law? The fact that the easy and free solution is to just tell users to turn off all cookies in their browsers makes any laws of this type a waste.

Sorry for the brevity, but the only thing I can think of is: A-fucking-men. This is a colossal waste of time and resources, and it's a completely distraction from other -real-, -actual- privacy concerns that every day citizens should have. This is not one of them, and there is already a solution.

Re: The stupid cookie law is dead at last

#67
post #64
post #63

Earlier quoted context omitted.

Cool, all sounds useful, so you have no issue asking for the user's permission to do this? Because it's still not technically necessary for the functioning of whatever it is that the user is trying to do on your particular site. These are all fine business reasons but (AFAICT) the entire intent of the law is that business reasons are not good enough to track people without their explicit knowledge and permission that…

Yet again, semantics matter. You didn't originally say " technically necessary," but my argument is not with you. It's with half-baked legislation. Does the legislation make the distinction? You use the phrase "technically necessary for the functioning of..." and the business guys in the company will continue to argue that yes, this is technically necessary for the functioning of their company/website/business etc. A…

"the business guys in the company will continue to argue that yes, this is technically necessary for the functioning of their company/website/business etc."

Except it's not.

"Ask the engineers whether these things are "technically necessary" to facilitate the business plan, because the business plan is the entire reason the company exists. The answer is yes."

The Business plan is irrelevant. You're clutching at (false) straws here and you know very well what I mean by technically necessary for the functioning of the site, the law and/or guidelines even talk about implied consent covering only what is needed to allow the interaction between a site (the site you are ON, not a third party) and the user). In any other circumstances you have to ask. I don't understand what you find so hard about this - are you setting the cookie to enable the user to have a session on your site? Cool. Are you using it to track their movement? Not cool. End.

"Are we going to start legislating every detail of business?"

Where it starts to impinge on personal privacy, I hope so, yes.

Re: The stupid cookie law is dead at last

#68

Earlier quoted context omitted.

This entire argument boils down to "if you don't want to get raped, don't wear short skirts in public". People shouldn't have to take protective action in order to not get stalked by advertisers and marketers. Such activities require opt-in and informed consent, and standard browser functionality doesn't even come close to supporting that. Oh, I agree that the current law doesn't solve the problem. But "educating the…

This entire argument boils down to "if you don't want to get raped, don't wear short skirts in public". That's a pretty spot-on analogy and I, for one, am impressed by the depth and nuance you've bought to this discussion.

The point of the analogy is "blaming the victim", which imho is spot-on.

But yeah, I could have chosen more tasteful and less over the top comparison. My apologies.

Re: The stupid cookie law is dead at last

#69

Earlier quoted context omitted.

> You can obviously configure cookies in your browser settings but I imagine for most users this option is overly complex for them to understand. Can't one argue the same thing for setting up your website to be compliant with this law? The fact that the easy and free solution is to just tell users to turn off all cookies in their browsers makes any laws of this type a waste.

Sorry for the brevity, but the only thing I can think of is: A-fucking-men. This is a colossal waste of time and resources, and it's a completely distraction from other -real-, -actual- privacy concerns that every day citizens should have. This is not one of them, and there is already a solution.

Actually that would be a good potential solution to have cookies on browsers automatically disabled but one that advertising networks and companies that rely heavily on advertising revenue (Google for example) are lobbying hard against for obvious reasons. As a result, I don't think this option will make an appearance anytime soon.

Re: The stupid cookie law is dead at last

#70
post #44

Earlier quoted context omitted.

This entire argument boils down to "if you don't want to get raped, don't wear short skirts in public". People shouldn't have to take protective action in order to not get stalked by advertisers and marketers. Such activities require opt-in and informed consent, and standard browser functionality doesn't even come close to supporting that. Oh, I agree that the current law doesn't solve the problem. But "educating the…

> This entire argument boils down to "if you don't want to get raped, don't wear short skirts in public". This is a ridiculous comparison. Lets not go that way. > Such activities require opt-in and informed consent, and standard browser functionality doesn't even come close to supporting that. Yes, as I said that's where the problem lies, so that's what should be altered. This can either be done by education, or by m…

Again with the disinformation.

First, the law doesn't force websites to display popups, the law forces informed consent.

The pop-ups are hack on top of existing sites which I agree quite clearly doesn't work. Also, there has been a clear failure by those enforcing the law in constructively thinking about the way in which such consent should be given.

Second, the law is very explicitly not about cookies nor any kind of specific form of technology. It's about invasive tracking, and other applications of cookies are in no way affected by the law. If Facebook finds a way to track people without cookies, it will still be covered by the law. The misleading name "cookie-law" is product of the anti-privacy lobby.

The law in it's current form may not have the desired result, but please stop pretending it's law created by ignorant politicians that don't understand cookies, because that is simply untrue, and it poisons any constructive debate just as much as my admittedly over the top comparison.

Post reply on HN