Live data from Hacker News

CCPA goes into effect January 1, but nobody’s sure how the new rules work

latimes.com

101–110 of 129 posts

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#101

Earlier quoted context omitted.

Websites don't need to use personalized ads.

Thats an odd thing to say. Websites don't need to allow free access either. I can't comment on any particular revenue model but I imagine many websites chose personalized ads as they provide better revenue returns than non-personalized ads. would switching to non-personalized advertisements without taking additional steps support the website enough? Maybe but its hard to say one way or the other without looking at th…

> Thats an odd thing to say. Websites don't need to allow free access either. I can't comment on any particular revenue model but I imagine many websites chose personalized ads as they provide better revenue returns than non-personalized ads.

Another way to get revenue, which doesn't itself transgress against these privacy-focused laws, is to charge directly for providing your service. That's totally legal! Well, but maybe some companies would find that they don't get enough subscribers to fund their business—then the solution, in a privacy-focused environment, is that those business don't exist, rather than that they get a shadow source of funding by accepting bribes for participating in scummy privacy violations. This would be a very different environment from the one in which we live—clearly better in some ways and clearly worse in others—but it's far from impossible.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#102
post #80

Earlier quoted context omitted.

It's a classic example of a legislative loophole. What the cookie law was actually trying to do was provide a way for users to opt-out of cookie-based tracking. But, someone figured out that if you just ask for permission to use cookies (for any reason) and refuse service if the opt-out, you'd still be following the letter of law (but not the intent). Arguably, this is one of the reasons why the GDPR was necessary.

> if you just ask for permission to use cookies (for any reason) and refuse service if the opt-out Is that even true? If I never consent do I get no cookies left on my browser?

It (in theory) should be, but most often if you click "opt-out" they kick you off the site -- hence "refuse service". With GDPR (loosely) that is no longer allowed when it comes to the opt-in nature of data processing disclosures (if you opt-out, they can't refuse you service for not opting-in -- with certain limitations).

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#103
post #98

Earlier quoted context omitted.

What entire industry? The internet affects everyone.

The industry that sells your info to the highest bidder.

That would be the credit reporting agencies. Either way, cookies and PII are far more involved than just a single industry.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#104

Regarding the GDPR: > 95% of users choose to be tracked in exchange for access to websites and services The GDPR explicitly disallows the practice of conditioning access to a site or service on acceptance. Without that it would be rather useless. Once that bit is also enforced (current fines for violation sadly week focused on poor data safety measures and similar) I think the online ad landscape actually may start t…

No it doesn't. The "freely-given consent" clause is incredibly vague and cannot force a business to provide a value to consumers against their choice and/or for free.

There are also dozens of workarounds from legitimate use of data to contract-in-effect (like email newsletters). This is an example of the poor legislation aspects of GDPR and other privacy laws that are not based in technical reality.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#105

Earlier quoted context omitted.

Just for interest sake, do you ever read news on the internet, and if so how do you pay for it? I personally read a lot of news online, most of it is such utter trash that I would not want to pay for it. I have paid for some specific sites intermittently - currently I pay about $20 USD a month to one specific content creator that produces news content - but that is mostly because it is rather niche news that nobody e…

Websites don't need to use personalized ads.

Cookies and (wrongly considered) PII data like IP addresses are not only used for personalized ads. Contextual ads would also require them to function properly, which is an immediate "legitimate use" workaround.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#106

Earlier quoted context omitted.

Fundamentally, the solution to cookie warning spam is simple: Stop letting these companies disclaim their way out of unethical business practices. Start making those business practices illegal and shut down companies built around them. Companies built on surveillance capitalism should be shut down. Full stop.

What business practices? Cookies aren't just used for ads. You could get rid of adtech and not have any change in cookie notices because of how the laws are written.

how? Functional cookies don't need permissions.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#107
post #101

Earlier quoted context omitted.

Thats an odd thing to say. Websites don't need to allow free access either. I can't comment on any particular revenue model but I imagine many websites chose personalized ads as they provide better revenue returns than non-personalized ads. would switching to non-personalized advertisements without taking additional steps support the website enough? Maybe but its hard to say one way or the other without looking at th…

> Thats an odd thing to say. Websites don't need to allow free access either. I can't comment on any particular revenue model but I imagine many websites chose personalized ads as they provide better revenue returns than non-personalized ads. Another way to get revenue, which doesn't itself transgress against these privacy-focused laws, is to charge directly for providing your service. That's totally legal! Well, but…

Why are people not allowed to choose for themselves? Should we start banning what people can share on social media too for their own protection? Also not everyone can pay for content so you're punishing people who can least afford it by having direct payment be the only way forward.

Privacy laws that remove freedom and opportunity aren't very good laws.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#108

Earlier quoted context omitted.

Because browsers make it an all or nothing setting (all, 1st party, none) and there are many more combinations. On top of that, the laws are there to prevent companies from tracking people at will, and the DNT header that was supposed to make that an easy browser setting completely failed.

> Because browsers make it an all or nothing setting (all, 1st party, none) At least for Firefox this is not the case. Anyway, extensions like uMatrix exist. > the DNT header The DNT header is yet another way for sites to track you. I am glad it failed.

> The DNT header is yet another way for sites to track you. I am glad it failed.

And clicking decline on cookie banners or your unique combination on the multiple choice cookie disclaimers wont allow sites to track you?

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#109

Regarding the GDPR: > 95% of users choose to be tracked in exchange for access to websites and services The GDPR explicitly disallows the practice of conditioning access to a site or service on acceptance. Without that it would be rather useless. Once that bit is also enforced (current fines for violation sadly week focused on poor data safety measures and similar) I think the online ad landscape actually may start t…

I dunno, man. As you mentioned, all of the people who implement or enforce GDPR compliance seem to think that "our business model relies on ads" is a sufficient reason to require tracking. Maybe the regulators are just biding their time before pouncing, but I'm not sure why they'd want to do that or what they're waiting for after a year and a half. It seems more likely that GDPR as an ad industry killer was just a pi…

It's more complicated than that for ads but GDPR is incredibly vague and contradictory to the point that it has major issues in effectiveness.

It can be costly to be in perfect compliance but nobody is really is afraid of GDPR risk anymore, especially since most internet companies are not in the EU anyway and are completely unaffected by regional legislation.

Re: CCPA goes into effect January 1, but nobody’s sure how the new rules work

#110

Earlier quoted context omitted.

What business practices? Cookies aren't just used for ads. You could get rid of adtech and not have any change in cookie notices because of how the laws are written.

how? Functional cookies don't need permissions.

Not all cookies are functional or ad related. Also the EU cookie directive requires you to inform users that cookies are being used regardless of the reason why.
Post reply on HN