Live data from Hacker News

I don't care about cookies

i-dont-care-about-cookies.eu

111–120 of 193 posts

Re: I don't care about cookies

#111

Earlier quoted context omitted.

> Yes, I can't fathom why the hate is on the law, and not the companies now being exposed by the law.. Because the law obviously didn't help stopping companies from doing shady shit and made the user experience of the web worse?

The law forced the companies to be explicit about what they do, and ask for consent. The user experience is made shit by the companies doing shady things. If they didn't do shady shit, they wouldn't have to display any banner. I'd rather be informed, at least I can make a decision that way. Why shoot the messenger? The part that is missing is making rejecting as easy as accepting. So far there are a lot of dark patte…

How is something like having Google Analytics on your site "shady shit"? I would think counting unique visitors is a legitimate business interest for most businesses. And there is no way to do that without a cookie, or without storing IP address (which is considered personally identifiable info).

The law could have been much better if it simply asked browser makers to provide a single place to configure your preference, and then forced companies to abide by that setting.

Re: I don't care about cookies

#112
post #76

Earlier quoted context omitted.

These popups are designed to waste your time. What's needed is a global setting to say no to everything. Daniel from Croatia, perhaps could you add a checkbox (opt-in) to the extension with the text: «I declare that I don't want to be tracked and don't want to be bothered with questions about privacy.» and a link to a more detailed manifesto, if not already done?

Speculating here, we could call the checbox "Do Not Track", and make it a browser setting. HN would probably love this. Oh, wait...

The EU is working on legislation to make Do Not Track enforced by law, which should get rid of a lot of the popups.

https://ec.europa.eu/digital-single-market/en/proposal-epriv...

Re: I don't care about cookies

#114
post #7

The consent popups you see aren't just about cookies though. They want (and sometimes illegally force) you to consent to processing of your personal information for reasons beyond just providing you with a service (or more commonly just reading an article). Cookies might be one technical means to assist with that, but it's not the only means.

Any good examples of these terms. I would like to read through them. I see very few of these pop-ups because I rarely use a graphical browser, and if I do, Javascript is disabled unless necessary. It does seem like the GDPR is being exploited to manipulate how users consent in a way that benefits the website's online ad scheme more than the user's experience. If I were drafting a GDPR, I would standardise the consent…

The reason GDPR doesn't standardise a consent mechanism is because GDPR isn't about websites, its about data protection. It applies to offline companies just as much as it applies to online companies. GDPR has nothing to do with cookies (that's a separate directive), but is about personal data, personally identifiable data, the use of this data and user rights over their data.

Re: I don't care about cookies

#115
post #101

Earlier quoted context omitted.

Or you know, people could just disable cookies IN THE BROWSER SETTINGS if they don't like them. Which is the only place technical measures against cookies can be enforced anyways. And stop bothering the rest of us with these pointless popups.

Apparently THE LAW can force companies to put up these annoying popups. Couldn't THE LAW force companies to respect Do Not Track? Yes, yes, I know, smaller sites will not give a fuck. But I bet Google, FB and other ones will. Which is why they fight against this so hard. Just try enabling Do Not Track in Chrome and watch the scary dialogs you need to go through which will make regular people think it's a dangerous th…

Its a law that's hard to enforce. How'd you verify that a company isn't tracking you without auditing their whole codebase and infrastructure at multiple points in time?

Re: I don't care about cookies

#116

Earlier quoted context omitted.

No, it is not a good thing. GDPR is a highly complex piece of legislation that is very hard to navigate and therefore only established companies with big bucks to spend on lawyers and extra engineering can profit from the ecosystem while everybody else is put at risk. Complex legislation and regulations is the best way to keep monopolies in place. Same goes for the financial sector, telecoms, etc. It's nearly impossi…

GDPR is sooo easy to follow as a startup. Just gather the data you need and not everything else,and ask for consent. If anything, it was the big players getting work to do. Thousands of people on mailing lists with no control of how they got there. Asked and kept insane amounts of not necessary data. Data floating in hundreds of database tables spread over various services and third party vendors and data centers wit…

It really isn't that easy. Something like an IP address is considered personally identifiable information, and most web servers and frameworks log that by default. If you really want to comply it takes quite a bit of effort you are not accidentally logging IP addresses somewhere. You can argue you need that info for the operation of your site, but it's been established that you would still need to ask permission in that case, did you do that?

Of course, they are unlikely to come after a startup for an infringement like that, but the point is that they could if they wanted to.

Re: I don't care about cookies

#118
post #28

Earlier quoted context omitted.

This is wrongly downvoted despite being absolutely right. There's a big misunderstanding behind these "cookie" consent prompts. They are actually about overall data processing consent regardless of technical means - this includes cookies but also things like browser fingerprinting, IP addresses, etc which will persist despite clearing cookies. Using an extension that automatically grants consent and merely deletes co…

At least if you’re in EU, active consent is required to comply with the GDPR. This means that if you do what this extension does (filter out the UI elements and ignore dialogs), it’s illegal for a website to save PII about you and your visit. Many websites and data processors violate this, but since that’s the case for those sites the only winning move is not to play.

Many websites are not compliant though, so while its illegal, they're still doing it. For example, GDPR requires opt-in, many websites have opt-out. Its illegal, but if its not being enforced, then...

Re: I don't care about cookies

#119
post #101

Earlier quoted context omitted.

Or you know, people could just disable cookies IN THE BROWSER SETTINGS if they don't like them. Which is the only place technical measures against cookies can be enforced anyways. And stop bothering the rest of us with these pointless popups.

Apparently THE LAW can force companies to put up these annoying popups. Couldn't THE LAW force companies to respect Do Not Track? Yes, yes, I know, smaller sites will not give a fuck. But I bet Google, FB and other ones will. Which is why they fight against this so hard. Just try enabling Do Not Track in Chrome and watch the scary dialogs you need to go through which will make regular people think it's a dangerous th…

>>Apparently THE LAW can force companies to put up these annoying popups

Where do the law force companies to use annoying popups? I see the annoying popups as companies doing all they can do try to make users feel it is the laws fault and not the sites fault that a site require to get consent using an annoying popup. In most of the cases the popup do nothing except of annoy the users, is often no difference in what is loaded before or after users are tricked into giving consent.

To follow the law you could only handle data directly relevant to the functionality of the site/app or you could have a place where users could select reject all or see what to allow. Allow all or see more, like for instance google is using, is not following the law

Re: I don't care about cookies

#120
post #72

Earlier quoted context omitted.

The list of cookies is so long that one might read 5 articles before reading the entire thing written in small print. Good luck if English is your second language.

Then don't and refuse the cookies and tracking.

How is that a solution?
Post reply on HN