Live data from Hacker News

Consent-O-Matic: Automatic handling of GDPR consent forms

github.com

121–130 of 137 posts

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#121

I wish there was a standard browser API for this. If the law is going to force this to be a thing, and it's not going away, web standards should respond. It could even just be a flag in the cookie itself declaring that something isn't strictly necessary.

It can't be. At least not if you want to accept cookies. Declining is easy. You can just decline everything (technically) not necessary. The problem is, that consent must be given freely and fully informed. And this is the catch. Automatic acceptance isn't fully informed and with that the consent isn't valid. So it would put the companies in danger and therefore no company could honor this standard. Sadly - as it wou…

I'm really surprised nobody caught this and that the law even managed to pass unmodified.

They're treating "Accept cookies" with the same seriousness you'd expect from "Do you consent to me putting a whole package of cookie dough up your rear".

The whole GDPR seems to be one step away from censorship. And it seems almost like the real intent has less to do with user choice and informed consent, and more to do with just trying to kill off data collection as a business model completely, before we have a replacement for it.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#122
post #51

Earlier quoted context omitted.

Clicking a checkbox that says "accept all tracking/cookies purpose from any website" and having the browser accept for you absolutely is informed consent. A court would look at this and a person who mindlessly clicked "accept all" on every website as equivalent. Browsers could propose an API for this functionality and no doubt some websites would implement it. They havent but they could. Whether there's any point is…

> Clicking a checkbox that says "accept all tracking/cookies purpose from any website" and having the browser accept for you absolutely is informed consent. IANAL so it's pointless for me to argue on that point. Of course if somebody is happy to accept in advance any privacy policy and will confirm all of those automated choices in a court (if they'll ever be challenged, can't think why), no problem with that. My poi…

Why not? Google loves tracking(At least when it's their own) and users hate popups.

A feature saving 2 seconds on 90% of sites is a big deal.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#123
post #51

Earlier quoted context omitted.

Clicking a checkbox that says "accept all tracking/cookies purpose from any website" and having the browser accept for you absolutely is informed consent. A court would look at this and a person who mindlessly clicked "accept all" on every website as equivalent. Browsers could propose an API for this functionality and no doubt some websites would implement it. They havent but they could. Whether there's any point is…

If I sign a form that says "I accept all medical procedures being done to me in the next month.", that wouldn't be informed consent for a surgery two weeks later if I hadn't been aware of the risks of the surgery at the time that I signed the form. Being informed of the specifics for a particular procedure is necessary, not just being informed of the general risks of medical procedures. In the same way, GDPR requires…

We cannot have a modern technological society if we treat tracking with the same concern we treat medical consent.

That road leads to banning street photography and CCTV, and being able to get a gag order to stop people from saying "Yeah I saw Brian at the bar last night". When does it stop?

There are no uses of cookies an average user cares about that aren't already illegal.

They are basically all for the same thing, to spy on you and sell your data to third parties to the fullest extent of the law, excluding any data you would actually notice being sold like credit card numbers, and many users don't care.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#124

Earlier quoted context omitted.

"Accept all" and the "Deny all" must be both be the same level of "easy-ness" I think this is not clear until it has been tested in court. Many websites now have two offers: Free with 3rd part ads and paid. Surely paying is much less easy than clicking "Ok, show me the content with 3rd party ads". It will be very interesting, how courts see this.

In Germany, the media sites that offered "either tracking/advertising" on vs "paid content approach" were already in court with that practice and won. The current situation is, that the courts decided, that the business model (advertising and by that tracking the sh*t out of people) is valid if they offer an alternative were people pay them for access to the content.

I hope that's true, because disallowing the tracking based business model completely would be a horrendous thing causing making it harder for people who aren't rich to be informed.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#125
post #63

I wish there was a standard browser API for this. If the law is going to force this to be a thing, and it's not going away, web standards should respond. It could even just be a flag in the cookie itself declaring that something isn't strictly necessary.

You mean like "Do Not Track"? There is a misconception, they don't want it do be convenient, the all purpose is to as annoying as possible and legal, to force you to use the easy allow-all-path. So even if there is an API they won't use it. They don't want to give you a choice, they want that you to allows all access.

If the API covers allow-all with a fallback to a prompt the'll use it.

Even with a deny all feature, they will use it if it's legally mandated, since apparently that's how we handle privacy now

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#126
post #81

Earlier quoted context omitted.

> I wish there was a standard browser API for this. There was: https://en.wikipedia.org/wiki/P3P

And Google was caught exploiting a weakness in the P3P implementation to bypass it entirely. Google was also caught exploiting a loophole in Safari when it added 3rd party cookie blocking: https://www.zdnet.com/article/google-pays-17m-to-settle-safa... AdTech companies want to track you, and it's naive to think they will ever honestly and voluntarily use any APIs that blocks it. Current deliberately-awful cookie cons…

They'll use an API if it makes it easier and less noticable to track most people. They should do a study and find out how many people will just set "Enable all cookies from all sites".

If the number of people who would use "Deny all nonessential" is less than the number of people who currently deny consent, it's a win for them.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#127

I wish there was a standard browser API for this. If the law is going to force this to be a thing, and it's not going away, web standards should respond. It could even just be a flag in the cookie itself declaring that something isn't strictly necessary.

There's no valid reason for the third party cookies. There are browsers that get this right (lynx lets you choose to accept and reject cookies (including an "always/never and never bother me about it again option.)

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#128
post #51

Earlier quoted context omitted.

Clicking a checkbox that says "accept all tracking/cookies purpose from any website" and having the browser accept for you absolutely is informed consent. A court would look at this and a person who mindlessly clicked "accept all" on every website as equivalent. Browsers could propose an API for this functionality and no doubt some websites would implement it. They havent but they could. Whether there's any point is…

> Clicking a checkbox that says "accept all tracking/cookies purpose from any website" and having the browser accept for you absolutely is informed consent. IANAL so it's pointless for me to argue on that point. Of course if somebody is happy to accept in advance any privacy policy and will confirm all of those automated choices in a court (if they'll ever be challenged, can't think why), no problem with that. My poi…

>It looks so much following the letter of the law and circumventing the spirit of it.

I dont think this is true either. The consent options would typically come under a few pretty well defined headers (e.g. advertising) and could include the capability of raising specific exceptions for nonstandard requests.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#129
post #81

Earlier quoted context omitted.

And Google was caught exploiting a weakness in the P3P implementation to bypass it entirely. Google was also caught exploiting a loophole in Safari when it added 3rd party cookie blocking: https://www.zdnet.com/article/google-pays-17m-to-settle-safa... AdTech companies want to track you, and it's naive to think they will ever honestly and voluntarily use any APIs that blocks it. Current deliberately-awful cookie cons…

They'll use an API if it makes it easier and less noticable to track most people. They should do a study and find out how many people will just set "Enable all cookies from all sites". If the number of people who would use "Deny all nonessential" is less than the number of people who currently deny consent, it's a win for them.

We've had this bet with Do Not Track, and the whole idea died as soon as one browser set it by default.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#130
post #67

Earlier quoted context omitted.

> How do sites abuse Legitimate Interest? By pretending that advertisement and tracking are part of Legitimate Interest, and having a "secondary section" that is not only pre-accepted, but also overrides the proper consent part. To really decline consent in those cases, you must uncheck all "Legitimate Interest" checkboxes. Not only those things are not legitimate interest, this also overrides the lack-of-consent pro…

LI is separate Legal Basis to Consent, that's why there are two lists in the CMP. The user's choices for each Legal Basis are sent separately in the TCF consent strings and entities are expected to adhere to these rules. One does not override the other. The full list of the LI purposes claimed by adtech players is available at [0] As for why they're enabled by default... I'd imagine there's a legal reason. GDPR doesn…

> LI is separate Legal Basis to Consent, that's why there are two lists in the CMP.*

I never said the opposite and never said that was problem. Presenting non-Legitimate Interest as if it were, however is shady and probably illegal.

> The user's choices for each Legal Basis are sent separately in the TCF consent strings and entities are expected to adhere to these rules.

I never said that being separated is a problem. The problem is using anything that is firmly NOT in the Legitimate interest camp as if it were, and using that to mislead customers.

> One does not override the other.

It does in this case, and it is easily verifiable. Even if I disallow a certain tracking vendor, it will still load stuff from this vendor in websites, even though nothing from this vendor configures "Legitimate Interest". And all my data will still be piped to those adware, etc, vendors, that provide no functions other than adware, tracking and other shady stuff that GDPR requires consent for.

> As for why they're enabled by default... I'd imagine there's a legal reason. GDPR doesn't just apply to adtech, it's everything.*

That's beside the point. If it were really Legitimate Interest, there would be no need for asking.

Post reply on HN