Live data from Hacker News

RFC 35140: HTTP Do-Not-Stab (2023)

5snb.club

121–130 of 219 posts

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#122
If Monty Python made an RFC it would look very much like this one, just with more fruit.

On a more serious note: yeah wtf. I hope we in the EU draw the conclusion of companies even being unable (unwilling?) to gain informed consent and just start treating these privacy breaches as an outright crime.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#124

It’s great satire, but it really does mirror a larger societal shift where the burden of safeguarding personal autonomy has shifted from institutions/regulators to individual users. Do-Not-Stab, Do-Not-Track, whatever it might be, any sort of “voluntary compliance” is a non-starter in the face of financial pressures IMO we need to start normalizing being militant about this stuff again, to aggressively and adversaria…

> IMO we need to start normalizing being militant about this stuff again, to aggressively and adversarially defend the freedom to use your computer the way you choose to use it

Yes. As a millennial the times of civil disobedience was better. Not only did we get a better internet for consumers, but better companies were rewarded and won. Rose tinted glasses? Possibly, but there’s another reason for disobedience: the other side does it, and they do it just for money.

Concretely, is there something like Adblock that can be done for cookies? I don’t think blocking is as effective as poisoned data though. They ask for data, they should get it. If you don’t get consent, poisoned data is merely malicious compliance.

It could even be standardized as an extension to DNT: “if asking for consent after a DNT header, a UA MAY generate arbitrary synthetic data”.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#125
post #23

Earlier quoted context omitted.

So the EU is bad because you can't learn to screw on a bottle cap that's different than before?

I am not joining the whole “EU is bad argument”, however the new caps are very annoying, especially the limited benefits they provide.

The non-profit Plastic Deposit Organisation, responsible for managing Denmark's container deposit system, estimates that this change alone will enable them to collect and reuse approximately 70 million additional bottle caps annually. This equates to 140 tonnes of plastic each year.

https://www.emballagefokus.dk/goer-noget-uden-at-goere-noget...

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#126

Earlier quoted context omitted.

And if the regulators didn't predict such compliance they should be replaced with competent actors in their jobs. That was the obvious outcome. What did people predict: site owners leaving money on the table? Who pays for operating the sites then?

When GDPR was first going through the public circuit I remember reading the proposed laws and being pleasantly surprised to find that they specifically called out and forbade the likely workarounds, including the obnoxious banners we now see everywhere. I would love to know what happened. Did the laws get "revised" to re-open the loophole? Was superseding legislation passed? Did the courts reject it? Are there enforc…

TL;DR the enforcement simply lacks manpower, and the most egregious cases go to court which also takes time.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#127
post #97

Earlier quoted context omitted.

I'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.

No,.all the companies running the sites chose to add a cookie banner. And you choose to keep going there

Yes, and my life world be more convenient if this banner would go away or I could declare a universal preference.

I miss the old Internet where nobody cared about their privacy.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#128
post #53

Earlier quoted context omitted.

And if the regulators didn't predict such compliance they should be replaced with competent actors in their jobs. That was the obvious outcome. What did people predict: site owners leaving money on the table? Who pays for operating the sites then?

All the sites that need advertising like that can just die off and leave the internet a better place.

Did we ever think that would be the end result of all this?

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#129

Earlier quoted context omitted.

Yeah and the fuss about it being enabled by default is not really relevant. In the EU tracking must be opt-in anyway. So this is expected behaviour. However the EU dropped the ball by not making it mandatory to respect this flag. If they had we wouldn't have had the huge cookiewall mess we have now.

The annoying thing is that they have regulations in trilogue that would actually make the DNT header obligatory to follow, the ePrivacy Regulation. That was supposed to drop alongside GDPR, but has instead been delayed for 6 years now. It's apparently supposed to be finally finalized somewhere in 2024, so I hope to see it sometime soon.

Oh that's good news, that would be great, then I can just set that flag and will never have to bother with cookie banners again <3

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#130

Earlier quoted context omitted.

I'm registering my elderly relatives for dmachoice.org, to prevent them from getting junk mail. These clowns create the problem and then have the audacity to charge you to be added to the opt out list. I was really skeptical about the GDPR when it was passed and I am now fully on board for an American version.

I'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.

The problem is GDPR isn't prescriptive enough. That makes it ripe for "technically correct but really annoying" solutions.

It also failed to actually ban ad tracking.

Post reply on HN