Live data from Hacker News

RFC 35140: HTTP Do-Not-Stab (2023)

5snb.club

131–140 of 219 posts

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#131

Earlier quoted context omitted.

The standard for cookies should be updated with a way to include or retrieve a description of each cookie separately. Then, require sites to provide that description, and let users choose per cookie in the browser.

That's nonsense. It's not about the cookies, it's about the data collection. You can use cookies without having to use a cookie banner by simply not gathering data you don't need. And if you do gather that data without using cookies you still need to ask for consent.

I can tell you, with absolute certainty, that nobody knows how to implement the law or what it even means, legislators, lawyers, engineers alike. There was a good somewhere and now we're in hell.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#133

Earlier quoted context omitted.

I'm registering my elderly relatives for dmachoice.org, to prevent them from getting junk mail. These clowns create the problem and then have the audacity to charge you to be added to the opt out list. I was really skeptical about the GDPR when it was passed and I am now fully on board for an American version.

I'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.

Key to note that the cookie banner fiasco wasn't GDPR, it was a separate policy that should be changed.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#134
post #131

Earlier quoted context omitted.

That's nonsense. It's not about the cookies, it's about the data collection. You can use cookies without having to use a cookie banner by simply not gathering data you don't need. And if you do gather that data without using cookies you still need to ask for consent.

I can tell you, with absolute certainty, that nobody knows how to implement the law or what it even means, legislators, lawyers, engineers alike. There was a good somewhere and now we're in hell.

Nah, companies don't want to implement it as it's bad for their business model so they feign ignorance.

I still remember being at an all hands at a former employer where the team presenting the revised cookie banners promoted as a benefit that it had opt in rates that would make an authoritarian dictator embarrassed to claim as uninfluenced

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#135
post #110
post #95

Earlier quoted context omitted.

I wonder how many web developers actually honour Do Not Track. I do, in all the websites I've made for my employer too, but I think I'm only getting away with it because my employer doesn't know. I've even made it so that browsing with Do-Not-Track enabled also skips the cookie consent banner and just assume the user wants no cookies other than the strictly necessary ones (like their session/login cookie), and doesn'…

A better option would be to just make tracking illegal, and heavily fine companies that are found to be doing it. And make it strict liability, so intent doesn't matter. I can dream...

This sounds like a recipe to reduce the internet to a handful of heavily-financed publishers who can afford legal protection against strict liability.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#136
post #16

Earlier quoted context omitted.

I feel like that section ruins the joke.

Maybe it’s just me, but I fundamentally disagree with the mentality that we should prioritize the “feeling of being special” among those who already get the joke (and corresponding point) at the expense of those who have yet to appreciate the message. You can still laugh at the joke with the section there, you’ll just have fewer confused people to correct, and be in one less elite club.

The thing is, the last part does not just explain the joke, it is a very angry rant, and it ruins it for me because of the change of tone.

Imagine in real life, someone starts making a joke, and then suddenly starts cursing and yelling. I wouldn't be comfortable with what feels like a lack of self-control and I will try to move away before things get violent.

Either do the "joke" style or the "angry rant" style, not both. The joke can be explained calmly if there is a need to.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#137
post #5

For the low price of $20/1000 clicks, I will provide you with a stabbing consent banner, fully compliant with upcoming EU and CA regulations on web-based stabbing.

By the way, studies show users only opt in to stabbing with our competitors banner 95% of the time, but they opt in with ours 98% of the time, thanks to our banner taking 50% longer to properly opt out of, so you should really go with us.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#138
post #124

It’s great satire, but it really does mirror a larger societal shift where the burden of safeguarding personal autonomy has shifted from institutions/regulators to individual users. Do-Not-Stab, Do-Not-Track, whatever it might be, any sort of “voluntary compliance” is a non-starter in the face of financial pressures IMO we need to start normalizing being militant about this stuff again, to aggressively and adversaria…

> IMO we need to start normalizing being militant about this stuff again, to aggressively and adversarially defend the freedom to use your computer the way you choose to use it Yes. As a millennial the times of civil disobedience was better. Not only did we get a better internet for consumers, but better companies were rewarded and won. Rose tinted glasses? Possibly, but there’s another reason for disobedience: the o…

> Concretely, is there something like Adblock that can be done for cookies?

I use a combination of two browser extensions: Cookie AutoDelete[0] and I don't care about cookies[1]. The second hides any GDPR 'compliance' popup; the first deletes any cookies set by a website when you close the last tab with it open. Both extensions have whitelist functionality.

[0] https://github.com/Cookie-AutoDelete/Cookie-AutoDelete

[1] https://www.i-dont-care-about-cookies.eu/

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#139
post #138
post #124

Earlier quoted context omitted.

> IMO we need to start normalizing being militant about this stuff again, to aggressively and adversarially defend the freedom to use your computer the way you choose to use it Yes. As a millennial the times of civil disobedience was better. Not only did we get a better internet for consumers, but better companies were rewarded and won. Rose tinted glasses? Possibly, but there’s another reason for disobedience: the o…

> Concretely, is there something like Adblock that can be done for cookies? I use a combination of two browser extensions: Cookie AutoDelete [0] and I don't care about cookies [1]. The second hides any GDPR 'compliance' popup; the first deletes any cookies set by a website when you close the last tab with it open. Both extensions have whitelist functionality. [0] https://github.com/Cookie-AutoDelete/Cookie-AutoDelete…

ublock origin now has specific filters for cookie popups, you just need to turn them on in the filter lists. I'd say this is probably preferential to downloading another addon (that already had a scare with being sold off)

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#140
post #110

Earlier quoted context omitted.

A better option would be to just make tracking illegal, and heavily fine companies that are found to be doing it. And make it strict liability, so intent doesn't matter. I can dream...

This sounds like a recipe to reduce the internet to a handful of heavily-financed publishers who can afford legal protection against strict liability.

That's reasonable. Could also decimate the adtech industry and cut them down to just serving ads based on keyword searches and location, like they did 20 years ago
Post reply on HN