Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

151–160 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#151
post #82

Yes there is. More specifically, it’s the Privacy and Electronic Communications Directive 2002/58/EC, which each member state adjusts their own laws to follow. It’s published here: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A... The relevant part: > Article 5 > Confidentiality of the communications > 3. Member States shall ensure that the storing of information, or the gaining of access to information…

I think you might not have fully grasped the meaning of the post. Let me rephrase it for clarity: there is no cookie banner law, but a consent law, but it doesn't need to be as ugly, intrusive or user-unfriendly as the current cookie banners. One alternative is to opt out of using cookies on your website entirely (which is what I do, by the way), and then you won't need to ask for consent. Or to use a simple, unremar…

I think you might not have read beyond the first line of my comment. Why are you telling me that there are alternatives? I literally said that in my comment.

Re: Dear Paul Graham, there is no cookie banner law

#152
post #70

>, Paul Graham came up with the thought, that the EU forces companies to have cookie banners. There is no law for cookie banners. [...] Companies could easily avoid any cookie banner. Just don’t track. KingOfCoders/amazingcto, of course you are technically correct but Paul Graham wasn't talking about the letter of the law. Instead, you have to interpret his complaint with the lens of game theory . I.e. The Law of Uni…

(author here)

I'm a fan of second-order thinking and unintended consequences, so I'm with you there. How would you frame a "don't track people without consent" without unintended consequences?

The article tries to make the point (perhaps fails), that companies do this intentionally to get the "consent" of people against their will, therefor running the tight line of breaking the law without breaking it.

Re: Dear Paul Graham, there is no cookie banner law

#153
post #120

Earlier quoted context omitted.

If you want to click “no” it’s often dozens of clicks (e.g. to explicitly disable each “trusted partner” with “legitimate interest”) alongside constant attempts to trick you into clicking “yes” accidentally.

This is actually in violation of the rules. Withholding consent is supposed to be as easy as giving consent.

Yes, I know. It’s infuriating but understandable that the regulations aren’t enforced properly.

Re: Dear Paul Graham, there is no cookie banner law

#154
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

> On this issue in the group that complain about the cookie law there are some people who are very wrong on purpose because it's in their interest, and some people who are very wrong because they genuinely don't understand the position they're defending, complaining about being made aware of the fee, instead of the fees themselves or the fact that the companies hide them if not forced by law. The reality is that I (a…

> The reality is that I (and others who are complaining, as well as many who have resigned themselves to their fate) are happy to have a website "track me", certainly if the cost of non-tracking are having to click away an annoying popup, and think that people who compare a website wanting to know the number of their visitors to "hidden fees" are kind of being ridiculous.

I agree that wanting to know the number of visitors is benign and it is not abuse.

But saying companies should be allowed to track me (for whatever purpose) across the web without my consent is also pretty ridiculous.

Re: Dear Paul Graham, there is no cookie banner law

#155
post #94

Earlier quoted context omitted.

> Not only that, I'm not an EU citizen and I'm not browsing websites based in EU but I'm still bombarded with cookie banners non-stop. Again, that's the fault of the companies putting those up, they could make it opt-in to collect your data, they could just put a small notice on the footer with 2 simples links "Accept all/Reject all". But they chose, they decided to pester you with those banners as annoyingly as poss…

The fact that companies are doing that says more about the bad law than the companies which is exactly Paul Graham's point.

Or it says more about the manipulative intentions of the companies than anything about a good law.

Re: Dear Paul Graham, there is no cookie banner law

#157

I wonder - why didn't the the EU put the burden on user agents a.k.a. web browsers to handle the cookie notices? When I visit a site, before saving any cookies, have my user agent ask me if I want to allow cookies for that site. Could have a default "no cookies" option with a whitelist, or default "yes" with a blacklist. It would have been so much easier, with a far more consistent UX, wouldn't it have? Now we have t…

The EU doesn't tend to require specific implementations - the banners aren't a required implementation, either. It's just what the advertisers thought works best to get their desired outcome.

There was the DNT header. Few sites acknowledge it (and thanks to those who do!), and when Microsoft went against spec by setting it default-on in their browser, advertisers whined that they can't see informed consent anymore and just shut down the whole initiative. Note: Microsoft is also in the advertising business, so if you're into that, that might be another angle for your favorite conspiracy theories.

Finally, there's consent-o-matic, available as browser extension for various browsers, and it lets you state your preferences. https://consentomatic.au.dk/ Would it have been better to integrate that into browsers properly? Sure. But the social and economical dynamics being what they are, this is probably the best we can get.

Re: Dear Paul Graham, there is no cookie banner law

#158
post #42

Note that this isn't a cookie law, it's also the EU's main anti-malware law. The principle is that no piece of third-party controlled software should write information to your computer/phone, or read info from it, over the Internet, without your prior informed consent (with narrow exceptions for storage/reads that are needed to provide a service you've asked for, or equally narrow functions like load balancing). This…

did they try to make it a standard for browser? I tried searching but I couldn't find anything

The standard for browser was called Do Not Track [0], but of course adtech killed it, there is another one now, but unless this is mandated by law or courts it won't go anywhere. Note there seems to be a court decision upholding DNT as rejection of consent [1], but this would have to be much more powerful and broadly adopted to work.

[0] https://en.wikipedia.org/wiki/Do_Not_Track

[1] https://dig.watch/updates/german-court-affirms-legal-signifi...

Re: Dear Paul Graham, there is no cookie banner law

#159
post #94

Earlier quoted context omitted.

> Not only that, I'm not an EU citizen and I'm not browsing websites based in EU but I'm still bombarded with cookie banners non-stop. Again, that's the fault of the companies putting those up, they could make it opt-in to collect your data, they could just put a small notice on the footer with 2 simples links "Accept all/Reject all". But they chose, they decided to pester you with those banners as annoyingly as poss…

The fact that companies are doing that says more about the bad law than the companies which is exactly Paul Graham's point.

What exactly is bad about the law that allows companies to do the annoying cookie banner?

Re: Dear Paul Graham, there is no cookie banner law

#160
post #105

Earlier quoted context omitted.

If you want to click “no” it’s often dozens of clicks (e.g. to explicitly disable each “trusted partner” with “legitimate interest”) alongside constant attempts to trick you into clicking “yes” accidentally.

On most websites I use, it's 1 click. On the rest, it's 2. I've never once encountered a website that required "dozens" of clicks

It definitely happens where they don't give you a 'reject all' option, so you have to go 'select options' or similar and untick each one, or at least each category, and then 'confirm choices'.

As an aside, it's supposed to be as easy to decline as to accept; so if you give a 1 click 'accept all' then more than that (whether two or dozens) is unacceptable.

Post reply on HN