Live data from Hacker News

RFC 35140: HTTP Do-Not-Stab (2023)

5snb.club

161–170 of 219 posts

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#161

Earlier quoted context omitted.

I'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.

I click no to all of them, but it would be really nice if the Do-Not-Track header essentially let you pick in advance — for you (0) or for me (1)

The only hope I still have is for some kind of fully local LLM-driven "agent" browser that does the browsing for me, navigating search engines, cookie banners and showing me what it found, nothing else.

Unfortunately entire businesses are built around preventing people from using bots, for obvious reasons, so the only obvious way forward to make browsing the web a better experience will also mean ending up on the wrong side of that battle.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#162
post #137
post #5

For the low price of $20/1000 clicks, I will provide you with a stabbing consent banner, fully compliant with upcoming EU and CA regulations on web-based stabbing.

By the way, studies show users only opt in to stabbing with our competitors banner 95% of the time, but they opt in with ours 98% of the time, thanks to our banner taking 50% longer to properly opt out of, so you should really go with us.

I raise you 5000% longer, which gets you to four nines.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#163

It's important to note that the Do-Not-Stab header has been deprecated because one browser engine switched it on by default and requiring users to opt into stabbing hurt the bottom line of the stabbing industry, so it's no longer respected. Luckily someone came up with General Assault Control, a non-standard alternative, which also only has one value, so you can set Sec-GAC to 1 to request websites not to assault you…

Why is it a binary value? What about masochists, or people who lost a bet and want to be stabbed just a little? Or strangled?

You can put a window that covers the bottom half of the content the defaults to all assaults being allowed also has a way to customize which assaults you would like. It shouldn't be possible to uncheck necessary assaults for the website might not work.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#165

Earlier quoted context omitted.

Why is it a binary value? What about masochists, or people who lost a bet and want to be stabbed just a little? Or strangled?

You can put a window that covers the bottom half of the content the defaults to all assaults being allowed also has a way to customize which assaults you would like. It shouldn't be possible to uncheck necessary assaults for the website might not work.

And “by not work” we mean “will work exactly as it should, but little Timmy in marketing will get a frowny face and won’t go out for drinks on Friday, so you have to tick it”.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#166
post #153

Earlier quoted context omitted.

We value your body integrity. We and our 1492 partners would like to stab you.

Please use this outlandishly convoluted form to opt out of every single one individually. You might also want to read our ToS in order to stay informed about the multiple ways, some of them illegal under EU law, you still will get stabbed. (Approximate reading time: 4h53m, assuming a law degree and multiple years of experience in data protection law practice)

We also have a monthly paid plan that allows you to avoid some of the stabbing automatically (but not all of it).

Estimated cost for paying every random website you stumble upon: one bazillion dollar / month (imitates Dr. Evil face)

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#168

Earlier quoted context omitted.

> aggressively and adversarially defend the freedom to use your computer the way you choose to use it Sadly even if you’re inclined to do this, it’s always a war of attrition, and corporations seem to realize they can just up the cost of your resistance in terms of time/frustration, and that’s enough for them to win in the long term. The history and trajectory of platforms, from browsers to AppStore’s to SaaS-all-the…

Worth noting the times where you have the choice to engage or not with a company with bad practices. Make it unprofitable for them to provide horrible service. Particularly applicable to tech, because most of it is useless rubbish we don't really need anyway!

Reminds me of Graphene OS, which forces you to directly give money to Google to buy a Pixel, if you care about privacy and security.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#169

> it’s fucking depressing when even the fucking bare minimum form of regulation is followed to the letter and no more, because every company out there fucking hates you and would sell you out to make a bit more money if they legally could. and even if they couldn’t, who’s going to stop them? Certainly not any government. If you think the EU's regulation are of any help to the consumer you are gravely mistaken. The EU…

> while Elon Musk created Tesla, SpaceX and Starlink the EU [created] some regulation that mandates that bottle caps must hold to the bottle

At least the EU made something useful

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#170
post #110
post #95

Earlier quoted context omitted.

I wonder how many web developers actually honour Do Not Track. I do, in all the websites I've made for my employer too, but I think I'm only getting away with it because my employer doesn't know. I've even made it so that browsing with Do-Not-Track enabled also skips the cookie consent banner and just assume the user wants no cookies other than the strictly necessary ones (like their session/login cookie), and doesn'…

A better option would be to just make tracking illegal, and heavily fine companies that are found to be doing it. And make it strict liability, so intent doesn't matter. I can dream...

I know we all have our pitchforks out, and I hate tracking as much as everyone else here, but "tracking" is a very broad term, and is not always malicious. Unless you want to outlaw access logs, for example.
Post reply on HN