Live data from Hacker News

I don't care about cookies

i-dont-care-about-cookies.eu

171–180 of 193 posts

Re: I don't care about cookies

#171
post #7

The consent popups you see aren't just about cookies though. They want (and sometimes illegally force) you to consent to processing of your personal information for reasons beyond just providing you with a service (or more commonly just reading an article). Cookies might be one technical means to assist with that, but it's not the only means.

Yes, I can't fathom why the hate is on the law, and not the companies now being exposed by the law.. Seriously, if you don't do shady shit your site doesn't need a popup asking for consent. But even Github has misunderstood it's not about the cookies. They had an article earlier about removing the popup since they managed to do stuff without cookies. The law doesn't care about cookies, it cares about tracking and ill…

> Yes, I can't fathom why the hate is on the law, and not the companies now being exposed by the law.. Seriously, if you don't do shady shit your site doesn't need a popup asking for consent.

What problem do you believe is being solved by the popup? The idea that it will get consumers to boycott garbage websites and internet services (read: the vast majority) is wishful thinking. Consumers do not care in the slightest and just want to be cool and fit in and use the same thing as everyone else. Anyone who is tunnel visioned on web privacy (which doesn't and will never exist, due to how webcrap is built) will go to the bottom of the page and click "privacy policy". Websites shouldn't have means of collecting data about you at all in the first place. Banking and shopping should be done with software instead of insecure web scripts. Yes smaller steps can be taken but there is such thing as too small.

EDIT: Oh I think you're saying that the popup is indeed redundant because your website shouldn't have it because if it does your website is crap. I agree, but I don't agree with the law since I still use those websites regarldess of how trash they are and all the popup does is make it more annoying.

Re: I don't care about cookies

#172
post #57
post #36

Earlier quoted context omitted.

> The consent popups you see aren't just about cookies though. I don't care about all the other stuff the popups are about either. The popups are pointless, click-through damage and they serve no purpose. The laws that caused them to exist are equally pointless. There is no measurable benefit to any of this privacy theater and no less tracking is occurring since the advent of all of these pointless popups.

Have you tried going through these new popups? If they are trustworthy then the current ones allow you to disable some cookies and give you an idea of who is doing the tracking. Even though there are far better ways to manage cookies with browser settings and extensions: the options are sometimes quite limited (e.g. Chrome on Android) and many people would simply be unaware of cookies without these popups. Those peop…

The idea that people will go through these popup menus for every site they visit is just insane. It goes to show how governments and standards bodies really have no clue. When opening a hyperlink, you aren't meant to establish a relationship with this new website (at least not most of the time). It's supposed to be fast, possibly just to read a small part of that page and go back to the previous website.

Re: I don't care about cookies

#173

Earlier quoted context omitted.

Some sites use localstorage instead of cookies for session tracking.

Thank you. According to a quick search [1], """ Cookies and local storage serve different purposes. Cookies are primarily for reading server-side, local storage can only be read by the client-side. So the question is, in your app, who needs this data — the client or the server? If it's your client (your JavaScript), then by all means switch. You're wasting bandwidth by sending all the data in each HTTP header. If it'…

PHPBB era forums would let you authenticate by putting a session ID in the URL. No cookies needed. There are many ways to do authentication without cookies. There's also basic auth. The whole "we use cookies" thing is a weird misnomer to make laypeople understand that the website is talking about the same concept those FUD articles about web tracking have talked about (tracking can be done through thousands of different vectors, no cookies needed).

>So I guess server-side no-JS applications are going to be caught in this crossfire?

No, as nicbou said, the "we use cookies" popup seems to be only required for tracking/advertising cookies.

Re: I don't care about cookies

#174
post #73
post #61

Earlier quoted context omitted.

That means you also gave permission for them to identify you, store and process that data. And with things like canvas fingerprinting it doesn't matter that you deleted the cookies, they have a persistent identifier for you anyway.

>they have a persistent identifier for you anyway I don't believe this to be true. My CS1 browser fingerprinting[1] results shows that Internet Explorer and Chromium (Chrome etc.) are trackable with fingerprinting but Firefox (at least for me) is not, neither on desktop or mobile. Of course they might have found something the researchers have not. 1: https://browser-fingerprint.cs.fau.de/

Thanks, I gave away my information by signing up for the project and they say that Firefox Focus can not be 'tracked uniquely over time' after I did a test scan on my phone. Plain Firefox from the Android store had the same result, but that app actually does store my cookies.

Re: I don't care about cookies

#175
post #73

Earlier quoted context omitted.

>they have a persistent identifier for you anyway I don't believe this to be true. My CS1 browser fingerprinting[1] results shows that Internet Explorer and Chromium (Chrome etc.) are trackable with fingerprinting but Firefox (at least for me) is not, neither on desktop or mobile. Of course they might have found something the researchers have not. 1: https://browser-fingerprint.cs.fau.de/

Thanks, I gave away my information by signing up for the project and they say that Firefox Focus can not be 'tracked uniquely over time' after I did a test scan on my phone. Plain Firefox from the Android store had the same result, but that app actually does store my cookies.

You have to test over time to get a useful result. Also note that this test only test Fingerprinting. They don't use cookies to test if you can be tracked.

Re: I don't care about cookies

#176

Earlier quoted context omitted.

I meant terrified of doing shady stuff (as I was responding to the assertion that it didn't stop doing shady stuff), not terrified in general. Running a website without a popup is easy . Just stop any processing that is not necessary for you to provide the service. "But I want to track what users are doing!" - Well, then you have to show them a popup about that. The GDPR holds that data protection is a fundamental ri…

> "But I want to track what users are doing!" - Well, then you have to show them a popup about that. I think most website owners don't care about that, but they do care about earning money to actually run the website. > The GDPR holds that data protection is a fundamental right. The GDPR says that if the user asks to use your service then you have to offer them the service regardless whether they're willing to pay fo…

> I think most website owners don't care about that, but they do care about earning money to actually run the website.

Again -- the GDPR recognizes the right to data as a a fundamental right, and thus the ability to earn money with a website comes second to user's rights.

Argumenting against this is a bit like Big Tobacco complaining that they're not allowed to sell cigarettes to children.

> The GDPR says that if the user asks to use your service then you have to offer them the service regardless whether they're willing to pay for it or not. You cannot not show content to users who refuse to share the data. Effectively, everyone else has to subsidize them.

Sure you can. All you have to do is offer two models: (a) a model where the user pays for the service, and (b) a model were the user receives the service in exchange for a agreeing to tracking etc.

Re: I don't care about cookies

#177

Earlier quoted context omitted.

No, it is not a good thing. GDPR is a highly complex piece of legislation that is very hard to navigate and therefore only established companies with big bucks to spend on lawyers and extra engineering can profit from the ecosystem while everybody else is put at risk. Complex legislation and regulations is the best way to keep monopolies in place. Same goes for the financial sector, telecoms, etc. It's nearly impossi…

GDPR is sooo easy to follow as a startup. Just gather the data you need and not everything else,and ask for consent. If anything, it was the big players getting work to do. Thousands of people on mailing lists with no control of how they got there. Asked and kept insane amounts of not necessary data. Data floating in hundreds of database tables spread over various services and third party vendors and data centers wit…

Is every startup hiring a lawyer who specializes in data protection laws? Publishing an impact assessment and waiting 8±6 weeks for permission to deploy? GDPR is the size of a novel and adds a lot of bureaucracy beyond not doing bad things. I think everyone in other jurisdictions needs to consider whether revenue from serving EU users covers compliance costs and risks.

Re: I don't care about cookies

#178

Earlier quoted context omitted.

I meant terrified of doing shady stuff (as I was responding to the assertion that it didn't stop doing shady stuff), not terrified in general. Running a website without a popup is easy . Just stop any processing that is not necessary for you to provide the service. "But I want to track what users are doing!" - Well, then you have to show them a popup about that. The GDPR holds that data protection is a fundamental ri…

> "But I want to track what users are doing!" - Well, then you have to show them a popup about that. I think most website owners don't care about that, but they do care about earning money to actually run the website. > The GDPR holds that data protection is a fundamental right. The GDPR says that if the user asks to use your service then you have to offer them the service regardless whether they're willing to pay fo…

I think you know charging for services is allowed.

You say normal. Others say pernicious.

Re: I don't care about cookies

#179

Earlier quoted context omitted.

> Yes, I can't fathom why the hate is on the law, and not the companies now being exposed by the law.. Because the law obviously didn't help stopping companies from doing shady shit and made the user experience of the web worse?

> Because the law obviously didn't help stopping companies from doing shady shit It helped immensely . I work in the financial sector in an EU country, and most institutions in my country are terrified about the GDPR. The fact that some people will happily operate on the border or even closely beyond the border of law, applies to any other regulation as well.

Oh yeah, thanks EU, now I can't read most USA local newspapers because they don't have money to waste complying with this and it's easier to region ban users

Re: I don't care about cookies

#180
post #7

The consent popups you see aren't just about cookies though. They want (and sometimes illegally force) you to consent to processing of your personal information for reasons beyond just providing you with a service (or more commonly just reading an article). Cookies might be one technical means to assist with that, but it's not the only means.

Yes, I can't fathom why the hate is on the law, and not the companies now being exposed by the law.. Seriously, if you don't do shady shit your site doesn't need a popup asking for consent. But even Github has misunderstood it's not about the cookies. They had an article earlier about removing the popup since they managed to do stuff without cookies. The law doesn't care about cookies, it cares about tracking and ill…

What if I, the end user, don't care what they do with that information?

Why should the EU decide that it's a bad thing for me and I need to be asked about? I hate the banners much more than the tracking.

Post reply on HN