Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

171–180 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#171
post #94

Earlier quoted context omitted.

> Not only that, I'm not an EU citizen and I'm not browsing websites based in EU but I'm still bombarded with cookie banners non-stop. Again, that's the fault of the companies putting those up, they could make it opt-in to collect your data, they could just put a small notice on the footer with 2 simples links "Accept all/Reject all". But they chose, they decided to pester you with those banners as annoyingly as poss…

The fact that companies are doing that says more about the bad law than the companies which is exactly Paul Graham's point.

what a ridiculous point of view.

do you think the same thing about laws against murder?

about fraud?

Re: Dear Paul Graham, there is no cookie banner law

#172
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

> On this issue in the group that complain about the cookie law there are some people who are very wrong on purpose because it's in their interest, and some people who are very wrong because they genuinely don't understand the position they're defending, complaining about being made aware of the fee, instead of the fees themselves or the fact that the companies hide them if not forced by law. The reality is that I (a…

The reality is that most people don't want to be tracked:

https://arstechnica.com/tech-policy/2021/07/facebook-adverti...

Re: Dear Paul Graham, there is no cookie banner law

#173
post #134

Earlier quoted context omitted.

> On this issue in the group that complain about the cookie law there are some people who are very wrong on purpose because it's in their interest, and some people who are very wrong because they genuinely don't understand the position they're defending, complaining about being made aware of the fee, instead of the fees themselves or the fact that the companies hide them if not forced by law. The reality is that I (a…

"Number of visitors" does not constitute tracking. The tracking in question here is to discover who you are specifically and the absurd amount of detail about your online activities collected and shared with data brokers for aggregation and resale. A few of these cookie prompts during the day and they'd be able to tell everything from where your kids go to school to the kind of prn you prefer to watch on weekdays and…

I used to work at an online video advertisement company, you'd be horrified how much information we tracked across all the ads, especially since the ad was played with a special media player "plugin" loaded inside the other media player.

This is how ad companies can sell premium views, don't show cosmetics to men, increase car related ads to people who has watched other car related ads and so on.

There's no such thing as server-side "private browsing".

Re: Dear Paul Graham, there is no cookie banner law

#174
post #105

Earlier quoted context omitted.

If you want to click “no” it’s often dozens of clicks (e.g. to explicitly disable each “trusted partner” with “legitimate interest”) alongside constant attempts to trick you into clicking “yes” accidentally.

On most websites I use, it's 1 click. On the rest, it's 2. I've never once encountered a website that required "dozens" of clicks

The typical pattern I see is:

- bright red or green “OK” button that opts in to all tracking

- muted “save settings” button

But aha, gotcha, the default settings still have a bunch of tracking enabled, so you have to uncheck all of those, then remember to press “save” and not “OK”.

In the worst ones there’s an artificial delay when you uncheck one of the third-party boxes, as if it has to file a form in triplicate for the unusual request of not immediately sending all your account info there.

Re: Dear Paul Graham, there is no cookie banner law

#175
post #101

Earlier quoted context omitted.

> are cookie banners really so frustrating They would be a LOT less frustrating if: a) they were standardized — they currently add a hefty cognitive load while parsing them, deciding which action to take, etc. b) they worked properly — I would say, more often than not, they 'forget' the previous setting. I should never see a cookie popup on the same site twice unless I clear my browser settings.

Standardization would certainly be nice, since we could automate it then (I imagine doing so now would require specific cases for most sites)

Most consent banners are produced by a relatively small set of providers. As such, https://consentomatic.au.dk/ does a decent job of submitting your preferences and pushing them out of sight.

Re: Dear Paul Graham, there is no cookie banner law

#176
post #70

>, Paul Graham came up with the thought, that the EU forces companies to have cookie banners. There is no law for cookie banners. [...] Companies could easily avoid any cookie banner. Just don’t track. KingOfCoders/amazingcto, of course you are technically correct but Paul Graham wasn't talking about the letter of the law. Instead, you have to interpret his complaint with the lens of game theory . I.e. The Law of Uni…

Except many companies respond to the cookie law with a cookie consent popup that violates the law (by making opt-out harder than opt-in).

Could we really have predicted from the "Law of Unintended Consequences" that companies would respond not by tracking less nor by giving people an easy way to opt out, but with a cookie consent popup that is not compliant and also really annoying to their visitors?

This is better explained by business operators being ignorant of the actual law and being ignorant of the UX impact.

Re: Dear Paul Graham, there is no cookie banner law

#177
post #94

Earlier quoted context omitted.

> Not only that, I'm not an EU citizen and I'm not browsing websites based in EU but I'm still bombarded with cookie banners non-stop. Again, that's the fault of the companies putting those up, they could make it opt-in to collect your data, they could just put a small notice on the footer with 2 simples links "Accept all/Reject all". But they chose, they decided to pester you with those banners as annoyingly as poss…

The fact that companies are doing that says more about the bad law than the companies which is exactly Paul Graham's point.

So the problem is that the legislator did not expect companies to be even worse assholes than they already were...?

Laws are not borne in a perfect state; very much like programs, sometimes you need a few versions to see how the system actually works in practice and fix a few bugs. The fact that v1.0 has such bugs is not a good reason to just give up, nor it's an indication that the programmer is bad at programming.

Re: Dear Paul Graham, there is no cookie banner law

#178
post #61

can you build a website nowadays with analytics without using cookies? or violating GDPR?

You can track the number of visits without using cookies, but its practically impossible to track the number of unique visitors without using cookies.

The number of unique visitors is a very useful metric (both in itself, and combined with the number of visits).

The EU has made it impossible to track this simple and harmless metric without inconveniencing all users with awful UX.

Under the GDPR / ePrivacy Directive, ANY user-based unique identifer used for advertising, analytics and tracking will trigger the need for consent.

---

General Data Protection Regulation (GDPR)

Article 4(1) defines personal data as "any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."

Article 6(1) outlines the lawfulness of processing and states that processing is only lawful if and to the extent that at least one of the following applies: "the data subject has given consent to the processing of his or her personal data for one or more specific purposes."

---

ePrivacy Directive (Directive 2002/58/EC)

Article 5(3) requires prior informed consent for the storage of or access to information stored on a user's device: "Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service."

Re: Dear Paul Graham, there is no cookie banner law

#179
post #121
post #79

Earlier quoted context omitted.

This is 100% what PG means IMO and the most sane take on this. Either write the law correctly so it's not easily bypassed or just don't touch anything because you will only make it worse.

The law is not bypassed, the annoying banners with no simple option to reject are illegal . The issue is that enforcement is slow, not that the law is badly written. GDPR's Article 7 [0] is very clear: > 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving con…

> The issue is that enforcement is slow, not that the law is badly written.

The enforcement/implementation of a law is so deeply entwined with the text that it's deceptive to separate them.

If a law is written in a way so as to make enforcement hard, or if the government doesn't have the resources to quickly and consistently apply it, then it's a bad law because it enables weaponized targeted/selective enforcement of a new law that wasn't present before.

Re: Dear Paul Graham, there is no cookie banner law

#180
it is pure HN that there's so many people commenting who

1) didn't bother to read the article

2) didn't bother to read any previous articles and so have continually spread nonsense about what the regulations actually required

3) defending all the companies that decided to be fuckwits with barrages of notices to users instead of actually sincerely trying to reduce their creepy nonsense and then - if anything was left that required disclosure - explained it honestly

Post reply on HN