Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

181–190 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#181
post #16

Earlier quoted context omitted.

What if the ads are required for the operation of the website, because without them the site has to close? People are rarely willing to pay for big sites, they surely won't pay for many small sites separately. Smaller sites don't have the resources to curate their own ads, that's why they use ad networks. If we are strict about this then this rule will eliminate small sites while tightening the grip of the big sites…

> What if the ads are required for the operation of the website, because without them the site has to close? That's why you ask people. If enough people agree to paying for your content with their data, your site lives on. If too many opt to not pay for your content with their data, your site dies unless it can find another way of making money, such as subscriptions. Yes, it absolutely can mean that the giants will e…

> That's why you ask people.

Most people don't care and just choose the default option to get to the site. If opt out is the default and opt in requires a conscious decision then the majority of users won't opt in, because most users don't read the options, only clicks on the default option or the close popup X.

> Yes, it absolutely can mean that the giants will expand and lots of small sites that use ad networks will die.

And we already see the current situation where Facebook is dominant. If more small sites die and the big ones get even stronger then the situation will continue to deteriorate.

Re: Cookie Warning Shenanigans Have Got to Stop

#182

What I don't understand is why websites hosted outside the EU, for non-EU users have the cookie banners. At least keep it in Europe, use the IP to geolocate, let the EU users deal it. Some companies have outright banned EU traffic, sounds like only showing the banners for EU IPs seems ok.

The law doesn't just apply to pages being served to the EU, it applies to pages being served to EU citizens, wherever they happen to be at the moment. So geolocation is not a satisfactory option.

> wherever they happen to be at the moment

In the vast majority of cases that's not how laws actually work from one nation to the next. That isn't how legal jurisdiction works. If it were, any nation could impose its laws on any other nation at any time.

> So geolocation is not a satisfactory option.

In fact it is. I can safely disregard the EU and nearly all of its laws including GDPR and privacy laws in the EU. I don't operate in the EU, either physically or in terms of hosting. They have no access to me, my finances, my business, and have zero jurisdiction over me as a US citizen. I'm bound by US law, not EU law.

I can do anything I want to with data from EU citizens that visit my US-based services, so long as I obey US laws. The exception to that is if I need to operate in the EU, then I should comply with EU law.

The EU also does not rule China (1.4 billion people, world's second largest economy), for a strong reference on how the EU's laws don't actually apply globally. While you're in China, as an EU citizen, you are not governed by EU law, you are governed by Chinese law. Give that a test run, you'll find out instantly how it works. If you visit sites located in China, they're going to obey Chinese law, not EU law. Millions of Chinese sites are not concerning themselves with GDPR compliance, because it does not apply to them at all.

Re: Cookie Warning Shenanigans Have Got to Stop

#183
post #5

This is like a case study of well-intentioned, carefully designed regulation doing more harm than good. Honestly, I'd rather just have a browser addin that blocks the cookies I don't want. The market was working fine. Now every new website is a pain, and my organization has hired some amiable lady to be "GDPR expert". She doesn't appear to know anything about anything, but she sure seems nice.

The harm is being done by companies attempting to keep the status quo by nagging users unless they give consent. I hope some of the worst offenders in this regard get slapped by regulators. You can be 100% GDPR compliant and have a functional website without needing any cookie or GDPR consent boxes.

Re: Cookie Warning Shenanigans Have Got to Stop

#184

This shows utter incompetence and detachment from reality by European legislators. Maybe it seemed like good idea in theory but the only practical significant impact is that browsing the web has become more annoying. Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes?

“incompetence”, “detachment” right.

I, for one, am happy that bullshit like “hey, we send your data to 244 trackers uncontrollably” has become visible and is being called out.

I mean, visible only in the EU.

Dark patterns and site-blocking are anti-GDPR, so I’m hoping for some heavy fine across the board. And, hopefully, if not the end then curtailing of the intrusive and tracking cookies, ads etc.

Re: Cookie Warning Shenanigans Have Got to Stop

#185
post #149

Earlier quoted context omitted.

Most of the cookie warnings are clearly against guidance which says that consent must not be a condition of service to be considered freely given, must be opt in not opt out and that even with consent the use of pii must be in the user's interests. Almost no cookie warnings meet the law and many of the ones that do could use a different lawful basis and not show a dialog at all.

> consent must not be a condition of service So what do you do if your website literally cannot function without cookies?

Then you do not need to ask consent to use them. You only need consent for cookies or data collection if it is not necessary to the service (and 'necessary for tracking ads' does not count as necessary).

Re: Cookie Warning Shenanigans Have Got to Stop

#186
post #19

I'm sure there's some good reason not do it, so I'll ask if anyone here knows: why doesn't the law just require some technical implementation that can be automated? Why can't the law just specify something similar to the DNT header (finer grained) and require compliance with that?

The law should lay out principles, not techniques. The GDPR works for any kind of data processing, it is not specific to browsing on the Web.

The core issue is that the ~150 companies of the Oath network will effectively go out of business when they comply with GDPR. So now they try to play some games, until the fines handed out to them become too large to sustain in EU.

Re: Cookie Warning Shenanigans Have Got to Stop

#187

This shows utter incompetence and detachment from reality by European legislators. Maybe it seemed like good idea in theory but the only practical significant impact is that browsing the web has become more annoying. Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes?

> Surely there are solutions that don't require a popup on every webpage you visit?

I don't get any popups or cookie notices on visiting HN or several other sites. It's not like it's a fundamental need to set hundreds of tracking cookies on a visitor's browser to show them a website.

Re: Cookie Warning Shenanigans Have Got to Stop

#188
post #111

Its too bad nobody invented a browser header to be sent with HTTP requests for Allow-Cookies: SURE_YES_WHATEVER_OMG_STOP_ASKING_PLZ

We could further optimize by just assuming that people are OK with it if they didn't send the header, and then have them opt in to sending it. Maybe we could call it something like "DoNotTrack", to get the idea across. DNT was mostly ignored, but if it had the weight of law behind it, it could still be great.

And now Safari removed DNT because sites were using it as a part of fingerprinting across websites.

Advertisers couldn’t care less about privacy.

Re: Cookie Warning Shenanigans Have Got to Stop

#189
post #145

Earlier quoted context omitted.

So websites are supposed to just absorb the cost? That seems like a ridiculous stance.

> So websites are supposed to just absorb the cost? That seems like a ridiculous stance. The €0.00002 it took to serve that one page just because the user doesn't want to consent to cookie placement/tracking? Is it really that harmful? NPR seems to do this just fine for GDPR reasons: Decline and Visit Plain Text Site

In fairness it can add up pretty quickly on popular sites.

I do love NPRs approach though.

Re: Cookie Warning Shenanigans Have Got to Stop

#190
post #114

Earlier quoted context omitted.

Amusingly I actually just added a ton of Prop 65 warnings to a ton of things because someone got tired of thinking about if it should be applied to every third thing. So now it is on everything .... That was kinda vauge as I don't want to get into specifics as it is job related, but man it was timely ;)

Don't forget to apply a sticker to the roll of stickers themselves. You never really know what's in that adhesive, after all...

I in fact added to warning to a comment in the code, and the commit, and so on ;)
Post reply on HN