Live data from Hacker News

Please stop putting cookie pop-ups on your website (2022)

olivergrimsley.com

181–190 of 211 posts

Re: Please stop putting cookie pop-ups on your website (2022)

#181

Earlier quoted context omitted.

It doesn't matter what they want. It doesn't matter why they want it. They are not entitled to this information. They should not be able to know anything at all about us without our explicit consent. We should not have to sacrifice our privacy and peace of mind so that businesses can succeed. If they can't succeed without surveilling us and selling us out, then let them go bankrupt.

And you aren't entitled to visit their website. Seems like everything is working fine then? Most of them won't go bankrupt just because you stop visiting; based on reality, most of them are doing relatively fine.

Sure I am. You cannot deny me service because I refused to consent to surveillance capitalism nonsense. It's literally written in the laws. And that's the way it should be. It should be illegal for them to punish people in any way whatsoever for exercising their rights.

Charge people money up front if you require payment. My attention and personal information are not currencies to pay for services with.

Re: Please stop putting cookie pop-ups on your website (2022)

#182
post #143

Earlier quoted context omitted.

> I don't understand why the EU didn't mandate the do not track flag to be obeyed. GDPR is a general regulation. It doesn't concern itself with browsers, or cookies. It's on industry to come up with a solution for specific technologies. Oh, and for browsers they did. It's called the "Do Not Track" header, and the industry immediately sed it to fingerprint and track users. > By not doing this the EU keeps getting flak…

> Oh, and for browsers they did. It's called the "Do Not Track" header, and the industry immediately sed it to fingerprint and track users. They do this anyway. They should have mandated this be honoured (or any other type of tech). If that were the case the browsers would have brought it back in short order. > The EU never mandated the cookie walls. It's the industry's calculated malicious compliance. Exactly. And t…

> They should have mandated this be honoured (or any other type of tech)

GDPR mandates honoring user consent.

It's a general data protection regulation. It doesn't talk about specific technologies.

> this is their fault for not regulating this properly.

What "this". Should there be a separate law for browsers? And a separate law for mobile apps? And a separate law for desktop apps? And a separate law for offline businesses? And...

Or should we blame the people and industries who couldn't care less about user privacy?

Re: Please stop putting cookie pop-ups on your website (2022)

#183
post #142

Earlier quoted context omitted.

EU: Don't track users, don't obtain vast amounts of data on users, don't sell that data to third parties. If you you do, ask users for informed consent. Industry: we hear you. Here's "informed consent" form riddled with dark patterns because we believe that all data is ours by God's decree, and our 15 000 "partners" agree with us ... HN: The EU is to blame for this

What would the 'light' pattern be in this case, where the business wants to comply with regulation and maximize profit?

Have a business that doesn't rely on pervasive and invasive tracking, and on wholesale sales of that data to thousands of "partners"?

Re: Please stop putting cookie pop-ups on your website (2022)

#184
post #152
post #142

Earlier quoted context omitted.

EU: Don't track users, don't obtain vast amounts of data on users, don't sell that data to third parties. If you you do, ask users for informed consent. Industry: we hear you. Here's "informed consent" form riddled with dark patterns because we believe that all data is ours by God's decree, and our 15 000 "partners" agree with us ... HN: The EU is to blame for this

This is correct. However, I always thought that legislation is pretty stupid. It isn't exactly comparable to alcohol/tobacco warnings. Actually, I always thought they are stupid too, but at least they can count as an "informed nonsent", since it's pretty clear, what's the harm they are taking about. Cookies, on the other hand... Even for me, who was perfectly aware of the problem long before this legislation, and who…

> Even for me, who was perfectly aware of the problem long before this legislation, and who was privacy-oriented to begin with, it isn't clear, what's the consent I'm giving.

Indeed, and that's exactly what the industry wants. Show me where exactly GDPR mandates the cookie dialogues. Or ePrivacy Directive for that matter.

> Well, it's not GDPR you should blame, it's Strava and all their partners/competitors

Yes. And yet you somehow twist it to blame GDPR

> but it doesn't seem GDPR is effectively enforcing what it is supposed to.

Yea. Enforcement has been sadly lacking

Re: Please stop putting cookie pop-ups on your website (2022)

#185
post #169

Earlier quoted context omitted.

> The point is that they do not limit them sufficiently, clearly. I agree. The law should’ve been stronger. But we work now with the hand we have. > People who complain about the popups want to blame the businesses Not in my experience. There’s a split between people blaming the business and blaming the EU. > but the business are doing in compliance with the law. Most aren’t. The GDPR says explicitly that withdrawing…

> There’s a split between people blaming the business and blaming the EU. I mainly just see Europeans defending it as not the EU, and I see that as patriotism and not an argument from merit. I have to see it that way because blaming the businesses for engaging in a legal activity and doing something mandated by regulation is crazy to me. > Most aren’t. The GDPR says explicitly that withdrawing consent must be at leas…

> I mainly just see Europeans defending it as not the EU, and I see that as patriotism and not an argument from merit.

That’s absurd. By that logic Europeans would also have defended Chat Control, but that wasn’t the case. A person doesn’t become a blind zealot because they think differently from you.

> I have to see it that way

No, you choose to see it that way.

> blaming the businesses for engaging in a legal activity

Perhaps you’re too attached to the rule of law. Being legal does not mean being right, moral, or generally good. Slavery was legal at one point and then it wasn’t. Lead paint was legal and then it wasn’t. Those things weren’t good when they were legal. Companies knowingly engage in harmful legal behaviours every day.

https://www.sydney.edu.au/news-opinion/news/2024/05/02/how-c...

https://www.decof.com/documents/dangerous-products.pdf

> Most popups have two buttons, accept or reject. It doesn't really get simpler than that.

I addressed that in the previous comment. That’s becoming more common now, after years of fighting malicious compliance. Again, thank noyb and organisations like it.

Re: Please stop putting cookie pop-ups on your website (2022)

#186
post #177
post #167

Earlier quoted context omitted.

That is explained right at the top of the page : > Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used. Let’s please engage in good-faith conversation. If you don’t read a prominent explanatory banner with a blocky information icon at the top of an explanatory page, I don’t know what to tell you.

You said: > Don’t invade user’s privacy and you don’t need cookie banners. But when it's pointed out all EU websites use cookie banners, you shift goalposts and pretend that others are engaging in bad faith.

> But when it's pointed out all EU websites use cookie banners

Because you keep failing to read properly (and even had one comment flagged on the same subject), I’ll emphasise it this time:

> Use of the cookie consent kit is mandatory on each page of the DGs and executive agencies-owned websites, regardless of the cookies used.

Again:

> regardless of the cookies used

In case you still don’t understand, that means it doesn’t matter what type of cookies the EU websites use, they still have to show the banner even for cookies no one else has to show a banner for.

Re: Please stop putting cookie pop-ups on your website (2022)

#187
post #169

Earlier quoted context omitted.

> The point is that they do not limit them sufficiently, clearly. I agree. The law should’ve been stronger. But we work now with the hand we have. > People who complain about the popups want to blame the businesses Not in my experience. There’s a split between people blaming the business and blaming the EU. > but the business are doing in compliance with the law. Most aren’t. The GDPR says explicitly that withdrawing…

> There’s a split between people blaming the business and blaming the EU. I mainly just see Europeans defending it as not the EU, and I see that as patriotism and not an argument from merit. I have to see it that way because blaming the businesses for engaging in a legal activity and doing something mandated by regulation is crazy to me. > Most aren’t. The GDPR says explicitly that withdrawing consent must be at leas…

> I see that as patriotism

Don't take the piss!

It's about a _GENERAL_ data protection act that prevents companies and jobsworths having free rein to your personal data. This has sweet FA to do with patriotism as you know perfectly well.

Re: Please stop putting cookie pop-ups on your website (2022)

#188
post #163

Earlier quoted context omitted.

What would the 'light' pattern be in this case, where the business wants to comply with regulation and maximize profit?

Make a good product that does not rely on exploiting user data. Advertise in relevant locations without tracking (e.g. if you sell cars, advertise on a car-centric website/forum/magazine).

You don't have to reply to every comment I make in reply to someone else in this thread, just FYI.

> Make a good product that does not rely on exploiting user data. Advertise in relevant locations without tracking (e.g. if you sell cars, advertise on a car-centric website/forum/magazine).

No, none of this is a light pattern. It's just abstaining from the activity entirely.

Re: Please stop putting cookie pop-ups on your website (2022)

#189
post #183

Earlier quoted context omitted.

What would the 'light' pattern be in this case, where the business wants to comply with regulation and maximize profit?

Have a business that doesn't rely on pervasive and invasive tracking, and on wholesale sales of that data to thousands of "partners"?

That's not a light pattern, that's giving up the activity entirely.

If an activity is explicitly legal, even with regulations, then there should be a light pattern for that activity is there is a dark pattern.

Look at selling cigarettes in the 80s. A dark pattern would be trying to influence kids on the low, which mascots like Joe Camel.

A light pattern would not be abstaining from selling cigarettes entirely, analogous to what you suggest, but rather voluntarily adding labels to packaging and taking other precautions.

Re: Please stop putting cookie pop-ups on your website (2022)

#190
post #185

Earlier quoted context omitted.

> There’s a split between people blaming the business and blaming the EU. I mainly just see Europeans defending it as not the EU, and I see that as patriotism and not an argument from merit. I have to see it that way because blaming the businesses for engaging in a legal activity and doing something mandated by regulation is crazy to me. > Most aren’t. The GDPR says explicitly that withdrawing consent must be at leas…

> I mainly just see Europeans defending it as not the EU, and I see that as patriotism and not an argument from merit. That’s absurd. By that logic Europeans would also have defended Chat Control, but that wasn’t the case. A person doesn’t become a blind zealot because they think differently from you. > I have to see it that way No, you choose to see it that way. > blaming the businesses for engaging in a legal activ…

> That’s absurd.

It's hardly absurd, it's a common pattern in nations and online rhetoric.

> By that logic Europeans would also have defended Chat Control, but that wasn’t the case.

Just because people may defend one thing out of tribalism doesn't mean they would defend everything out of tribalism.

It's specifically EU users on HN I see trying ti shift the blame to corporations. I find it bizarre, honestly. Correlation isn't causation but in this case I do think there's a link.

> No, you choose to see it that way.

Meh. I believe it's a reasonable position backed by evidence.

> Being legal does not mean being right, moral, or generally good.

Yeah, this has nothing to do with the actual root point being discussed though, which is which entity gets the blame/credit for the popups.

That's the EU, no question. You don't like the data collection practices or consider them immoral? That's fair and reasonable, and we can talk about that, but it's a separate albeit adjacent issue.

> Slavery was legal at one point and then it wasn’t.

This is why you shift the goalposts. Now you're talking about slavery. The original point you made in this thread and the topic being discussed are the popups, regulation of an activity not the activity itself.

Slavery is not analogues to popups. An analogy involving slavery would be if there were government mandate signage every 100 feet in town centers advising slaves are people and should be treated humanely (which obviously didn't happen, but it's hard to twist such a bad faith example to still make a point).

> That’s becoming more common now,

It's been common, i.e. the norm, since the laws came into effect.

Post reply on HN