Live data from Hacker News

RFC 35140: HTTP Do-Not-Stab (2023)

5snb.club

181–190 of 219 posts

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#181
post #131

Earlier quoted context omitted.

That's nonsense. It's not about the cookies, it's about the data collection. You can use cookies without having to use a cookie banner by simply not gathering data you don't need. And if you do gather that data without using cookies you still need to ask for consent.

I can tell you, with absolute certainty, that nobody knows how to implement the law or what it even means, legislators, lawyers, engineers alike. There was a good somewhere and now we're in hell.

You're right in the sense that it tends to be hard to understand things when your salary depends on you not understanding them. This seems to describe most web developers from the number of non-compliant consent popups in the wild.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#182

Earlier quoted context omitted.

I'm registering my elderly relatives for dmachoice.org, to prevent them from getting junk mail. These clowns create the problem and then have the audacity to charge you to be added to the opt out list. I was really skeptical about the GDPR when it was passed and I am now fully on board for an American version.

I'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.

Good job rewarding those companies for adding the nag screen. I'm sure that will get them to stop.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#183
post #7

I’ve always wondered, since an RFC is a request for comment, how does one leave a comment? And who?

A bit of lore that I learned in my networking class in college was that the RFC name was chosen as tongue in cheek in that by the time a proposal gets to the RFC stage, comments are very much not appreciated. You're supposed to comment well before that point. No idea if that bit of lore is true but it is certainly the case that RFCs are usually the final word on the relevant standard. In fact, once they get their ID,…

That's apocryphal, the name just lasted beyond the original workflow of a now 55 year old publishing system.

The idea that a published RFC is a final word is a newer idea too. Yeah, you can't modify an RFC, you have to publish a newer one, but that was a pretty good way of doing distributed change control in 1969.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#184

Earlier quoted context omitted.

I'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.

Good job rewarding those companies for adding the nag screen. I'm sure that will get them to stop.

If by 'companies' you mean https://commission.europa.eu/ then sure.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#185

Earlier quoted context omitted.

It's gotten entirely out of hand. Most EU national government websites have cookie banners. Even the European Commission website has a cookie banner! This should have been implemented at the browser level. Let the browser generate a nice consistent UI to nag EU users when visiting websites about accepting cookies and let the rest of us opt out.

The standard for cookies should be updated with a way to include or retrieve a description of each cookie separately. Then, require sites to provide that description, and let users choose per cookie in the browser.

They already provide description: "improve user experience", lol.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#186

Earlier quoted context omitted.

I am not joining the whole “EU is bad argument”, however the new caps are very annoying, especially the limited benefits they provide.

The non-profit Plastic Deposit Organisation, responsible for managing Denmark's container deposit system, estimates that this change alone will enable them to collect and reuse approximately 70 million additional bottle caps annually. This equates to 140 tonnes of plastic each year. https://www.emballagefokus.dk/goer-noget-uden-at-goere-noget...

This assumes a 90% cap return rate before (which seems low) and a 100% return rate afterwards (not in Denmark myself but I can't be the only one to have returned zero of the new caps vs almost 100% before).

The whole thing smells like a made up issue concocted by some company wanting to sell their bottle cap solution.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#187
post #20

Earlier quoted context omitted.

[flagged]

No, he needs to learn how to screw on a bottle cap. We keep soda bottles horizontal in our fridge, and they don't leak.

Dismissing people's real concerns is how you get them to vote for parties you don't like. Fact is that the new caps do make it easier to end up without a good seal.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#188

It's important to note that the Do-Not-Stab header has been deprecated because one browser engine switched it on by default and requiring users to opt into stabbing hurt the bottom line of the stabbing industry, so it's no longer respected. Luckily someone came up with General Assault Control, a non-standard alternative, which also only has one value, so you can set Sec-GAC to 1 to request websites not to assault you…

It's now customary, in order to comply with European regulations, to present users with a list of possible violent crimes against their person that they can opt out of before using a website. This ensures that non-consent to stabbing is always an active choice, so that users who want to be stabbed or otherwise maimed won't accidentally miss out on the opportunity.

Is this part of a long term plan for opt-in suicide booths in New New York City?

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#189
post #131

Earlier quoted context omitted.

I can tell you, with absolute certainty, that nobody knows how to implement the law or what it even means, legislators, lawyers, engineers alike. There was a good somewhere and now we're in hell.

You're right in the sense that it tends to be hard to understand things when your salary depends on you not understanding them. This seems to describe most web developers from the number of non-compliant consent popups in the wild.

Can you give an example?

If your claim is that sites that use cookie banners don't understand the law, I don't know how we square that claim with the European Commission site's cookie banner. Certainly, the government itself can interpret the law successfully, right?

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#190

Earlier quoted context omitted.

I'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.

> ... "it basically added a cookie banner to every every website I visit" ... Yeah, no. Hostile advertising companies added that cookie banner as a form of "malicious compliance" with the law purely to annoy everyone like a buncha spoil't little brats who didn't get their way, so now they're gonna make everyone suffer... If we get a similar law in the USA, you can expect to see annoyances just like it (and probably w…

That heavily incentivizes me to advocate against any such law.
Post reply on HN