Live data from Hacker News

Who wants to be tracked?

quantable.com

201–210 of 273 posts

Re: Who wants to be tracked?

#201
post #164

Earlier quoted context omitted.

1. Your proposal is not enough for EU privacy law, so you'd still see banners. First-party tracking is still tracking and you still need a banner if you're going to store any data on the client that is not "strictly necessary" for the user's request. 2. Your proposal gives a pretty crummy experience in cases where users do expect the site to store data on the client longer. For logins you're popping up a confusing ba…

No consent is required to store cookies required for the site to function. Login cookies, shopping carts etc are fine. The only reason websites display these banners is because they want to track you, and they rely upon misunderstandings like you are propagating to whitewash the request.

Sites can function just fine without storing my shopping carts locally.

Re: Who wants to be tracked?

#202
post #164

Earlier quoted context omitted.

1. Your proposal is not enough for EU privacy law, so you'd still see banners. First-party tracking is still tracking and you still need a banner if you're going to store any data on the client that is not "strictly necessary" for the user's request. 2. Your proposal gives a pretty crummy experience in cases where users do expect the site to store data on the client longer. For logins you're popping up a confusing ba…

No consent is required to store cookies required for the site to function. Login cookies, shopping carts etc are fine. The only reason websites display these banners is because they want to track you, and they rely upon misunderstandings like you are propagating to whitewash the request.

Login cookies, yes: by entering the username and password the user is requesting that you log them in.

Shopping carts, sort of: if they don't check out immediately and you keep the item in their cart (which they may want but didn't explicitly request) you're in violation: https://ec.europa.eu/justice/article-29/documentation/opinio...

Other things: it has to be "strictly necessary" which is a high bar and many things don't meet it. For example, implicitly learning your preferences from your behavior doesn't.

Re: Who wants to be tracked?

#203

Earlier quoted context omitted.

No consent is required to store cookies required for the site to function. Login cookies, shopping carts etc are fine. The only reason websites display these banners is because they want to track you, and they rely upon misunderstandings like you are propagating to whitewash the request.

Sites can function just fine without storing my shopping carts locally.

They don't have to store the whole contents of your cart locally, but they need to store at least a token on your machine so they can remember that this cart is yours.

Re: Who wants to be tracked?

#204
post #177

My spouse will sometimes mention in conversation with others that I invented the cookie. This always puts me on the spot, and I have to enter into a long explanation of the what and the why of cookies least they believe that I some sort of evil software hacker. (Now for a short explanation so that HN readers don’t think that I’m an evil hacker: I invented them, with the help of a colleague, while at IBM where we were…

Yeah, I remember in the mid-late 90's when companies would actually disable cookies altogether. Most non-technical people just don't understand the what/how/why cookies work, or were really needed in the browsers.

In the end, it's definitely been used in excessive and somewhat intrusive ways. I also wish that browsers had better controls over second and third party cookies and tracking (similar for nested iframe) in order to bubble some of it closer to the surface. In the end, pihole, ublock origin and privacy badger goes a long way to limiting this.

Re: Who wants to be tracked?

#205
post #191

Earlier quoted context omitted.

Great, so when time travel becomes a thing, I'll add you to the list of people to have a chat with about needing to envision longer term visions for how nefarious people can be. I love that at one point in a not so distant galaxy, er time, that there was a thing of innocence. Now, that innocence can no longer be tolerated and every new thing must have more time invested on how the new thing can be abused rather than…

Really? I didn't invent it for browsers, I invented it for distributed file systems before the "World Wide Web" had even been invented. You might as well have a talk with William Shockley or Vint Cerf.

Exactly. How could you have known it would be used for what's it's used for now. That's the entire point of the conversation someone from the future could tell you. Why is that unclear? Maybe you're assuming a negative conversation? There are many decisions in my life that if a future me or someone else could show me exactly how things will play out in ways not foreseen by me at the time, I'd be less hostile than you apparently are at the idea.

Re: Who wants to be tracked?

#206

Better question here is, why is this not handled through the browser instead of relying on individual web apps to do it. Block third party cookies by default, delete other cookies on the last tab or window closed and prompt user to save cookies on a form submit ("do not delete cookies for this domain when leaving" type of prompt, for pages with logins, settings, etc). Also remove features that make easy fingerprintin…

On mobile safari, private tabs isolate cookies from each other. Also, once you are in private mode, all links open in new private tabs. Close the tab, and the cookies are gone. I never turn private mode off. I wish firefox and chrome also worked this way.

My default browser on Android is Firefox Focus. No history, no tracking, cookies removed on close.

Re: Who wants to be tracked?

#207

Earlier quoted context omitted.

Given a boolean flag, if 94% of users would select state X, then selecting X by default doesn't seem problematic at all. Microsoft (for once) did nothing wrong. The problem is the DNT flag was unenforceable, and that's something governments should have pushed on.

> and that's something governments should have pushed on They did. Our current anti-tracking laws all come from pushing on that. The problem is that the DNT is way too simplistic. Browsers fail to inform the users abut it and keep track of sites independently, and the protocol fails to allow the site to request fine-grained authorizations and inform why they are needed. There's a sibling talking about P3P that has ne…

Mozilla should put a red tracker count in the URL bar. That would make people aware of how they're being exploited.

Re: Who wants to be tracked?

#208
post #196

Earlier quoted context omitted.

Somewhat probably, don't take it serious. You did good.

Thanks...I'm think I'm too sensitive about it since this comes up every f'ing time.

Not too sensitive. All of us get annoyed at things we have to constantly reiterate. At least that other user revealed their insanity after they kept talking. Literally explaining why you could never have known, despite claiming you should have "thought harder." Don't feel guilty, you're not the one with the evil idea. We should, of course think long (and sometimes evil), but it's impossible to predict what others will use your tech for.

You did good and there's no problems with what you did.

Re: Who wants to be tracked?

#209
post #193

Earlier quoted context omitted.

> the EU regulation that forced these cookie acceptance forms No such regulation has ever existed in the EU.

That's correct. The regulation is about providing consent to process personal data. Many people fail to see the difference.

There was a cookie law prior to GDPR. That's when the obtrusive dialogs started showing up.
Post reply on HN