Live data from Hacker News

Please stop putting cookie pop-ups on your website (2022)

olivergrimsley.com

201–210 of 211 posts

Re: Please stop putting cookie pop-ups on your website (2022)

#201
post #195

Earlier quoted context omitted.

> It's specifically EU users on HN I see trying ti shift the blame to corporations. You keep saying that. How do you know? Even if you looked at the profile of everyone you interacted with, I doubt you’d be able to ascertain nationality. > I find it bizarre, honestly. And I find it bizarre that someone would kowtow to corporations purposefully exploiting them, but I’m not going to pretend to know where those people l…

> You keep saying that. How do you know? Because I find the position not to blame the EU so baffling and irrational that I was curious about the people who advocate that position. The first few times I checked the profiles it was very clearly EU users. I kept checking, while being very aware of and cautious of falling prey to confirmation bias, yet the same pattern kept holding. > Even if you looked at the profile of…

> You keep talking about the immoral yet explicitly legal practices of these companies

I did a search for “moral” in this thread’s history. I matched exactly once (twice with this one). That’s not “keep talking about”, that’s one mention. Even then it was a general point of not conflating legality with morality, it was not specific to this practice.

You’re ascribing preconceived notions from the straw man in your head, not my words. I thus point you to those same HN guidelines (I agree they are quite good).

> As long as those companies are engaging in legal activities, then the blame for how they engage with them goes to the regulators.

This, right there, encompasses the whole nature of our disagreement. This law prescribes several ways to comply and not be annoying to people. Thus if a company complies in an annoying way, it’s on them. It’s absurd to say that the blame for how you engage with a rules is on regulators. The text of the rule is on regulators, how someone engages with that text is on them.

Re: Please stop putting cookie pop-ups on your website (2022)

#202
post #80

Earlier quoted context omitted.

The issue is also that the cookie banner has become a meme for non technical "deciders". That means even sites that do not track you will have the banner.

Do you have an example for such a site? Where does one even find a site without tracking nowadays? How is such a banner even supposed to work when there is no choice for the user to make? I mean, someone has to make that banner, so it's quite a way from the rash decision to its execution, where at any point (preferrably immediately) someone could and should step in and say "we are not required to do that and we shoul…

It costs time of people who don't weant to spend the time to decide if a cookie banner is needed. its the default. it COSTS money to decide not to have it.

Re: Please stop putting cookie pop-ups on your website (2022)

#203
post #194

Earlier quoted context omitted.

> That's not a light pattern, that's giving up the activity entirely. What's not right? Giving up pervasive and invasive tracking and selling user data? > but rather voluntarily adding labels to packaging and taking other precautions. GDPR, literally, is: if you use data not strictly required for the functioning of your business, ask user for consent. How is this not a "light pattern"?

> What's not right? Giving up pervasive and invasive tracking and selling user data? Exactly. Abstaining isn't a light pattern. A light pattern would be doing the thing in a non malicious way. > GDPR, literally, is: if you use data not strictly required for the functioning of your business, ask user for consent. You're missing the point. You were alleging businesses are using dark patterns while being in compliance w…

> Abstaining isn't a light pattern.

"Abstaining from selling hard drugs to minors isn't a light pattern. Show me how we can sell hard drugs to minors even with all the regulations in place"

Though I hate analogies, but this is what this sounds like to me.

> I'm asking what a light pattern would be for collecting as much data as possible which is an explicitly legal activity as long as the regulations are followed.

You either follow GDPR or do not engage in this activity. What is so hard to understand?

Instead the industry came up with the obnoxious cookie banners tricking users into providing any and all data and selling that data to thousands of "partners".

Re: Please stop putting cookie pop-ups on your website (2022)

#204
post #203

Earlier quoted context omitted.

> What's not right? Giving up pervasive and invasive tracking and selling user data? Exactly. Abstaining isn't a light pattern. A light pattern would be doing the thing in a non malicious way. > GDPR, literally, is: if you use data not strictly required for the functioning of your business, ask user for consent. You're missing the point. You were alleging businesses are using dark patterns while being in compliance w…

> Abstaining isn't a light pattern. "Abstaining from selling hard drugs to minors isn't a light pattern. Show me how we can sell hard drugs to minors even with all the regulations in place" Though I hate analogies, but this is what this sounds like to me. > I'm asking what a light pattern would be for collecting as much data as possible which is an explicitly legal activity as long as the regulations are followed. Yo…

> Though I hate analogies, but this is what this sounds like to me.

The difference though is that selling drugs to kids is flat out illegal, no ifs ands or buts.

Data collection is explicitly legal as long as regulations are followed, so I think it's a flawed analogy.

> What is so hard to understand?

That the businesses are complying with the GDPR but you're still saying it's a dark pattern and complaining about what they are doing.

I need to remind you at this point the topic of discussion is who is responsible for the cookie popups, not the morality or legality of the activity that the EU felt required regulation. The answer is the EU, because that's how they chose to address the issue.

> Instead the industry came up with the obnoxious cookie banners tricking users into providing any and all data and selling that data to thousands of "partners".

Most cookie banners are not deceptive at all. They are the result of complying with the legislation the EU mandated.

In fact, the cookie banners that are as straightforward and clear as possible, and as non intrusive as possible, are an example of a light pattern in this context.

Re: Please stop putting cookie pop-ups on your website (2022)

#205
post #201

Earlier quoted context omitted.

> You keep saying that. How do you know? Because I find the position not to blame the EU so baffling and irrational that I was curious about the people who advocate that position. The first few times I checked the profiles it was very clearly EU users. I kept checking, while being very aware of and cautious of falling prey to confirmation bias, yet the same pattern kept holding. > Even if you looked at the profile of…

> You keep talking about the immoral yet explicitly legal practices of these companies I did a search for “moral” in this thread’s history. I matched exactly once (twice with this one). That’s not “keep talking about”, that’s one mention. Even then it was a general point of not conflating legality with morality, it was not specific to this practice. You’re ascribing preconceived notions from the straw man in your hea…

> I did a search for “moral” in this thread’s history. I

Well that's the wrong approach. I didn't say you kept using the exact word 'immoral', I said you were talking about the "immoral yet explicitly legal practices". That doesn't mean you are using the same exact words I used generalize your various comments and position.

> That’s not “keep talking about”, that’s one mention.

No, it is “keep talking about”, because in every comment discussing who is responsible for the cookie banners, you refer to the activities that are being regulated, rather than the regulation which is what is actually relevant.

> You’re ascribing preconceived notions from the straw man in your head, not my words.

No, no strawman. Every time you try to shift the buck to blaming the companies and not the regulation, and that's what I'm responding to and calling out.

> I thus point you to those same HN guidelines

Out of a petty attempt to do so after I did it because of your snark? I haven't violated the guidelines in any of my replies, and there is no strawman here. I'm addressing your arguments and your arguments only.

> This law prescribes several ways to comply and not be annoying to people.

What method do you propose companies that want to engage in the explicitly legal activity of data collection as long as user consent is obtained obtain that user account? In a method less annoying than a cookie banner?

If you again suggest they just abstain from the explicitly legal activity of data collection as long as user consent is obtained, then you would again be trying to shift the goalposts.

> Thus if a company complies in an annoying way, it’s on them.

So what's the less annoying way than a cookie banner at the bottom of the screen to obtain consent, that doesn't rely on the goodness of the hearts of people running the corporations (because that would very surely be a very naive outlook to think that was realistic)?

> The text of the rule is on regulators, how someone engages with that text is on them.

Sure, and the cookie banners are pretty much the least annoying approach that is compliant with the regulation.

Re: Please stop putting cookie pop-ups on your website (2022)

#207
post #142

Earlier quoted context omitted.

EU: Don't track users, don't obtain vast amounts of data on users, don't sell that data to third parties. If you you do, ask users for informed consent. Industry: we hear you. Here's "informed consent" form riddled with dark patterns because we believe that all data is ours by God's decree, and our 15 000 "partners" agree with us ... HN: The EU is to blame for this

What would the 'light' pattern be in this case, where the business wants to comply with regulation and maximize profit?

Make a settings page where I can go and explicitly enable tracking rather than make it popup.

Oh, right, nobody is going to use that page. So, is it really the EU fault for the cookie popup, which is a dark pattern?

Re: Please stop putting cookie pop-ups on your website (2022)

#208
post #162

Earlier quoted context omitted.

> You're talking about asking a business voluntarily not engage in lucrative legal business activities. Why would they do that? It is baffling that you can make that claim without realising your mistake. Yes indeed, why would businesses do that voluntarily? The answer is they aren’t doing it voluntarily, they are forced by law . In other words, the EU has made the practice illegal. Specifically, it is illegal to enga…

> It is baffling that you can make that claim without realising your mistake. I'm not making any mistake. You continue to make the mistake to blame the businesses doing *legal* activities and complying with the *EU Regulation* that dictates the cookie popups. > The answer is they aren’t doing it voluntarily, They are not abstaining from legal behavior that makes them money, like literally every other business in acce…

I think your point of view is overlooking the concept of loophole or more precisely, malicious compliance.

Businesses can make a separate page, a settings page, where you enable tracking. This solves the problem.

But obviously the cookie popup is HUGE to cover your view of the page and it's as confusing as possible, even with the requirement of an explicit reject all button.

This is textbook malicious compliance, and the EU has been trying to combat it (the explicit reject all button), but I suspect they don't want to codify in law the exact pattern they want to see (law becomes outdated)

Re: Please stop putting cookie pop-ups on your website (2022)

#209

Earlier quoted context omitted.

> It is baffling that you can make that claim without realising your mistake. I'm not making any mistake. You continue to make the mistake to blame the businesses doing *legal* activities and complying with the *EU Regulation* that dictates the cookie popups. > The answer is they aren’t doing it voluntarily, They are not abstaining from legal behavior that makes them money, like literally every other business in acce…

I think your point of view is overlooking the concept of loophole or more precisely, malicious compliance. Businesses can make a separate page, a settings page, where you enable tracking. This solves the problem. But obviously the cookie popup is HUGE to cover your view of the page and it's as confusing as possible, even with the requirement of an explicit reject all button. This is textbook malicious compliance, and…

> I think your point of view is overlooking the concept of loophole or more precisely, malicious compliance.

I don't think I am, because even if the cookie popups were made with the genuine best intentions to adhere to the regulations, no malicious compliance at all, the people I am disagreeing with would still blame the corporations engaging in legal activity and not the regulations themselves that dictate the popups.

I don't doubt malicious compliance exists or is a problem, but I don't think it makes much of a difference in this context.

Re: Please stop putting cookie pop-ups on your website (2022)

#210
post #83

Earlier quoted context omitted.

> I don't understand why the EU didn't mandate the do not track flag to be obeyed. 1. Because the implementation is simply left open? 2. Because it's nearly impossible to verify?

How are cookie banners any better in regards to 2? Not sure what you mean by 1.

Point 1 means that e.g. the GDPR doesn't mandate a specific implementation. It describes the outcome, which is quite reasonable.

Point 2: you can't check/verify if parties, especially those outside the jurisdiction of the EU, really honor things like the 'don't track' flag.

It's unfortunate that so many companies decide to implement the requirements in the laziest and sleaziest possible ways.

Post reply on HN