Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

231–240 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#231
post #70

>, Paul Graham came up with the thought, that the EU forces companies to have cookie banners. There is no law for cookie banners. [...] Companies could easily avoid any cookie banner. Just don’t track. KingOfCoders/amazingcto, of course you are technically correct but Paul Graham wasn't talking about the letter of the law. Instead, you have to interpret his complaint with the lens of game theory . I.e. The Law of Uni…

(author here) I'm a fan of second-order thinking and unintended consequences, so I'm with you there. How would you frame a "don't track people without consent" without unintended consequences? The article tries to make the point (perhaps fails), that companies do this intentionally to get the "consent" of people against their will, therefor running the tight line of breaking the law without breaking it.

Fines for data breaches is one idea? If we want to disincentivize data hoarding, the main cost to data hoarding is data breaches, so we could perhaps penalize that.

This would have a different issue, specifically companies would no longer self-report data breaches, but it's just an idea. There are alternative approaches to getting to "don't track people without consent" that aren't a toothless stick by making it more expensive to track.

Re: Dear Paul Graham, there is no cookie banner law

#232

Earlier quoted context omitted.

I clicked on that link and immediately got a cookie banner. Am I missing something?

Interesting. Clearly I am providing out of date information.

More interestingly, that article says:

> We are also committing that going forward, we will only use cookies that are required for us to serve GitHub.com.

A few pixels further down, on the cookie banner:

> We use optional cookies to improve your experience on our websites and to display personalized advertising based on your online activity.

I guess now we finally have a rule-of-thumb figure for what "going forward" means: 3-4 years, tops.

Re: Dear Paul Graham, there is no cookie banner law

#233
post #207

Earlier quoted context omitted.

That update doesn’t matter because the original has the same exception. I quoted it.

Then there isn't cookie law?

If there are exceptions to copyright such as fair use, does that mean that there is no copyright law?

Re: Dear Paul Graham, there is no cookie banner law

#234

Hate this way of thinking where the government (with seemingly good intentions) tries to stop something but leaves a loophole where all our lives are made more tedious and then people defend it saying the companies should just not do it, well we needed the law in the first place so it's a bit silly thinking to suggest they stop doing it after the law, no?. If the cookie law was written properly then it would have jus…

> but leaves a loophole

There's no loophole. There's just limited enforcement. Most of the banners you see every day do not match the requirements at all.

Re: Dear Paul Graham, there is no cookie banner law

#235
post #4

Dumb take. “Just run your business with 10% of the revenue? What’s the problem?” Edit: to those downvoting, yea, it’s agreed that tracking is bad but the tone of the article completely ignores that a lot of the web’s content depends on this model so if it “just didn’t track” a large swath would no longer exist.

In this logic it is totally unfair that I am not allowed sell drugs while I could make a lot of revenue from it.

Re: Dear Paul Graham, there is no cookie banner law

#236

> Companies could easily avoid any cookie banner. Just don’t track. Well, then, the EU should've just made _this_ the law. And we'd have called it the "Just don't track" law. Rant & Details: > There is no law for cookie banners. > What the EU is saying, you need my consent when you want to track me, profile me and sell my behavior off to ad companies. > or “Look, Why take a chance?” (Remo Gaggi), This kinda proves PG…

The law punishes companies, not private citizens. If lawyers are overreacting or companies cannot discern between essential tracking and non-essential then perhaps they are the incompetent ones.

Re: Dear Paul Graham, there is no cookie banner law

#237
post #72
post #21

Part of what it means to be "good at regulation" is to anticipate the likely consequences of regulations. So a regulation that says that "businesses must now give away their products for free, unless they honk each customer's nose" will result in a lot of sore noses. Which is basically the case here. Almost all websites make money through ads, or at least keep logs of user activity to help them optimize their website…

> Almost all websites make money through ads, Doesn't require tracking of individuals. > or at least keep logs of user activity to help them optimize their website Doesn't require tracking of individuals.

Correct me if I'm wrong, aren't but IP addresses are considered to be "personal information" and therefore collecting them is "tracking" under the GDPR?

Re: Dear Paul Graham, there is no cookie banner law

#238
post #50
post #27

Putting up a wall in the middle of a busy street and then getting upset when people find ways around it doesn't make sense. The solution is either to remove the wall or ensure it cannot be bypassed. Right now, it's just irritating for the average person and slightly inconveniencing those who actually break the rules. This is the same situation with the cookie banner regulations. If the goal is to eliminate tracking,…

Since this is around the 5th time this sentiment has been expressed in this thread, I have to ask... are cookie banners really so frustrating? Oh no, gotta click one, maybe 2, more buttons...

Fun fact, they are illegal if they require more clicks to reject than accept; so this is not a consequence of the law anyway.

Re: Dear Paul Graham, there is no cookie banner law

#239
post #227

Note that this isn't a cookie law, it's also the EU's main anti-malware law. The principle is that no piece of third-party controlled software should write information to your computer/phone, or read info from it, over the Internet, without your prior informed consent (with narrow exceptions for storage/reads that are needed to provide a service you've asked for, or equally narrow functions like load balancing). This…

What do you mean by "the original (now decades-old) law" ? The GDPR is 8 years old.

The ePrivacy directive, mostly referred to as "Cookie law" is from 2002.

https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A...

Re: Dear Paul Graham, there is no cookie banner law

#240
post #110

Hate this way of thinking where the government (with seemingly good intentions) tries to stop something but leaves a loophole where all our lives are made more tedious and then people defend it saying the companies should just not do it, well we needed the law in the first place so it's a bit silly thinking to suggest they stop doing it after the law, no?. If the cookie law was written properly then it would have jus…

It would be 100% ok for it to be a browser setting. It isn't though, because that would make too many people opt out. That's what the article is about.

I don't think a browser setting would make any difference. The setting would have to be either "I don't want to be tracked by anyone ever" or "I'm ok with being tracked by everyone all the time". Everyone would just choose the first setting. But just because someone has that setting doesn't mean you can't ask them specifically if they're ok with being tracked on your specific website for some specific purpose. So then you're back at the cookie banners.

(Also, if a lot of people did choose the 'everyone all the time' setting, that would arguably be a poor outcome, because it's unlikely that this is really what people want.)

Post reply on HN