Live data from Hacker News

Analysis of economic and productivity losses caused by cookie banners in Europe

legiscope.com

241–250 of 395 posts

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#241
The numbers are much lower I think, at least nowadays.

> On average, a user visits about 100 websites per month, totaling 1,200 websites per year.

The number of 100 websites per month is pulled out of thin air. Following the links it seems to be based on the number of web PAGES visited DAILY by Americans in 2007.

In my anecdata most people are online a lot but mostly in just a few apps and websites.

So I guess all numbers in the article should be much much lower.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#242
post #137

Why should websites even be trusted with implementing these banners in the first place? Browser vendors should be responsible for implementing these controls per-origin. Give a little banner pop-up built into Chrome, Firefox, Safari, and the rest. Have it display every time a new site sets a cookie for the first time. Or have it reject every cookie by default, unless I whitelist a site. This would result in a consist…

> Why should websites even be trusted with implementing these banners in the first place?

Because these "banners" are not just about cookies but about data processing and storage. Cookies are just the most obvious and immediate aspect because they're browser-facing and thus consent needs to be obtained early on. But there's nothing special about cookies when it comes to the need to obtain consent (even the ePrivacy directive which singles them out only does so to explain what information needs to be disclosed in order for consent to be possible).

> Instead, we are trusting the very websites we are blaming on tracking us in the most decietful, malicious ways possible to self-regulate and implement these controls.

Yes. Because they break the law if they don't comply or try to trick you to "opt in".

> So there's no consistency.

Yes. Most consent dialogs are breaking the law by being intentionally non-compliant to mislead visitors into opting in. The ePrivacy directive makes it pretty clear what a compliant dialog would look like. For example if you have a big "accept all" CTA you need to have an equally prominent "reject all and proceed" CTA.

> And 90% of the time you can't disable all the cookies anyway, because there's that little grayed out toggle control for "strictly necessary cookies."

If they're strictly necessary, they are required for the site to function. Disabling them would make the site not work.

> How do I know one of those cookies you consider "strictly-necessary" or "crucial for site functionality" doesn't connect back to some evil tracking algorithm, the blocking of which was the whole point of this banner debacle in the first place?

Because that would break the law.

> So we have essentially asked websites to self-regulate the way the US's vitamin/supplement industury does, except its worse because I don't have to click a fucking banner before I take a capsule of what may or may not be vitamin C.

No, we have created a law they have to follow and which they can be fined for violating. We have also established privacy and the right to your personal data as a universal right because everything else in the GDPR and ePrivacy directive follows downhill from that.

They're not self-regulating, they're regulated. This is literally how regulation works: they have to follow the law or they risk a fine. The problem right now is some DPAs dragging their heels, most being underfunded and foreign companies getting special "One Stop Shop" deals where a ridiculously corrupt DPA (hello Ireland) gets to be the single DPA in charge of handling complaints about them.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#243

I am kind of frustrated by the widespread misunderstandings in this thread. Laws are best when they are abstract, so that there is no need for frequent updates and they adapt to changing realities. The European "cookie law" does not mandate cookie banners, it mandates informed consent. Companies choose to implement that as a banner. There is no doubt that the goals set by the law are sensible. It is also not evident…

> The European "cookie law" does not mandate cookie banners, it mandates informed consent. Companies choose to implement that as a banner. Would there exist any other method of implementing it that would be substantially different? Its hard to imagine. I suppose they could implement it by not having tracking cookies. I think the ideal situation is that people could just set it as a browser preference and be done with…

Setting a browser preference is not giving explicit opt-in informed consent to handle my personal data (for that is what this is about) on a case by case basis.

That is what the law requires.

Blame the unnecessary gathering of personal data (and think about why they want it!), not the 'cookie law'.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#244
post #9

This destroyed the world wide web, which was the major driver of the internet as a consumer application. I'm referring to the experience of intelligent & creative publishers sharing content openly on the web. This did far more to destroy the world wide web than ads or tracking

The only reason this exists is because of the ad/tracking parasites that infected the entirety of the internet.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#245
And how much time is wasted clicking away mailing list banners, popup ads, trying to parse the real download button on a page, watching through unskippable video ads, trying to decipher which part of a website is the article vs an ad etc?

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#246

I am kind of frustrated by the widespread misunderstandings in this thread. Laws are best when they are abstract, so that there is no need for frequent updates and they adapt to changing realities. The European "cookie law" does not mandate cookie banners, it mandates informed consent. Companies choose to implement that as a banner. There is no doubt that the goals set by the law are sensible. It is also not evident…

I am informed and chose "No" each time. Why do EU lawmakers not allow me to automatically say no? All they have to do is add a line to the law enforcing companies to respect the DNT or GPC header.

https://en.wikipedia.org/wiki/Do_Not_Track

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#247

The whole thing is a colossal waste too, it was a law written by people who don't understand tech for special interest groups who don't want to actually make things better. If you don't want a website doing something on your computer, you start with the browser, not the website.

It's not about your computer, it's about your data. Tracking cookies are just one aspect. The GDPR is about consent and ownership of your personal data. It literally defines your rights with regard to your pesonal data.

The GDPR and ePrivacy directive aren't just about cookies. They limit what a company can do with your data in general, who can access it and how long. Cookie banners are just a downstream consequence of it and the reason they're bad is that most companies try to be clever and design them maliciously in ways to coerce you into "opting in" even though this makes them non-compliant.

If DPAs were serious about enforcing the law, every single website not giving at least equal visual weight to the "refuse all and continue" button (or hiding it behind other options or using individual "legitimate interest" toggle buttons to sneak in their partners despite the existence of the toggle button invalidating the claim of "legitimate interest") would be punished with the maximum fine because they have purposefully and maliciously violated the law.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#248
post #230

Earlier quoted context omitted.

I don't think DNT settings were not considered – they were probably discarded as they hurt user privacy. Fingerprinting tools use the DNT setting as an extra flag to identify the user, so having it set to a non-default means you actually get tracked more, not less.

The cookie banners still have to be implemented somehow. I dont think there is a difference in the amount of tracking here.

My point is that if the tracking settings came from the browser whether it was DNT or another one, they would actually be used to track people more effectively by bad actors
Post reply on HN