Live data from Hacker News

Facebook’s tracking of non-users ruled illegal again in Europe

techcrunch.com

251–260 of 395 posts

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#251
post #16

Earlier quoted context omitted.

You can read more about the cookie law here: https://www.cookielaw.org/the-cookie-law/ Basically EU wanted sites to obtain consent to use users' cookies (and for the users to give/take away that consent). However, pretty much all the sites just decided to provide you with a banner saying something like "if you're using this site you agree to our cookie policy". Therefore the law became ineffective and just a nuisance…

But what's the alternative approach to the cookie law? A yes/no consent page before your site, and if you click no, the user doesn't get to access it? Because that's basically the same thing, but even more annoying.

If you click no, a single, non-tracking cookie (i.e. "optout=true", not a session ID) is set, and you get to use the parts of the web site that don't require cookies to function (which, for 99% of the cookie banners I've seen, is all I wanted).

Furthermore, if I remember correctly, no explicit consent is required where the cookie has to be used for features the user requested, like a shopping cart.

So, if the law was actually written to require what it was supposed to require, and actually enforced, a web site operator would have the options to either:

a) implement an opt-out globally across the entire site to ensure no part sets a cookie and doesn't track them, with a high risk if you get it wrong, annoy every visitor with a modal yes/no before letting them onto the site (which would hurt your conversion rates etc.), where the "no" would be a meaningful choice that would still let them use your site, and there would be very little incentive for the user to click yes

b) stop tracking users unnecessarily in general

As it is written, the options are:

a) implement an opt-out globally across the entire site to ensure that no part sets a cookie and doesn't track the users, with a high risk if you get it wrong

b) slap an annoying banner on your web site

One of these options is significantly less work and allows you to keep tracking users, so guess what gets done.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#252
post #123
post #50

One of the good things about HN is that the engineers working and building these features are likely reading these posts too, I'm curious how one implements these things. Are engineers (some of the brightest ones) not realizing that some of their actions are ethically questionable, or is the big picture not visible to the average engineer in a large company like FB? I assume that many have the exact same reaction and…

In an ideal world, engineers would be perfectly ethical. But, you know, said hyperbolically, sociopaths can be engineers too. You should not induce from your own values to people in general. Even apart from people without any values.. most engineers don’t hang out on HN, and don’t care much about global scale politics. They care about things that affect them in a very immediate way - family wellbeing, friends, cowork…

Yeah, most people see the world like this:

* Turn up to job. Nice people, good desk, good canteen. Benefits good.

* Work is interesting - working on cutting edge, dynamic web experiences that are changing the way we interact with people.

* Solved a knotty engineering problem today. Was very pleased, boss was impressed.

* Shipped product today. New sprint starts tomorrow. No defects!

The actual implications of any one feature, the borders between personal data and pure engineering problems blur. Your effort is only a small part of hundreds of effort-hours taken to ship and maintain a product. The decisions about where the lines are drawn were taken months or years ago by people who may or may not be at the company and who were also probably just trying to solve the problem that was in front of them.

You, the engineer, are never sat alone in a room with a user story that breaks GDPR for a product that is fully compliant. The future of the product never rests with you and only you.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#253

Earlier quoted context omitted.

Websites in the Netherlands (and German public broadcasters) already follow the original ideal: Before accessing the website, you get a choice between yes and no. If you select no, the site will not do any tracking, no analytics — some sites disable ads in that case entirely. You still get to access the site. If you select yes, you getthe tracking.

Honestly asking... Does anyone ever click yes?

Probably, because many other sites implement it as "yes means you get to go to the site, the no button is a link to google.com"

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#254

What is Facebook's end game here, I don't get it. GDPR is around the corner, it certainly won't fly under GDPR so why the jurisdiction argument even, the days for tracking people without consent is numbered - a rational organization would realize this. I would think just say ok we stop doing it because we're going to have to stop doing it anyway. But they're not stopping, what is the plan?!?

If Facebook's business model is built around collecting and selling personal data, and more than 4% of their revenue globally comes from EU citizens, then they could decide to wilfully flout GDPR and just pay the maximum fine every year.

Another way they could deal with it is by disputing the EU-US privacy shield[1] or disputing the decision that overturned the original privacy safe harbour[2]. IANAL so I have no idea how they would do this, but it will be costly for ECJ and FB.

[1] https://en.wikipedia.org/wiki/EU-US_Privacy_Shield [2] https://en.wikipedia.org/wiki/International_Safe_Harbor_Priv...

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#255

Earlier quoted context omitted.

To be pedantic, I can attest that in California drivers ed they teach you that it's safest to keep with the flow of traffic. The difficulty is in proving that traffic was going as fast as you.

Is this rule above the other rules like speed limits, stooping at red light ? It seems to me that this kind of fuzzy rules can undermine the others.

They both can apply. The flow of traffic laws, such as the one in California, are to prevent people from going significantly below the speed limit. Its a better approach, in my opinion, then a minimum speed limit law that many states use.

That said, you'll end up driving white-knuckled and fearful of your life if you dare go the speed limit on the Mass Pike. You'd have to drive 70-75 minimum here just to feel safe.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#256

Earlier quoted context omitted.

> I think the implication is more, "why are you only paying attention to us?" I read that as: why are you only paying attention now ? (i.e. after allowing the industry to reach its current, pathological state)

EU is working for years on laws to protect the citizens rights from this internet companies, the laws take years to be created and when done are announced and it also takes a long period of time before the laws will start to apply. Do you prefer that we create laws for fixing problems that do not exist yet?

You misunderstand. Facebook probably knew that the new law was in the making, but they probably thought: by the time this law passes, everybody is doing it!

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#257

What is Facebook's end game here, I don't get it. GDPR is around the corner, it certainly won't fly under GDPR so why the jurisdiction argument even, the days for tracking people without consent is numbered - a rational organization would realize this. I would think just say ok we stop doing it because we're going to have to stop doing it anyway. But they're not stopping, what is the plan?!?

If Facebook's business model is built around collecting and selling personal data, and more than 4% of their revenue globally comes from EU citizens, then they could decide to wilfully flout GDPR and just pay the maximum fine every year. Another way they could deal with it is by disputing the EU-US privacy shield[1] or disputing the decision that overturned the original privacy safe harbour[2]. IANAL so I have no ide…

I don't think that 4% is limited per annum, so that if you've paid 4% for case 1 in that year you pay out 0% for case 2+ in that year.

on edit: looking here https://www.i-scoop.eu/gdpr/gdpr-fines-guidelines-applicatio... it seems the second level of fines go up to 2% and are on a per case basis.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#258
post #156

Earlier quoted context omitted.

Well then the site dies. Sites die all the time, why should Facebook be any different (on the long run of course)? If users want your service, they will pay for it. If they don't, well then your services is not needed.

Because that destroys a whole industry of sites that are not good enough for people to pay for them, but thanks to the economy of scale, they can create quality content (and a living out of it) anyways. Your claim that it is not needed is proven not true by the very existence of these sites. There are many blogs that are sole income of many people, this will now cease to exist. How is that a good thing? This argument…

This assumes that because it was viable in the past, it must be viable today. Maybe ads had more revenue then, but times and people change, and now ads aren't that lucrative anymore. One needs to factor this in the decision to continue hosting a blog or whatever else. This trend was forseeable. On a personal note, this is good. Ads are either annyoing or outright dangerous. So the less, the better.

If you want to host your blog, then just pay for it. I do the same. Not because I want to earn money with it, but because I want to. I can see why this is a problem for commercial entities, but not for personal stuff.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#259

Earlier quoted context omitted.

EU is working for years on laws to protect the citizens rights from this internet companies, the laws take years to be created and when done are announced and it also takes a long period of time before the laws will start to apply. Do you prefer that we create laws for fixing problems that do not exist yet?

You misunderstand. Facebook probably knew that the new law was in the making, but they probably thought: by the time this law passes, everybody is doing it!

That is true, and FB will try to appeal and move the final decision for 10 years like Intel is doing.

Re: Facebook’s tracking of non-users ruled illegal again in Europe

#260
post #255

Earlier quoted context omitted.

Is this rule above the other rules like speed limits, stooping at red light ? It seems to me that this kind of fuzzy rules can undermine the others.

They both can apply. The flow of traffic laws, such as the one in California, are to prevent people from going significantly below the speed limit. Its a better approach, in my opinion, then a minimum speed limit law that many states use. That said, you'll end up driving white-knuckled and fearful of your life if you dare go the speed limit on the Mass Pike. You'd have to drive 70-75 minimum here just to feel safe.

Yes, it makes sense for the minimum speed, here in Europe the max speed can't be exceeded and on top of that you have to adapt your speed to the actual condition, if is ice or the road is wet, or there is fog the law says you have to reduce your speed until you are safe, if you did not reduced it enough and did an accident you are guilty.

I hate when someone drivers respecting the limit and you get jerks with big cars or trucks behind you and force you to go faster(by force I mean get close behind you, use the horn and other bad behavior that can intimidate a new driver).

Post reply on HN