Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

261–270 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#261

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

Hmm, there are features that one literally can't provide without state (cookies). I think the real problem here is that the technical feature of cookies providing browser state is a poor proxy for what EU/DPA _really_ wants to regulate, which is privacy-related tracking. There are tons of sites I've written which use cookies, but have no ads and perform no user-tracking whatsoever, not even Google Analytics. It is tr…

> Hmm, there are features that one literally can't provide without state (cookies).

The biggest lie in most cookie warning popups is that you need to accept them for the site to function. It is often not true. Those are session cookies and you don't need to warn users about them, they're just allowed.

I didn't know this, and neither do any of the cookie warnings mention this. So like many people I thought the cookie law was the stupidest thing ever because like you say, you gotta have state. But the session cookies used to make a site hold state, those aren't considered tracking. When I learned about this little fact, it changed my opinion about the cookie law considerably.

Re: Cookie Warning Shenanigans Have Got to Stop

#263
post #96

Earlier quoted context omitted.

And there's another category of people that understand but don't care.

Not proud of it, but I fit somewhere in that bucket. I do consider it and I have made (slightly) inconventient choices in the name of privacy, but when it comes down to it, I typically say "screw it" because I want what I want.

Oh yeah, I'm definitely including myself in that bucket too.

Re: Cookie Warning Shenanigans Have Got to Stop

#264

This is honestly what your “regulated internet” looks like. None of the solutions ultimately address the real issue and are done purely for liability purposes.

It's what it looks like without any enforcement of the spirit of the law, sure.

You'll see malicious or smart-aleck compliance with any rule that a group doesn't agree with or when they feel that it personally spites them.

Re: Cookie Warning Shenanigans Have Got to Stop

#265

Earlier quoted context omitted.

This is the view of a US person: These are private owned and operated web sites. The site owner determines what is "essential." If you do not agree to to the terms, do not use the site. If you don't want to be tracked for advertising, that's on you to install ad blockers.

Are you allowed to sell your kidney in the US? (No, you aren't.) This means that a site operator can't offer you access to a super awesome news site in exchange for your kidney. They can't get away by saying "but you can choose not to use the site". Well, Europe does the same thing for your personal data.

Trading a kidney for access to a news site would obviously be insane, and we should have laws to prevent insane people from harming themselves.

On the other hand, if a person of sound mind decided they would rather have $1,000,000 than both of their kidneys, why shouldn't they be able to sell one, logically?

The idea of selling one's organs sets off the human involuntary disgust/outrage reaction ("of COURSE it should be illegal! how DARE you suggest such a thing?!"), but if we put that aside, is there a rational reason it shouldn't be allowed?

Re: Cookie Warning Shenanigans Have Got to Stop

#266
I think what is missing from this discussion is possible solutions that don't involve allowing free for all surveillance.

The obvious one to me is to just ban consent. Make anything you would need consent for outright illegal. No one in the right mind would be giving consent for tracking without compensation (which is what the GDPR asks for) anyways.

Maybe leave a small prohibitively expensive loophole for projects that do need to track things (e.g. scientific studies). For instance requiring approval by an ethics committee and a contract signed in person by hand by both parties after jointly reviewing every term.

Re: Cookie Warning Shenanigans Have Got to Stop

#267
post #154

Earlier quoted context omitted.

No, they're supposed to serve generic, non-tracking ads. Non-targeted, or whatever the terminology is. It's hilarious how everyone has just forgotten that used to be a thing. The people on this website are literally the problem, you can't even conceive of a website that doesn't track every click you make across the whole internet, and you guys are the people building the new web.

"It's hilarious how everyone has just forgotten that used to be a thing" Ads were always a thing, they're just going to be better targeted with more info. There is no free lunch, so what this means is the 'no cookie' users may be exposed to more ads. I understand the market dynamics are not working very well, but we have to remember that information provided is not free either.

you will get as many ads as the typical user is able to bare no matter what.

Re: Cookie Warning Shenanigans Have Got to Stop

#268
post #235

Earlier quoted context omitted.

Hmm, there are features that one literally can't provide without state (cookies). I think the real problem here is that the technical feature of cookies providing browser state is a poor proxy for what EU/DPA _really_ wants to regulate, which is privacy-related tracking. There are tons of sites I've written which use cookies, but have no ads and perform no user-tracking whatsoever, not even Google Analytics. It is tr…

Most discussion about the EU cookie directive doesn't mention it, but not all cookies require consent. From https://privacypolicies.com/blog/eu-cookie-law/#some-cookies... : "This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information socie…

" in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service."

If I need to get explicit opt-in for "So, remembering your shopping cart when you come back requires cookies, that okay with you?" I'm not sure how much better that would be. It's still gonna be information overload "false positives".

But I think that is what the regulations actually intend. "We need cookies to give you: Shopping cart; search history; login to your account; whatever -- opt in or out to each one, you can still use the site just without those features if you go out."

A) That is actually fairly expensive to implement. B) I think it _still_ wouldn't accomplish the goals, it's still _way too much information_. Nobody cares whether or not you use cookies to implement a shopping cart. They care about things related to "tracking", especially aggregated tracking, and profiling. C) But you are exactly right that no company is ever going to tell you what you _really_ care about. Unless regulations make them maybe. These regulations were trying. Not there yet.

Re: Cookie Warning Shenanigans Have Got to Stop

#269
post #154
post #145

Earlier quoted context omitted.

So websites are supposed to just absorb the cost? That seems like a ridiculous stance.

No, they're supposed to serve generic, non-tracking ads. Non-targeted, or whatever the terminology is. It's hilarious how everyone has just forgotten that used to be a thing. The people on this website are literally the problem, you can't even conceive of a website that doesn't track every click you make across the whole internet, and you guys are the people building the new web.

I have my own ad that I made for a client. No third party is offering these kinda of ads because of fraud.

Re: Cookie Warning Shenanigans Have Got to Stop

#270
post #145

Earlier quoted context omitted.

So websites are supposed to just absorb the cost? That seems like a ridiculous stance.

Well, saying it's ridiculous isn't an argument. it's expensive and maybe non-viable for many websites. But it's not like all websites need to exist? There was a world wide web before cookies.

The WWW before cookies was pretty limited, and didn't last long. I mean, the first web browser was released in 1990, and cookies were introduced in 1995.

We didn't have e-commerce before cookies.

Post reply on HN