Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

261–270 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#261
post #70

>, Paul Graham came up with the thought, that the EU forces companies to have cookie banners. There is no law for cookie banners. [...] Companies could easily avoid any cookie banner. Just don’t track. KingOfCoders/amazingcto, of course you are technically correct but Paul Graham wasn't talking about the letter of the law. Instead, you have to interpret his complaint with the lens of game theory . I.e. The Law of Uni…

(author here) I'm a fan of second-order thinking and unintended consequences, so I'm with you there. How would you frame a "don't track people without consent" without unintended consequences? The article tries to make the point (perhaps fails), that companies do this intentionally to get the "consent" of people against their will, therefor running the tight line of breaking the law without breaking it.

Probably the same way most laws end up. We see the unintended consequences, then revise the law to counter the consequences. Thus the cat/mouse game continues.

An idea could be that the tracking has to be opt-in AND the webpage cannot stop critical use of the page as part of the opt-in process.

Then another round of consequences.. rinse repeat...

Re: Dear Paul Graham, there is no cookie banner law

#262

Note that this isn't a cookie law, it's also the EU's main anti-malware law. The principle is that no piece of third-party controlled software should write information to your computer/phone, or read info from it, over the Internet, without your prior informed consent (with narrow exceptions for storage/reads that are needed to provide a service you've asked for, or equally narrow functions like load balancing). This…

> Note that this isn't a cookie law, it's also the EU's main anti-malware law. The principle is that no piece of third-party controlled software should write information to your computer/phone, or read info from it, over the Internet, without your prior informed consent

So it is a responsibility of the browser vendor to implement this.

Re: Dear Paul Graham, there is no cookie banner law

#263

Earlier quoted context omitted.

Our lawyers told us otherwise. Regardless of the answer here, the fact that there's still a debate about what basic functionality requires a cookie banner is really a testament to how bad this legislation is. How long has this been around, 20 years? And there's still widespread debate and lack of understanding as to what specific functionality requires a cookie banner?

> How long has this been around, 20 years? No. It took effect in 2018.

Cookies banner are a response to the ePrivacy directive from 2002.

Re: Dear Paul Graham, there is no cookie banner law

#264
post #133

He's not saying there is though? The "cookie law" is 14 years old now, and it looks like the proverbial Brussels effect failed to change how the whole industry operates, except we now have cookie banners.

Customers are more informed. Savvy companies now only do essential tracking, so don't have to bother users. Or at least more will as enforcement catches on.

Re: Dear Paul Graham, there is no cookie banner law

#265
post #254
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

I don’t think this is strictly accurate. There’s nothing about cookies themselves that makes them a problem. It’s the way they are used. Needing to inform people you are using cookies for sessions is like needing to inform people you are using a fork to eat. The problem is that some people are using the fork to stab people, so now we require everyone to say how they’re going to use it in advance. Instead of just proh…

You don't need a cookie banner for session cookie, not in eprivacy nor in gdpr, same applies for all cookies that are "strictly necessary" for the functionnal operation of the website on the technical level. Language selection cookie, "remember me" cookie, etc ... Are all perfectly fine.

Re: Dear Paul Graham, there is no cookie banner law

#266
> What the EU is saying, you need my consent when you want to track me, profile me and sell my behavior off to ad companies.

Huh. I always thought that as soon as you use a long-term cookie that could technically be used for tracking, you have to get permission.

Which also means you have to get permission when someone logs in to your website. Though I guess the act of logging in could be seen as giving permission.

Anyway: I don't add cookie banners on my websites, and I don't use any tracking.

Re: Dear Paul Graham, there is no cookie banner law

#267
post #244

Earlier quoted context omitted.

Using your analogy, I think what ends up happening is that even companies that don't collect hidden fees will put up a banner just in case. Not only that, I'm not an EU citizen and I'm not browsing websites based in EU but I'm still bombarded with cookie banners non-stop.

Just been in Europe last week (I live in US): you have no idea what a nightmare internet is in Europe. You are only seeing a side effect here.

It's crazy how censored the internet is too, you need a VPN to access even piracy adjacent sites in Germany. Unheard of that an ISP would block a website in the US without the FBI itself taking it down.

Re: Dear Paul Graham, there is no cookie banner law

#268
post #207

Earlier quoted context omitted.

Then there isn't cookie law?

If there are exceptions to copyright such as fair use, does that mean that there is no copyright law?

The context was very specific in this case. Like you are always required to present a banner when you use a cookie. But that is not the case.

Re: Dear Paul Graham, there is no cookie banner law

#269

Earlier quoted context omitted.

As far as I can tell, politicians don't spend much if any time thinking about second and third order consequences. GDPR is but one example, but instances of this abound. The default should be to mistrust new laws. Reagan takes lots of flak on the internet, but he was right on the scariest phrase being "I'm from the government, and I'm here to help". Even worse, this thread is full of armchair lawyers that will confid…

> Even worse, this thread is full of armchair lawyers that will confidently tell you there's no need for cookie banners in particular cases. Nevermind that there's hardly any case law about this and each country seems to interpret it differently. Any actual lawyer would tell you to slap it on there to stay protected. I bet the number of cases of illegal implementations due to insufficient consent are vastly smaller t…

> Any actual lawyer would tell you to slap it on there to stay protected.

Presumably, lawyers err on the side of caution? That doesn't mean they're right.

Re: Dear Paul Graham, there is no cookie banner law

#270
> just listen to “Do Not Track” headers (it’s deprecated because companies did hate this)

It was my understanding that it is deprecated because it was completely disregarded and thus gave a false sense of safety from tracking and it was used by tracking company to do additional tracking.

Post reply on HN