Live data from Hacker News

No Cookie for You

github.blog

281–290 of 634 posts

Re: No Cookie for You

#281
post #203

Earlier quoted context omitted.

The cookie banner is NOT regulated by the GDPR. It's related to the ePrivacy Directive, which is deeply intertwined with GDPR but a separate piece of legislation. It's not clear whether the GDPR's territorial applicability also holds for ePD. France in particular is drawing a divide between GDPR and ePD, because ePD lets them fine Google directly but GDPR require they mediate through the Irish DPA.

The "cookie law" as part of the ePD is indeed older than the GDPR, but the GDPR kinda supersedes it by including all tracking/data collection not just cookie data collection. It's also not entirely correct that the GDPR would require going through the Irish DPA or wherever a company in violation has their primary EU presence for tax purposes. True, the GDPR says the nation where a company has the primary presence of…

Alright, so this gets in the weeds.

GDPR does not supercede the ePD. The ePD is, according to its own text, a law that extends the general privacy regulations to certain aspects of internet technology. So in many cases it defers out to the general privacy law in effect.

When ePD was passed, that law was the DPD, Data Privacy Directive. When GDPR was passed, all ePD references to the DPD became references to GDPR instead (this is Article 94 of GDPR). But ePD remains entirely in effect, just with updated references.

Most importantly, ePD requires Consent in certain cases, but defers to DPD/GDPR for what is the definition of consent. GDPR's definition of consent is much more stringent.

In cases where the ePD did not refer out to DPD, it remains unchanged by the passage of GDPR. So, according to CNIL, it does not include the one-stop-shop mechanism. See section "The competence of the CNIL" in the link below:

https://www.cnil.fr/en/cookies-financial-penalties-60-millio...

Re: No Cookie for You

#283
post #78

Earlier quoted context omitted.

“And we would rather not have this crap but nobody pays for content are there only two types of ad networks: privacy preserving and paying so we’re stuck. Please call your congressperson to complain [here].”

I'm confused.... AFAIK the biggest ad company, Google, doesn't share your private info. It's not in their interest to do so. Instead they keep it to themselves and then offer ads by categories so as a 3rd party I can say "Please target this ad at 'video game players'" but I can't ask "give me the names of video game players"

Google is the company that your info gets shared with.

Google being the biggest ad company does not give them the right to surveil all that walks the earth.

Re: No Cookie for You

#284

I hate the standard wording on Cookie banners. Most of them should read: "The site uses cookies. Actually it doesn't - you are not logged on and we don't need to maintain state. But our advertising partners, their partners, and their partner's partners all love to set tracking cookies. Click here to consent to three dozen cookies from around the globe."

Good lord, everyone needs banners and popups? Why not just let browsers controls who sets what cookies? I'm tired the endless cookie popups, can we come up with an "allow cookies if the browser accepts them" standard as long as that guarantees no cookie popups? Then browser vendors can ship a delete all non same origin cookies on tab close or something.

> Why not just let browsers controls who sets what cookies?

Because it doesn't have anything to do with cookies. You don't need a banner if you use CSRF cookies, you don't need a banner if you use them for stuff like CloudFlare's anti-DDoS script, and you certainly don't need a banner if your site requires cookies for basic functionality like logging in.

The browser can't possibly tell what the server is doing with its cookies. It might even be using a single cookie as CSRF protection and ad tracking at the same time.

Re: No Cookie for You

#285

Earlier quoted context omitted.

My favorite of the week: Doordash. Doordash does not use two-factor authentication, except for one thing: opting out of having your data sold. For that, it sends an SMS message to your phone. Since I signed up for them using a landline, the SMS message is lost.

Its a shame the EU became laser focused on cookies, which can be managed technically by browser settings, and not on dark patterns like these. Or how US consumers complain about being able to subscribe to a service via the web but must call a customer service person to cancel, often with a lengthy wait, dropped calls, and being transferred to a sometimes rude 'retention specialist.' There's so much more pressing than…

Contrary to popular belief, GDPR has nothing to do with cookies and isn't even about the web specifically. It is - as it says right in the name - a General Data Protection Regulation.

The very long and well-sourced wikipedia article doesn't even contain the word "cookie": https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

Re: No Cookie for You

#286

Earlier quoted context omitted.

My favorite of the week: Doordash. Doordash does not use two-factor authentication, except for one thing: opting out of having your data sold. For that, it sends an SMS message to your phone. Since I signed up for them using a landline, the SMS message is lost.

Its a shame the EU became laser focused on cookies, which can be managed technically by browser settings, and not on dark patterns like these. Or how US consumers complain about being able to subscribe to a service via the web but must call a customer service person to cancel, often with a lengthy wait, dropped calls, and being transferred to a sometimes rude 'retention specialist.' There's so much more pressing than…

Oh man this makes my blood boil, another reason ill never thouch MS again is they they removed the cancel xbox live subscription button for NZ subscribers and I assume other locales where they didnt have some law forbidding it, the feature to cancel was there but they decided if they could to hold you hostage and made you call and waste lots of time via as painfull process as possible to cancel

Re: No Cookie for You

#287

I hate the standard wording on Cookie banners. Most of them should read: "The site uses cookies. Actually it doesn't - you are not logged on and we don't need to maintain state. But our advertising partners, their partners, and their partner's partners all love to set tracking cookies. Click here to consent to three dozen cookies from around the globe."

You sound like the guy who wrote this: "We're not going to lie to you. Your privacy isn't our priority. It's not even close. Not because we want to track your every move. But because we simply don't care. We'd rather spend what limited time we have actually improving the web site. We're into taking pictures and adding content, not obsessing over what your dog had for lunch so we can sell it to MegaEnormousBigCo. We'r…

The last sentence is the key part. I could respond in kind: No one cares if you care or not. We only care about the people who are willing to buy that stuff from you.

Re: No Cookie for You

#288

I hate the standard wording on Cookie banners. Most of them should read: "The site uses cookies. Actually it doesn't - you are not logged on and we don't need to maintain state. But our advertising partners, their partners, and their partner's partners all love to set tracking cookies. Click here to consent to three dozen cookies from around the globe."

Good lord, everyone needs banners and popups? Why not just let browsers controls who sets what cookies? I'm tired the endless cookie popups, can we come up with an "allow cookies if the browser accepts them" standard as long as that guarantees no cookie popups? Then browser vendors can ship a delete all non same origin cookies on tab close or something.

At least it raises awareness on how tracked we are.

Re: No Cookie for You

#289

I hate the standard wording on Cookie banners. Most of them should read: "The site uses cookies. Actually it doesn't - you are not logged on and we don't need to maintain state. But our advertising partners, their partners, and their partner's partners all love to set tracking cookies. Click here to consent to three dozen cookies from around the globe."

You sound like the guy who wrote this: "We're not going to lie to you. Your privacy isn't our priority. It's not even close. Not because we want to track your every move. But because we simply don't care. We'd rather spend what limited time we have actually improving the web site. We're into taking pictures and adding content, not obsessing over what your dog had for lunch so we can sell it to MegaEnormousBigCo. We'r…

The thing is, that's bullshit.

Here's the other perspective: Data brokers don't really want your data if you don't want them to have it. It's a legal liability for them, and most of them are struggling to work at the scale their customers demand already. But publishers want high advertising rates and that means advertisers want to make good bids and that means both actually want a data broker involved to deal with the technical (collection, filtering, aggregation, ETL) and legal (GDPR) bullshit.

But then publishers and advertisers don't do their due diligence or decent engineering and just shovel illegal shit to data brokers on the backend. The ones that shut up and launder it do well; the ones that actually try to do a good (technical, legal) job drown in account management and data processing overhead.

So fuck that site. They are the ones that care about your data, they're just making a show of keeping their hands clean while they pay someone else for the dirty work and hiding behind their (half willful half stupid) ignorance of how their own industry works.

Re: No Cookie for You

#290

Earlier quoted context omitted.

Does anyone happen to know of a service like this that is free (not self hosted) for non-commercial, low-traffic sites? Or which costs less than ~$10 per year. I have a basic Github Pages site, and I currently don't know whether anyone is looking at it, beyond the very few who take the time to email me. I don't need (or want) to know anything about my visitors, but it would be nice to know that I'm not simply tossing…

Few years back I created some HelloWorld application on Google's AppEngine (requires Java, Python or Go) and was positively surprised about its statistics on theirs dashboard.

I was also surprised but the number of different dumb bots that had tried to brute-force our app engine site on /wp-login.php

and it wasn't even running on wordpress

Post reply on HN