Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

281–290 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#281
post #40

Earlier quoted context omitted.

> Almost all websites make money through ads The EU regulation does not prevent ads from being shown, it specifically targets tracking. No tracking > no banner > everyone is happier > go ahead and show all the ads that are required.

And all that tracking comes down with inability to take risk on business side. Ad company wants to be 100% sure that ads are shown to humans, and pay only for those shown to humans(going deeper - to specific cohorts of humans, which in the past was approximated by content of the site showing ads). Whereas sites serving ads want to extract as much money as it is possible from advertisers based on their audience count.…

Well said. It's frustrating seeing people earnestly pretending as if the 'solution' we're living with now is any kind of improvement.

Re: Dear Paul Graham, there is no cookie banner law

#282
post #205

Earlier quoted context omitted.

> Not sure why it makes sense to complain about the EU and not the companies. Unfortunately a non-negligible number of people in tech also have libertarian leanings, with a default “gubmint bad!” position, which makes them easy prey for adtech propaganda.

> Unfortunately a non-negligible number of people in tech also have libertarian leanings Why is this unfortunate? Because you don't agree with us? The "they would agree with me if they were smarter" trope is tired and gets us nowhere.

> Why is this unfortunate?

GP answered your question, for some reason you decided to cut the quote right before the answer. Here is the part that is missing from your quote which answers your question: '[...]with a default “gubmint bad!” position'

Re: Dear Paul Graham, there is no cookie banner law

#283
post #127

Earlier quoted context omitted.

Do you have /any/ examples of websites that don't have a bunch of 3rd party cookies that still have a cookie banner? Middle managers absolutely love anything with charts and graphs because it makes their decisions feel more scientific. That's why they want tracking software included on their websites. And if the law requires disclosure then a cookie popup is the solution.

My company recently announced a game, and we launched a website for the game. There's no ̶t̶h̶i̶r̶d̶ ̶p̶a̶r̶t̶y̶ e:tracking cookies (I didn't make the site, but I do run it). Our US based legal team told us we needed a cookie banner if we were going to have visitors in the EU. I pushed back, but I lost, and ultimately it's not my fight.

Thanks for this, it seems a lot of cookie popups are there just due to cargo culting

Re: Dear Paul Graham, there is no cookie banner law

#284
post #72

Earlier quoted context omitted.

> Almost all websites make money through ads, Doesn't require tracking of individuals. > or at least keep logs of user activity to help them optimize their website Doesn't require tracking of individuals.

Correct me if I'm wrong, aren't but IP addresses are considered to be "personal information" and therefore collecting them is "tracking" under the GDPR?

My guess is that they are because ISPs may keep records of them—I think they are required to in some jurisdictions. But you don't have to store IPs in your server logs.

Re: Dear Paul Graham, there is no cookie banner law

#285

Earlier quoted context omitted.

(author here) I'm a fan of second-order thinking and unintended consequences, so I'm with you there. How would you frame a "don't track people without consent" without unintended consequences? The article tries to make the point (perhaps fails), that companies do this intentionally to get the "consent" of people against their will, therefor running the tight line of breaking the law without breaking it.

Fines for data breaches is one idea? If we want to disincentivize data hoarding, the main cost to data hoarding is data breaches, so we could perhaps penalize that. This would have a different issue, specifically companies would no longer self-report data breaches, but it's just an idea. There are alternative approaches to getting to "don't track people without consent" that aren't a toothless stick by making it more…

Here's my idea - no data collection without compensation. For example, you must pay me in advance 1 cent for the permission to access 1 byte of my personally identifiable information for the following month, whether that's stored in a cookie or in your own database or you access it via a third party (e.g. Meta). So instead of a "cookie consent" pop-up, I want a "cookie payment" pop up where the site will ask me for my payment details and say how much they'll pay me (again, in advance) for each of the options I can toggle.

Re: Dear Paul Graham, there is no cookie banner law

#286
At one company where I worked the head of legal and the compliance officer scheduled a meeting with me[1] without any notice. I showed up and it turns out they wanted to know why we didn't have a cookie banner. I explained we didn't have any cookies.

They insisted we implement a cookie banner which would set a cookie to say whether or not you had accepted cookies. This was the only cookie.

[1] Never a good sign when legal and compliance just book a meeting with you like that and you don't know any normal context.

Re: Dear Paul Graham, there is no cookie banner law

#287
A personal anecdote: I was charged with adding a cookie banner to my company’s website after having successfully resisted having one for many years. The reason given to me by the new owners of the business being that the marketing department wanted to try some new stuff, and the lawyers told them that it required consent on the part of our users. I was also told that I shouldn’t spend a lot of time on this, and to therefore use an off-the-shelf product (OneTrust), and to not customize it any way. When I remarked that the default texts for the banner sounded very scary and implied that we did a lot of things that we weren’t actually doing, I was told to leave them unchanged, because we had to assume that they had been vetted by (OneTrust’s) lawyers, and that it would be too legally risky to change them. My argument that OneTrust’s offering was a one size fits all that had to be compliant with the sleaziest, most ad-tech compromised media sites out there, but that we were not that, failed to make an impression.

A couple of observations:

1. Players like OneTrust and the consultants who specialize in this, are highly incentivized to play up the risks of not being compliant. My layman’s estimation of the legal risks is that the risk for good faith actors is actually pretty low. If the authorities find that you are not in compliance, you will most likely get a chance to rectify this, and possibly a slap on the wrist. Those scary fines measured in percent of global revenue, is not going to be what you face for an honest mistake.

2. Those businesses that rely on invasive tracking, and therefore really must use these banners, benefit from everyone else mistakingly believing that they too must compromise their UX with these banners. It makes what they do seem normal and acceptable.

Re: Dear Paul Graham, there is no cookie banner law

#288

Earlier quoted context omitted.

The fact that companies are doing that says more about the bad law than the companies which is exactly Paul Graham's point.

what a ridiculous point of view. do you think the same thing about laws against murder? about fraud?

I've got to admit, I'm unclear what the equivalent of a cookie banner for murder would be.

This criminal uses murder! If you continue to interact, you consent to being murdered.

Murders you anyway

Re: Dear Paul Graham, there is no cookie banner law

#289
post #254
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

I don’t think this is strictly accurate. There’s nothing about cookies themselves that makes them a problem. It’s the way they are used. Needing to inform people you are using cookies for sessions is like needing to inform people you are using a fork to eat. The problem is that some people are using the fork to stab people, so now we require everyone to say how they’re going to use it in advance. Instead of just proh…

See for example GitHub's statement [1] about no longer displaying a cookie banner. While ironically the blog still does display them, the main site doesn't.

[1] https://github.blog/2020-12-17-no-cookie-for-you/

Post reply on HN