Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

31–40 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#31
post #5

This is like a case study of well-intentioned, carefully designed regulation doing more harm than good. Honestly, I'd rather just have a browser addin that blocks the cookies I don't want. The market was working fine. Now every new website is a pain, and my organization has hired some amiable lady to be "GDPR expert". She doesn't appear to know anything about anything, but she sure seems nice.

GDPR absolutely does not do "more harm than good". It extends well, well beyond these dumb cookie warnings. GDPR puts the citizen/customer in power of their own data. They can ask for their data, they can ask for it to be deleted, they have (however shitty the UX) control over where it goes. They can contact large corporations and request these things and be heard out . I don't know how to explain it any other way: T…

I like the spirit of GDPR. I think it is important.

It also doesn't matter if people aren't educated and don't care.... or simply don't care if they are educated.

It's not clear to me that any progress has been made by GDPR in those areas.

Re: Cookie Warning Shenanigans Have Got to Stop

#32
It's time GDPR is actually enforced. I tried to get my country's law enforcement on the tail of some violators but they're toothless.

I don't understand the downvotes though, are you disagreeing that certain countries do not have the manpower to enforce GDPR to the extent they could? Please.

Re: Cookie Warning Shenanigans Have Got to Stop

#33
post #12

I feel like GDPR and such had some good spirit to it... but the result isn't what they had in mind and the consumers just click through everything / have no more clue. Piling on or malforming GDPR seems like it would just make the already unworkable situation more of a mess. I like the "ideas" behind GDPR, it's just this isn't the way to do it and really accomplish anything that really helps an individual.

I wonder how often we'll repeat the error of treating user privacy as something the user cares deeply about (against all this observable evidence to the contrary) before we accept that the well-demonstrated-and-documented default is users do not care (and if we want the behavior of websites to change, step 1 is educating users as to why they should care and what the risk models are).

I mean, for the average person, it's pretty rational not to care. The only result they see from tracking is seeing more relevant ads. 99.99% of people for the foreseeable future will not have a bad experience from commercial tracking (that they wouldn't have from non-tracked ads anyway).

Re: Cookie Warning Shenanigans Have Got to Stop

#34

As a web developer I gotta say the only true solution to this is to stop using the internet altogether. Might as well shut the internet down. We can't authenticate you without cookies or some other form of identification, so that throws out any site with an account. Even if I am not even remotely interested in tracking what pages you view on my website if I need to have you login and authenticate I need some form of…

While I'm certainly not going to argue in favor of the GDPR, the "cooking warning" actually specifically excludes cookies used for things like authentication. It covers cookies used for other purposes, such as trackers.

Re: Cookie Warning Shenanigans Have Got to Stop

#35

As a web developer I gotta say the only true solution to this is to stop using the internet altogether. Might as well shut the internet down. We can't authenticate you without cookies or some other form of identification, so that throws out any site with an account. Even if I am not even remotely interested in tracking what pages you view on my website if I need to have you login and authenticate I need some form of…

As I'm sure you'll be told by the time I finish writing this comment: authentication cookies do not need a compliance banner.

Re: Cookie Warning Shenanigans Have Got to Stop

#36
post #14

Earlier quoted context omitted.

Of course you have a choice, but in reality who leaves a site because they see that warning? I imagine almost no one. Hell, I understand the implications and I don't care because site X has what I'm after and perhaps no one else does (or they all have the same warning anyway.) I have no reasonable option but to accept whatever these sites want. The warnings accomplish nothing. It's just another nag screen. It was a b…

... and users appear to disagree on whether there's a wound to seal.

It's difficult for the average person to understand the long term implications of this sort of data collection. They don't realize how powerful all these little details can be when put together.

Re: Cookie Warning Shenanigans Have Got to Stop

#37
post #16
post #13

Earlier quoted context omitted.

That's how the GDPR works - unless the data being collected is required for the operation of the service, you cannot make data collection a requirement of using the service.

What if the ads are required for the operation of the website, because without them the site has to close? People are rarely willing to pay for big sites, they surely won't pay for many small sites separately. Smaller sites don't have the resources to curate their own ads, that's why they use ad networks. If we are strict about this then this rule will eliminate small sites while tightening the grip of the big sites…

My understanding is that something being 'required for product to function' refers to technical requirements, not revenue requirements. So, yes I agree that it's a problem for small sites (or really anyone who tries to make money on ads).

Re: Cookie Warning Shenanigans Have Got to Stop

#38
FTA he's quoting:

> And the Dutch DPA’s guidance makes it clear internet visitors must be asked for permission in advance for any tracking software to be placed — such as third-party tracking cookies; tracking pixels; and browser fingerprinting tech — and that that permission must be freely obtained. Ergo, a free choice must be offered.

Neither cookies, nor tracking pixels, nor browser fingerprinting are software. Your web browser is software. The server side runs software. These are data.

It seems pedantic, but I think it shows that the lawmakers have an underlying misunderstanding of how tech (and the world) works.

To make an analogy, cookies and tracking pixels are akin to license plates. I think the authors of this law thought they were more like cellular GPS beacons.

It's one thing to say, "no installing a device which actively communicates home on your visitors". It's quite another to say, "No remembering your visitor's face unless they tell you it's ok."

Re: Cookie Warning Shenanigans Have Got to Stop

#39
post #31

Earlier quoted context omitted.

GDPR absolutely does not do "more harm than good". It extends well, well beyond these dumb cookie warnings. GDPR puts the citizen/customer in power of their own data. They can ask for their data, they can ask for it to be deleted, they have (however shitty the UX) control over where it goes. They can contact large corporations and request these things and be heard out . I don't know how to explain it any other way: T…

I like the spirit of GDPR. I think it is important. It also doesn't matter if people aren't educated and don't care.... or simply don't care if they are educated. It's not clear to me that any progress has been made by GDPR in those areas.

Recently a company I trust was sold to a company I utterly dislike and have zero trust in.

Before the sale was executed, as a EU citizen I was informed that my consent was required for the transfer of my personal data to the new owners.

I did not consent. My data is not in the hands of the new owners. And under GDPR, I was able to request all the data they had on myself in order to make an archive of it before the execution of the sale.

None of this was possible a year ago. Know your rights, use them, you'll get to appreciate them.

Re: Cookie Warning Shenanigans Have Got to Stop

#40
post #16
post #13

Earlier quoted context omitted.

That's how the GDPR works - unless the data being collected is required for the operation of the service, you cannot make data collection a requirement of using the service.

What if the ads are required for the operation of the website, because without them the site has to close? People are rarely willing to pay for big sites, they surely won't pay for many small sites separately. Smaller sites don't have the resources to curate their own ads, that's why they use ad networks. If we are strict about this then this rule will eliminate small sites while tightening the grip of the big sites…

Advertisement doesn't require profiling and surveillance. That is what GDPR and other efforts like some ad blockers are trying to protect against. The emerging consensus is surveillance capitalism is unethical and increasingly illegal.
Post reply on HN