Live data from Hacker News

Europe's war on cookies

wired.co.uk

31–38 of 38 posts

Re: Europe's war on cookies

#31
post #24

Earlier quoted context omitted.

> It's reminiscent of secret police behaviour with their networks of informants That's a bit of a stretch. Also I don't believe the vast majority of people care about an organisation generating a profile of your interests, otherwise services like GMail and Facebook would have failed.

Right, I agree that this 'secret police' comparison is off. But your Facebook/GMail comparison is different as well: They are not useful/popular because of user tracking, they provide us with a free and (limited..?) useful service. I'd argue that's a bad thing as well, but I'd separate multiple levels of evil tracking: 1) You track me to sell my data and to profit from the ads. I gain nothing (you might be very lucky…

> You track me to sell my data and to profit from the ads. I gain nothing

Sure you do; you get to use Gmail and Facebook for free because they generate enough money from ads not to have to charge.

I can understand that there people like yourself that don't want to be tracked, that's cool, but if the majority of people don't care, should the system at least be opt-out? Or left up to the user to use the do-not-track features of browsers?

I'm not saying tracking must be forced on everyone, but this piece of legislation seems like a massive hammer to hit a very tiny nail.

Re: Europe's war on cookies

#32
post #28

One thing I don't get is how a site-owner is meant to know what cookies a 3rd party may send. If I add a Facebook "like" button to my site, does FB send a cookie? What if they don't now but decide to later. And if FB does decide to use cookies down the line, how do they ask your opt-in? You can send cookies with any HTTP reply, so how do you know if that image you are hot-linking from a 3rd party site doesn't send ba…

This seems to be pretty hazy. The ICO report says we would advise anyone whose website allows or uses third party cookies to make sure that they are doing everything they can to get the right information to users and that they are allowing users to make informed choices about what is stored on their device.

Re: Europe's war on cookies

#33
post #31

Earlier quoted context omitted.

Right, I agree that this 'secret police' comparison is off. But your Facebook/GMail comparison is different as well: They are not useful/popular because of user tracking, they provide us with a free and (limited..?) useful service. I'd argue that's a bad thing as well, but I'd separate multiple levels of evil tracking: 1) You track me to sell my data and to profit from the ads. I gain nothing (you might be very lucky…

> You track me to sell my data and to profit from the ads. I gain nothing Sure you do; you get to use Gmail and Facebook for free because they generate enough money from ads not to have to charge. I can understand that there people like yourself that don't want to be tracked, that's cool, but if the majority of people don't care, should the system at least be opt-out? Or left up to the user to use the do-not-track fe…

You didn't understand my post. Might be completely my fault though, so let me add one last remark:

I presented two tracking reasons/models. You quote my model 1), which is about user tracking for your own sake only, without giving something in return. In other words: There's no direct connection between you selling out what you collect about me and my usage.

You talk about GMail/Facebook, which I presented as another, different example/model, 2). The quote does not apply here.

For these services I trade privacy for usage and I merely wish that the trade would be more transparent so that everyone and his mom can decide if they want to give up these details for your service or not. But - it's at least a "deal" of some sort: You give me something valuable/useful, I have to cope with your privacy invasion.

Re: Europe's war on cookies

#34
post #21

I see this also covers the use of Flash cookies, but I wonder about the use of Etags as a tracking mechanism. If I recall correctly, some of these sites use cookies, Flash cookies and also unique Etags on an object in the browser cache to try to work around people blocking cookies from their domains.

Any technology causes client machines to store information for later access are within the scope of the law. The exact wording is a person shall not store or gain access to information stored, in the terminal equipment of a subscriber or user unless the requirements ... are met.

OK - that's great.

In practical terms though, all they're storing is a key. The actual data is held elsewhere. In the same way, an entity tag on a cached object is like a key to identify whether the object has been modified on the server since the last time it was sent.

How would it be possible to spot that it was being used for tracking a user rather than just part of the normal functioning of the browser?

Re: Europe's war on cookies

#35
post #31

Earlier quoted context omitted.

> You track me to sell my data and to profit from the ads. I gain nothing Sure you do; you get to use Gmail and Facebook for free because they generate enough money from ads not to have to charge. I can understand that there people like yourself that don't want to be tracked, that's cool, but if the majority of people don't care, should the system at least be opt-out? Or left up to the user to use the do-not-track fe…

You didn't understand my post. Might be completely my fault though, so let me add one last remark: I presented two tracking reasons/models. You quote my model 1), which is about user tracking for your own sake only, without giving something in return. In other words: There's no direct connection between you selling out what you collect about me and my usage. You talk about GMail/Facebook, which I presented as another…

Ah sorry I see your distinction, I misread model 2), thought you were referring to gmail/facebook in model 1).

Yeah if a company is tracking me which results in me gaining nothing and them gaining income, that is quite annoying, I'm not disagreeing that in that case it's wrong. But I still don't think you are harmed in a way that requires such a sweeping piece of legislation. These sorts of rules may land up harming the free services you refer to in model 2).

If there was a way to target just the companies in model 1) without interferring too much in the user experience of all web-users, I'd be for it.

Re: Europe's war on cookies

#36
post #21

Earlier quoted context omitted.

Any technology causes client machines to store information for later access are within the scope of the law. The exact wording is a person shall not store or gain access to information stored, in the terminal equipment of a subscriber or user unless the requirements ... are met.

OK - that's great. In practical terms though, all they're storing is a key. The actual data is held elsewhere. In the same way, an entity tag on a cached object is like a key to identify whether the object has been modified on the server since the last time it was sent. How would it be possible to spot that it was being used for tracking a user rather than just part of the normal functioning of the browser?

That's really an enforcement problem, not a legislative problem.

Even so, I think the answer is clear: it depends on whether you store data that permits you to infer privacy-intruding things about the user. If you store a cookie that just encodes preferences and you store no persistent data about the cookie on your side, you should be fine. It's the making a relationship between client local state and your customer profiles that's key.

Re: Europe's war on cookies

#37
post #3

The UK Information Commissioner's report on the coming legislation: http://www.ico.gov.uk/~/media/documents/library/Privacy_and_... There is no requirement to ask for permission to issue cookies if the cookies are "strictly necessary" for the task, such as for logging into a user account or using a one-click -style purchase. I have the impression that it will principally affect user-tracking systems like Google Analy…

Page 4, section "What will happen to me if I don’t do anything?": > In light of this if the ICO were to receive a complaint about a website, we would expect an organisation's response to set out how they have considered the points above and that they have a realistic plan to achieve compliance. So basically compliance isn't required, just a plan to achieve compliance. "Our realistic plan is to implement an invasive p…

I interpreted that as describing their response to the first raising of a complaint, not a limit on the measures ultimately available to them.

Re: Europe's war on cookies

#38
post #8

> Traditionally, the US and the UK have taken a more relaxed approach to privacy. But the legislative and interventionist tendencies of Europe -- and of France and Germany in particular Now, this is the first time in a decade that I couldn't avoid a smug face and tiny bit of affection formy home country.. Seriously: As others pointed out here, this is a targeted law against privacy breaches. If your company builds it…

What's wrong with advertising geared towards your interests? Or do you enjoy watching ads on penis enlargements, gambling, whitening teeth and How To Get Rich While Sleeping?

For me, informed consent is the issue here. If I sign up for your website and then log in, I think it's probably fair game to target things to them. In fact, that's generally the point.

My real world analogy is an invisible store employee following you around, helping you shop, but also writing down every movement you make, and every conversation you have.

It's more than a little creepy if they do it without asking.

Post reply on HN