Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

301–310 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#301

Earlier quoted context omitted.

> Not sure why it makes sense to complain about the EU and not the companies. Unfortunately a non-negligible number of people in tech also have libertarian leanings, with a default “gubmint bad!” position, which makes them easy prey for adtech propaganda.

That's beside the point. If you are in favour of government intervention you should be all the more interested in good policies that have the intended effect. Bad laws boost libertarianism.

Also, lying about good laws boosts libertarianism.

At least until you realise what they're doing, then you think they're skeevy corporate toadies with no morals.

Re: Dear Paul Graham, there is no cookie banner law

#302
post #265
post #254

Earlier quoted context omitted.

I don’t think this is strictly accurate. There’s nothing about cookies themselves that makes them a problem. It’s the way they are used. Needing to inform people you are using cookies for sessions is like needing to inform people you are using a fork to eat. The problem is that some people are using the fork to stab people, so now we require everyone to say how they’re going to use it in advance. Instead of just proh…

You don't need a cookie banner for session cookie, not in eprivacy nor in gdpr, same applies for all cookies that are "strictly necessary" for the functionnal operation of the website on the technical level. Language selection cookie, "remember me" cookie, etc ... Are all perfectly fine.

I’ve often wondered if necessary cookies could just be carved out and designed (and named) differently to improve handling. You could then just configure your browser to inherently accept the benign from a site, which would then only ask for non-essential ones.

The real nirvana, IMO, would be better sandboxing between sites.

Re: Dear Paul Graham, there is no cookie banner law

#303
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

This is a bad example because the market usually fixes this problem. The reason why the market doesn’t fix the cookie banner problem and the reason why this is bad law is because users defacto do not care, it is merely annoying.

There’s a law in California that says that businesses which have chemicals that might cause cancer on the premises need to let people know. That’s great but the levels they set turn out to be lower than what you can feasibly test for and as a result all properties pretty much just put up the signs that say “there might be chemicals here”. The warning is useless and annoying because of market forces which is another way of saying the law incentivized the behavior that occurred.

Re: Dear Paul Graham, there is no cookie banner law

#304
post #205

Earlier quoted context omitted.

> Unfortunately a non-negligible number of people in tech also have libertarian leanings Why is this unfortunate? Because you don't agree with us? The "they would agree with me if they were smarter" trope is tired and gets us nowhere.

> Why is this unfortunate? GP answered your question, for some reason you decided to cut the quote right before the answer. Here is the part that is missing from your quote which answers your question: '[...]with a default “gubmint bad!” position'

Pretty clearly implying the diminished mental capacity which prevents us from agreeing with him, no? I addressed this above:

> The "they would agree with me if they were smarter" trope is tired and gets us nowhere.

Re: Dear Paul Graham, there is no cookie banner law

#305
post #121
post #79

Earlier quoted context omitted.

This is 100% what PG means IMO and the most sane take on this. Either write the law correctly so it's not easily bypassed or just don't touch anything because you will only make it worse.

The law is not bypassed, the annoying banners with no simple option to reject are illegal . The issue is that enforcement is slow, not that the law is badly written. GDPR's Article 7 [0] is very clear: > 3. The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving con…

Yes, that very much is an example of the law being badly written.

"Prior to giving consent, the data subject shall be informed thereof."

Means there must be some sort of a cookie notification (which could of course take a small space of the screen, but still).

The existence of this notification makes it easier to initially give consent. If withdrawing later is to be as easy, the notification must never disappear.

Re: Dear Paul Graham, there is no cookie banner law

#306
post #254
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

I don’t think this is strictly accurate. There’s nothing about cookies themselves that makes them a problem. It’s the way they are used. Needing to inform people you are using cookies for sessions is like needing to inform people you are using a fork to eat. The problem is that some people are using the fork to stab people, so now we require everyone to say how they’re going to use it in advance. Instead of just proh…

A few places allow you to opt for a spoon instead, or drink right from the bowl without utensils. Note that it's not the customers who use the forks for stabbing; it's the restaurants themselves. To show their goodwill to a customer who does not trust them with a fork, they can offer a spoon.

The further we take this analogy, the more strained it becomes.

Yes, it's natural to use a cookie to track a session; this is a mechanism invented for that purpose. It's much less natural to share this tracking information with third parties, especially along with a record of your purchases or other interesting actions.

But ad revenue is much harder to obtain without targeting and thus tracking. And a lot of places depend mostly on ad revenue.

This is another case of "buy now, pay later" pattern, stretched to "take for free now, pay in loss of your privacy later". In a funny enough way, many people don't value the information they get on many ad-supported sites as highly as the marketers paying to grab their attention, so simply compensating by adding a subscription or one-time payment to go ad-free sometimes does not even work; the more generic / "doom-scrollalbe" the content is, the worse it works.

Re: Dear Paul Graham, there is no cookie banner law

#307
post #72

Earlier quoted context omitted.

> Almost all websites make money through ads, Doesn't require tracking of individuals. > or at least keep logs of user activity to help them optimize their website Doesn't require tracking of individuals.

Correct me if I'm wrong, aren't but IP addresses are considered to be "personal information" and therefore collecting them is "tracking" under the GDPR?

Yes but it depends what you're doing with them as to whether you need consent. If you're keeping a record of my IP address and what I do on your site to sell me stuff then yes you're tracking me and need my consent for that. If you've got my IP address in your logs because you keep security logs for reasonable timeframes then you don't need my consent - though you do need to handle them appropriately because it's my personal data.

Re: Dear Paul Graham, there is no cookie banner law

#308
I think pg is talking about the advertising banners, and yes, congratulations EU you have ruined our web experience to the benefit of even-worse-tracking that mobile applications do.

I think the bigger issue here is that this law did not fix anything, destroyed what little EU online advertising business existed, and focused on the wrong thing. For starters, the european people did not ask for this law, they have bigger problems, it was campaigned by specific german interest groups for which most EU citizens are indiffernt. Ad tracking is/was not a concern for the vast majority of EU citizens (who , again were never asked about this law) . Internet and social media addiction, however, IS an issue that most citizens have, and the EU has spent so much energy and capital on this pointless cookie banners issue, that it doesnt have more to spend on solving the addiction issue. Premature legislation always does that, and the worst is, there will never be accountability for such wrong decisions. The people who inspired the legislation are not up in some kind of election, and the upcoming MEP elections have nothing to do with EU politics and everything to do with domestic politics (Show me a country where MEP election results are not considered a proxy for national elections).

But it doesnt matter how many times someone points the political misaligments , there is no mechanism to change that until something really grave happens, when it will be too late.

Re: Dear Paul Graham, there is no cookie banner law

#309

> Companies could easily avoid any cookie banner. Just don’t track. Well, then, the EU should've just made _this_ the law. And we'd have called it the "Just don't track" law. Rant & Details: > There is no law for cookie banners. > What the EU is saying, you need my consent when you want to track me, profile me and sell my behavior off to ad companies. > or “Look, Why take a chance?” (Remo Gaggi), This kinda proves PG…

> The law is reason people think "Look, Why take a chance?" and build crap like cookie banners in.

Really, no. Not being willing to let go of user tracking, and now realizing that it's against the law if you get it wrong, is why people think "Look, why take a chance?" and grasp for shitty dark patterns to cover their asses.

My business did not track its customers online and had no banner. Period.

Re: Dear Paul Graham, there is no cookie banner law

#310

This article just reminded me that I should always choose NO when asked. And that probably can be automated...

I've been running Consent-o-matic [1] in both Chrome and Firefox for quite a while now, which automates a lot of them. You can set your preferences for what categories of cookies you want to allow.

[1] https://github.com/cavi-au/Consent-O-Matic

Post reply on HN