Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

311–320 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#311

Hate this way of thinking where the government (with seemingly good intentions) tries to stop something but leaves a loophole where all our lives are made more tedious and then people defend it saying the companies should just not do it, well we needed the law in the first place so it's a bit silly thinking to suggest they stop doing it after the law, no?. If the cookie law was written properly then it would have jus…

As far as I can tell, politicians don't spend much if any time thinking about second and third order consequences. GDPR is but one example, but instances of this abound. The default should be to mistrust new laws. Reagan takes lots of flak on the internet, but he was right on the scariest phrase being "I'm from the government, and I'm here to help". Even worse, this thread is full of armchair lawyers that will confid…

Even worse, this thread is full of armchair lawyers

...

Any actual lawyer would tell you

Assuming you're not yourself a lawyer, doesn't speculating about what an actual lawyer would say or do make you an armchair lawyer?

Re: Dear Paul Graham, there is no cookie banner law

#312
post #199

Earlier quoted context omitted.

(author here) I'm a fan of second-order thinking and unintended consequences, so I'm with you there. How would you frame a "don't track people without consent" without unintended consequences? The article tries to make the point (perhaps fails), that companies do this intentionally to get the "consent" of people against their will, therefor running the tight line of breaking the law without breaking it.

The problems with the current law are: - no fines for non-compliance (or malicious compliance) - no legal liability for data leaks of PPI When businesses believe (correctly or incorrectly) that the benefit of tracking outweighs the cost (annoying users, regulatory noncompliance) they will do it. The fix is to make tracking too costly for businesses.

> - no fines for non-compliance (or malicious compliance)

"The Biggest GDPR Fines of 2023"

1. Meta – €1.2 billion (Ireland)

2. Meta – €390 million (Ireland)

3. TikTok – €345 million (Ireland)

4. Criteo – €40 million (France)

5. TikTok – €14.5 million (UK)

6. Axpo Italia Spa – €10 million (Italy)

7. Tim S.p.A. – €7.6 million (Italy)

8. WhatsApp – €5.5 million (Ireland)

9. EOS Matrix – €5.5 million (Croatia)

10. Clearview AI – €5.2 million (France)

"GDPR fines are designed to make non-compliance around data security a costly mistake and they can be separated into two tiers. Less severe infringements can result in a fine of €10 million or 2% of a firm’s annual revenue from the preceding financial year, depending on which amount is higher. More serious violations can result in a fine of up to €20 million or 4% of a firm’s annual revenue from the preceding year, depending on what is higher."

via https://www.eqs.com/compliance-blog/biggest-gdpr-fines/

Re: Dear Paul Graham, there is no cookie banner law

#313
post #134

Earlier quoted context omitted.

"Number of visitors" does not constitute tracking. The tracking in question here is to discover who you are specifically and the absurd amount of detail about your online activities collected and shared with data brokers for aggregation and resale. A few of these cookie prompts during the day and they'd be able to tell everything from where your kids go to school to the kind of prn you prefer to watch on weekdays and…

Honestly I don't mind them collecting this data, what is really infuriating is the fact they won't share it with me. I would love to know what kind of porn I prefer on weekdays. I think they shouldn't be allowed to track anything with consent or without it unless they share all the data with the subject of spying. And aside from that, I think it should be much more expensive to say sorry than ask for permission. In m…

I call BS. Give me your email password and your browser history and I'll share everything I learn about you with you. I'll also keep it and share it with whomever else I want to, but I'll definitely share it with you, too.

Re: Dear Paul Graham, there is no cookie banner law

#314

Earlier quoted context omitted.

I think the goal was to give citizens the possibility to make informed decisions about where their personal data is being used. If you don't care about tracking, ok. But some do. The EU tried to cater to both audiences which I think is fair. Turns out most people that did not care about tracking would also not consent when they are asked about it specifically and there are no immediately perceived downsides visible.

> informed decisions And therein lies the false premise that makes the whole thing absurd. Most people have no idea what "cookies" are, don't understand what difference it makes when you reject them, and are never going to learn - and we shouldn't expect them to! Leave the technical stuff for the programmers. The cookie law only makes sense if you think that there's any significant overlap between "people who underst…

There is no cookie law. There is a law that makes companies ask for consent when they share personal data or store identifiers that make this possible.

If companies wouldn't try to frame the whole thing in technicalities, it could be a simple popup listing the features on the website that need sharing personal info and users could turn that off.

Re: Dear Paul Graham, there is no cookie banner law

#315
post #203

Earlier quoted context omitted.

The blog clearly works from the actual outcome lense. It's repeated. Several times. The companies could just not track . The actual outcome is that they do want to track, and use adversarial patterns and malicious compliance to twist your arm and "force consent." Paul Graham is still wrong.

>The blog clearly works from the actual outcome lense. [...] The companies _could_ just not track. No, you've inadvertently stated a contradiction . Your use of the word _"could"_ is literally a hope/wish/intention of the law. In contrast, the actual outcome is that the companies didn't stop tracking. We _wish_ they would stop tracking. (I.e. "The companies _could_ just stop tracking us!") But that hope still doesn't…

The law is not code. Equating hope with the intention of the law is a poor way to think about it. The law is to protect users against opaque companies and to enable them making informed choices.

If companies act maliciously to contort around the law and force users back to making uninformed choices, it is the companies' fault and not the law's. Companies could have followed the interpretation of the law unobstrusively. But they didn't.

Invoking "reality," semanticking a position, do not make Graham's position justified. Neither does it make the blog wrong.

Re: Dear Paul Graham, there is no cookie banner law

#316

Earlier quoted context omitted.

Correct me if I'm wrong, aren't but IP addresses are considered to be "personal information" and therefore collecting them is "tracking" under the GDPR?

My guess is that they are because ISPs may keep records of them—I think they are required to in some jurisdictions. But you don't have to store IPs in your server logs.

You're also allowed to store IP addresses in your logs, you just have to take care with the data and the reason you're storing them needs to be justified - either because you have a legitimate interest in doing so (e.g. security) or because you have my explicit consent.

If I order something from an online shop, they don't need to have a banner in order to take my name and address to post the item to me - that's fully expected and reasonable. They do need my consent if they want to use that to post adverts to me though.

Re: Dear Paul Graham, there is no cookie banner law

#317

Earlier quoted context omitted.

Shopping carts and notification preferences don't require a consent banner.

Our lawyers told us otherwise. Regardless of the answer here, the fact that there's still a debate about what basic functionality requires a cookie banner is really a testament to how bad this legislation is. How long has this been around, 20 years? And there's still widespread debate and lack of understanding as to what specific functionality requires a cookie banner?

You can find a lot of guidelines around GDPR or ePrivacy made by the EDPB or a DPA. For instance:

https://ec.europa.eu/justice/article-29/documentation/opinio...

This says that cookies for a shopping cart or user preferences are exempted from consent. The ICO and the CNIL say the same, as expected.

Re: Dear Paul Graham, there is no cookie banner law

#318
I see a lot of comments about how it is some sort of an unforeseen second-order consequence. But it isn't. If you want to have no tracking, you write a law that nans tracking. If you write a law about mandatory notifications, bombardment of notifications is the most direct consequence one can imagine.

Re: Dear Paul Graham, there is no cookie banner law

#319
Both ideas are simplistic nonsense.

It's how we wish people worked, but it's not how people work. The area of people that actively care about being tracked is not equal to the area of people, that would say yes if you point blank ask them "do you want to be tracked?" (with all the fears that this question triggers), and it's not equal to the area of people who would actually be happy to give up the affordances that tracking allows for in their every day life, even if they really do not like to say "yes" when asked to be tracked.

All of this is compatible because, hi, this is us. We close our eyes, and pretend they are open. We love to not consider consequences, while thinking of ourselves as considerate. Well, not always. We do make "a few mistakes" every now and then, of course. This makes the whole thing believable, to ourselves and each other.

I understand that it makes for good internet banter to ignore all that but what else it is good for, I do not know.

Re: Dear Paul Graham, there is no cookie banner law

#320
post #70

>, Paul Graham came up with the thought, that the EU forces companies to have cookie banners. There is no law for cookie banners. [...] Companies could easily avoid any cookie banner. Just don’t track. KingOfCoders/amazingcto, of course you are technically correct but Paul Graham wasn't talking about the letter of the law. Instead, you have to interpret his complaint with the lens of game theory . I.e. The Law of Uni…

Everyone knows that bad actors will continue to behave badly in the face of the law. This isn't the insight you seem to think it is.

Really, PG's tweet has little to do with game theory or anything else. It is a first-world-problem whinge about having to click through cookie banners. Assessing the "actual outcome" of complex regulation and legislation is a task beyond the scope of a single tweet.

It might be useful for Graham to determine what claim he is trying to make in the first place. Is he rebutting a particular EU representative for boasting about how good they are at regulation? Or is the idea that the EU shouldn't have the audacity to attempt to regulate in the first place?

Post reply on HN