Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

321–330 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#321

Earlier quoted context omitted.

Agree. How much corporate propaganda are people consuming that legislators are seen as wholly responsible for the bad behavior and malicious compliance actions of corporations? What does it say about the relationship between businesses and consumers that the first response to this bad behavior is to shout "look what you made them do!" Seemingly it is everyone's fault except the bad actors themselves.

Many of us had no real problem with the ad-supported web in the first place. I was happy with the status quo. So yes, I do blame the government as I would be fine returning to the prior state.

"I would like website operators to assume that I consent to being tracked, so I'm annoyed that website operators are not allowed to assume that everybody consents to being tracked."

Re: Dear Paul Graham, there is no cookie banner law

#322
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

Agree. How much corporate propaganda are people consuming that legislators are seen as wholly responsible for the bad behavior and malicious compliance actions of corporations? What does it say about the relationship between businesses and consumers that the first response to this bad behavior is to shout "look what you made them do!" Seemingly it is everyone's fault except the bad actors themselves.

The funny thing is it's not just corporations. When you open the German state railways' website, somehow you get a GDPR overlay, When you open the German revenue agency's website, you get greeted by a cookie banner on top.

I call upon all German users of this website to write to their MPs! Obviously the German civil service is a bad actor! The German deep state is plotting to discredit our beloved eurocrats and must be shut down! Den Sumpf trockenlegen!

Re: Dear Paul Graham, there is no cookie banner law

#323
post #265

Earlier quoted context omitted.

You don't need a cookie banner for session cookie, not in eprivacy nor in gdpr, same applies for all cookies that are "strictly necessary" for the functionnal operation of the website on the technical level. Language selection cookie, "remember me" cookie, etc ... Are all perfectly fine.

I’ve often wondered if necessary cookies could just be carved out and designed (and named) differently to improve handling. You could then just configure your browser to inherently accept the benign from a site, which would then only ask for non-essential ones. The real nirvana, IMO, would be better sandboxing between sites.

Browser based solution not mandated by law but made by the industry wouldn't work, because all 4 major browser vendor makes significant revenues from Ads.

At a time a solution appeared with "do not track", and we ended up with the industry making sure it was as toothless as possible, opt-in, and google pushing hard to control the browser market.

Re: Dear Paul Graham, there is no cookie banner law

#324
post #127

Earlier quoted context omitted.

Do you have /any/ examples of websites that don't have a bunch of 3rd party cookies that still have a cookie banner? Middle managers absolutely love anything with charts and graphs because it makes their decisions feel more scientific. That's why they want tracking software included on their websites. And if the law requires disclosure then a cookie popup is the solution.

My company recently announced a game, and we launched a website for the game. There's no ̶t̶h̶i̶r̶d̶ ̶p̶a̶r̶t̶y̶ e:tracking cookies (I didn't make the site, but I do run it). Our US based legal team told us we needed a cookie banner if we were going to have visitors in the EU. I pushed back, but I lost, and ultimately it's not my fight.

It is not about third party or not, but what it is used for. Consent may be required even if there are no cookies at all.

Re: Dear Paul Graham, there is no cookie banner law

#325
post #230
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

I don't want to be tracked either. But if companies can play the law this easily, I think it's a pretty bad law.

Are we all such spoiled brats that some cookie banners interrupting our web browsing is all it takes for us to give up and call the malicious companies the winners and the law(s) trying to protect our privacy "bad"?

We're a pathetic lot.

Re: Dear Paul Graham, there is no cookie banner law

#326
post #240
post #110

Earlier quoted context omitted.

It would be 100% ok for it to be a browser setting. It isn't though, because that would make too many people opt out. That's what the article is about.

I don't think a browser setting would make any difference. The setting would have to be either "I don't want to be tracked by anyone ever" or "I'm ok with being tracked by everyone all the time". Everyone would just choose the first setting. But just because someone has that setting doesn't mean you can't ask them specifically if they're ok with being tracked on your specific website for some specific purpose. So the…

> The setting would have to be either "I don't want to be tracked by anyone ever" or "I'm ok with being tracked by everyone all the time".

The only alternative to that binary logic is cookie banners. So to be clear, you are advocating for cookie banners.

The reality is that the overwhelming majority of people do legitimately want option 1, which makes cookie banners redundant. The only reason that cookie banners exist is as a high pressure sales tactic to sell users into option 3.

Re: Dear Paul Graham, there is no cookie banner law

#327

Earlier quoted context omitted.

Agree. How much corporate propaganda are people consuming that legislators are seen as wholly responsible for the bad behavior and malicious compliance actions of corporations? What does it say about the relationship between businesses and consumers that the first response to this bad behavior is to shout "look what you made them do!" Seemingly it is everyone's fault except the bad actors themselves.

The funny thing is it's not just corporations. When you open the German state railways' website, somehow you get a GDPR overlay, When you open the German revenue agency's website, you get greeted by a cookie banner on top. I call upon all German users of this website to write to their MPs! Obviously the German civil service is a bad actor! The German deep state is plotting to discredit our beloved eurocrats and must…

> I call upon all German users of this website to write to their legislators! Obviously the German civil service is a bad actor! The German deep state must be shut down!

I understand the joke you're trying to make but you clearly don't understand the relation between germans and privacy/tracking regulation to think this makes sense.

Re: Dear Paul Graham, there is no cookie banner law

#328

Earlier quoted context omitted.

> How long has this been around, 20 years? No. It took effect in 2018.

Cookies banner are a response to the ePrivacy directive from 2002.

They weren't widely implemented until post GDPR, and in fact post https://curia.europa.eu/juris/document/document.jsf;jsession...

Re: Dear Paul Graham, there is no cookie banner law

#329

Earlier quoted context omitted.

Shopping carts and notification preferences don't require a consent banner.

Our lawyers told us otherwise. Regardless of the answer here, the fact that there's still a debate about what basic functionality requires a cookie banner is really a testament to how bad this legislation is. How long has this been around, 20 years? And there's still widespread debate and lack of understanding as to what specific functionality requires a cookie banner?

Here is an authoritative source[0]:

> consent is not required [for] cookies that are strictly necessary to provide an online service that the person explicitly requested. e.g. […] when your customers use a shopping basket

So shopping carts (user clicked to add to cart) and notification preferences (user clicked to indicate preference) don’t require consent. Same for authentication cookies.

The page is quite clear; the confusion likely arises from how companies implement it.

[0]: https://europa.eu/youreurope/business/dealing-with-customers...

Re: Dear Paul Graham, there is no cookie banner law

#330

Earlier quoted context omitted.

The law punishes companies, not private citizens. If lawyers are overreacting or companies cannot discern between essential tracking and non-essential then perhaps they are the incompetent ones.

> If lawyers are overreacting or companies cannot discern between essential tracking and non-essential then perhaps they are the incompetent ones. If the EU is incapable of creating a law where it is unclear even to quite some lawyers where the boundary between allowed and forbidden is, the EU politicians are the incompetent ones.

There are a bazillion unclear laws all over the world. It's common practice, really, to formulate things a little bit generally, and let practitioners (lawyers and courts) figure out the details.

In this case, the unclear point is around the notion of "legitimate interest". I guess something like fraud prevention can be thought of legitimate interest. But ad companies just said, "well, we make money out of tracking the hell out of users, so it's in our legitimate interest to keep doing it, and never mind that the whole point of the law was explicitly to rein in our industry's nasty behaviour."

So now law practitioners how to hash out amongst themselves what "legitimate interest" actually means in 2024, and this of course can change in 2034, so you write the law to not have to be updated every time the tech industry invents new ways of being naughty.

Post reply on HN