Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

341–350 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#342
post #331

Earlier quoted context omitted.

Trading a kidney for access to a news site would obviously be insane, and we should have laws to prevent insane people from harming themselves. On the other hand, if a person of sound mind decided they would rather have $1,000,000 than both of their kidneys, why shouldn't they be able to sell one, logically? The idea of selling one's organs sets off the human involuntary disgust/outrage reaction ("of COURSE it should…

Yes: it protects the poor and weak. Thought experiment: a multi-billionaire wants to beat a human to death, and offers $10 million for it. A grandfather decides he would like to take that offer, for his children and grandchildren. Would you allow that? If you also would not allow it (that's what I hope), then where is the proper boundary? What should we outlaw, and what allow?

If the grandfather consents to it, then what is actually wrong with him taking up that offer?

Your thought experiment (or at least your "hope" re: the "correct" answer) presupposes that suicide is wrong. Personally, I believe the only one who is allowed to dictate whether I live or die is myself; if I want to die, and have good reason to want to die (financial security for my children and grandchildren would certainly be compelling!), then that's my right, and it ain't your place to deny me that right.

Re: Cookie Warning Shenanigans Have Got to Stop

#343
post #296

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

We are now in the middle game of GDPR. Companies whose business model depends on tracking users essentially have now an illegal business model, because practically no user will give informed consent when they are offered the same service without consenting. So what can these - now shady - companies do? They probe the limits of the law, and try to keep their business model alive as long as they can. We need to wait an…

> Then EU will essentially become free of tracking networks. It might take a few years, but I think the intermediate annoyance is worth it.

I don't disagree with you but I think it is more likely that these companies will just not let EU peoples use their sites at all.

One BIG fine (and you know they're salivating at the prospect of getting multi-billions out of Google and/or FB) and doing business in the EU becomes too much of a gamble for a company to justify the risks.

Re: Cookie Warning Shenanigans Have Got to Stop

#344
post #296

Earlier quoted context omitted.

We are now in the middle game of GDPR. Companies whose business model depends on tracking users essentially have now an illegal business model, because practically no user will give informed consent when they are offered the same service without consenting. So what can these - now shady - companies do? They probe the limits of the law, and try to keep their business model alive as long as they can. We need to wait an…

> Then EU will essentially become free of tracking networks. It might take a few years, but I think the intermediate annoyance is worth it. I don't disagree with you but I think it is more likely that these companies will just not let EU peoples use their sites at all. One BIG fine (and you know they're salivating at the prospect of getting multi-billions out of Google and/or FB) and doing business in the EU becomes…

Some will choose to adjust practices, others might choose to block the EU. If they're happy to lose that many users, as they think tracking is more important, would that be so terrible?

It might even encourage some more ethical alternatives, or some real attempts to solve micropayments.

Re: Cookie Warning Shenanigans Have Got to Stop

#345
post #91

Earlier quoted context omitted.

These organizations do have such an incentive. The very essence of GDPR is to create these incentives. The EU's goal with GDPR was to make user data a liability , and to encourage organizations to reconsider their need to hoover and hoard it. The GDPR is unlikely to be overturned, and there are plenty in the EU who are eager to enforce it. Just because it's not being enforced right this second doesn't mean the law wo…

> there are plenty in the EU who are eager to enforce it But we haven't yet seen it enforced, have we?

https://news.ycombinator.com/item?id=18416887

Re: Cookie Warning Shenanigans Have Got to Stop

#347
post #136

internet visitors must be asked for permission in advance for any tracking software to be placed — such as third-party tracking cookies; tracking pixels; and browser fingerprinting tech — and that that permission must be freely obtained... Is this really what we want? Yes. I'm not even European, and I'm perfectly fine with this. Ask me to track me. If I like you, your web site, or your content, then sure. I'll give y…

>Yes. I'm not even European, and I'm perfectly fine with this. >Ask me to track me. If I like you, your web site, or your content, then sure. I'll give you a little personal data. This should be a setting you choose in your browser and the rest of us (> 99%) should be able to ignore.

Yeah, it should be a header sent with every request. If it's 0, then feel free to track me. If it's 1, then please don't track me.

We could even call it "DNT", for "Do Not Track".

Re: Cookie Warning Shenanigans Have Got to Stop

#348
post #256

Earlier quoted context omitted.

> This shows utter incompetence and detachment from reality by European legislators. > Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes? Wait, what? There are such solutions. GDPR, and the "cookie law" before it, don't "require" any popups. They allow cookies, 1x1 pixel images, browser fingerprinting, Flash supercoo…

What evidence is there it is working? That evidence only shows that people have change their web experience to be more annoying out of fear of the EU. It does not show there is less tracking or more public support for privacy. Most people hate the UX change but don’t care about the privacy so probably a net loss for the EU.

That's because the sites currently have an option (or think that they have an option) to make tracking mandatory for their visitors, so long as they consent - which is the easiest way for them to deal with it. It sounds like this Dutch agency is saying that it is not actually compliant with GDPR.

Re: Cookie Warning Shenanigans Have Got to Stop

#349
post #91

Earlier quoted context omitted.

These organizations do have such an incentive. The very essence of GDPR is to create these incentives. The EU's goal with GDPR was to make user data a liability , and to encourage organizations to reconsider their need to hoover and hoard it. The GDPR is unlikely to be overturned, and there are plenty in the EU who are eager to enforce it. Just because it's not being enforced right this second doesn't mean the law wo…

> there are plenty in the EU who are eager to enforce it But we haven't yet seen it enforced, have we?

we have definitely seen movement (plenty of data protection authorities have issued warnings), but it really hasn’t been that long (it’s been less than a year)

the only way that a law like the GDPR that’s purposefully vague and broad can work is to allow plenty of lead time for warnings and fixes before fines

it’s a process; you shouldn’t expect it to change everything overnight

Re: Cookie Warning Shenanigans Have Got to Stop

#350
post #312

Most cookie warnings are beyond useless, in that they don't even try to actually comply with the GDPR. The fact that your site uses cookies is irrelevant, and there's no need to tell anyone. However! If your site stores personal information (directly or via a partner), you need to have a valid reason. The definitions of "personal information" and "valid reason" are, fortunately, not exhaustively enumerated in the GDR…

Very true, that can't be stressed enough. One note though:

> The fact that your site uses cookies is irrelevant, and there's no need to tell anyone.

Let's not forget the infamous ePrivacy directive, e.g. Recital 66:

"Third parties may wish to store information on the equipment of a user, or gain access to information already stored, for a number of purposes, ranging from the legitimate (such as certain types of cookies) to those involving unwarranted intrusion into the private sphere (such as spyware or viruses). It is therefore of paramount importance that users be provided with clear and comprehensive information when engaging in any activity which could result in such storage or gaining of access. ... Exceptions to the obligation to provide information and offer the right to refuse should be limited to those situations where the technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user."

Of course, the relationship between GDPR and the old ePrivacy directive is rather ambiguous.

Post reply on HN