Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

361–370 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#361
post #197

This shows utter incompetence and detachment from reality by European legislators. Maybe it seemed like good idea in theory but the only practical significant impact is that browsing the web has become more annoying. Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes?

Back in the early days, browsers used to prompt you for every cookie: https://i.imgur.com/FThIFHe.png

When trying to view this I got a full page opt out (not gdpr complaint) dark patten based dialogue obscuring the entire page. The irony

Re: Cookie Warning Shenanigans Have Got to Stop

#362
post #200
post #197

Earlier quoted context omitted.

Back in the early days, browsers used to prompt you for every cookie: https://i.imgur.com/FThIFHe.png

i don't think i ever saw that. which browser?

Older versions of Internet Explorer did it (3 or 5 can’t recall) Konquerer, Netscape, and lynx too if I recall correctly.

Re: Cookie Warning Shenanigans Have Got to Stop

#363

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

Which doesn’t mean they have to provide access for free, they are most likely allowed to ask a fee for that. From the same website you link [1]: “Does anyone refuse tracking cookies? Then you still need to give this person access to your website or app, for example after payment.” (google translated) [1]: https://autoriteitpersoonsgegevens.nl/nl/onderwerpen/interne...

The problem with asking for a fee is that Europe operates under the "transaction takes place at the buyer's location" model for such transactions, meaning you have to collect and report VAT on those fees in each country you have a paying user in. (The same goes for state sales tax in most US states).

If a site makes its money from ads, on the other hand, the location of the visitors is irrelevant when it comes to taxation. The payments from the ad network will just be ordinary business income at the place the site is located.

I don't think the charge a fee model has a chance, except for a few large sites, until some sort of intermediate service is developed that isolates the sites from having to deal with taxes in a bazillion jurisdictions. Something like a Spotify for site access, where users can pay the service a subscription fee, and the service pays sites after taking care of the appropriate taxes on the user's subscription fees so that the sites don't have to deal with it.

Re: Cookie Warning Shenanigans Have Got to Stop

#365
post #313

Earlier quoted context omitted.

I’ve been hearing this since 1997 when the first Data Protection directive happened. The enforcement never happens unless it’s serving a political goal, such as singling out a Chinese company or whatever.

GDPR is the result of many lessons learned in prior attempts. The EU Commission put particular attention on not repeating the mistakes being made in the Cookies directive, which rendered it essentially useless and only annoying. Fines are to be handed out by the national data protection agencies. In Germany, the data protection agency regularly goes after violators since the 1990s. They audit German administrations a…

I have to concede that German regulators have set the pace, but the penalties are still negligible on the global or even regional scale. If every member state went in with as much conviction as Germany, we might see some results after two decades of mostly-empty promises.

Re: Cookie Warning Shenanigans Have Got to Stop

#366
post #154
post #145

Earlier quoted context omitted.

So websites are supposed to just absorb the cost? That seems like a ridiculous stance.

No, they're supposed to serve generic, non-tracking ads. Non-targeted, or whatever the terminology is. It's hilarious how everyone has just forgotten that used to be a thing. The people on this website are literally the problem, you can't even conceive of a website that doesn't track every click you make across the whole internet, and you guys are the people building the new web.

Data addiction. Just say no.

Re: Cookie Warning Shenanigans Have Got to Stop

#367
post #213

Earlier quoted context omitted.

Why? It's relatively common for governments to prohibit businesses and services from discriminating against certain types of users, why do you think it's ridiculous in this specific case?

Whether we like it or not, tracking data used for ads is the currency of the free internet. It is how things are paid for. This is like a government saying to a restaurant "You can't discriminate against people who don't want to pay you money for the food. You can ask them if they are willing to give you money for the sandwich, but if they say no, you still have to give them the sandwich"

If that's so, it's as if an unknown and possibly arbitrary amount of money was taken from your wallet every time you picked something up from a store. Yes, it's nice that I can walk into Whole Foods and just pick up a few oranges and leave, but if I get home and it turns put they cost $25 each, is it worth it? The data market is not mature and transparent enough for the transactions it's capable of making.

Re: Cookie Warning Shenanigans Have Got to Stop

#368

Earlier quoted context omitted.

Yes absolutely! Websites need to find revenue models that don’t depend on violating the privacy of their users. That stance makes a lot of sense to me.

There are tons of websites that have other revenue models. Subscriptions, referral models, etc. Shouldn't people be able to choose what currency they want to pay for something in?

> Shouldn't people be able to choose what currency they want to pay for something in?

Thats a very libertarian position statement and I understand it. But the EU is much less capitalist/libertarian than you are. Their parliament made the call that they don't want people paying for services with their personal data.

There's valid arguments on both sides here. Some arguments supporting the EU's stance:

- If online newspapers get paid in proportion to views, they make more money by writing divisive clickbait

- Privacy is a fundamental right; not a currency. Treating it as currency means only wealthy people will be free from spying, and that is borderline dystopian.

- Advertising on the internet worked just fine before everyone was tracked and monitored through every click. Don't annoy me with cookie notices. Just don't use cookies for tracking and we'll get along fine.

Re: Cookie Warning Shenanigans Have Got to Stop

#369

This shows utter incompetence and detachment from reality by European legislators. Maybe it seemed like good idea in theory but the only practical significant impact is that browsing the web has become more annoying. Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes?

The EU has generally been a really positive force when it comes to consumer rights, but I'm not a fan of this either. The question I have is, what did web company do to deserve this kind of regulation? It is quite unusual to see governments enact regulations, without the existence of a measurable harm being caused - but solely on the premise, that the act of collecting data is 'unethical'. I mean this is really not n…

> if you look how regulations worked in the past for other industries, it has always been a response to very clear quantifiable harm being caused.

It should be straightforward to show quantifiable harm to people’s right to privacy. You could survey a large number of people to ask if they would be OK with having their online habits monitored in detail by unknown companies (whose websites they didn’t even visit) for the purpose of targeting ads to them at later dates. If close to 100% of respondents say this is an invasion of their privacy, then that’s what it is. You could also do some more technical research to work out how many times per week people’s privacy is invaded in this way. You’d probably arrive at a very big number, rising every year.

Re: Cookie Warning Shenanigans Have Got to Stop

#370

Earlier quoted context omitted.

> This shows utter incompetence and detachment from reality by European legislators. > Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes? Wait, what? There are such solutions. GDPR, and the "cookie law" before it, don't "require" any popups. They allow cookies, 1x1 pixel images, browser fingerprinting, Flash supercoo…

> Sounds like the dissuasion is working. It clearly isn't. Vast majority of people (me too) are trained to automatically accept whatever cookie BS the website asks for, just to get rid of the popup as quickly as possible and get to content. And no, these "spyware" sites such as reddit.com or bloomberg.com won't switch to non-tracking ads to get rid of the popup.

well the GDPR does say many things about how the tracking consent can’t be the default right? so yeah it’s working if you just click through... of course if businesses are breaking the law, that’s different and enforcement will come

for reference there are at least 2 parts that make this outcome true:

“Consent must be freely given, specific, informed and unambiguous ... Any element of inappropriate pressure or influence which could affect the outcome of that choice renders the consent invalid”: a default choice if “i agree” is influence

“The withdrawal must be as easy as giving consent”: if you hit “i agree” in a box that automatically pops up to give consent, there must be a withdrawal mechanism that’s as easy as that to withdraw (and then they must delete your tracking data)

https://gdpr-info.eu/issues/consent/

Post reply on HN