Live data from Hacker News

Analysis of economic and productivity losses caused by cookie banners in Europe

legiscope.com

361–370 of 395 posts

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#361

Earlier quoted context omitted.

Scummy companies won't magically disappear or stop scummy practices. We can and should blame them, but it's pretty much obvious that the legislation (despite good intents!) resulted in a de-facto shitshow that failed to recognize basic social/behavior sciences, technical details, or anything else. It should've been an user-agent centered feature rather than individual website gimmick - that's the only way it could've…

> none of their identifiers would be persisted unless user agent allows it. Wrong. And the GDPR is not just for the web.

> Wrong

How? I fail to understand why if a browser, configured to not persist anything by default (without a consent) would persist anything. Save for a bug, of course.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#362

Earlier quoted context omitted.

> never seem to blame the web companies for doing the naughty things on their websites Part of the problem is that the law didn't seek to distinguish between tame first-party cookies and the really naughty third-party cookies so the burden is equal regardless of how malicious the service is. > For the company, it's a one time JIRA ticket for a junior software engineer to code up a banner. This is actually not true. T…

> Part of the problem is that the law didn't seek to distinguish between tame first-party tokens and the really naughty third-party tokens Maybe I'm an outlier, but ideally I don't want them collecting any "tokens" without my consent. I don't care if they're first party or third party or birthday party. I should be able to browse web sites in peace without some company collecting anything. If the web site doesn't wor…

There is basic non-identifying logging that is almost entirely necessary to operate a website. I assume you're okay with that much?

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#363

Earlier quoted context omitted.

> Non-standard: This feature is non-standard and is not on a standards track. Do not use it on production sites facing the Web: it will not work for every user. There may also be large incompatibilities between implementations and the behavior may change in the future. I tried looking at the various browser standards positions, and as far as I can see, nobody has even asked Blink or WebKit if they are interested in s…

There's movement from the Internet Advertising Bureau, they explicitly say that this signal must be adhered to if the header is present, and this signal must be forwarded to Demand Side Platforms.

I mean is there any movement in getting major browsers to adopt this?

Normally when a spec. like this is written that needs adoption from web browsers, an explainer is written and then the major rendering engines are asked for their feedback. For instance, here’s an explainer:

https://github.com/krgovind/first-party-sets

Here’s where WebKit was asked for their position on it:

https://github.com/WebKit/standards-positions/issues/93

Here’s where Mozilla was asked for their position on it:

https://github.com/mozilla/standards-positions/issues/350

Here’s the process Blink goes through to get a new feature like this going:

https://www.chromium.org/blink/launching-features/

I tried to find where this was done for GPC and couldn’t find anything. Did they just write a spec. and not bother doing any of the work involved in getting it adopted? Or is there progress being made that I didn’t see? Hence my question: Is there any movement on this at all? Or is the process of getting it adopted by Blink and WebKit at absolute zero?

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#364

Earlier quoted context omitted.

There is a "Yes-Track" header – DNT: 0 Granted, you can't legally use it like that where EU laws apply, per the GDPR. Hence the complaints about the GDPR you see in other comments.

It's not really a Yes Track if it's simply absent. The user hasn't requested to be tracked. I'm not even sure with it set to 0 that you can assume that intent. I guess it would depend on the browsers behavior, but as you say the law is not compatible with that use.

According to the specification,

DNT: 0 = Yes, track me.

DNT: 1 = No, do not track me.

> I'm not even sure with it set to 0 that you can assume that intent.

That's the problem. Someone not paying attention might inadvertently set DNT: 0, which is why the law is written the way it is. But at the same time we have techies who knowingly and carefully set such values and want the service to acknowledge it, contrary to the law. Hence the contention.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#365
It is literally that meme where the guy pushes a stick into the spokes of his own bicycle only to blame others.

You don't need to ask people for their consent if you do not store personal data client side to track them. There are clear definitions what is personal and what isn't, you can store cookies for legitimate reasons which are also clearly outlined.

So if you don't want to ask for consent, you can avoid that by not doing things that require it.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#366
post #232

Earlier quoted context omitted.

What I find funny about the whole thing is that the grand majority of companies with cookie banners are not implementing them correctly, and therefore are still in breach of the law. I see constantly banners on sites that set tracking cookies by default, and delete them if you reject them in the banner (or even worse, not delete them at all!) – this is not compliant as the cookies were set before consent was given Al…

Look at how Google does it for Blogger. There is an OK button and a "Learn more" one. There is no reject. Are you saying they are breaking the law? EU would love nothing more than to levy more fines.

Yes.

GDPR says on Consent:

> The basic requirements for the effectiveness of a valid legal consent are defined in Article 7 and specified further in recital 32 of the GDPR. Consent must be freely given, specific, informed and unambiguous. In order to obtain freely given consent, it must be given on a voluntary basis. The element “free” implies a real choice by the data subject. Any element of inappropriate pressure or influence which could affect the outcome of that choice renders the consent invalid.

Pretty clear, isn't it?

There have been subsequent rulings stating that not giving a equally styled no/reject option or letting people choose between one yes option and thousand separate no options is already a influence that nullifies consent.

Also specific means you can't just tell them you have to use a cookie for technical reasons and use it for tracking later — they might have given you consent for that cookie for the purpose you told them about, not for the purpose of tracking.

All kinds of actors try to bend the rules here, while the rules are verh clear.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#367

Earlier quoted context omitted.

So many pop-ups these days, for every little thing. Tracking. OS permissions. Browser permissions. Take a survey. Speak to our AI assistant. Do you agree to this. Donate. Sign up. Pay. So many clicks. Used to be viruses, but we have the same result with our complexity.

It's not complex. It's simple. It's greed. It's absolutely ridiculous that we as a species put up with all of this nonsense because we have a faulty foundational understanding of what is and should be normal. The brain rot that we've subjected ourselves to is absolutely ludicrous.

You can always find disagreement if you look for it. Maybe this is your thing, given user name, your account makes an interesting study on it. Though in this case, I wouldn't be so reductive. Not all complexity (I ascribe to the result) is due to bad intentions (e.g. greed). There's also the EU GDPR trying to protect kids. AI assistant might be a tool to try to help users. If you want to simplify the cause here, how about a lack of focus or failure to tame the complexity of the world with our technologies, or tendency to add rather than delete?

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#368

Earlier quoted context omitted.

Me navigating to a webpage is far from consent. How do I even know that you want to try and farm my personal data until I go there? Perhaps you should put a click through gateway that states that "proceeding on to this website will sell your personal information to spammy, scummy advertising".

Setting a cookie isn't farming personal data. You can configure your web browser to only send first-party cookies back and never set others. Or configure a subset of domains. If you're worried about it you should be doing that anyway, since the cookies could be set despite the pop-up (or some websites might ignore the consent pop-up requirement entirely).

Consent isn't required for setting a cookie.

You don't appear to know what the regulation is. The "cookie banner" isn't even about setting cookies, its data sharing.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#369
post #262

Earlier quoted context omitted.

> Why do EU lawmakers not allow me to automatically say no? What do you mean? There is no law banning companies from honoring a DNT header, companies just choose not to do so. The law already allows it, it just doesn't mandate it.

>What do you mean? ... The law already allows it, it just doesn't mandate it. That's exactly what I meant by: >All they have to do is add a line to the law enforcing companies to respect the DNT or GPC header.

Microsoft, in its eagerness to hit Google's revenue, universally set DNT on its browser of the day, which muddied the water on informed consent, and gave Google and other trackers an excuse not to respect it, since it wasn't technically the user requesting not to be tracked, but Microsoft.

Re: Analysis of economic and productivity losses caused by cookie banners in Europe

#370

Earlier quoted context omitted.

Sure, and that's a perfectly reasonable law. There's no "oh you actually can sell alcohol after 10pm as long as your customers fill in a 5 page form, which is what the EU has caused.

If you're using third party cookies you have to display a "please consent" button. If you're not, then all you need is a privacy policy somewhere stating that you use cookies and that they are all first party. That seems fair to me. I like to know if cookies are used or not regardless if they are site or third party only.

It's perfectly fair, but it's also extremely annoying. That's the whole point.
Post reply on HN