Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

391–400 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#391
post #91

Earlier quoted context omitted.

The law isn't that bad actually, just that the courts have been very slow. The dark UI patterns are actually illegal and have been judged so in court now. This realization just has to trickle down to the companies writing these cookie banners.

My take is that law tries to dictate UX more than just set groundrules which good laws do. They pre-emptively set the law such that it prevents any use when the focus is on misuse. The law is about 1st party and 3rd party cookies, not just 3rd party. In an ideal case, if it was just a law, a simpler wording could be "you are allowed to collect anonymized data, but not monetize/share it without permission from users.…

[deleted]

Re: Dear Paul Graham, there is no cookie banner law

#392
post #346
post #312

Earlier quoted context omitted.

> - no fines for non-compliance (or malicious compliance) "The Biggest GDPR Fines of 2023" 1. Meta – €1.2 billion (Ireland) 2. Meta – €390 million (Ireland) 3. TikTok – €345 million (Ireland) 4. Criteo – €40 million (France) 5. TikTok – €14.5 million (UK) 6. Axpo Italia Spa – €10 million (Italy) 7. Tim S.p.A. – €7.6 million (Italy) 8. WhatsApp – €5.5 million (Ireland) 9. EOS Matrix – €5.5 million (Croatia) 10. Clearv…

Which ones of those fines were because of inappropriate use of cookie consent popups? You just copy-pasted a list of GDPR fines.

> fines were because of inappropriate use of cookie consent popups?

see: "8 companies that faced cookie consent fines"

https://www.cookieyes.com/blog/cookie-consent-fines/

"In January 2023, France’s data protection watchdog, CNIL, fined TikTok €5 million ($5.4 million) for making it difficult to refuse cookies on its website. The CNIL found that TikTok manipulated consent by discouraging users from rejecting cookies. They required multiple clicks to refuse cookies, but only one click to accept them. TikTok resolved the issue by adding a “Refuse all” button to its site."

Re: Dear Paul Graham, there is no cookie banner law

#394

Hate this way of thinking where the government (with seemingly good intentions) tries to stop something but leaves a loophole where all our lives are made more tedious and then people defend it saying the companies should just not do it, well we needed the law in the first place so it's a bit silly thinking to suggest they stop doing it after the law, no?. If the cookie law was written properly then it would have jus…

There has been a browser setting for tracking cookies since 2002! https://www.w3.org/P3P/

It has even been implemented in Internet Explorer when it had 90%+ market share.

And then Google intentionally sent malformed P3P header to bypass user preferences in IE.

When Safari added a heuristic rejecting Google's 3rd party cookies, Google has found a technical workaround to bypass it (and has been fined for doing this).

When IE and P3P were totally dead, browsers have tried to give adtech the simplest to implement bare minimum setting - the DNT header. The adtech has completely ignored it.

There are trillion-dollar businesses relying on tracking, and they will do whatever they can to undermine any technology and lobby against any law that would harm their business.

Re: Dear Paul Graham, there is no cookie banner law

#395
post #352
post #296

Earlier quoted context omitted.

If it only were that simple. When the GDPR came out, a lot of confusion and misunderstanding ensued. Not only regarding the damn cookie banner. Even totally legitimate health-care providers started to collect signatures to be on the safe side. I still rememeber receiving a basic GDPR training where we were told that opt-out/signing is only necessary if the entity is planning to do weird stuff with your data. IOW, if…

I kinda hate saying this, but Microsoft (or at least github) got it right in a week. Some OSS publishers also got it right, like nexedi, and some i'm sightly upset with (gitlab) but it is true that for the commercial internet it seems to be invasive. I do not use the commercial internet much, and like any person with greasemonkey, i took a rainy afternoon to remove the most annoying banners (i think now i use a plugi…

The fact that you have to use a plugin or other thecnical remedies to fix the cookie banner situation is all the proof we need to see that the EU totally fucked up. It is easy to declare that you just need to install this or that to get a obstruction-free internet again. But it is also very very elitist. Not even 1% of the population is truly capable of handling that.

Re: Dear Paul Graham, there is no cookie banner law

#396
Thats right, however, there is a consent needed for cookies that are not necessary. If you don't have the cookie banner asking for consent to track you with the unnecessary tracking cookies you can get a letter from the abmahnanwalt which means that in germany there is a defacto cookie banner law (next to the self censorhip brain bucket) just to be on the safe side.

Re: Dear Paul Graham, there is no cookie banner law

#397
post #296

Earlier quoted context omitted.

Agree. How much corporate propaganda are people consuming that legislators are seen as wholly responsible for the bad behavior and malicious compliance actions of corporations? What does it say about the relationship between businesses and consumers that the first response to this bad behavior is to shout "look what you made them do!" Seemingly it is everyone's fault except the bad actors themselves.

If it only were that simple. When the GDPR came out, a lot of confusion and misunderstanding ensued. Not only regarding the damn cookie banner. Even totally legitimate health-care providers started to collect signatures to be on the safe side. I still rememeber receiving a basic GDPR training where we were told that opt-out/signing is only necessary if the entity is planning to do weird stuff with your data. IOW, if…

Incompetent lawyers and managers did a half-assed job, and some exemplary fines will motivate them with respect to the other half.

Re: Dear Paul Graham, there is no cookie banner law

#398
post #75
post #11

Earlier quoted context omitted.

In this case, it is just showing that most companies are collecting more data than they need. You don’t need a banner for the data that is necessary for the service to work at minimum level. There is no role for the consent since the site won’t work otherwise.

This is something a lot of people seem to misunderstand about GDPR. At its core it says you should only process people’s personal data within a lawful basis. There are 6, and consent is only one. (a) Consent: the individual has given clear consent for you to process their personal data for a specific purpose. (b) Contract: the processing is necessary for a contract you have with the individual, or because they have a…

The thing is, if you have any of (b)-(f), why shouldn't you also get (a)?

The maximum fine is 20 million euros or 4% of revenue, whichever is higher. Sure, it probably won't be imposed on a first time violation, but why take the chance?

Could you imagine any lawyer advising a company against requiring consent, even if they have some cover because of a legal obligation? Isn't it much safer to deny service to those that refuse to consent?

Sure, it'll annoy the customer, but right now the customer is used to minor annoyances.

Re: Dear Paul Graham, there is no cookie banner law

#399
post #172

Earlier quoted context omitted.

The reality is that most people don't want to be tracked: https://arstechnica.com/tech-policy/2021/07/facebook-adverti...

The problem is that most people don't want to pay for any of the internet services they use either.

Great, then maybe we can all finally go outside and smell the damn roses.

Re: Dear Paul Graham, there is no cookie banner law

#400
post #240
post #110

Earlier quoted context omitted.

It would be 100% ok for it to be a browser setting. It isn't though, because that would make too many people opt out. That's what the article is about.

I don't think a browser setting would make any difference. The setting would have to be either "I don't want to be tracked by anyone ever" or "I'm ok with being tracked by everyone all the time". Everyone would just choose the first setting. But just because someone has that setting doesn't mean you can't ask them specifically if they're ok with being tracked on your specific website for some specific purpose. So the…

The DNT (Do-Not-Track HTTP header) setting has died the moment Microsoft made it too easy to enable it during setup of Edge, making most of their users default to do-not-track.

The adtech will absolutely freak out and destroy any attempt to make such setting as soon as there's a risk of it working.

Post reply on HN