Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

41–50 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#41
post #5

This is like a case study of well-intentioned, carefully designed regulation doing more harm than good. Honestly, I'd rather just have a browser addin that blocks the cookies I don't want. The market was working fine. Now every new website is a pain, and my organization has hired some amiable lady to be "GDPR expert". She doesn't appear to know anything about anything, but she sure seems nice.

GDPR absolutely does not do "more harm than good". It extends well, well beyond these dumb cookie warnings. GDPR puts the citizen/customer in power of their own data. They can ask for their data, they can ask for it to be deleted, they have (however shitty the UX) control over where it goes. They can contact large corporations and request these things and be heard out . I don't know how to explain it any other way: T…

You beg the question by saying it's "their own data" in the first place.

The idea that, because it's about you it's therefore yours, is wrong.

Re: Cookie Warning Shenanigans Have Got to Stop

#42

As a web developer I gotta say the only true solution to this is to stop using the internet altogether. Might as well shut the internet down. We can't authenticate you without cookies or some other form of identification, so that throws out any site with an account. Even if I am not even remotely interested in tracking what pages you view on my website if I need to have you login and authenticate I need some form of…

While I'm certainly not going to argue in favor of the GDPR, the "cooking warning" actually specifically excludes cookies used for things like authentication. It covers cookies used for other purposes, such as trackers.

From my understanding if the cookie is for an account on a website (which usually is only required to store private information such as name, email, address, etc) you would need to display the cookie warning.

Re: Cookie Warning Shenanigans Have Got to Stop

#43
post #37
post #16

Earlier quoted context omitted.

What if the ads are required for the operation of the website, because without them the site has to close? People are rarely willing to pay for big sites, they surely won't pay for many small sites separately. Smaller sites don't have the resources to curate their own ads, that's why they use ad networks. If we are strict about this then this rule will eliminate small sites while tightening the grip of the big sites…

My understanding is that something being 'required for product to function' refers to technical requirements, not revenue requirements. So, yes I agree that it's a problem for small sites (or really anyone who tries to make money on ads).

So this is a bad rule, because enforcing it will result in eliminating independent small sites which have no other means for financing themseves than ads.

Re: Cookie Warning Shenanigans Have Got to Stop

#45

Earlier quoted context omitted.

That they're not important to everyone doesn't make them unimportant for everyone. It's kinda like other rights such as free speech. Some people don't need/use it. Some specific people might arguably be better off without it. But Everyone needs it; as in, it needs to be available to everyone for it to work.

It's worth noting that the United States considers a right to keep and bear arms as important as a right to free speech. Internationally, reasonable disagreement on rights seen by some as fundamental is to be expected.

You make a fair point, but the right to bear arms is mainly controversial for safety reasons. What safety issues are there with providing customers control (or at least visibility) over their data?

It's also worth pointing out that the right to bear arms, by its origin, should probably be called the "right to revolt". While this is still a controversial issue for governments (governments don't want revolt), it's less controversial for citizens.

Re: Cookie Warning Shenanigans Have Got to Stop

#46
What I don't understand is why websites hosted outside the EU, for non-EU users have the cookie banners.

At least keep it in Europe, use the IP to geolocate, let the EU users deal it.

Some companies have outright banned EU traffic, sounds like only showing the banners for EU IPs seems ok.

Re: Cookie Warning Shenanigans Have Got to Stop

#47

FTA he's quoting: > And the Dutch DPA’s guidance makes it clear internet visitors must be asked for permission in advance for any tracking software to be placed — such as third-party tracking cookies; tracking pixels; and browser fingerprinting tech — and that that permission must be freely obtained. Ergo, a free choice must be offered. Neither cookies, nor tracking pixels, nor browser fingerprinting are software. Yo…

Tracking cookies, pixels, etc., are implemented by server-side software; perhaps the matter you would like to contend is what the meaning of the word "placed" is.

Re: Cookie Warning Shenanigans Have Got to Stop

#48
post #40
post #16

Earlier quoted context omitted.

What if the ads are required for the operation of the website, because without them the site has to close? People are rarely willing to pay for big sites, they surely won't pay for many small sites separately. Smaller sites don't have the resources to curate their own ads, that's why they use ad networks. If we are strict about this then this rule will eliminate small sites while tightening the grip of the big sites…

Advertisement doesn't require profiling and surveillance. That is what GDPR and other efforts like some ad blockers are trying to protect against. The emerging consensus is surveillance capitalism is unethical and increasingly illegal.

> Advertisement doesn't require profiling and surveillance.

Targeted ads pay much more. Eliminating targeted ads can result in a revenue drop of 50% or more, effectively killing small sites which most of the time make not much more money from ads than what is needed for financing themselves.

Re: Cookie Warning Shenanigans Have Got to Stop

#49

Earlier quoted context omitted.

While I'm certainly not going to argue in favor of the GDPR, the "cooking warning" actually specifically excludes cookies used for things like authentication. It covers cookies used for other purposes, such as trackers.

From my understanding if the cookie is for an account on a website (which usually is only required to store private information such as name, email, address, etc) you would need to display the cookie warning.

Cookies are only affected if they are not a core and essential part of the product's functionality, and can identify the user. You could also argue that authentication may not be an essential part of an app's functionality, but you would not be successful; it's well-established by now.

Re: Cookie Warning Shenanigans Have Got to Stop

#50
post #31

Earlier quoted context omitted.

I like the spirit of GDPR. I think it is important. It also doesn't matter if people aren't educated and don't care.... or simply don't care if they are educated. It's not clear to me that any progress has been made by GDPR in those areas.

Recently a company I trust was sold to a company I utterly dislike and have zero trust in. Before the sale was executed, as a EU citizen I was informed that my consent was required for the transfer of my personal data to the new owners. I did not consent. My data is not in the hands of the new owners. And under GDPR, I was able to request all the data they had on myself in order to make an archive of it before the ex…

I think that is great.

But I think it might be a case where Troy notes, you're educated on the topic, and like cookie tracking, you probabbly could have dealt with cookie tracking before GDPR too on your own.

I'm not at all sure that applies to more than a handful of people. If that's the case, GDPR is not helping most people.

Post reply on HN