Live data from Hacker News

Europe's cookie nightmare is crumbling. EC wants preference at browser level

theverge.com

41–50 of 99 posts

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#41
post #3

This was the correct decision and could have been made a decade ago. An .. institutional deficiency was trying to make the GDPR as completely general as possible rather than doing a technology mandate. But this had two consequences: bad actors could circumvent it, and good actors just trying to comply ended up horribly confused (e.g. is logging an IP address in an Apache log "personal data"?). DNT header. Legally bin…

Cookie consent banners and such come from the ePrivacy Directive, not the GDPR. The banners themselves were never mandated, but lacking any other standardized opt-in signal, that's what everyone converged on anyway.

To be clear, the other option was to respect privacy by default and comply with the GDPR without any banner.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#42
post #22
post #13

Earlier quoted context omitted.

False dichotomy, just advertise based on the content of the site without spying on people

Loaded language, it can’t be “spying” if the user consents.

The preponderance of dark UI/UX patterns in advertising and cookie consent pop-ups, as well as the grey-hat browser fingerprinting and DRM based tracking, unfortunately stand testament to exactly that.

Given that ~98% of Internet users couldn't even articulate what javascript does as part of their browsing experience, the exfiltration and reassembling of their PII via meta-data into sellable profiles for targeted auctions is completely beyond their capacity to comprehend or engage with. Thus consent is de facto ungrantable.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#43
post #4

> This is not a real choice made by citizens This is something which courts should consider more about other things, such as EULA and Terms and Conditions. Same reasons.

Are EULAs even enforceable?

In the EU, it's complicated.

There is a very clear law that forbids any additional contract terms post the point of sale, so that if you go to a store, purchase a box with software in it and then go home to install it, when it pops up a dialog for you to "agree" on, you can just ignore it, nothing in that is enforceable at all. And no, small print text on the box that says you have to agree to terms in the software does not change anything. But that's not how software is sold anymore.

EULAs in general are not unenforceable, so long as they are presented before the sale. This is precisely why Steam (for example) now gives you the EULA before it lets you buy anything.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#44
Users will overwhelmingly use browsers in vanilla config. The question here will be how browser vendors show this option. If - say - a company that gives away a browser for free but makes money from ads designed this, then they'll hide the option deep in some obscure menu, never remind people it exists, and reset it on every update.

So the devil is in the details. The best option I think isn't a secret setting in a browser, but a standardized consent dialog. Basically the sites communicate to the browser a standardized data format for consent. Then the browser shows that query in a popup that looks the same for every site. That means 1) the sites no longer have a chance to do dark patterns 2) it's less confusing for end users since the UX is always the same 3) it allows users to check a "Automatically reject for all sites". The site should not know whether the user has auto-rejected this, or manually rejected it. There should be no option to automatically consent for all sites (Can't have that). So the only ergonomic choice is to set it to auto reject.

Having this "use this choice (reject) for all sites" is the really important part here. Because it means that ALL users of ALL browsers will quickly see this choice, so in short order a huge chunk of users will have made this permanent rejection choice.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#45
post #12

yes. everyone install Cookie Auto Delete. the problem is a plugin like that would take out entire industries because it would basically end anonymous tracking cookies.

They no longer track you by (only) cookies- the GPDR made sure of that. Fingerprinting is the current standard and there’s no easy way to block that.

The GDPR surely didn't have an influence on that.

The GDPR is technologically agnostic about tracking. You don't accept, then no tracking either way.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#46
post #34

Just ban individually targeted advertising and be done with it.

When the Digital Services/Markets Act was written this was actually considered. But there's also companies that surveil your browsing data and sell that for other purposes not just advertisement. Market Research and such. I'd have been for a blanket ban though.

Sadly, this is mostly a matter of not enforcing the GDPR enough. Things such as "data minimization" and the erosion of "technically necessary" already should protect us. Instead the Business Community chose malicious compliance on a vast scale and the data protection agencies did nothing.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#48
post #16

Much like the current cookie banner shitshow, a "centrally configured" setting which "websites must respect" will accomplish nothing. There is no consent, informed or otherwise. Advertisers and their ilk are still hoovering up all the data they can, with or without cookies or consent. Locking up a few people who don't respect their users' privacy would be a much more effective way of achieving actual results. AFAIK n…

>Locking up a few people who don't respect their users' privacy would be a much more effective way of achieving actual results. AFAIK no big adtech or data brokers have been punished in any way.

I'm a big fan of personal accountability in the corporate world.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#49

Earlier quoted context omitted.

Are EULAs even enforceable?

they are generally thought to be, but require litigation- which is a problem for the general population! corporations have enough money to tie you up in court with lawyers.

People always say this, but are there any real examples of corporations extracting damages from EULA violations?

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#50
post #13

Earlier quoted context omitted.

False dichotomy, just advertise based on the content of the site without spying on people

Untargeted pay less than 90% of targeted ones generally. And there's not a lot of companies that can handle a 90% drop in revenue. The real solution would be to make users pay for the content, but charging for something that users used to get for "free" is also essentially impossible.

That's going to rapidly change if targeted ones are no longer available.

Right now why would you spend money on untargeted ads when you have better options.

Post reply on HN