Live data from Hacker News

The stupid cookie law is dead at last

blog.silktide.com

41–50 of 70 posts

Re: The stupid cookie law is dead at last

#41

Earlier quoted context omitted.

Yes, but browser's user generally doesn't (in easily accessible way).

At least on Chrome, they are displayed precisely in the same manner as cookies.

The user doesn't have the same fine-grained control. In the case of HTTP cookies you can control whether session cookies are permitted independently of whether persistent cookies are allowed. I believe no such control exists in the domain of local storage.

Re: The stupid cookie law is dead at last

#42
post #36
post #34

Earlier quoted context omitted.

How about "session cookies for ecommerce and other transactional style web interaction, that track users across multiple sites without their knowledge or consent"? Are these good or bad? We can decide on a case by case basis whether any particular use of cookies is good or bad, but coming up with a generic rule to do so is fraught with difficulties.

Well those would be bad, as they've clearly strayed well beyond necessary use of cookies as a mechanic of the website operating and into tracking people without their knowledge or consent. What about "Tracking people without their knowledge or consent" being A Bad Thing is hard to understand? The original poster said " in certain cases, implied consent would be appropriate and this is judged on the basis of the type…

"...necessary use of cookies as a mechanic of the website [operation]..."

My shopping cart cookie that tracks you across multiple websites is necessary because it keeps my prices lower than my competition giving me the competitive advantage and my customers a better price on the things they want.

Your turn.

Re: The stupid cookie law is dead at last

#43
post #17

Earlier quoted context omitted.

One thing that is still unclear to me about the Dutch law: Is the Dutch law only for .nl domains? Domains hosted in NL? Sites owned by Dutch companies?

The Dutch law applies to any company doing business in the Netherlands. So it applies to Facebook and Google as well as local Dutch sites, because they have offices here and accept money from Dutch users/advertisers. It's almost just like in the real world... (Also, there's plenty of jurisprudence for that when for instance it comes to online gambling.)

"Doing business" is also complicated.

We're a Dutch not-for-profit, running under a US .org domain name, with some servers hosted in Germany, and our visitors come from everywhere.

Right now the decision is only to annoy Dutch visitors (based on IP), but I've been waiting to implement it until there is some clarity.

Re: The stupid cookie law is dead at last

#44
post #22

Earlier quoted context omitted.

In the abstract, I agree. Only somebody who does not understand cookies would say such a thing in this context however (like our Dutch politicians). You, the website visitor, are running a program called a browser. This browser sends and receives data from servers that host the web sites you visit. Some of that data contains a request to store a piece of information on your computer. Your browser stores that piece in…

This entire argument boils down to "if you don't want to get raped, don't wear short skirts in public". People shouldn't have to take protective action in order to not get stalked by advertisers and marketers. Such activities require opt-in and informed consent, and standard browser functionality doesn't even come close to supporting that. Oh, I agree that the current law doesn't solve the problem. But "educating the…

> This entire argument boils down to "if you don't want to get raped, don't wear short skirts in public".

This is a ridiculous comparison. Lets not go that way.

> Such activities require opt-in and informed consent, and standard browser functionality doesn't even come close to supporting that.

Yes, as I said that's where the problem lies, so that's what should be altered. This can either be done by education, or by making the browser more resilient (e.g. let the browser do opt-in for all cookies or at least cookies sent via stuff embedded in other web pages like Google analytics and Facebook like buttons). The current solution of forcing Dutch websites to display popups is a farce as I explained because (A) it doesn't actually protect your privacy in any meaningful way (B) it's annoying. By giving a false sense of privacy it actually makes the problem worse.

Privacy laws should be about protecting privacy in general, not about a specific technology like cookies. There are plenty of genuine applications of cookies (keeping you logged in to HN for example), and there are plenty of ways for Facebook to track you without using cookies that they would happily switch to if this law applied to them (but note that those methods cannot be used to keep you logged in to HN because they are not secure so that might give somebody else access to your account -- but Facebook doesn't care about 100% reliability for tracking purposes, 99% is enough).

Re: The stupid cookie law is dead at last

#45
post #42
post #36

Earlier quoted context omitted.

Well those would be bad, as they've clearly strayed well beyond necessary use of cookies as a mechanic of the website operating and into tracking people without their knowledge or consent. What about "Tracking people without their knowledge or consent" being A Bad Thing is hard to understand? The original poster said " in certain cases, implied consent would be appropriate and this is judged on the basis of the type…

"...necessary use of cookies as a mechanic of the website [operation]..." My shopping cart cookie that tracks you across multiple websites is necessary because it keeps my prices lower than my competition giving me the competitive advantage and my customers a better price on the things they want. Your turn.

Nope, you're still tracking someone without their consent, your reason is nothing to do with the technical operation of your website.

Keep trying though, this is entertaining.

Re: The stupid cookie law is dead at last

#46
post #22

Earlier quoted context omitted.

In the abstract, I agree. Only somebody who does not understand cookies would say such a thing in this context however (like our Dutch politicians). You, the website visitor, are running a program called a browser. This browser sends and receives data from servers that host the web sites you visit. Some of that data contains a request to store a piece of information on your computer. Your browser stores that piece in…

This entire argument boils down to "if you don't want to get raped, don't wear short skirts in public". People shouldn't have to take protective action in order to not get stalked by advertisers and marketers. Such activities require opt-in and informed consent, and standard browser functionality doesn't even come close to supporting that. Oh, I agree that the current law doesn't solve the problem. But "educating the…

   This entire argument boils down to "if you don't want to get raped, don't wear short skirts in public".
That's a pretty spot-on analogy and I, for one, am impressed by the depth and nuance you've bought to this discussion.

Re: The stupid cookie law is dead at last

#47

This is just more disinformation and FUD from the anti-privacy marketing clowns at Silktide. Nothing has changed when it comes to the EU rules on tracking cookies. Of course it doesn't help that the UK's authority tasked with enforcing the law is utterly incompetent.

How exactly am I spreading Fear, Uncertainty or Doubt here? (I wrote that article, and run Silktide).

We have no problem with privacy - quite the opposite, I wish it were being taken seriously - but this law is not remotely about that. If you look at the ICO's latest report they say their audit of sites like Facebook and Google was done purely "visually". They are literally evaluating privacy by looking for banners or legal pages, and not at say the technology or intent behind it.

This event is newsworthy because their site - which is clearly going to be looked at as an exemplar of best practice - is changing from explicit opt-in to implicit. Essentially we're now back to 2009, when sites were expected to include privacy policies that explain if they use cookies.

Re: The stupid cookie law is dead at last

#48

I'm sorry but hasn't this been the case for a good while now? I remember seeing this on the Guardian last year: http://www.guardian.co.uk/technology/2012/may/26/cookies-law... And isn't that why sites like The Guardian, BBC etc. have been using a banner anyway?

It's significant because they're the regulator, and now they're changing to do what everyone else is, instead of telling everyone else to do what they've been doing.

Re: The stupid cookie law is dead at last

#49
post #40
post #31

Earlier quoted context omitted.

The basement analogy is flawed. It's like a proxy holding your keys and giving them to anyone that asks, without your knowledge. Education wasn't going to happen without notices like these.

Yes, I wanted to keep it simple. The fact is that that proxy (the browser) is the problem, and is also where the solution lies, not in the subset people that Dutch law happens to apply to who make use of that proxy to obtain your keys.

Making them tell you they want the keys and give you a reason isn't all bad.

But yes, the proxy ought to do more to encourage people. One problem is that two of the major browsers (Firefox and Chrome) are funded by a company that makes all its money from tracking and advertising (google), and it's pretty unlikely they would turn off third-party cookies by default, which I think would be a good start.

Re: The stupid cookie law is dead at last

#50
post #49
post #40

Earlier quoted context omitted.

Yes, I wanted to keep it simple. The fact is that that proxy (the browser) is the problem, and is also where the solution lies, not in the subset people that Dutch law happens to apply to who make use of that proxy to obtain your keys.

Making them tell you they want the keys and give you a reason isn't all bad. But yes, the proxy ought to do more to encourage people. One problem is that two of the major browsers (Firefox and Chrome) are funded by a company that makes all its money from tracking and advertising (google), and it's pretty unlikely they would turn off third-party cookies by default, which I think would be a good start.

I wouldn't be against a law that requires browsers to make third party cookies opt-in. Note also that the current law has no effect on Google's tracking whatsoever.
Post reply on HN