Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

401–410 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#401

Earlier quoted context omitted.

Whether we like it or not, tracking data used for ads is the currency of the free internet. It is how things are paid for. This is like a government saying to a restaurant "You can't discriminate against people who don't want to pay you money for the food. You can ask them if they are willing to give you money for the sandwich, but if they say no, you still have to give them the sandwich"

Tracking is not necessary to make money online. It’s just helpful. It’s more like the government saying, you can’t discriminate against people who demand that their food is cooked in a kitchen that isn’t filled with cockroaches. It’s going to hurt the bottom line, and might kill some businesses, but it doesn’t reduce to a prohibition on making money.

> It’s more like the government saying, you can’t discriminate against people who demand that their food is cooked in a kitchen that isn’t filled with cockroaches

What?! Are you seriously speaking of prohibiting cockroaches?

Cockroaches are everywhere! They are essential to survival of businesses! And it would be impossible to completely get rid of them anyway. Prohibiting cockroaches in public restaurants would push immense cost upon eaters. Without cockroaches how could we possibly get rid of the food waste, that routinely accumulates in kitchens? Do you expect us to spray our kitchens with toxic pesticides? To hire some specialized people of to lick food scraps off kitchen stoves with their bare tongues?? Insane!

Clearly, you are the enemy of the people.

Re: Cookie Warning Shenanigans Have Got to Stop

#402

I find the clarification about cookie walls being out of compliance with GDPR to be a real headscratcher. Here's part of the Dutch authority's FAQs[0] thanks to Google Translate: "At a cookie wall, website visitors have no real or free choice. It is true that they can refuse tracking cookies, but that is not possible without adverse consequences. Because refusing tracking cookies means that they cannot access the web…

No, it's not a free choice. You cannot pay with your personal data the same way that you cannot sell yourself into slavery, even if you wanted to. These cookie notices are also almost invariably violating the GDPR. There must be a clear choice, and if you choose not to be tracked, you must be able to still use the service unimpeded; then there must be a clear and understandable description to the intents of data coll…

>You cannot pay with your personal data the same way that you cannot sell yourself into slavery, even if you wanted to.

So, what you're telling me is that GDPR actually limits my rights as a private citizens because that think I'm too stupid to make my own decisions? I guess I shouldn't be surprised.

Re: Cookie Warning Shenanigans Have Got to Stop

#403
Troy’s statement that accepting one advertiser’s agreements means accepting all their partners’ agreements, and all their partners agreements, and so on is interesting.

It lead me to the idea that it might be interesting to build a bot that builds a “consent graph” which will tell you exactly how many (and perhaps draw connections visually) different companies you have to provide consent to from a given advertiser/company/website.

This is a pretty interesting argument against the clumsy rules of GDPR which exist, in my opinion, practically entirely outside reality.

Re: Cookie Warning Shenanigans Have Got to Stop

#404

Earlier quoted context omitted.

There was e-commerce before cookies. The same functionality of correlating multiple requests for a single request (building sessions upon packets) was just more difficult to use by encoding the session ID as a parameter in query string for each request. Many frameworks still support this mode.

Cookies pre-date SSL, so how were they securing that e-commerce that existed before cookies?

By using secure networks? PPP is older than SSL and have been in widespread use for longer time.

SSL is largely irrelevant to banking security anyway. Actual security is built upon charge-back system. The underlying security model was designed when everyone trusted written checks.

Re: Cookie Warning Shenanigans Have Got to Stop

#405
post #378

Earlier quoted context omitted.

HN doesn't have ads though.

Don’t they have hiring advertisements for their startups?

True, but very different. That’s not the highly-targeted, audience-segmented approach to advertising that parent commenter (and most people on the internet) is referring to by saying “ads”.

Re: Cookie Warning Shenanigans Have Got to Stop

#406

Earlier quoted context omitted.

So once you've determined that you like a site you are going through the hassle of figuring out how you can reenable the tracking after you disabled it on your first visit?

“you’ve visited this site a few times recently. are you still okay with these settings? (if you ever change your mind, click privacy at the bottom of the page)” just because we don’t currently have solutions doesn’t mean they aren’t out there. i guarantee my 5 second developer definitely not UX idea is the LEAST that a real UX professional will come up with, when pushed *EDIT: and yes this kind of cookie is okay with…

It can also be implemented purely on the client side: store the counter in the browser, increment on each visit, and prompt the user after N visits.

This way, no information about the client is sent to the server at all.

Re: Cookie Warning Shenanigans Have Got to Stop

#407
post #148

Earlier quoted context omitted.

Could say Germany, decide differently? GDPR seems like it could evolve quite quickly, and sort of fork a bit here... Also makes me wonder, do they have to have access to the whole site? This feels like a war on cookies, and there are bad things done with cookies, but I'm not sure if they're fighting on the right front long term here. If people simply just say yes all the time / don't know, not sure we're making progr…

> This feels like a war on cookies, and there are bad things done with cookies, but I'm not sure if they're fighting on the right front long term here. Problem is will-full misinformation. It's a war on tracking cookies, not session cookies for login state, etc. But all the cookie warning dialogs make it sound like it's a war on all cookies no matter what, so "just accept because otherwise this site won't work, also…

Maybe I'm just dense but I have my doubts that there are many cookie prompts that are intended to push misinformation about "cookie law".

Re: Cookie Warning Shenanigans Have Got to Stop

#408

Earlier quoted context omitted.

The news site was an obviously over-the-top example, but the more realistic $1,000,000 offer would be just as illegal. The rational reason for that is that in the real world, not all choices are made by perfectly rational, superhumanely intelligent actors that have and consider all the information. Also, not all decisions on a free market are truly freely made. If all standard housing/mortgage contracts contain that…

> With data on web sites, it's the same. Almost every web site collects data. You don't realistically have the option of going to a different news site if you don't like that deal. You have plenty of choice: make your own, feed them wrong information, feed them no information or find a site that doesn't. If enough people care about this niche then your website would succeed.

I don't agree. None of these is a real option.

- I cannot just make a website or service. It is usually a huge project that only few people can solve.

- I have no way to feed wrong information without diving very deep into that website's code. We are not just talking about data I enter, also about things that are collected without conscious effort on my part. It is not practical at all to feed false or no information. If they sell my IP address, how can I feed wrong or no information?

- Finding a site that does not act like this is the only way left, and it is exactly what the parent explained does not exist, because realistically, there are many topics for which virtually every site does act like this.

Re: Cookie Warning Shenanigans Have Got to Stop

#409

To add insult to injury the big players with most trackers just refuse to show the cookie warnings at all. At least that's the situation Germany where most major news outlets are full of ads and trackers and handle all of it via opt-out(!) in the privacy policy. For a example see spiegel.de, the most widely read German-language news website. It's mostly small and medium sized firms that show the cookie warning out of…

Spiegel.de also sometimes refuses to serve you content if you have DNT flag set which in theory would be a convenient way of getting rid of cookie banners.

Re: Cookie Warning Shenanigans Have Got to Stop

#410

This shows utter incompetence and detachment from reality by European legislators. Maybe it seemed like good idea in theory but the only practical significant impact is that browsing the web has become more annoying. Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes?

I've rather radical thought: I don't think tracking itself is fundamentally a bad thing. I rather see useful relevant ads then irrelevant ones. Yes, it may be creepy but its not a bad thing that people in ad industry are working hard to figure out things that would be worth my time and interest. However, what is bad is how else is tracking data used? Who else has access to it and for what purpose? GDPR should have created law that tracking data may not be used for anything other than machine generated recommendations by same company and it would have been 1000X more beneficial.

Downvotes may begin now.

Post reply on HN