Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

411–420 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#411

Earlier quoted context omitted.

Thanks for this, it seems a lot of cookie popups are there just due to cargo culting

I don't quite think Cargo Culting is the right label for it. It's not just because everyone's doing it. My experience when legal meets code is that common sense, intent and what is actually allowed go out the window, and cover-your-ass wins. My experience with Legal has been that they default to no "just in case" for every question you come to them with. It's a battle to get them onboard to not taking the safest poss…

Yeah, people often approach legal in the wrong way: people often want to ask "is this OK?" and have the lawyers say "yes", but basically no lawyer is going to say that for almost anything. Instead you need to ask them to explain what the risks of different courses of action are and take a view as to whether they are important or not.

Re: Dear Paul Graham, there is no cookie banner law

#412
post #127

Earlier quoted context omitted.

Using your analogy, I think what ends up happening is that even companies that don't collect hidden fees will put up a banner just in case. Not only that, I'm not an EU citizen and I'm not browsing websites based in EU but I'm still bombarded with cookie banners non-stop.

Do you have /any/ examples of websites that don't have a bunch of 3rd party cookies that still have a cookie banner? Middle managers absolutely love anything with charts and graphs because it makes their decisions feel more scientific. That's why they want tracking software included on their websites. And if the law requires disclosure then a cookie popup is the solution.

Aggregate data is not considered personal data by the GDPR.

Managers and everyone else can have charts and graphs without retaining personal data.

The processing of personal data prior to anonymisation to turn it into aggregate data, that part needs protection. But you can do it in a variety of ways that don't require personally invasive tracking.

Re: Dear Paul Graham, there is no cookie banner law

#413
post #172

Earlier quoted context omitted.

The reality is that most people don't want to be tracked: https://arstechnica.com/tech-policy/2021/07/facebook-adverti...

I've stopped going to Ars Technica exactly because their cookie pop-up lets me know that Condé Nast wants to share my data with at least (according to the popup) 159 partners. They have so many "partners" that their cookie popup comes with a search bar. 56 of their "partners" want my precise geolocation data! 16 "partners" want to actively scan my device! 101 "partners" want to "match and combine data from other data…

> The only way I can really object is to close the tab, so that's what I do.

Isn't it too late by then?

Re: Dear Paul Graham, there is no cookie banner law

#414

Earlier quoted context omitted.

> The issue is that enforcement is slow, not that the law is badly written. The enforcement/implementation of a law is so deeply entwined with the text that it's deceptive to separate them. If a law is written in a way so as to make enforcement hard, or if the government doesn't have the resources to quickly and consistently apply it, then it's a bad law because it enables weaponized targeted/selective enforcement of…

[flagged]

I'm very clearly not conflating the legislature and judiciary, as evidenced by the fact that I differentiated between them in my comment.

> a lack of resourcing to quickly enforce laws makes those laws bad

Is true, and you haven't refuted it, only used the emotionally manipulative phrase "bad faith argument".

Re: Dear Paul Graham, there is no cookie banner law

#416
post #227

Earlier quoted context omitted.

What do you mean by "the original (now decades-old) law" ? The GDPR is 8 years old.

The ePrivacy directive, mostly referred to as "Cookie law" is from 2002. https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A...

Yes. Although in fairness, the "cookie rule" part has been updated since then. But not anytime recently.

And the GDPR's subsequent entry into force created the current emphasis on how actively (and individually) you need to consent to things, and how much you have to be told about them first. Stuff like "clicking anywhere on this site, tells us you consent" was a lot more common, pre-GDPR

Re: Dear Paul Graham, there is no cookie banner law

#417

Note that this isn't a cookie law, it's also the EU's main anti-malware law. The principle is that no piece of third-party controlled software should write information to your computer/phone, or read info from it, over the Internet, without your prior informed consent (with narrow exceptions for storage/reads that are needed to provide a service you've asked for, or equally narrow functions like load balancing). This…

> Note that this isn't a cookie law, it's also the EU's main anti-malware law. The principle is that no piece of third-party controlled software should write information to your computer/phone, or read info from it, over the Internet, without your prior informed consent So it is a responsibility of the browser vendor to implement this.

No moreso than the OS itself. The real responsibility actually lies with the people causing the remote access (e.g. the website operator, the remote hacker, etc).

Re: Dear Paul Graham, there is no cookie banner law

#418
Paul Graham is right still.

Eu bureaucrats could have expected that many companies _need_ tracking to survive.

While most people do not actually care about tracking.

Not to mention that behind most companies are the people who earn their living. By honest work (advertising is not guns smuggling you know).

So eventually those stupid bureaucrats didn’t really solve anything, but made life slightly worse for everyone.

Which proves original Paul’s point.

Re: Dear Paul Graham, there is no cookie banner law

#419
post #91

Hate this way of thinking where the government (with seemingly good intentions) tries to stop something but leaves a loophole where all our lives are made more tedious and then people defend it saying the companies should just not do it, well we needed the law in the first place so it's a bit silly thinking to suggest they stop doing it after the law, no?. If the cookie law was written properly then it would have jus…

The law isn't that bad actually, just that the courts have been very slow. The dark UI patterns are actually illegal and have been judged so in court now. This realization just has to trickle down to the companies writing these cookie banners.

> The law isn't that bad actually

I've clicked 3 cookie banners today alone and its not even 2pm yet.

How many cookie banners have I clicked in my life so far? How many cookie banners can I expect to click over the remaining 40-50 years of my life?

The law is objectively bad.

Re: Dear Paul Graham, there is no cookie banner law

#420

Earlier quoted context omitted.

I don't quite think Cargo Culting is the right label for it. It's not just because everyone's doing it. My experience when legal meets code is that common sense, intent and what is actually allowed go out the window, and cover-your-ass wins. My experience with Legal has been that they default to no "just in case" for every question you come to them with. It's a battle to get them onboard to not taking the safest poss…

Yeah, people often approach legal in the wrong way: people often want to ask "is this OK?" and have the lawyers say "yes", but basically no lawyer is going to say that for almost anything. Instead you need to ask them to explain what the risks of different courses of action are and take a view as to whether they are important or not.

That's been my experience, but unfortunately _that's_ where cargo culting comes in. As part of $NEW_WEBSITE_CHECKLIST we have to "check with legal" which inevitably involves a laundry list of stuff like this, and the default is to accept what legal says, unless we _really_ don't like the answer at which point we're going to do it anyway...
Post reply on HN