Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

451–460 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#451

Earlier quoted context omitted.

The idea that a site should automatically generate revenue simply for existing, especially when it's relying on unwitting invasion of visitors' privacy in an increasingly illegal manner, is ridiculous at best; malicious and predatory at worst.

The site generates revenue by providing a service. That's why people visit it and that generates the revenue via ads. E.g. an independent news site provides news articles and people visit it. People won't pay for many small sites separately, so until we have a viable alternative (e.g. automatic micropayments) eliminating targeted ads would effectively eliminate independent journalism as well (regular ads pay much les…

The site does NOT directly generate revenue by providing a service to their visitors, nor even by selling space to advertisers. The site generates revenue by selling to 3rd parties intimate access to its visitors without the knowledge or consent of the "average" visitor. It is broken in principle, running afoul of the nature of marketplace regulation and privacy rights.

This is just "the ends justify the means", because the consequences fall on the visitors, not the site owners, advertisers, or data brokers. It's a disgusting, predatory rationalization for offloading the damage while reaping the rewards.

Patreon on its own delivers hundreds of millions of dollars of funding a year. Web ads existed long before individualized tracking, and still are that way in pretty much every other medium (print, billboards, broadcast media, product placement, etc). Independent journalism existed in websites, blogs, pre-monetization youtube, etc as well. Heck, SV investment is available and all about spending money without any real revenue plans anyway. :-P Just this one very particular ad model needs to be ended for everybody, big and small, and the advertising market still has everything else covered. The "big money" sites also still need to monetize somehow (and much more voraciously), and wouldn't be allowed tracking ads, either.

If you can't make money without violating your audience, then you don't get to make money at it, and all scales should be held to the same account if it is genuinely considered an issue of rights.

Re: Cookie Warning Shenanigans Have Got to Stop

#452
post #412

Earlier quoted context omitted.

From your reply I think you did not entirely understand the parent's reasoning. I think you don't follow the consequences of your points to the end, where it becomes visible that they are not desirable. I believe that is what the parent is aiming at.

Instead of just saying that it's obvious, it's visible, etc., can you explain the reasoning?

One scenario is easy to figure out: Once it's simple for poor beggars to sell their kidneys, it becomes normalized and common. It's expected that you'll sell your kidney or you clearly don't need help that badly. The price drops from abundant desperate supply until it's only enough to live on for a few months. A few years down the road and you have just as many poor beggars but all of them are missing a kidney and less resilient to illness.

The root problem here is that if people are put in desperate situations, some amount of choice is forcibly removed from them. Certain agreements can't be fairly negotiated unless you remove the desperation first.

Re: Cookie Warning Shenanigans Have Got to Stop

#453
post #443
post #313

Earlier quoted context omitted.

GDPR is the result of many lessons learned in prior attempts. The EU Commission put particular attention on not repeating the mistakes being made in the Cookies directive, which rendered it essentially useless and only annoying. Fines are to be handed out by the national data protection agencies. In Germany, the data protection agency regularly goes after violators since the 1990s. They audit German administrations a…

It’s rather obvious it learned nothing. After seeing cookies banners, it was entirely evident and predictable that GDPR will result in more aggressive banners. Which it, surprising no one competent, did.

There's one important caveat you're missing: the vast majority of these cookie banners are illegal under GDPR. So yes, it's rather obvious the EU learned a lot.

The law forbids dark patterns, coercing into accepting, delegating opt-outs to third party sites, and requiring collection of more data than is strictly necessary to operate the site.

Re: Cookie Warning Shenanigans Have Got to Stop

#454

This shows utter incompetence and detachment from reality by European legislators. Maybe it seemed like good idea in theory but the only practical significant impact is that browsing the web has become more annoying. Surely there are solutions that don't require a popup on every webpage you visit? For example enforcing no tracking by default for advertising purposes?

The EU has generally been a really positive force when it comes to consumer rights, but I'm not a fan of this either. The question I have is, what did web company do to deserve this kind of regulation? It is quite unusual to see governments enact regulations, without the existence of a measurable harm being caused - but solely on the premise, that the act of collecting data is 'unethical'. I mean this is really not n…

> The question I have is, what did web company do to deserve this kind of regulation?

Have you been asleep for the past decade? Pervasive tracking and spying on consumers has been the topic of discussion even long before that.

EU countries have had data protection laws since late 90s, and the web companies have taken a collective dump on them. So now the EU has created a single law that is quite sensible (if not without flaws) which says: you can only collect the data you absolutely require to work. If you collect other data and especially if you send to third parties, you must ask the person using your site if that's ok.

Oh my, did web company do to deserve this? Oh, I don't know. Open TechCrunch and opt out of ~300 tracking, data collection and ad companies, and tell me what they have done.

Re: Cookie Warning Shenanigans Have Got to Stop

#455

Earlier quoted context omitted.

> Hmm, there are features that one literally can't provide without state (cookies). The biggest lie in most cookie warning popups is that you need to accept them for the site to function. It is often not true. Those are session cookies and you don't need to warn users about them, they're just allowed. I didn't know this, and neither do any of the cookie warnings mention this. So like many people I thought the cookie…

I went through a similar thing which resulted in me removing cookie warnings from all but one of the websites I manage, yet I still believe that the law is stupid. It's like outlawing guns to solve your murder problem without considering all the other murder weapons all while keeping the act of murder itself legal. As far as I understand it, the GDPR does everything and more than the cookie law was supposed to, so IM…

The directive containing the cookie law (ePrivacy) was indeed being revised in 2017. I haven't heard much about it since though. It Essentially enshrined the Do Not Track header into law and also expanded the rules for privacy etc of sms to internet messeging services. I wonder how much of the information in this thread is about the original directive and how much is about the new one.

Re: Cookie Warning Shenanigans Have Got to Stop

#456

In The Netherlands the Data Protection Authority announced this month that websites are no longer allowed to block access when people click "NO" in the cookie warning; Clicking 'no' should still allow people to view the website, but without placing any tracking cookies. Source (in Dutch): https://autoriteitpersoonsgegevens.nl/nl/nieuws/websites-moe...

I haven't read the full decision but I'm always surprised at how little regard European courts have for property rights. If it's my website, I should be able to decide who has access and under what terms. Don't like cookies? No one is forcing you to visit a particular website. I also feel like tech companies could adopt an open standard for cookie acceptance preferencesin web browsers, but they're afraid to lest they…

This is an ignorant position. When you extend an open invitation to the public to enter your private property, it becomes subject to public regulation under common law due to the open invitation. Under civil law, they can just dictate the regulation. Regulations of businesses which are open to the public is not some uniquely European invention.

Obviously you cannot do whatever you want to a person who physically enters your business. This is a facile point. The same is true of websites: simply because a person navigates to your website, you do not automatically have the right to place tracking cookies into their browser.

Re: Cookie Warning Shenanigans Have Got to Stop

#457

As a web developer I gotta say the only true solution to this is to stop using the internet altogether. Might as well shut the internet down. We can't authenticate you without cookies or some other form of identification, so that throws out any site with an account. Even if I am not even remotely interested in tracking what pages you view on my website if I need to have you login and authenticate I need some form of…

Wow, you are a complete moron.

Re: Cookie Warning Shenanigans Have Got to Stop

#458

Earlier quoted context omitted.

> If you want to use external tracking and be GDPR-compliant, you must offer a clear choice ("yes/no") and you must not use pre-ticked boxes (i.e. an opt-out approach) Exactly this. Basically what the GDPR says is: if your business doesn't require the data, you cant use it without the user's consent. And data used for better advertising is NOT essential to e.g. a news site. What's more, the regulation syas that you c…

This is the view of a US person: These are private owned and operated web sites. The site owner determines what is "essential." If you do not agree to to the terms, do not use the site. If you don't want to be tracked for advertising, that's on you to install ad blockers.

If that's how you want to look at it ... you can consider the EU to be making the same offer to businesses "accept our terms or you can not use the EU".

Re: Cookie Warning Shenanigans Have Got to Stop

#459

Earlier quoted context omitted.

The EU has generally been a really positive force when it comes to consumer rights, but I'm not a fan of this either. The question I have is, what did web company do to deserve this kind of regulation? It is quite unusual to see governments enact regulations, without the existence of a measurable harm being caused - but solely on the premise, that the act of collecting data is 'unethical'. I mean this is really not n…

> The question I have is, what did web company do to deserve this kind of regulation? Have you been asleep for the past decade? Pervasive tracking and spying on consumers has been the topic of discussion even long before that. EU countries have had data protection laws since late 90s, and the web companies have taken a collective dump on them. So now the EU has created a single law that is quite sensible (if not with…

how does "TechCrunch" "~300 tracking, data collection and ad companies" impact you?

i'm asking because my government knows everything about me: my private and public IPs, what sites I visit, my comments on those sites, how old I am, how often I go downtown etc etc etc

Re: Cookie Warning Shenanigans Have Got to Stop

#460
post #154
post #145

Earlier quoted context omitted.

So websites are supposed to just absorb the cost? That seems like a ridiculous stance.

No, they're supposed to serve generic, non-tracking ads. Non-targeted, or whatever the terminology is. It's hilarious how everyone has just forgotten that used to be a thing. The people on this website are literally the problem, you can't even conceive of a website that doesn't track every click you make across the whole internet, and you guys are the people building the new web.

It has never been a thing, that's why. Adverts have been targeted for decades before the internet existed at all.

Do you think TV adverts are placed randomly? They aren't. Different times of day have different value to different advertisers. TV ads are targeted based on detailed knowledge of audience demographics.

Do you think billboard ads are placed randomly? They aren't. Their placement is optimised based on the beliefs of the ad firms about who will drive past them or see them.

Do you think internet ads were placed randomly before AdSense? No, they were targeted by rough demographic guessed from the sites content just like TV and billboard ads were.

All that's changed on the internet is that targeted has got more precise and more sophisticated. But there's no bright line separating "generic" from "targeted" ads, like you imagine. And the better targeting is hardly an optional feature like the DPAs seem to imagine. It increases revenues which enables firms to provide new content and new features. Roll back the web to 1990s era ad techniques and now all the ads on generic sites like news or search with no clearly defined audience will be barrel-scraping "punch the monkey" animations, for those of us who remember that stuff.

Post reply on HN