Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

451–460 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#451

Earlier quoted context omitted.

Yeah, people often approach legal in the wrong way: people often want to ask "is this OK?" and have the lawyers say "yes", but basically no lawyer is going to say that for almost anything. Instead you need to ask them to explain what the risks of different courses of action are and take a view as to whether they are important or not.

That's been my experience, but unfortunately _that's_ where cargo culting comes in. As part of $NEW_WEBSITE_CHECKLIST we have to "check with legal" which inevitably involves a laundry list of stuff like this, and the default is to accept what legal says, unless we _really_ don't like the answer at which point we're going to do it anyway...

Legal counsel is there to advise, not to design product UX. Some companies have bonehead policies like “you must develop whatever Legal advises” but that’s a choice the company is making. Sensible companies treat their in house counsel as advisory, and weigh the risks like they would weigh any other risks.

Re: Dear Paul Graham, there is no cookie banner law

#452

Earlier quoted context omitted.

It's not supposed to make sense, it's supposed to show the absurd position of the post I'm replying to. The less it makes sense, the better. And I only picked Germany, because it's one of the few EU countries where stuff like that is rigorously enforced. In the rest of the EU, everything unrelated to the common market and/or getting money from the EU is at best haphazardly enforced. If you want to, check out france.f…

I get no overlay on france.fr

Me neither, unless I disable ad blockers and anti-annoyance extensions.

Re: Dear Paul Graham, there is no cookie banner law

#453

Earlier quoted context omitted.

A site can serve ads without tracking (and the banner) - the ads just couldn't be targeted at individuals. Instead they'd have to guess what ad was appropriate ("Rolling Stone" could serve everybody ads for Taylor Swift's latest album without a banner, etc).

>> A site can serve ads without tracking (and the banner) - the ads just couldn't be targeted at individuals. The biggest problem with online advertising is not tracking users. It's a lack of trust between advertisers and pretty much everyone else. If you're going to pay for an ad, you want to be sure it was seen by a real person. I'm not sure that's the concern any more because click-through is more important than "…

Embedded banner ads with a third party sampling the site to see that ads are fairly displayed according to paid quota. Maybe something like that?

Re: Dear Paul Graham, there is no cookie banner law

#454
post #296

Earlier quoted context omitted.

If it only were that simple. When the GDPR came out, a lot of confusion and misunderstanding ensued. Not only regarding the damn cookie banner. Even totally legitimate health-care providers started to collect signatures to be on the safe side. I still rememeber receiving a basic GDPR training where we were told that opt-out/signing is only necessary if the entity is planning to do weird stuff with your data. IOW, if…

> they are made to sign things which essentially reduce their rights... But not as much as you might think. Consent under GDPR only applies to what you were informed of when you consented, and you're allowed to revoke consent (with prospective effect) at any time.

Yeah, but these are rather theoretical practicalities. In the majority of cases, consent is coaxed out of the consumer. If you show up for a MRI, and you get a piece of paper with the comment "It is for data protection", almost nobody has the time or nerve to actually read the text, and even less people have the inclination to decline to sign. After all, they (sometimes desperately) need the service. Let alone that the accompanying comment is deliberately phrased such that some people will believe they need to sign in order for their data to be protected. Dark patterns all over the place. My bank implemented the consent (for a while) as a reoccuring pop-up after login. Yes, you get the popup as long as you decline to sign it, over and over again. I think they gave up on that practice, and it was partly a dark pattern (IOW, there were two buttons to decline to sign, and one would result in the popup reoccuring). Examples are all over the place if you walk an EU country with open eyes.

Re: Dear Paul Graham, there is no cookie banner law

#455

Earlier quoted context omitted.

It's not supposed to make sense, it's supposed to show the absurd position of the post I'm replying to. The less it makes sense, the better. And I only picked Germany, because it's one of the few EU countries where stuff like that is rigorously enforced. In the rest of the EU, everything unrelated to the common market and/or getting money from the EU is at best haphazardly enforced. If you want to, check out france.f…

I get no overlay on france.fr

Shows for me - https://i.imgur.com/c8c3MDk.png

Re: Dear Paul Graham, there is no cookie banner law

#456
post #205

Earlier quoted context omitted.

> Unfortunately a non-negligible number of people in tech also have libertarian leanings Why is this unfortunate? Because you don't agree with us? The "they would agree with me if they were smarter" trope is tired and gets us nowhere.

> Why is this unfortunate? GP answered your question, for some reason you decided to cut the quote right before the answer. Here is the part that is missing from your quote which answers your question: '[...]with a default “gubmint bad!” position'

Perhaps you should consider the possibility that the reason why libertarians assume a default "gubmint bad!" reaction to new policy interventions is that they are sensitized due to decades of experience seeing multitudes of government interventions both (a) to achieve their intended outcomes and (b) create unintended consequences, often worse than the problems they are meant to solve, instead.

Personally, I find it very very strange that many of the people who call for regulation as a remedy to perverse incentives manifest in commercial markets seem unwilling to recognize the existence of even more perverse incentives in the political realm. If people seeking profit sometimes do bad things to get it, why would people seeking political power be expected to behave differently?

Re: Dear Paul Graham, there is no cookie banner law

#457
post #203

Earlier quoted context omitted.

The blog clearly works from the actual outcome lense. It's repeated. Several times. The companies could just not track . The actual outcome is that they do want to track, and use adversarial patterns and malicious compliance to twist your arm and "force consent." Paul Graham is still wrong.

>The blog clearly works from the actual outcome lense. [...] The companies _could_ just not track. No, you've inadvertently stated a contradiction . Your use of the word _"could"_ is literally a hope/wish/intention of the law. In contrast, the actual outcome is that the companies didn't stop tracking. We _wish_ they would stop tracking. (I.e. "The companies _could_ just stop tracking us!") But that hope still doesn't…

But companies have stopped tracking (or they've started lying). I can now opt out. I could not before.

Re: Dear Paul Graham, there is no cookie banner law

#458

Is it just me or does someone else finds it curious that a post with 414 points in 2 hours and many comments is on page 2? There are posts with less points, and less comments in more time that are on the first page. Is the HN ranking algorithm public?

It's now magically made it to page 6, seems a bit odd

Re: Dear Paul Graham, there is no cookie banner law

#459

Earlier quoted context omitted.

As far as I can tell, politicians don't spend much if any time thinking about second and third order consequences. GDPR is but one example, but instances of this abound. The default should be to mistrust new laws. Reagan takes lots of flak on the internet, but he was right on the scariest phrase being "I'm from the government, and I'm here to help". Even worse, this thread is full of armchair lawyers that will confid…

Even worse, this thread is full of armchair lawyers ... Any actual lawyer would tell you Assuming you're not yourself a lawyer, doesn't speculating about what an actual lawyer would say or do make you an armchair lawyer?

No one only needs to be familiar with lawyers themselves to speculate about what they might do. They are a cautious bunch. This is distinct from dispensing legal advice.

Re: Dear Paul Graham, there is no cookie banner law

#460

Earlier quoted context omitted.

The blog clearly works from the actual outcome lense. It's repeated. Several times. The companies could just not track . The actual outcome is that they do want to track, and use adversarial patterns and malicious compliance to twist your arm and "force consent." Paul Graham is still wrong.

Can you really say that confidently? I think a lot of these companies would go out of business if they didn't track users so it seems like under the law they have no option but to show cookie banners. Or are you claiming the law exempts companies in such circumstances?

I'm sure illegal/unethical actions would help a lot of struggling companies.
Post reply on HN