Live data from Hacker News

No Cookie for You

github.blog

471–480 of 634 posts

Re: No Cookie for You

#471

Earlier quoted context omitted.

I can see a need for cookies to mitigate against things like DDoS attacks, session management for paywalled content or just to leave comments on articles, favoriting certain sections. There are several reasons why as a reader you would want the site to be stateful.

How would cookies help mitigate against DDoS attacks?

Helps separate real traffic from DDoS traffic. e.g. traffic from someone that also visited the site prior to the start of the DDoS is vastly more likely to be real traffic.

Re: No Cookie for You

#472
post #465

Earlier quoted context omitted.

> A lot of people have the misconception that the EU cookie law applies to all cookies, but as the blog post correctly points out, that just isn't the case. A lot of people also have the misconception that the EU cookie law applies to them, even if they are not in the EU and have no EU physical presence.

Wait, is that true? You need to have a physical presence in the EU? If so, why did everyone scramble to meet the requirements. Was it a scam?

It's not about physical presence. It's about whether the EU could do something to punish you. For every big company that is true. For example the EU can force Visa/MasterCard to stop doing business with you.

If you're small enough, then the EU won't bother doing anything.

If you don't even depend on any 3rd party that is vulnerable to EU will then you can fully ignore everything. That can be tricky to achieve though. No common money transfer methods and you must be self-hosting.

Also, all of this isn't new. The US has been enforcing its will globally in a similar fashion for a long time.

Re: No Cookie for You

#473
post #465

Earlier quoted context omitted.

> A lot of people have the misconception that the EU cookie law applies to all cookies, but as the blog post correctly points out, that just isn't the case. A lot of people also have the misconception that the EU cookie law applies to them, even if they are not in the EU and have no EU physical presence.

Wait, is that true? You need to have a physical presence in the EU? If so, why did everyone scramble to meet the requirements. Was it a scam?

People get scared of lawsuits, especially if they're from a very litigious country like the EU. Companies lobbied against the law hard, spreading the idea that any visitor of your website could sue you for millions because you sent a cookie header. Reality is much less scary for most decent people.

Technically, the law applies to everyone worldwide, regardless of location. However, if you have no business in the EU and don't plan to expand your current business operations to the EU, you don't need to worry.

Hell, if you don't meet the requirements, the relevant enforcement departments generally give you plenty time to implement the necessary requirements or block access if you're a dick. The exception, of course, is data brokers and huge companies like Facebook or Google where the impact is much larger.

The GDPR doesn't expose you to lawsuits from anyone but the privacy monitoring instances of EU member states. The average American blog or news site isn't nearly large enough for any government instance to start a lawsuit.

You can also ask yourself: so what if they fine my company a €10.000. They're not going to send a team of special forces over the Atlantic or through Russia just to extract the cash from you. You only need to pay the fine if your company ever needs to do business in the EU. If your company structure makes your personally liable, this also impacts your future holiday destination decisions, but you can live perfectly fine without seeing the Eiffel tower.

A lot of very similar laws are also being passed in California right now, which will probably be a lot more dangerous than any GDPR restriction, but if you follow the GDPR you're pretty much set to protect yourself from Californian lawsuits as well.

Most of the GDPR is just "don't be a dick with people's data". If the fear of not meeting requirements stops the free-for-all data exchange market, then I'm perfectly fine with that.

Re: No Cookie for You

#474
post #465
post #3

A lot of people have the misconception that the EU cookie law applies to all cookies, but as the blog post correctly points out, that just isn't the case.

> A lot of people have the misconception that the EU cookie law applies to all cookies, but as the blog post correctly points out, that just isn't the case. A lot of people also have the misconception that the EU cookie law applies to them, even if they are not in the EU and have no EU physical presence.

The GDPR applies to anyone anywhere processing personal information (such as IP addresses) of people inside the EU (both EU and non-EU residents).

That doesn't mean that you're necessarily at risk of any lawsuits or effective action, but what you're stating is wrong. Physical presence has nothing to do with it.

Re: No Cookie for You

#475
post #322

Earlier quoted context omitted.

Microsoft/GitHub as businesses incorporated in the United States are bound by the law of the United States. I am not sure of what you are insinuating here.

Oh, great, they have an excuse. Just like they have an excuse for allowing the NSA direct access to all of your data, right?

Yes, I don't understand this weird movement where businesses are expected to go against the government.

You disagree with your own government that's perfectly fine, and for the record I agree with you on the issues themselves, but if you want embargoes against Iran to be lifted or for the NSA to stop hoarding Americans' data you have to do the boring work of convincing the people to vote for people who share those ideas.

Real change will not come from corporations, it simply cannot because their mission if profitability, they support movements if there is no financial risk to do so.

Re: No Cookie for You

#476
post #404

Earlier quoted context omitted.

That depends on what personal data they're collecting and for what purpose, in the case that a person hasn't explicitly opted-in by giving consent freely. I don't think it's possible for us to figure those details out exhaustively merely by observation from the outside.

Yes, and it's not like the EU is going to send surprise inspections to go dig into Microsoft's code and databases to check whether they are violating this or not?

Sure, but it's also likely that Microsoft's lawyers allowed the Github team to do this if they didn't think that Github was still in compliance.

Re: No Cookie for You

#477

Earlier quoted context omitted.

No, it applies to every resident in EU and EU citizens all over the world. Edit: https://gdpr-info.eu/art-3-gdpr/ ("where Member State law applies" and "subjects who are in the Union" [...] "regardless of whether the processing takes place in the Union or not" respectively) Edit 2: https://gdpr.eu/companies-outside-of-europe/ for more info: "The whole point of the GDPR is to protect data belonging to EU citizens and…

What about former EU residents? (such as the Brits; or foreign residents)

The GDPR is implemented in British law, that's how these directives work.

Once the UK leaves the EU, they're no longer obliged to keep their implementation of the GDPR. The government can choose to keep their implementation, and in practice keep the same regulations as the GDPR, or they could reduce or remove their privacy protection laws as they see fit.

With London being famous for their camera surveillance, I expect the UK to reduce some if not all of the privacy protections the GDPR brought to the world.

Re: No Cookie for You

#478
post #243

Earlier quoted context omitted.

Good lord, everyone needs banners and popups? Why not just let browsers controls who sets what cookies? I'm tired the endless cookie popups, can we come up with an "allow cookies if the browser accepts them" standard as long as that guarantees no cookie popups? Then browser vendors can ship a delete all non same origin cookies on tab close or something.

Two objections. 1. A law that aims to prevent stealing should be deterring thieves, not just regulating padlocks. 2. Technical measures are insufficient because cookies are regulated by purpose . A third-party cookie for fraud detection is allowed; a first-party cookie for analytics requires consent. It also prevents using necessary cookies for secondary purposes, something that literally cannot be accomplished throu…

The reason you are provided many free services is because you ARE tracked / analyzed and marketed to. That is the CORE of the business. The popup will say, do you accept this cookie and being tracked to use this free service. Everyone literally clicks yes. I can't believe the billions of wasted clicks and manhours that have gone into this charade.

Re: No Cookie for You

#479
post #324

Somehow the rest of the internet was sold to the idea of "EU is forcing you to put cookie banners, these are nothing but annoyance" rhetoric. Whoever pulled that off, bravo! In reality, the idea was to make people aware that they are being tracked across the web and and give them options and somehow everyone pretended that "No tracking, no banners" is not an option. I am so glad that GitHub is coming forward and poin…

they are an annoyance because they are redundant, out of band, and pass the burden onto individuals who have no authority.

They are like CA Prop 65 lead warnings: useless spam that everyone ignores.

Re: No Cookie for You

#480

This is fantastic. Thank you, GitHub. I hope this is a good demonstration of a hands-off approach at Microsoft in regard to company culture. I realize you likely still collect some analytics for yourself and that this change does nothing to alleviate that. EG, first party javascript. But it's great that it's divorced from 3rd parties. Presumably Microsoft has access to those metrics, though? I wonder how deeply that…

> I hope this is a good demonstration of a hands-off approach at Microsoft in regard to company culture.

I might 1‰ buy that if they restored the Widevine repos they snuck down for Google under cover of the controversy caused by complying with the MS-funded RIAA’s quasi-legal youtube-dl takedown request.

Post reply on HN