Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

51–60 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#51
Everything in California is labeled carcinogenic, and so nobody pays it any mind, but it's still done anyway because that's what regulations and the law say. Similarly, this isn't just a bunch of people who operate websites deciding to write these wacky cookie banners because they think people really care about cookies.

When I implemented one of these it was because lawyers told my team to do it. We didn't want this, neither as developers nor as users of websites. Neither were our designers thrilled at the prospect of cluttering up our site with this dingus.

I get that this is just a general rant, and I agree that people just click through them and don't actually care. But it's important to keep in mind how this actually came about, and (as a somewhat separate point) that lots of things in our society operate this way. Which is not intended as a defense, but it's more common than just cookies.

Or do you read every terms of service document shoved in your face when you sign up for something?

Re: Cookie Warning Shenanigans Have Got to Stop

#52

It's time GDPR is actually enforced. I tried to get my country's law enforcement on the tail of some violators but they're toothless . I don't understand the downvotes though, are you disagreeing that certain countries do not have the manpower to enforce GDPR to the extent they could? Please.

Are those violators outside the EU? I'm interested to know if the EU would seriously try to enforce their laws in foreign lands that never agreed to them.

Re: Cookie Warning Shenanigans Have Got to Stop

#53

Earlier quoted context omitted.

GDPR absolutely does not do "more harm than good". It extends well, well beyond these dumb cookie warnings. GDPR puts the citizen/customer in power of their own data. They can ask for their data, they can ask for it to be deleted, they have (however shitty the UX) control over where it goes. They can contact large corporations and request these things and be heard out . I don't know how to explain it any other way: T…

You beg the question by saying it's "their own data" in the first place. The idea that, because it's about you it's therefore yours, is wrong.

The famous difference between citizen-first EU and corporation-first US. Over here, we do believe that our data is ours. This is reflected in our legislation and regulation.

You don't want these rights and protections in the US? Well good news, you don't have them. They still apply to us however.

Re: Cookie Warning Shenanigans Have Got to Stop

#54

I find the clarification about cookie walls being out of compliance with GDPR to be a real headscratcher. Here's part of the Dutch authority's FAQs[0] thanks to Google Translate: "At a cookie wall, website visitors have no real or free choice. It is true that they can refuse tracking cookies, but that is not possible without adverse consequences. Because refusing tracking cookies means that they cannot access the web…

No, it's not a free choice. You cannot pay with your personal data the same way that you cannot sell yourself into slavery, even if you wanted to.

These cookie notices are also almost invariably violating the GDPR. There must be a clear choice, and if you choose not to be tracked, you must be able to still use the service unimpeded; then there must be a clear and understandable description to the intents of data collection; and lastly, the opt-out choice must be accessible equally simply as the opt-in choice (none of this "Accept" vs. "Manage options" bullshit.) For example, one of the very few larger pages where I've seen it done right is Wikia/Fandom.

> Am I allowed to offer users additional functionality in exchange for access to their data?

In a way, yes, but you're phrasing it in a roundabout way. You can ask for personal data to enable additional functionality that requires that data. For example, you're allowed to ask for location if you want to show them some offers nearby. They are allowed to refuse and in that case they cannot use the particular function that's tied to their realtime location. If they've given permission to use their data, you, however, are not allowed to use that location data for any other purpose other than what they explicitly agreed to and what's actually needed to provide the service. I.e. you can ask for the location to provide a location based service but you don't need their age and income data; also you cannot use their location for other purposes they aren't informed about. And you certainly aren't allowed to sell it to someone else without an express permission.

In short - you need a clear and explicit permission for specific purposes, and you cannot deny access to those parts of your service that don't require personal data.

Re: Cookie Warning Shenanigans Have Got to Stop

#57

What I don't understand is why websites hosted outside the EU, for non-EU users have the cookie banners. At least keep it in Europe, use the IP to geolocate, let the EU users deal it. Some companies have outright banned EU traffic, sounds like only showing the banners for EU IPs seems ok.

The law doesn't just apply to pages being served to the EU, it applies to pages being served to EU citizens, wherever they happen to be at the moment.

So geolocation is not a satisfactory option.

Re: Cookie Warning Shenanigans Have Got to Stop

#58

I find the clarification about cookie walls being out of compliance with GDPR to be a real headscratcher. Here's part of the Dutch authority's FAQs[0] thanks to Google Translate: "At a cookie wall, website visitors have no real or free choice. It is true that they can refuse tracking cookies, but that is not possible without adverse consequences. Because refusing tracking cookies means that they cannot access the web…

I am befuddled by your befuddlement. Consumer protection laws regularly put limits on the freedom of contracts between companies and consumers. A rental car agency can’t give you a rebate for renting an unsafe car. The fact that no money changes hands doesn’t change this. If you’re offering free taster portions of bread to passer-bys, you can not use lead as an ingredient. Neither being free, nor putting up a sign wi…

Agreed, but these rules are clearly defined, make sense to the common man and actually lead to what they should lead to, namely that I can, with great confidence, eat anywhere without being poisoned.

GDPR is terribly vague and creates a barrier-to-entry. Draconian measures may hurt large companies, but they threaten smaller ones.

EU is saying they don't like Silicon Valley behemoths' power but they want valley-like companies in the EU (sometimes even calling for a 'European Google', as if you could just pass a rule to make that happen). And then they create laws that make it easy for the large players and harder for their competition.

Everyone here spent a great deal of money for some compliance boo-hoo. FAANG has your consent and upgrades their policy, done.

To me, this seems like ineffective and incompetent lawmaking, no matter if the intentions were sound.

Re: Cookie Warning Shenanigans Have Got to Stop

#59
Well, only somebody completely out of touch with reality (=government folks) wasn't able to predict outcome of this law.

Good thing that there are browsers extensions which take care about removing these "cookies" notification so I don't have to deal with it.

Regular users absolutely do not care about privacy,cookies GDPR etc. When events like "cambridge analytica" occur they will be enraged, maybe even some "thumbs down" and "angry face" emotes will appear under facebook news notification before scrolling further down! Probably for HN users it is hard to comprehend because you are looking at the world from inside of your knowledge bubble.

More knowledgeable users know that this is total farce and masquerade and don't care about cookie notifications too.

Post reply on HN