Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

521–530 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#521
If you don't want websites to store (1st, 2nd or 3rd party) cookies then such behavior could/should simply be controlled within the browser. Just turn off cookies (although the browser cookie control options could be improved).

If I'm allowing my browser to set cookies, I don't need an EU law forcing websites to ask me everytime if I'm ok with a cookie being set.

Re: Dear Paul Graham, there is no cookie banner law

#522
post #404
post #173

Earlier quoted context omitted.

I used to work at an online video advertisement company, you'd be horrified how much information we tracked across all the ads, especially since the ad was played with a special media player "plugin" loaded inside the other media player. This is how ad companies can sell premium views, don't show cosmetics to men, increase car related ads to people who has watched other car related ads and so on. There's no such thin…

> This is how ad companies can sell premium views, don't show cosmetics to men, increase car related ads to people who has watched other car related ads and so on. It's really not. They already could do all that before cyberstalking was normalized. It's called content-based profiling, and it doesn't require any GDPR consent.

The ad companies wanted to aggregate information across multiple channels.

The example about "show more car ads to someone who watched other car ads"? It's not about showing car ad on a site whose content is about cars (or where the site owner decided they like that kind of thing).

It's about knowing you have wandered over to car comparison site recently so they can show you car advertisements when you look up sports news, show car-related merchandise when you're browsing some shopping site, show you insurance ads, etc.

Re: Dear Paul Graham, there is no cookie banner law

#523

Earlier quoted context omitted.

> The only way I can really object is to close the tab, so that's what I do. Isn't it too late by then?

Legally no, they can't store his data if he doesn't click yes.

Considering their consent banner isn't legal under GDPR anyway, I'd be wary of expecting them to be compliant with that either.

Re: Dear Paul Graham, there is no cookie banner law

#524
post #70

>, Paul Graham came up with the thought, that the EU forces companies to have cookie banners. There is no law for cookie banners. [...] Companies could easily avoid any cookie banner. Just don’t track. KingOfCoders/amazingcto, of course you are technically correct but Paul Graham wasn't talking about the letter of the law. Instead, you have to interpret his complaint with the lens of game theory . I.e. The Law of Uni…

The outcome would be much better if the law explicitly stated that the initial cookie banner must have a "Necessary cookies only" opt-out one-click option. And that this option means truly necessary, not the Internet Explorer is needed by the operating system 'necessary'.

Re: Dear Paul Graham, there is no cookie banner law

#525

Earlier quoted context omitted.

Governments are supposed to represent the whole of society. The justification for their policies is ideally based on democratic legitimacy. No entity outside of government can possibly have that legitimacy. In my opinion it is not audacious at all to reject the idea that corporations should intentionally pursue societal goals or claim to act out of a sense of duty. Of course we want the effect of what corporations do…

> In my opinion it is not audacious at all to reject the idea that corporations should intentionally pursue societal goals or claim to act out of a sense of duty. I still find it somewhat silly to reject the idea that a corporation (run by human beings) shouldn't intentionally be evil for the sake of maximizing profit, but I do understand that this is a fairly common Friedman-esque point of view. But, even so, I gues…

>I still find it somewhat silly to reject the idea that a corporation (run by human beings) shouldn't intentionally be evil for the sake of maximizing profit, but I do understand that this is a fairly common Friedman-esque point of view.

On a very general level, the idea is that not every part of a complex system has to incorporate all the principles of the system as a whole. Individual parts of the system can have limited roles and responsibilities. That's fine and it has nothing to do with being evil.

Defense lawyers must defend their clients to the best of their ability whatever horrible things they may have done. Juries, judges, prosecutors, they all have their specific roles to play.

It's the justice system as a whole that should result in justice being done. If everyone involved tried to pursue their own interpretation of generally desirable societal outcomes, the justice system would be unfit for purpose.

And here's the asymmetry again. Those designing the system as a whole have to think about societal outcomes as part of their job (as does every citizen). Those acting in a specific defined role as part of the system can only do that in limited ways or under exceptional circumstances.

Corporations are run by people, but these people act in a limited role that is defined in such a way that pursuing specific societal outcomes does not necessarily boost the likelihood of their personal success or the success of the corporations they run.

If there is a conflict between certain societal outcomes and making a profit then those executives willing to prioritise profits will be the ones running the successful corporations. That's why it's so futile to bet on corporations acting against their self-interest in significant ways. They are systemically incapable of doing that (on average - exceptions are always possible).

That's why I'm saying that if we want to make corporations act in desirable ways, we have to make laws rather than appealing to the conscience of those running the corporations.

>I don't mean to put words in your mouth, but the only way I can resolve this asymmetry in my mind is to have a framework where corporations doing things that are bad for society is okay, because the government is supposed to stop them; but if the government is unable to fully stop them from being bad, then it's STILL not the corporation's fault, but the government's...

The question I'm asking is who can fix a particular issue, and if the issue isn't getting fixed then I'm assigning blame to those whose job it is to fix it.

Corporations collectively can't fix an issue when the only fix is not exploiting a particular economic opportunity. If one corporation stops exploiting the opportunity, another one will.

That said, of course I do blame corporations for stuff all the time. There's nothing wrong with that. Blaming them is sometimes effective consumer power. It can take away the economic opportunity as the reputational damage may outweight the benefits. Blame can also help build momentum for a change in the law.

But if laws are made and they have giant loopholes in them, then I blame lawmakers for doing a shoddy job.

Re: Dear Paul Graham, there is no cookie banner law

#526

Earlier quoted context omitted.

> The cookie banner is an inconvenience to their mindless consumption, It’s an inconvenience to people who care about privacy and use browser configurations that don’t store state between visits. So now in an attempt to protect regular users, the law ended up hurting users that already cared. Additionally, the shadiest and incompetent sites still just track people with no cookie banner. So the law doesn’t really prov…

> It’s an inconvenience to people who care about privacy and use browser configurations that don’t store state between visits. > > So now in an attempt to protect regular users, the law ended up hurting users that already cared. Fair point about the banners mostly "hurting" users who care about privacy (but, really though- how much does it really "hurt" you? I'm "hurt" more by the fact that I have to fold laundry sev…

> Companies are under no legal obligation to make those banners as obnoxious as they are

Actually every single lawyer we asked about implementing GDPR advised us to have one of those obnoxious banners. Because the law is so ambiguous and the penalties so high that is better to play it safe. And we have no ads nor tracking at all on our product website.

You can ignore your lawyer's advice if you want, but it's a bit like a lawyer office ignoring my data security and backup advice: assuming a huge amount of risk.

Re: Dear Paul Graham, there is no cookie banner law

#527
post #254

Earlier quoted context omitted.

I don’t think this is strictly accurate. There’s nothing about cookies themselves that makes them a problem. It’s the way they are used. Needing to inform people you are using cookies for sessions is like needing to inform people you are using a fork to eat. The problem is that some people are using the fork to stab people, so now we require everyone to say how they’re going to use it in advance. Instead of just proh…

You don’t need to inform people you are using cookies. It is not about cookies.

> You don’t need to inform people you are using cookies.

Are you a lawyer? Are you willing to assume the liability I may incur if I follow your advice?

Re: Dear Paul Graham, there is no cookie banner law

#528
post #177

Earlier quoted context omitted.

The fact that companies are doing that says more about the bad law than the companies which is exactly Paul Graham's point.

So the problem is that the legislator did not expect companies to be even worse assholes than they already were...? Laws are not borne in a perfect state; very much like programs, sometimes you need a few versions to see how the system actually works in practice and fix a few bugs. The fact that v1.0 has such bugs is not a good reason to just give up, nor it's an indication that the programmer is bad at programming.

> companies to be even worse assholes

All companies? Every single company with a website even if without any trackers or ads?! All companies are evil and the single law that triggered their evil behaviour is good. Sure. Ever heard of Occam's razor?

Re: Dear Paul Graham, there is no cookie banner law

#529
post #492

Earlier quoted context omitted.

Paul is very unlikely to be invested in tracking unless he has some shares in Google/Facebook. Startups in tracking aren’t really a thing

I expect most startups "integrate" their regular revenues (if they have any) with some sort of adtech deal.

Any source for those allegations or is it only your imagination?

Re: Dear Paul Graham, there is no cookie banner law

#530
post #107

Earlier quoted context omitted.

Doesn't that argument work both ways? If you interpret the EU's regulation with the "lens of game theory", it is an unintended consequence of aggressive corporate data collection. Not sure why it makes sense to complain about the EU and not the companies.

Of course not. Only titans of industry and the landed gentry of the executive class are allowed to "move fast and break things", "ask for forgiveness rather than permission" and take "imperfect action rather than perfect action." It's more morally permissible for corporate decision makers to install a global surveillance complex than for civil servants to attempt to regulate it.

> It's more morally permissible for corporate decision makers to install a global surveillance complex

No, it's more transparent. Unlike cookie banners.

If only cookie banners protected the consumer, but shadow cookies work fine.

Post reply on HN