Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

551–560 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#551
post #527

Earlier quoted context omitted.

You don’t need to inform people you are using cookies. It is not about cookies.

> You don’t need to inform people you are using cookies. Are you a lawyer? Are you willing to assume the liability I may incur if I follow your advice?

"""

Cookies that do not require consent [...] or authentication cookies (when users authenticate themselves on your web site to log in in order to check online services such as their bank account).

"""

https://europa.eu/youreurope/business/dealing-with-customers...

Re: Dear Paul Graham, there is no cookie banner law

#552
post #40

Earlier quoted context omitted.

> Almost all websites make money through ads The EU regulation does not prevent ads from being shown, it specifically targets tracking. No tracking > no banner > everyone is happier > go ahead and show all the ads that are required.

And all that tracking comes down with inability to take risk on business side. Ad company wants to be 100% sure that ads are shown to humans, and pay only for those shown to humans(going deeper - to specific cohorts of humans, which in the past was approximated by content of the site showing ads). Whereas sites serving ads want to extract as much money as it is possible from advertisers based on their audience count.…

sites know their audience, they know their usual impressions, and that's how marketing saleshouses functioned for about one-two decade(s).

it's much simpler for both sides, no crying about bots, etc.

of course it's not great if you want to target Putin et al. ( https://www.wired.com/story/how-pentagon-learned-targeted-ad... )

ad networks can simply send out banners to sites for time slots, and that's it. do you want to advertise healthy food? send it to yoga sites (insert it on #yoga hashtag profile pages, insert it after videos/snaps/tiktoks/reels that the AI categorized as yoga, etc.) ... it's called item-to-item recommendation (use the content of the page - as it was done for - again - decades)

it's perfectly possible to ban and remove tracking bullshit

Re: Dear Paul Graham, there is no cookie banner law

#553
post #551
post #527

Earlier quoted context omitted.

> You don’t need to inform people you are using cookies. Are you a lawyer? Are you willing to assume the liability I may incur if I follow your advice?

""" Cookies that do not require consent [...] or authentication cookies (when users authenticate themselves on your web site to log in in order to check online services such as their bank account). """ https://europa.eu/youreurope/business/dealing-with-customers...

Again: are you a lawyer?! If not, in what quality are you advising businesses how to implement such a dangerous law? Have you seen the magnitude of the potential punishment? Will you cover my fines if you're wrong?

Re: Dear Paul Graham, there is no cookie banner law

#554
This seems like a very "um, akshuallyyy" response. There IS a cookie banner law. If the law says, "You must do X before doing Y," and you know that everyone is still going to do Y, you've effectively mandated X. The argument that simply not doing Y (which everyone does, and which you need to do to avoid being at a competitive disadvantage in the market) would avoid the mandate to do X is a pointless technicality.

Regardless of whether cookie banners could technically be avoided, Graham's point stands that this regulation has served no purpose other than to annoy consumers.

Re: Dear Paul Graham, there is no cookie banner law

#555
post #546
post #528

Earlier quoted context omitted.

> companies to be even worse assholes All companies? Every single company with a website even if without any trackers or ads?! All companies are evil and the single law that triggered their evil behaviour is good. Sure. Ever heard of Occam's razor?

Companies who don't track don't need any banner or popup. > All companies are evil No, but many, many companies are sociopathic assholes that exist just to make a buck. Otherwise we wouldn't need these laws.

All companies exist just to make a buck. And in the process they serve us with literally every single product and service we are using every second of every day. They play by the rules we put on them, making their life easier or harder, and in the process making our life easier or harder. Like this bad cookie law.

Re: Dear Paul Graham, there is no cookie banner law

#556
post #17

Imagine a market in which companies charge a lot of hidden fees behind their customers' back, and users are not happy when they realize after the fact. The law is updated to say you are not allowed to charge the user a fee unless you tell him in advance. Companies with tons of hidden fees decide to keep them but force you to read all the fees on every page of the menu before you can see the rest of the text, in the m…

The flaw in your analogy is that the modal consumer cares about hidden fees, wants to be made aware of them, and might even make a different decision with that knowledge. The modal consumer does not care about cookies.

Imagine you walk into a restaurant and they hand you a paper that details full allergy information for all of the foods they serve, and then they wait for you to say, "I consent to these ingredients being in the food," before they can seat you. I think that's a closer analogy. We can all agree that the restaurant shouldn't hide that information from you, and that some minority of people might want the information, but do we really have to add this inconvenient step to the process for all people? The current real-world system, where allergy information is available upon request, was working fine.

There are some things that everyone cares about and would be appalled by, that businesses should have to inform people about, and many things that a small minority of people care about. Why stop at cookies? Maybe we should mandate a popup if the website's server infrastructure was manufactured abroad, and another popup if the company that runs the website has higher than average carbon emissions, and another popup if the food in the food court that serves the headquarters of the company that runs the website is not kosher. The lobby of people who care about cookies is of similar size to the lobby of people who care deeply about binary size and about running JavaScript. Should there be mandatory popups to execute JavaScript? If the website is >10MB, should I have to consent on a lightweight page before downloading it? How do you determine which activities warrant a popup warning and which do not?

Re: Dear Paul Graham, there is no cookie banner law

#557
post #72
post #21

Part of what it means to be "good at regulation" is to anticipate the likely consequences of regulations. So a regulation that says that "businesses must now give away their products for free, unless they honk each customer's nose" will result in a lot of sore noses. Which is basically the case here. Almost all websites make money through ads, or at least keep logs of user activity to help them optimize their website…

> Almost all websites make money through ads, Doesn't require tracking of individuals. > or at least keep logs of user activity to help them optimize their website Doesn't require tracking of individuals.

> Doesn't require tracking of individuals.

Building a house doesn't require powertools, but if your company tries to do it with handtools we'll see who goes bankrupt first.

Re: Dear Paul Graham, there is no cookie banner law

#558
post #72

Earlier quoted context omitted.

> Almost all websites make money through ads, Doesn't require tracking of individuals. > or at least keep logs of user activity to help them optimize their website Doesn't require tracking of individuals.

> Doesn't require tracking of individuals. Building a house doesn't require powertools, but if your company tries to do it with handtools we'll see who goes bankrupt first.

Building a house doesn't require using cheaper but more dangerous materials either but people try to, that's why we have regulations.

Analogies can be pithy but are rarely useful as an argument. Talk about reality.

Re: Dear Paul Graham, there is no cookie banner law

#559

Earlier quoted context omitted.

Agree. How much corporate propaganda are people consuming that legislators are seen as wholly responsible for the bad behavior and malicious compliance actions of corporations? What does it say about the relationship between businesses and consumers that the first response to this bad behavior is to shout "look what you made them do!" Seemingly it is everyone's fault except the bad actors themselves.

It's so depressing. Many of the people who are pointing the finger at the regulators for the annoying cookie banners don't actually see the web site/app *as* a bad actor. The fact that they had been tracking tons of extra data via cookies without their consent or knowledge was totally fine to them as long as it wasn't inconveniencing them in any way. The cookie banner is an inconvenience to their mindless consumption…

> don't actually see the web site/app as a bad

Some of these bad actors actors with annoying cookie banners:

https://gdpr.eu/

https://european-union.europa.eu/

https://www.europarl.europa.eu/portal/en

Re: Dear Paul Graham, there is no cookie banner law

#560
post #454

Earlier quoted context omitted.

> they are made to sign things which essentially reduce their rights... But not as much as you might think. Consent under GDPR only applies to what you were informed of when you consented, and you're allowed to revoke consent (with prospective effect) at any time.

Yeah, but these are rather theoretical practicalities. In the majority of cases, consent is coaxed out of the consumer. If you show up for a MRI, and you get a piece of paper with the comment "It is for data protection", almost nobody has the time or nerve to actually read the text, and even less people have the inclination to decline to sign. After all, they (sometimes desperately) need the service. Let alone that t…

Under GDPR, your MRI example and your bank example do not qualify as consent. (For the MRI example, they might be able to claim basis b, but only if they're doing stuff that you could actually have requested.)
Post reply on HN