Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

591–600 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#591
Without even reading the whole article, I can tell the author is German.

Create dumb and pointless rules and enforce them with highest passion.

Believe that you're the smartest person who only understands these rules.

Serve nothing but the soul sucker bureaucracy.

Many people are leaving Germany pretty much because of this. Startup founders often do pointless work just to not get in prison.

The author of course has zero experience building anything. He is the amazing CTO. He'll teach you how to do. Because he's superior than rest of the world.

The society here has tendency to descend into madness with a strange group behaviour.

History. Rhymes.

Re: Dear Paul Graham, there is no cookie banner law

#592

Earlier quoted context omitted.

Uh, what? Because the EU is forcing you to do something that you want to do anyway, you now like it? If you want cookie banner laws in your non-EU country, vote for it. I don’t want some bureacrat I didn’t vote for issuing diktats that affect how I build my business and my websites. The entire point is that we all need representatives in government.

The EU isn't forcing me or you to do anything. The article elaborates on this point: There Is No Cookie Banner Law. Only bad website operators choosing to abuse their users with annoying consent dialogs. Nobody in Europe is issuing "diktats", meaning citizen-supported legislation I guess, or affecting your business, unless you're trying to deal with their citizens' data. Just don't process EU citizen data and it's no…

I actually self-host all my web assets and use Matomo already. So I do actually agree with the premise.

What I object to strenuously is someone dictating terms to the world from distant shores, especially since they seem not to get how the internet works (it’s all funded by ads, online sales, and ads for online sales, all of which involve metrics and tracking!)

The diktats I mentioned include a ruling that Google Fonts are illegal now. So if I’m using those, or I’m using Google Analytics, and a European happens across my site, I’m now a criminal? Fuck that.

The consequences of contravening the GDPR are uncertain but sounds scary. This is terrible for the open and free internet.

Re: Dear Paul Graham, there is no cookie banner law

#593
post #559

Earlier quoted context omitted.

It's so depressing. Many of the people who are pointing the finger at the regulators for the annoying cookie banners don't actually see the web site/app *as* a bad actor. The fact that they had been tracking tons of extra data via cookies without their consent or knowledge was totally fine to them as long as it wasn't inconveniencing them in any way. The cookie banner is an inconvenience to their mindless consumption…

> don't actually see the web site/app as a bad Some of these bad actors actors with annoying cookie banners: https://gdpr.eu/ https://european-union.europa.eu/ https://www.europarl.europa.eu/portal/en

I only got a cookie banner on the first of those links, and as far as cookie banners go it wasn't very annoying; I clicked "no" and it went away immediately.

Re: Dear Paul Graham, there is no cookie banner law

#594

Earlier quoted context omitted.

A site can keep logs of user activity to help optimize without tracking my personal data. As soon as a company needs to track me, it's doing more than "optimizing its website"—it's using my data to sell me stuff or selling my data to third parties. And I'm glad it needs permission to do those things.

What if I want to optimize my site for certain classes of users? Say a less than abled person. What if I want to make my product easier to use with various control schemes used by a handicapped person and my product is so complex that tracking this demographic’s usage of my product is the easiest or only way? and what if there is no intent to sell your data? I could ask permission and delay, or I could just capture t…

> What if I want to optimize my site for certain classes of users? Say a less than abled person.

What are you learning from users' personal data that changes how you do this? Shouldn't your site be accessible, regardless of usage?

Re: Dear Paul Graham, there is no cookie banner law

#595
post #538

Earlier quoted context omitted.

Of course this is "doing sketchy shit with people's data". Selling my personal info to external companies so that they can manipulate me easier is sketchy in my eyes if I don't consent

“ Selling my personal info to external companies” What? What are you even talking about? Google does not sell your personal info. You’re delusional

You attributed a medical diagnose to me for saying something that is possibly uninformed. That makes me not ever want to have a conversation with you again. Just food for thought...

Turns out you were the uninformed one. From the context through parent posts you can clearly see this was about a website using google adsense and by that, the company sells my info to an external (google) which then tries to take advantage of me to extract money from me.

That is what I am talking about and I think this was clear from the previous posts. I think you owe me an apology

Re: Dear Paul Graham, there is no cookie banner law

#596
post #553

Earlier quoted context omitted.

Again: are you a lawyer?! If not, in what quality are you advising businesses how to implement such a dangerous law? Have you seen the magnitude of the potential punishment? Will you cover my fines if you're wrong?

Note that putting a “we use cookies” banner on your website will not absolve you from GDPR fines anyway. You still need to adher to the law about informend consent, storing safely etc. If you are worried about GDPR, by far the safest is to just not collect personal information.

You are correct: implementing GDPR correctly is much, much harder and more expensive than people realise. Cookie banners are just the tip of the iceberg.

A few things not allowed under GDPR:

1. Analytics

2. Third-party resources like fonts or JS libraries

3. CDNs

4. DDOS protection services

And I am sure I am missing many more. I am not a lawyer, but I worked with a few.

Re: Dear Paul Graham, there is no cookie banner law

#597
post #552

Earlier quoted context omitted.

sites know their audience, they know their usual impressions, and that's how marketing saleshouses functioned for about one-two decade(s). it's much simpler for both sides, no crying about bots, etc. of course it's not great if you want to target Putin et al. ( https://www.wired.com/story/how-pentagon-learned-targeted-ad... ) ad networks can simply send out banners to sites for time slots, and that's it. do you want…

Hmm, what if people outside of yoga like health food? Or what if some people at the yoga site instead eat fried food but just have a good exercise routine? your solution here just makes ads less valuable, which isn’t a win for advertisers or sites. if you can remove tracking, and still allow targeting, then you’ve hit gold. short of that you won’t find meaningful buy-in.

Ad networks can offer to optimize the impressions, help to with targeting.

After all the current implicit user profiling and targeting is already not a 100%. Many people use adblockers, many devices are used by more than one user, etc. (In this day and age we are still baffled how Amazon/Google/whatever advertises us - for days - the same fucking thing we just purchased yesterday. Of course, because based on their model it's still the most likely thing the user might buy or click on, etc.)

Google seems to be already moving away from individual profiles with FLoC - of course they still want all of the data to be able do dynamically allocate users to cohorts (to maximize their profits).

And this is why Tiktok and Instagram just went ahead and are now doing direct sales. (They put a link on the video overlay where the user can go and buy whatever shit the video talks about.)

> isn’t a win for [...] sites

this is something that a lot of people are pushing back on, because their claim is that we need some slack in the system for sites to be able to pursue their own creative vision (however lame, banal, mundane, or seemingly useless it is). before every click was tracked it was okay if some article (or video) underperformed, because in general the advertiser got the increased sales (or brand awareness or whatever they measured)

Re: Dear Paul Graham, there is no cookie banner law

#598
post #499
post #496

Earlier quoted context omitted.

> the regulation is not getting what it wants (no tracking or informed tracking) That's an overstatement of the purpose of the regulation IMO. The purpose is to give the user control over the tracking of their data.

OK, fair enough. pg's point still stands I think - I believe that most users have zero idea what that popup is and don't bother doing anything but clicking on it immediately even if they do have some idea.

I find it pretty difficult to be sure what point pg is making, because he uses an ambiguous phrase "good at regulation". What does he mean by "good at regulation"? According to the UK's Institute of Chartered Accountants [0] good regulation satisfies five criteria:

* Transparency

* Accountability

* Proportionality

* Consistency

* Targeting

I'm not certain that the GDPR laws fail any of these. I'm guessing pg is getting at something more nebulous to do with how annoying the UX is as a result of the regulation, and whether it encourages civil engagement. But if he'd simply said "EU regulation has made UX annoying" then he wouldn't have such a snappy tweet.

[0] https://www.icaew.com/technical/trust-and-ethics/better-regu...

EDIT I googled some more and found a brochure from the National Audit Office titled "Principles of Effective Regulation": https://www.nao.org.uk/wp-content/uploads/2021/05/Principles...

It does have a statement in there:

> Good regulation maximises the benefits while minimising compliance costs and unintended consequences. The benefits of regulation can be both to wider society (such as improved environmental or safety standards) and to regulated (for example, through increased consumer confidence), but not all of the benefits are necessarily easy to quantify.

Put that way, I can get on board with what pg's saying.

Re: Dear Paul Graham, there is no cookie banner law

#599

Earlier quoted context omitted.

This is copying, not stealing though. But I agree, taking advantage of me telling you personal info by selling it to externals is unfair without consent

and yet these companies consider piracy stealing too, thats just copying for free without consent, where's the difference?

no difference, both is illegal without consent

Re: Dear Paul Graham, there is no cookie banner law

#600
post #276

Earlier quoted context omitted.

It only took two minutes to find at https://www.schwarzkuenstler.com/ and I'm sure I can find a dozen more in half an hour. Germany is a bit litigious w.r.t. internet or privacy, so the combination---cookie consent---is a doozy. Nearly every German website that does anything will have a consent notification, and the slightest misstep (e.g. using Google Fonts without asking permission) can be punishable.

Their privacy policy states they use Google reCAPTCHA, which requires disclosure.

True, I hadn't noticed that at first glance, and I didn't see that as a third-party cookie in my site data. Nonetheless, I regularly see cookie warnings on sites with purely first-party cookies or even "just" session storage. (Mostly, I have been alert to this for the past year as I've started making non-personal web sites in Europe.)
Post reply on HN