Live data from Hacker News

Cookie Warning Shenanigans Have Got to Stop

troyhunt.com

61–70 of 509 posts

Re: Cookie Warning Shenanigans Have Got to Stop

#61
post #14

I find the clarification about cookie walls being out of compliance with GDPR to be a real headscratcher. Here's part of the Dutch authority's FAQs[0] thanks to Google Translate: "At a cookie wall, website visitors have no real or free choice. It is true that they can refuse tracking cookies, but that is not possible without adverse consequences. Because refusing tracking cookies means that they cannot access the web…

Of course you have a choice, but in reality who leaves a site because they see that warning? I imagine almost no one. Hell, I understand the implications and I don't care because site X has what I'm after and perhaps no one else does (or they all have the same warning anyway.) I have no reasonable option but to accept whatever these sites want. The warnings accomplish nothing. It's just another nag screen. It was a b…

The warnings under the old law were idiotic. Under the GDPR, however, you're required to have clear consent with an easy refusal option. But just like the cookie warning, so, so many sites are violating that requirement because, hey, you cannot go after everybody, right? I don't think there were really any consequences for violating the old cookie law, so the majority are maybe approaching the GDPR the same way (even though this time there are actual punishment options.)

Re: Cookie Warning Shenanigans Have Got to Stop

#62

It's time GDPR is actually enforced. I tried to get my country's law enforcement on the tail of some violators but they're toothless . I don't understand the downvotes though, are you disagreeing that certain countries do not have the manpower to enforce GDPR to the extent they could? Please.

I think they are currently going after the big ones. Personally, I expect that to change once they are through with them. It simply makes no sense to go after big companies when there is still google and facebook to go after. And well, medium and small? I think those still have another year or 2.

Re: Cookie Warning Shenanigans Have Got to Stop

#63
post #50

Earlier quoted context omitted.

Recently a company I trust was sold to a company I utterly dislike and have zero trust in. Before the sale was executed, as a EU citizen I was informed that my consent was required for the transfer of my personal data to the new owners. I did not consent. My data is not in the hands of the new owners. And under GDPR, I was able to request all the data they had on myself in order to make an archive of it before the ex…

I think that is great. But I think it might be a case where Troy notes, you're educated on the topic, and like cookie tracking, you probabbly could have dealt with cookie tracking before GDPR too on your own. I'm not at all sure that applies to more than a handful of people. If that's the case, GDPR is not helping most people.

I entirely agree with the premise that citizens don't know their rights well enough. But that doesn't mean they shouldn't be available to them.

Most people don't know how to read nutrition labels either; they're still there and it's a good thing they're there. Do you think they should be removed simply because people don't know how to read them?

I can make the same argument as to why I believe open source is important. Most people don't know how to read source code.

Re: Cookie Warning Shenanigans Have Got to Stop

#64
post #47

FTA he's quoting: > And the Dutch DPA’s guidance makes it clear internet visitors must be asked for permission in advance for any tracking software to be placed — such as third-party tracking cookies; tracking pixels; and browser fingerprinting tech — and that that permission must be freely obtained. Ergo, a free choice must be offered. Neither cookies, nor tracking pixels, nor browser fingerprinting are software. Yo…

Tracking cookies, pixels, etc., are implemented by server-side software; perhaps the matter you would like to contend is what the meaning of the word "placed" is.

Cookies are data that is placed on the visitor's computer. Tracking pixels are software instructions placed on the visitor's computer.

The tracking that is akin "remembering a face" is user agent and ip address tracking.

In my mind, a store that uses facial recognition software to track my movement within the store and purchasing habbits is still incredibly creepy and highly invasive of my privacy.

Re: Cookie Warning Shenanigans Have Got to Stop

#65
post #52

It's time GDPR is actually enforced. I tried to get my country's law enforcement on the tail of some violators but they're toothless . I don't understand the downvotes though, are you disagreeing that certain countries do not have the manpower to enforce GDPR to the extent they could? Please.

Are those violators outside the EU? I'm interested to know if the EU would seriously try to enforce their laws in foreign lands that never agreed to them.

Nope, local violators.

Re: Cookie Warning Shenanigans Have Got to Stop

#66

Earlier quoted context omitted.

It's worth noting that the United States considers a right to keep and bear arms as important as a right to free speech. Internationally, reasonable disagreement on rights seen by some as fundamental is to be expected.

You make a fair point, but the right to bear arms is mainly controversial for safety reasons. What safety issues are there with providing customers control (or at least visibility) over their data? It's also worth pointing out that the right to bear arms, by its origin, should probably be called the "right to revolt". While this is still a controversial issue for governments (governments don't want revolt), it's less…

I think the safety issues with GDPR compliance are minimal (there's a weak argument to be made for inefficiency introduction and contributing to warning blindness, but it is a weak argument).

Larger arguments are in the space of tradeoffs. What could companies be doing with the engineering resources devoted to GDPR compliance (including compliance with the consumer-frustrating applications of the law, like the cookie walls)? Since the US doesn't have a GDPR compliance law (and companies in the US only comply when they want to do business in the EU), we'll probably see with time whether the inefficiency introduced is worth the tradeoffs in a highly-competitive world of software services.

Re: Cookie Warning Shenanigans Have Got to Stop

#67

It's time GDPR is actually enforced. I tried to get my country's law enforcement on the tail of some violators but they're toothless . I don't understand the downvotes though, are you disagreeing that certain countries do not have the manpower to enforce GDPR to the extent they could? Please.

I think they are currently going after the big ones. Personally, I expect that to change once they are through with them. It simply makes no sense to go after big companies when there is still google and facebook to go after. And well, medium and small? I think those still have another year or 2.

Let's hope so.

Re: Cookie Warning Shenanigans Have Got to Stop

#69

Its too bad nobody invented a browser header to be sent with HTTP requests for Allow-Cookies: SURE_YES_WHATEVER_OMG_STOP_ASKING_PLZ

There are browsers addons for removing these annoying notifications, most popular is named "I don't care about cookies"

Re: Cookie Warning Shenanigans Have Got to Stop

#70

Is it possible to write a browser extension that has the browser request access to store cookies just like it does for microphone or location access?

Firefox has had that built in for years but you have to manually accept or deny cookies for each website and you would still get the popups.

I just use this Firefox add-on to hide most of the popups: https://addons.mozilla.org/en-US/firefox/addon/i-dont-care-a...

Post reply on HN