Live data from Hacker News

Where did all the “reject” buttons come from?

noyb.eu

61–70 of 127 posts

Re: Where did all the “reject” buttons come from?

#61
post #37

The button is more prominent, yes. And it's still useless. Most tracking now comes from the "legitimate interest" purposes that you need to actively object to, which is buried in a tertiary hidden panel or not available at all, or even forces you to object to several dozens of trackers one by one.

What are these 'legitimate interest' things, and is it even possible to object to them, legally speaking? I have never seen these I believe, unless you mean 'analytics cookies' and 'functional cookies', which I never saw hidden. I did presume that a 'reject all' included rejecting these cookies, if not it would be great to know.

> What are these 'legitimate interest' things

While some comments are saying that legislation can narrow this down, I don't think it's anything that can be agreed up front any longer.

Web is heading toward a complete change of protocol. One that can operate between mutually hostile and untrustworthy principles. (that's what the web is now, let's face it)

What the service provider's and your "legitimate" requirements are, will have to be negotiated per transaction.

It's the end of the "uniform" web. But I think that already happened and we're long into "The Splinternet".

As I said in Digital Vegan, technology access will not be defined by the "have and the have-nots", but by the "will and the will-nots".

Re: Where did all the “reject” buttons come from?

#62
post #52

Earlier quoted context omitted.

1. GDPR isn't just about cookies. It's about your data in general . So it covers even offline interactions. 2. Governments shouldn't mandate solutions . Instead, EU stipulated a requirement . And industry as a whole decided that they will break the law for as long as possible until the governments chase after them. In the process the industry has convinced gullible developers that it is the law that it is bad, and no…

> Governments shouldn't mandate solutions Huh? That's what we have governments for.

There is a YouTube channel called Technology Connections which has a video about American car headlights: https://www.youtube.com/watch?v=c2J91UG6Fn8 which I think illustrated a good example of the difference between mandating a solution, and mandating requirements.

Considering car headlights. Obviously there are some requirements we should make - they need to be bright enough to safely light-up the road. They should not blind oncoming drivers. They need to be reasonably safe in the event of a collision.

Between the sixties and 1984, the government of the USA mandated a solution. Basically one model of headlights was permitted (with a few minor variations introduced over time). If you look at all car models from this time they have a similar appearance, and the same headlights are still in use in some commercial vehicles today.

In most European nations (and other parts of the world) instead a requirement, or series of requirements were made. If you met these standards for lighting level, glare, etc. your headlight was permitted.

This led to European and Japanese cars have very varied headlight models, while most American cars were forced to stick to the same old style. This meant that American drivers missed out on innovations in this space.

Mandates can very easily become out-dates. Whereas well written requirements are much more timeless.

Re: Where did all the “reject” buttons come from?

#63
post #48
post #37

Earlier quoted context omitted.

What are these 'legitimate interest' things, and is it even possible to object to them, legally speaking? I have never seen these I believe, unless you mean 'analytics cookies' and 'functional cookies', which I never saw hidden. I did presume that a 'reject all' included rejecting these cookies, if not it would be great to know.

There's some weird thing in the law. You can accept or reject data collection, but they can collect data for which a legitimate business interest exists unless you object - so if the law makes it default to no, you reject, but if it's default yes, you have to object. As far as I know, you have a right to object, so yes, legally speaking, it is possible to object to them. This means that there's frequently a second pa…

Is it possible to 'object' to these legitimate interest?

Is it possible for a website to say, if you object to these, just don't use our website/service?

Re: Where did all the “reject” buttons come from?

#65

I've set my browser to delete cookies at close. You can accept all cookies without problem, and after lunch everything is forgotten. A few websites that I go to often get special treatment (Hacker News!), because I'm to lazy to press ok each time.

In addition to the problems mentioned by siblings, this also sends the wrong message: you're signaling to the website owners that you're OK with tracking (or that you don't care, which is the same).

Re: Where did all the “reject” buttons come from?

#66

Earlier quoted context omitted.

>Just remove cookie banners unless you’re using an ad network You also need a cookie banner in EU in case your website uses any cookies that are not necessary to serve the content. This includes analytics, telemetry, and so on. It's not only ads. You can remove the cookie banner if your website uses cookies only for required functionality like log-on.

> You also need a cookie banner in EU in case your website uses any cookies that are not necessary to serve the content. Not quite, for two reasons: - The law doesn't care about cookies, it cares about personal data, which includes any data which can individually identify someone (like a cookie associating them with a user account). If you're collecting or processing any personal data, that requires consent; even if…

You're only talking about the GDPR. But the cookie banners aren't there because of the GDPR, they're there because of the ePrivacy Directive.

It's this directive (which pre-dates the GDPR) that makes it illegal to store or access data on the end user's devices without consent unless it is strictly necessary for the provision of the service.

Re: Where did all the “reject” buttons come from?

#67
post #37

The button is more prominent, yes. And it's still useless. Most tracking now comes from the "legitimate interest" purposes that you need to actively object to, which is buried in a tertiary hidden panel or not available at all, or even forces you to object to several dozens of trackers one by one.

What are these 'legitimate interest' things, and is it even possible to object to them, legally speaking? I have never seen these I believe, unless you mean 'analytics cookies' and 'functional cookies', which I never saw hidden. I did presume that a 'reject all' included rejecting these cookies, if not it would be great to know.

> What are these 'legitimate interest' things,

In most cases "legitimate interests" checkboxes, particularly those referring to 3rd parties, basically mean "we see you preference not to be stalked and, while we may claim to respect you and your privacy, fuck you and your silly desire for privacy".

> and is it even possible to object to them, legally speaking?

Legally, in theory, yes.

Practically, not really. You can go through and uncheck the hundreds of preselected consent options some sites present, but do you check that this actually results in tracking information not being dropped?

Re: Where did all the “reject” buttons come from?

#68
post #54

Earlier quoted context omitted.

My layman's understanding of the GDPR was that it was the primary website (i.e. the website you are actually and intentionally visiting) that could store your data on the basis of a legitimate business interest -- for example because they need that information to deliver some stuff you ordered from them. However someone seems to have found a legal loophole whereby third parties ostensibly are able to track you on the…

> Tracking is not, and will never be, a legitimate business. The problem is, the way the Internet and its services are financed, it is pretty much a requirement. A lot of services absolutely depend on advertising revenue because affordable micro-transactions still are not a thing, not to mention 20 years of cultural ingrainment that services on the Internet have to be free when they are aimed at the general public. T…

> The problem is, the way the Internet and its services are financed, it is pretty much a requirement.

A bad business model doesn't mean you get to ignore the law.

Re: Where did all the “reject” buttons come from?

#69
post #19
post #4

The EU cookie legislation was a mistake made by tech-illiterate bureaucrats that ruined the Web to a large degree. It's something that could've been built in to the browser. I have a hard time understanding why one would dedicate their time to this.

100% I think the underlying reason is that most people don’t consider trade-offs. “Yes, great let’s do the cookie banner thing. But before, let’s also consider how this could be a bad idea?” “Yes, great let’s ban plastic straws. But also let’s consider what we get instead and if that alternative is really better.” These conversations rarely take place in my experience. You can still decide to do it, but at least you…

The EU did not mandate a cookie banner.

The law requires you to ask for consent before collecting data you do not strictly need. Websites decided that they'd rather bother their visitors with cookie banners than stop collecting their data.

Hacker News does not have a cookie banner - despite using cookies. It doesn't need to ask for consent, because it has no intention of abusing your data.

Re: Where did all the “reject” buttons come from?

#70
post #63
post #48

Earlier quoted context omitted.

There's some weird thing in the law. You can accept or reject data collection, but they can collect data for which a legitimate business interest exists unless you object - so if the law makes it default to no, you reject, but if it's default yes, you have to object. As far as I know, you have a right to object, so yes, legally speaking, it is possible to object to them. This means that there's frequently a second pa…

Is it possible to 'object' to these legitimate interest? Is it possible for a website to say, if you object to these, just don't use our website/service?

Some sites certainly do present the only options "accept or go away", it slightly more subtle "by continuing..."¹.

IIRC this is against both the meaning and the letter of the law, but that is not practical to properly enforce so they get away with it.

Post reply on HN