Live data from Hacker News

RFC 35140: HTTP Do-Not-Stab (2023)

5snb.club

61–70 of 219 posts

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#61

Earlier quoted context omitted.

And if the regulators didn't predict such compliance they should be replaced with competent actors in their jobs. That was the obvious outcome. What did people predict: site owners leaving money on the table? Who pays for operating the sites then?

When GDPR was first going through the public circuit I remember reading the proposed laws and being pleasantly surprised to find that they specifically called out and forbade the likely workarounds, including the obnoxious banners we now see everywhere. I would love to know what happened. Did the laws get "revised" to re-open the loophole? Was superseding legislation passed? Did the courts reject it? Are there enforc…

That sounds like a legal minefield - I would point out that GDPR-style legislation exists because the legislators don't trust the industry to assess what is reasonable. So the industry would be in a position where:

1) They aren't trusted to be reasonable about user consent.

2) They are only to take action when they judge it is reasonable to check user consent.

It'd probably be a very rocky process to nail down what those words like "loophole" and "workaround" mean as the advertisers start abusing prescribed no-banner situations.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#62
post #51

Earlier quoted context omitted.

I'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.

The cookie banner is only there because the website in question uses non-functional cookies (e.g. targeted advertising)

Or if the legal department is concerned that someone could claim a cookie is non-functional, so to save the uncertainty and expense they advise always showing the banner. Especially since everyone else does.

It seems like there should be a parallel to “tragedy of the commons” that talks about how a good idea coupled with extreme penalties can lead to a bad outcome by making any risk calculation result in “jesus we just can’t take any chances here”.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#63

Earlier quoted context omitted.

I'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.

> ... "it basically added a cookie banner to every every website I visit" ... Yeah, no. Hostile advertising companies added that cookie banner as a form of "malicious compliance" with the law purely to annoy everyone like a buncha spoil't little brats who didn't get their way, so now they're gonna make everyone suffer... If we get a similar law in the USA, you can expect to see annoyances just like it (and probably w…

The worst part is that it wasn’t even malicious compliance: the cookie banners they added seldom even satisfied law, in ways completely obvious if you just read the law (which is pretty easy reading, only a few thousand words for the relevant parts). I don’t understand why relevant commissions didn’t make more noise about that, because it was obvious that major players were deliberately poisoning public perception.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#64

Earlier quoted context omitted.

I'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.

> ... "it basically added a cookie banner to every every website I visit" ... Yeah, no. Hostile advertising companies added that cookie banner as a form of "malicious compliance" with the law purely to annoy everyone like a buncha spoil't little brats who didn't get their way, so now they're gonna make everyone suffer... If we get a similar law in the USA, you can expect to see annoyances just like it (and probably w…

Can you source your claim? Because it seems like it would create a competitive advantage for a non-hostile advertising company. Websites aren’t any happier about cookie banners than users are. If it’s just an emotional, spiteful reaction, the grownups should be able to make a fortune.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#65
post #58

Earlier quoted context omitted.

Yes, the second one. I don't really care; it's not "my" data. It's data about me. When I walk down the street and sometime sees me go by, those aren't my photons they caught. By analogy, same with my browsing history.

It is, however worth at least considering restrictions on continuously following a person in public places and reporting all their observed activities to a third party. Of course there are practical limitations on that kind of physical surveillance. It's expensive, tends to attract attention, and even nation states can only do it to a few people at a time. Information technology allows it to scale to almost everyone,…

> It is, however worth at least considering restrictions on continuously following a person in public places and reporting all their observed activities to a third party.

I don’t see any difference between online “tracking” and real world stalking. If some one was following you every where you went taking notes on everything you did, interrupting you and preventing you from actually doing what your were actually wanting to do, you’d be able to have the police intercede in your behalf. Only now we think it is different because “on a computer”.???

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#66
post #51

Earlier quoted context omitted.

I'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.

The cookie banner is only there because the website in question uses non-functional cookies (e.g. targeted advertising)

The cookie banner is there to punish people who have cookies turned off or set to be deleted upon browser/tab close - and generally annoy everyone else.

Think about how obsessive companies are about "UX" and how disruptive the banner is. Bitch-slapping people for fighting against tracking is more important to them than the user being able to access or use the site at all.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#67
post #64

Earlier quoted context omitted.

> ... "it basically added a cookie banner to every every website I visit" ... Yeah, no. Hostile advertising companies added that cookie banner as a form of "malicious compliance" with the law purely to annoy everyone like a buncha spoil't little brats who didn't get their way, so now they're gonna make everyone suffer... If we get a similar law in the USA, you can expect to see annoyances just like it (and probably w…

Can you source your claim? Because it seems like it would create a competitive advantage for a non-hostile advertising company. Websites aren’t any happier about cookie banners than users are. If it’s just an emotional, spiteful reaction, the grownups should be able to make a fortune.

You'd think there'd be some "competitive advantage" to be had, but when their entire industry is built upon tracking and profiling everyone they possibly can, they'll do anything they can, fighting tooth-and-nail to the very end against any legislation that somehow interferes with their tracking, even if it means resorting to childish and petty temper tantrums that further enshittify the web. What little "competition" exists in that industry all fully believe that building massive profiles on everyone is the only way to make any money at advertising. They've been allowed to get away with it for so long that they can't even remember there was a time when tracking everyone all the time everywhere wasn't even a thing (and yet advertisers still managed to advertise back then, somehow)...

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#68
post #47

> because every company out there fucking hates you They don't actually hate you. Rather, they love your money and they have a depraved indifference for you.

No, they love the money they can make about you. I don’t know anybody giving their money to these people. It is other shady companies buying the data about for, shady companies that have collected. All of this is offered to you free of charge.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#69
post #16

Earlier quoted context omitted.

Maybe it’s just me, but I fundamentally disagree with the mentality that we should prioritize the “feeling of being special” among those who already get the joke (and corresponding point) at the expense of those who have yet to appreciate the message. You can still laugh at the joke with the section there, you’ll just have fewer confused people to correct, and be in one less elite club.

Sure, but the point of critical thinking club isn’t really its exclusivity. In this case if you don’t know which specific header this is parodying that’s completely understandable. But if you really think this is about computers stabbing people and can’t laugh at yourself about it when you find out that it isn’t then I don’t think we will be able to engage on this topic in a mutually rewarding manner.

I don’t think it’s about computers stabbing people, but that’s not relevant. The issue is your willingness to keep people in the dark so you can feel good that you got a reference without it being explained.

Re: RFC 35140: HTTP Do-Not-Stab (2023)

#70
post #58

Earlier quoted context omitted.

It is, however worth at least considering restrictions on continuously following a person in public places and reporting all their observed activities to a third party. Of course there are practical limitations on that kind of physical surveillance. It's expensive, tends to attract attention, and even nation states can only do it to a few people at a time. Information technology allows it to scale to almost everyone,…

> It is, however worth at least considering restrictions on continuously following a person in public places and reporting all their observed activities to a third party. I don’t see any difference between online “tracking” and real world stalking. If some one was following you every where you went taking notes on everything you did, interrupting you and preventing you from actually doing what your were actually want…

> interrupting you and preventing you from actually doing what your were actually wanting to do

This is the part that would get the police involved, and no-one online is doing anything like this.

Doris the curtain-twitcher compiles a dossier on everyone, maybe shares it in her gossip circles. No-one cares.

Post reply on HN