Live data from Hacker News

Dear Paul Graham, there is no cookie banner law

amazingcto.com

621–630 of 662 posts

Re: Dear Paul Graham, there is no cookie banner law

#621

Earlier quoted context omitted.

Please tone down the hyperbolic rhetoric and FUD. Consider how strongly you can make your point without them. To the point: Nobody in Europe is "dictating terms to the world", or "issuing diktats", meaning passing citizen-supported legislation I guess, or affecting your business, unless you're trying to deal with their citizens' data. > The diktats I mentioned include a ruling that Google Fonts are illegal now. So if…

Here's the problem. > 1. Don't process EU citizen data (block them). Many webmasters have neither the time nor inclination to read up on EU law. So blocking is the easiest and safest solution to minimize our legal risks. This is absolutely terrible - I grew up dreaming of an internet that is really humanity's network; not islands separated by political allegiance. I agree that I can tone it down, but 99.99% of the FU…

Luckily that's just 1 of the 4 options, and those 4 options are just 4 of many options, so no need to focus on 1 of many and say you don't like it: you can just choose another! Or you can choose to create the islands. I don't see what's so terrible about that.

Did website operators think they could keep violating the rights of EU citizens indefinitely? I mean, based on enforcement capacity, chances are most operators can, but it'd be good to stop. IMO, A network for humanity should prioritize humans and their rights, over tracking and ads, and the lack of respect for those rights is what I find terrible.

Real talk: if you have questions about the GDPR, ask them, and I'm sure the smart folks at HN will be able to help you find answers and overcome obstacles. You can build and not break laws, whether GDPR or ITAR, we can help. Nobody's saying it'll be zero work, but nobody's entitled to run a business doing whatever it wants with zero work, either, and shouldn't expect to.

Re: Dear Paul Graham, there is no cookie banner law

#622

Earlier quoted context omitted.

This means you get less money for it and can't survive due to the lesser revenue.

And not surviving would.be the best outcome in a large number of cases.

Yes, we all know how great countries with no free media do.

Absolute dreams.

Re: Dear Paul Graham, there is no cookie banner law

#623

Earlier quoted context omitted.

This means you get less money for it and can't survive due to the lesser revenue.

This is contrafactual. Many things survived on exact that model before hyper targetted ads. And besides, with targetted ads the middle men take most of the cut.

This is incorrect as companies will pay less for ads that convert less.

Re: Dear Paul Graham, there is no cookie banner law

#624
post #607
post #601

Earlier quoted context omitted.

Certainly one aspect of GDPR is about how you share data with third-parties. But self-hosted analytics are still subject to GDPR and/or ePrivacy restrictions if you process full (unredacted) IP addresses, any user-identifying tokens, or anything else deemed as PII (Personally Identifiable Information) for purposes such as analytics without seeking user consent.

That's true, but the "analytics" purpose is ambiguous. It could be for security most servers already have access logs by default, that stores IP addresses anyway, and it's often used for DDOS protection for example or fail2ban login attempts.

The ambiguity of this legislation is one of the biggest problems with it.

This ambiguity leads to companies implementing cookie warning popups based on a risk-averse interpretation of the law

Re: Dear Paul Graham, there is no cookie banner law

#625

Earlier quoted context omitted.

Agree. How much corporate propaganda are people consuming that legislators are seen as wholly responsible for the bad behavior and malicious compliance actions of corporations? What does it say about the relationship between businesses and consumers that the first response to this bad behavior is to shout "look what you made them do!" Seemingly it is everyone's fault except the bad actors themselves.

It's so depressing. Many of the people who are pointing the finger at the regulators for the annoying cookie banners don't actually see the web site/app *as* a bad actor. The fact that they had been tracking tons of extra data via cookies without their consent or knowledge was totally fine to them as long as it wasn't inconveniencing them in any way. The cookie banner is an inconvenience to their mindless consumption…

> totally fine

this is not true. It's just that most people are powerless to fight against the dark pattern onslaught.

Re: Dear Paul Graham, there is no cookie banner law

#626

Earlier quoted context omitted.

What do you mean no consequences? Haven't you heard they use this data to manipulate public opinion to push certain political agendas? And that is just one example of the tip of the iceberg. Information is power. They are not collecting it just for fun.

Who are “they”? And how my cookies exactly help push an agenda? Educate me step by step please using some simplified example.

By tracking people, they understand people's behavior, what hypes there are, what kind of things people are engaging with, interested in. Then they can target specific campaigns at certain groups of people, to manipulate their opinion, or exploit them.

"They" are the ones that have control over the data. The ones that collect and process all the data, or the ones that buy it. Mostly FAANG and their clients, which are also governments.

For example, a few months ago, ironically, a department within the EU ran a campaign on X, persuading people to vote for CSAM laws. But they micro-targeted specific groups. And this is actually prohibited by EU laws itself, by the Digital Services Act (DSA). See this article:

https://techcrunch.com/2023/11/15/oops-2/

And microtargetting is actually a common practice, used for political campaigns in the US, Australia. It's also used by Russia for disinformation campaigns. See:

https://www.nytimes.com/2018/08/16/technology/facebook-micro...

And:

https://www.justsecurity.org/41199/connecting-dots-political...

Also the wiki about microtargetting is interesting:

https://en.wikipedia.org/wiki/Microtargeting

I hope this helps you understand how tracking cookies can be used against you. Of course it doesn't affect you directly personally when you visit some websites. But you have to see it in the grander scale. We are collectively a group. And as a group we can be influenced, manipulated, etc. And ultimately that affects the individuals inside the group. And this has always happened, it just happens more automated these days. But if we, as a group, stand up against it, we can empower ourselves, and we can make life better for us as a group, which will ultimately impact our personal lives as well.

Re: Dear Paul Graham, there is no cookie banner law

#627

Earlier quoted context omitted.

And not surviving would.be the best outcome in a large number of cases.

Yes, we all know how great countries with no free media do. Absolute dreams.

There's no free media. It's propaganda from all sides. And I suspect it always was like that.

Re: Dear Paul Graham, there is no cookie banner law

#628
The cookie banners are the way they are because they comply with the law, so you can not say "you follow the law in a wrong way", except for these banners which do not allow to reject cookies as easy as to accept them, the banners comply with the law so you can not blame site owners.

Instead, the law and requirements should be adjusted to make the horror of cookie banners stop.

I never could understand who thought asking website owners to get your consent is a good idea. Think of when you are installing an app on your phone, is it the app asks permission to use your location or your OS? Access to cookie storage is the same, a browser should allow or not allow webpage to store something on your device. Same as most of the browsers do for notifications btw.

Fixing ~200 browsers is much easier than fixing millions of the websites, you can also setup default preference, you can also have a clear, unbiased UI.

Re: Dear Paul Graham, there is no cookie banner law

#629
post #92

Just in case this helps someone: you can just block cookie banners because before you click “accept” the default is no tracking. There are extensions like “I don’t care about cookies” for this but also uBlock Origin has a list checkbox for it.

The default should be no tracking.

[deleted]

Re: Dear Paul Graham, there is no cookie banner law

#630

Earlier quoted context omitted.

Here's the problem. > 1. Don't process EU citizen data (block them). Many webmasters have neither the time nor inclination to read up on EU law. So blocking is the easiest and safest solution to minimize our legal risks. This is absolutely terrible - I grew up dreaming of an internet that is really humanity's network; not islands separated by political allegiance. I agree that I can tone it down, but 99.99% of the FU…

Luckily that's just 1 of the 4 options, and those 4 options are just 4 of many options, so no need to focus on 1 of many and say you don't like it: you can just choose another! Or you can choose to create the islands. I don't see what's so terrible about that. Did website operators think they could keep violating the rights of EU citizens indefinitely? I mean, based on enforcement capacity, chances are most operators…

You keep missing my point, possibly on purpose, so I'll end this here.

The EU and the US and China disagree about what user rights are and what reasonable behaviour for a website is.

If one of those parties enforces their vision onto their traffic, it has a chilling effect - splittig the net into federations. By making GDPR super vague, the EU just makes everything worse, including for Europeans. If you disagree that the rules are vague, I'll refer you to the rest of this thread. Nobody knows what's being enforced or what the penalties are.

Post reply on HN