Live data from Hacker News

Europe's cookie nightmare is crumbling. EC wants preference at browser level

theverge.com

71–80 of 99 posts

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#71
post #67

Users will overwhelmingly use browsers in vanilla config. The question here will be how browser vendors show this option. If - say - a company that gives away a browser for free but makes money from ads designed this, then they'll hide the option deep in some obscure menu, never remind people it exists, and reset it on every update. So the devil is in the details. The best option I think isn't a secret setting in a b…

Dialog is already standardized in the current GDPR. There is literally an item there which states that Reject consent option should be the same and equally easily accessible as Accept consent option. So basically all dark pattern sites are already criminals. The problem is zero enforcement of the GDPR.

It's standardized in behavior only, it doesn't prescribe which button is where in the dialog etc. But yea for those that actually follow it, it's not a _big_ problem, but it's still an improvement to get an exactly similar dialog. Especially if you can check the [x] reject everything on every site

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#72

Related: https://news.ycombinator.com/item?id=45667866 Personally, I find this a move in the wrong direction where hostile behavior by websites is normalized and hidden. Cookie banners show web site true colors. When someone asks me to share data with a thousand of "partners", I leave.

> Personally, I find this a move in the wrong direction where hostile behavior by websites is normalized and hidden. Cookie banners show web site true colors. When someone asks me to share data with a thousand of "partners", I leave.

I kind of agree, but at the same time basically all websites are using some kind of tracking to know what kind of users visit, and I'm tired of clicking "allow all" just to read an article. Many websites don't even work if you refuse non-essential trackers, because their tag manager is configured incorrectly, or because by law if there's even a single textbox where users can put their email or name, they need to have the consent to show that and allow input on it.

Having a browser default of "nope" with the option to whitelist a broken website would save a ton of time for people and machines the same, and also reduce website latency a lot. There's a nice website that "tracks" this cost: https://cookiecost.eu/

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#73

Here's my proposal: * Let websites do whatever they want with cookies/local storage. * Let browsers delete them as often as they want. * Make other kinds of fingerprinting illegal.

> * Make other kinds of fingerprinting illegal. Speeding is illegal. Controlled substances are illegal. Murder is illegal. Embezzlement is illegal. Driving in a school zone while using a mobile device is illegal. Has the legality stopped any of it?

>Has the legality stopped any of it?

I'd suggest that illegality has in fact stopped most of it. We'd surely have many times as many murders if it was legal to murder people.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#74
post #16

Much like the current cookie banner shitshow, a "centrally configured" setting which "websites must respect" will accomplish nothing. There is no consent, informed or otherwise. Advertisers and their ilk are still hoovering up all the data they can, with or without cookies or consent. Locking up a few people who don't respect their users' privacy would be a much more effective way of achieving actual results. AFAIK n…

Only thing that actually worked against advertisers is ad blocker. Everything else made them laugh.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#75
post #16

Much like the current cookie banner shitshow, a "centrally configured" setting which "websites must respect" will accomplish nothing. There is no consent, informed or otherwise. Advertisers and their ilk are still hoovering up all the data they can, with or without cookies or consent. Locking up a few people who don't respect their users' privacy would be a much more effective way of achieving actual results. AFAIK n…

Me telling you that I don't want to be tracked, no matter what your argument is, is as informed as it gets. You just don't like the answer so you feel entitled to ask again.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#76

Earlier quoted context omitted.

I agree. I think it's one of those things that people complain about because other people complain about. You have to click a button. Wow. What an ordeal. The title of this thread used the term "nightmare". I would be thankful that my life is so wonderful that clicking a button is considered a "nightmare". It's transparent and if you don't like it, don't go to that site.

It's a nightmare because it is everywhere you turn, not because of the difficulty in dismissing the banner (although not all banners are made equally). But I'm pretty sure you're smart enough to realize you're intentionally making a strawman argument. It's the purpose of the argument I'm not sure.

It's on websites, not everywhere I turn. And it's very very very simple to deal with. At least it is for me.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#77

Earlier quoted context omitted.

Are EULAs even enforceable?

In the EU, it's complicated. There is a very clear law that forbids any additional contract terms post the point of sale, so that if you go to a store, purchase a box with software in it and then go home to install it, when it pops up a dialog for you to "agree" on, you can just ignore it, nothing in that is enforceable at all. And no, small print text on the box that says you have to agree to terms in the software d…

I'm not even sure you can generalize to "in the EU" here. A lot of contract law might be different between countries.

So for example, in Germany, an EULA would be considered an AGB, and subject to §303 BGB and following paragraphs, which e.g. means, "surprising" clauses which you cannot reasonably expect beforehand being part of the EULA would be unenforcable or §307 BGB would make certain kinds of one-sided/lop-sided clauses unenforcable.

Other EU countries might have other laws. I'm not really sure this is an area of unification, and a lot of the commonalities there is might be more due to the common heritage of Napoleon's Code Civil which underlies contract law in many european countries, instead of EU unification efforts.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#78
post #13

Earlier quoted context omitted.

False dichotomy, just advertise based on the content of the site without spying on people

Untargeted pay less than 90% of targeted ones generally. And there's not a lot of companies that can handle a 90% drop in revenue. The real solution would be to make users pay for the content, but charging for something that users used to get for "free" is also essentially impossible.

> Untargeted pay less than 90% of targeted ones generally.

If targeted advertising, as a whole, is banned, you can be pretty damn sure the payout for untargeted will come up—not necessarily to match what targeted is now, but way more than that 10% figure.

Ad spend, in aggregate, doesn't change that much based on new "innovations" in advertising annoyance. If you've still got roughly the same amount of money being spent on untargeted ads, continent-wide, as you do now on targeted, they're going to pay out much closer to parity.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#79

Earlier quoted context omitted.

Cookie consent banners and such come from the ePrivacy Directive, not the GDPR. The banners themselves were never mandated, but lacking any other standardized opt-in signal, that's what everyone converged on anyway.

To be clear, the other option was to respect privacy by default and comply with the GDPR without any banner.

A lot of sites put up the banner even when they're not serving anything but "essential cookies", just as a CYA mechanism mandated by legal. And to some degree, I can see legal's point: the site might be just fine now, but you just know somewhere in the sausage-making process, someone's eventually going to toss in a dependency that brings in a tracker without clearing it first, and boom, exposure.

Having a clear non-interactive signal that's legally recognized should go a long way toward clearing out those annoying banners.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#80

Earlier quoted context omitted.

It's a nightmare because it is everywhere you turn, not because of the difficulty in dismissing the banner (although not all banners are made equally). But I'm pretty sure you're smart enough to realize you're intentionally making a strawman argument. It's the purpose of the argument I'm not sure.

It's on websites, not everywhere I turn. And it's very very very simple to deal with. At least it is for me.

ugh. of course I didn't mean at your local 7-11 or grocery market and quite clearly meant everywhere you turn online. pedantry is so boring
Post reply on HN