Live data from Hacker News

The GDPR Is a Cookie Monster

emarketer.com

81–90 of 97 posts

Re: The GDPR Is a Cookie Monster

#81
post #29
post #19

Earlier quoted context omitted.

You mean like the "do not track" request header? https://en.wikipedia.org/wiki/Do_Not_Track It never ceases to amaze me the number of companies that "value" my privacy but still somehow ignore the do not track header.

Well, Microsoft kinda dropped the ball on that one by making it the default (although they later changed that).

I don't feel like they did drop the ball there. By default I don't want to be tracked. I think that tracking across the internet should be opt in and users should be made aware of what websites are doing _before_ they start doing it.

I also find the idea of secret shadow profiles to slightly immoral for the same reason.

Re: The GDPR Is a Cookie Monster

#82

Earlier quoted context omitted.

If you're looking for advertisers, all other things being equal, do you go with the advertiser who guarantees your ads will go to those most likely to have interest in your product, or do you go with the advertiser that will send your ads to random people? Of course they _can_ serve ads randomly, but they're competing to provide the best value for those buying ads.

Corporations want cheaper ads; I understand that but I don't understand why I should be tracked. They should develop better ads without violating someone's privacy or anonymity.

Companies aren't paying just to show you ads. They are almost always paying for clicks on those ads that lead users to their website.

That tracking allows them to build more accurate models on what ads a user will click on and then tailor ads to the user causing increased ad click rates which results in more revenue.

And I'm not really concerned about the big companies. I'm concerned about all the news agencies that are barely scraping by with targeted advertising revenue. Remove the targeting and web journalism will get even worse as they have to layoff more people and resort to even more clickbaity news.

Re: The GDPR Is a Cookie Monster

#83
post #56

The dark patterns in play now to get explicit consent are pretty bad now though. Take Mashable for example. On first visiting the site you are presented with the option to "Consent" or view more Options (where you can Opt Out of all - except you can't really because some require Opting Out on the specific Advertisers site). But if you do choose to Opt Out all, they will then show you the initial Option box on every v…

Article 7 of the GDPR specifically states that "It shall be as easy to withdraw as to give consent." > And if you ever accidentally click I Consent, then they opt you back in to everything again and then never show you that option box ever again. If this is accurate, then this is another violation of the same article, which also states that "The data subject shall have the right to withdraw his or her consent at any…

[deleted]

Re: The GDPR Is a Cookie Monster

#84

I just HATE all the pop-ups asking for permission to use cookies now. Seriously, having to opt-in on a per-site basis has led me to loathe the GDPR. It's a usability disaster. I never thought I'd hate anything more than the "sign up for our newsletter" pop-ups... but these are even more pervasive. If I'm the kind of person who hates cookies/tracking, I'll just install a blocker and block it everywhere, and then white…

I think we should have a de facto standard element class for legal notices with no required user action, like legal-notice-no-action-required. Webistes use the css class, uBlock Origin makes it a built-in default element filter. Website owners can fulfill their legal obligations and users that proactively shape their browsing experience are all set. Neither side wants these things messing up the browsing experience s…

> I think we should have a de facto standard element class for legal notices with no required user action, like legal-notice-no-action-required. Webistes use the css class, uBlock Origin makes it a built-in default element filter. Website owners can fulfill their legal obligations and users that proactively shape their browsing experience are all set.

Sounds like P3P ( https://en.wikipedia.org/wiki/P3P )

> Neither side wants these things messing up the browsing experience so, unlike the ad wars, we can work together.

Personally, I absolutely want to know when sites are trying to spy on me and sell the data. Despicable crap like that should be forced out into the public, not quietly agreed to by the browser. That's exactly what GDPR is for.

Re: The GDPR Is a Cookie Monster

#85

The GDPR should get one important update and that’s QUICK: You shouldn’t be allowed to ask for consent to do tracking or targeting as a pop up. The site must be completely usable using only “required” cookies (to which no consent should be required if it only tracks a limited set of data) and any option to consent to anything outside this must be a hidden option. That is: sites should have to work 100% without popups…

> The site must be completely usable using only “required” cookies (to which no consent should be required if it only tracks a limited set of data)

I think GDPR does actually say this.

> any option to consent to anything outside this must be a hidden option.

You're right that this would be a difference (although I imagine sites would still end up covered in dark patterns trying to get users to enable it)

Re: The GDPR Is a Cookie Monster

#86
post #82

Earlier quoted context omitted.

Corporations want cheaper ads; I understand that but I don't understand why I should be tracked. They should develop better ads without violating someone's privacy or anonymity.

Companies aren't paying just to show you ads. They are almost always paying for clicks on those ads that lead users to their website. That tracking allows them to build more accurate models on what ads a user will click on and then tailor ads to the user causing increased ad click rates which results in more revenue. And I'm not really concerned about the big companies. I'm concerned about all the news agencies that…

Without tracking the ad won't disappear, just some kinds of it can become more expensive and less effective; that is not a big problem. Companies can still show relevant ads: Google can show ads matching current search query, Youtube can show ads relevant to the video, and so on.

Regarding news sites, they have a lot of opportunities to earn money, for example, publish sponsored articles. They can also use subscription model. It is better than have mobile apps that scrap data from your phone, Google Maps that track every your step, and data brokers you never heard of but they have full information about you. We should not sacrifice our privacy only because someone out there cannot make the ends meet.

Google won't shut down if you stop it from tracking users' location. People will still search the internet and buy smartphones.

Re: The GDPR Is a Cookie Monster

#87

Earlier quoted context omitted.

Because GDPR includes provisions for handling US GDPR violators, a lot of security vendors were touting up the idea that if a European fills out a form on your site or gets cookied for any reason, you could be sued.

Honestly that is a classic "Come at me bro" type of moment. Sue me in the EU, it really doesnt matter if I don't do business there.

[deleted]

Re: The GDPR Is a Cookie Monster

#88
post #62
post #54

Earlier quoted context omitted.

At work I don't have any third-party blocking extensions (I use Chrome). At home and on my mobile I do (I use Firefox Focus), but neither let websites to "remember". Is there something I need to configure?

Firefox Focus deletes all data upon closing. That includes cookies where your consent was locally stored. That's why you're seeing it every time.

Yeah, but this problem exists even on Chrome which I have no extension.So Chrome has some built-in blocker interferring it?

Re: The GDPR Is a Cookie Monster

#89

The GDPR should get one important update and that’s QUICK: You shouldn’t be allowed to ask for consent to do tracking or targeting as a pop up. The site must be completely usable using only “required” cookies (to which no consent should be required if it only tracks a limited set of data) and any option to consent to anything outside this must be a hidden option. That is: sites should have to work 100% without popups…

> The site must be completely usable using only “required” cookies (to which no consent should be required if it only tracks a limited set of data) I think GDPR does actually say this. > any option to consent to anything outside this must be a hidden option. You're right that this would be a difference (although I imagine sites would still end up covered in dark patterns trying to get users to enable it)

Right. And ”hidden option” is perhaps the wrong word, but let’s say one that doesn’t prevent using the site/service in full.

Even supposedly serious outlets like WaPo does this. Full screen splash that says “by using the site you agree to targeted ads”. Why even bother with that when it’s so blatantly in violation? Isn’t it almost better to not look like you are deliberately in violation like that?

It’s not even a dark pattern, it’s just a big fat splash explaining how they don’t care about the GDPR and intend to show me targeted ads using tracking cookies.

Re: The GDPR Is a Cookie Monster

#90
post #11
post #8

Earlier quoted context omitted.

I honestly don't get why so many sites are even paying attention to GDPR. If they don't have a presence in the EU, it is irrelevant.

It is not. If their customers are in the EU they have to to comply.

I was specific. If I don't do business in the EU, it doesn't matter. I don't really care where my customers are but if they pay in the US, GDPR is not relevant to me.

I get that everyone is super excited about GDPR, but sorry to say most websites can safely ignore it.

Post reply on HN