Live data from Hacker News

Consent-O-Matic: Automatic handling of GDPR consent forms

github.com

81–90 of 137 posts

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#81

I wish there was a standard browser API for this. If the law is going to force this to be a thing, and it's not going away, web standards should respond. It could even just be a flag in the cookie itself declaring that something isn't strictly necessary.

> I wish there was a standard browser API for this. There was: https://en.wikipedia.org/wiki/P3P

And Google was caught exploiting a weakness in the P3P implementation to bypass it entirely. Google was also caught exploiting a loophole in Safari when it added 3rd party cookie blocking: https://www.zdnet.com/article/google-pays-17m-to-settle-safa...

AdTech companies want to track you, and it's naive to think they will ever honestly and voluntarily use any APIs that blocks it.

Current deliberately-awful cookie consent prompts are malicious compliance aimed to make law makers look incompetent and make people resent privacy protection laws.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#82
post #53

Earlier quoted context omitted.

As my hosts-file and ad/script blocker are configured to block tracking and advertising I always click: Accept all. This is by default the quickest way to get to the content. Without compromising privacy by using addons.

Wouldn't that still allow advertisers to track you through your IP or other means?

The extension in my browser block the outgoing call. If something goes through the host file redirects this to my local host that doesn't answer.

So no - advertisers never "see" me.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#83
post #61

Earlier quoted context omitted.

Hmm. How does one block ads without a plug-in?

You alias all the known ad-serving domains to unresolvable stuff in the hosts file. I just used one of the lists I found on GitHub.

Exactly that. I would recommend something like this [0].

[0]: https://github.com/StevenBlack/hosts

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#84

Earlier quoted context omitted.

It can't be. At least not if you want to accept cookies. Declining is easy. You can just decline everything (technically) not necessary. The problem is, that consent must be given freely and fully informed. And this is the catch. Automatic acceptance isn't fully informed and with that the consent isn't valid. So it would put the companies in danger and therefore no company could honor this standard. Sadly - as it wou…

"Accept all" and the "Deny all" must be both be the same level of "easy-ness" I think this is not clear until it has been tested in court. Many websites now have two offers: Free with 3rd part ads and paid. Surely paying is much less easy than clicking "Ok, show me the content with 3rd party ads". It will be very interesting, how courts see this.

In Germany, the media sites that offered "either tracking/advertising" on vs "paid content approach" were already in court with that practice and won.

The current situation is, that the courts decided, that the business model (advertising and by that tracking the sh*t out of people) is valid if they offer an alternative were people pay them for access to the content.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#85
post #53

Earlier quoted context omitted.

Wouldn't that still allow advertisers to track you through your IP or other means?

The extension in my browser block the outgoing call. If something goes through the host file redirects this to my local host that doesn't answer. So no - advertisers never "see" me.

The website you're connecting to could still log your IP and since you've agreed to tracking they can sell it on to advertisers.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#86

I wish there was an open source project for developers to implement those darn consent forms. Adsense offers an automatic consent modal. But the problem with that one is that it not only displays the consent modal but also injects a smaller widget into the site. It looks like the widget only pops up when the user scrolls down to the bottom of the page. Unfortunately, that also makes it pop up when the page is not lon…

I've seen this consent manager recommended: https://github.com/kiprotect/klaro

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#87

Earlier quoted context omitted.

"Accept all" and the "Deny all" must be both be the same level of "easy-ness" I think this is not clear until it has been tested in court. Many websites now have two offers: Free with 3rd part ads and paid. Surely paying is much less easy than clicking "Ok, show me the content with 3rd party ads". It will be very interesting, how courts see this.

In Germany, the media sites that offered "either tracking/advertising" on vs "paid content approach" were already in court with that practice and won. The current situation is, that the courts decided, that the business model (advertising and by that tracking the sh*t out of people) is valid if they offer an alternative were people pay them for access to the content.

    were already in court
Really? That surprises me. I did not hear about this.

Do you have a link to such a case?

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#88
I'm part of the team working on consent-o-matic at Aarhus University, and it's great to see the project getting some attention here. We've been running the project on a bit of a shoestring budget, but we are currently working on improving detection and adding more CMPs. We are also testing the plugin for Safari on both MacOS and iOS, and hopefully have it released soon. I can attest that it is very nice to have on the phone, and it makes me very happy every time I see my phone autofill a pop-up :-)

Since creating rules is one of the more time consuming parts of maintaining the project, we are happy for any help we can get through pull requests to the rule lists.

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#89

I'm part of the team working on consent-o-matic at Aarhus University, and it's great to see the project getting some attention here. We've been running the project on a bit of a shoestring budget, but we are currently working on improving detection and adding more CMPs. We are also testing the plugin for Safari on both MacOS and iOS, and hopefully have it released soon. I can attest that it is very nice to have on th…

What does it actually do? Does it automatically "accept everything"? Or reject everything? Or just supress the consent forms?

Re: Consent-O-Matic: Automatic handling of GDPR consent forms

#90
post #51
post #36

Earlier quoted context omitted.

That's not informed consent but if you decide to accept everything without reading anything, it's your right to do it. You won't be able to complain in case of "surprises". So yes, a browser could come with an "Accept all" setting, probably disabled by default, but which browser vendor is going to go through the trouble of implementing that, proposing an API and above all getting every Privacy Agency of the world to…

Clicking a checkbox that says "accept all tracking/cookies purpose from any website" and having the browser accept for you absolutely is informed consent. A court would look at this and a person who mindlessly clicked "accept all" on every website as equivalent. Browsers could propose an API for this functionality and no doubt some websites would implement it. They havent but they could. Whether there's any point is…

If I sign a form that says "I accept all medical procedures being done to me in the next month.", that wouldn't be informed consent for a surgery two weeks later if I hadn't been aware of the risks of the surgery at the time that I signed the form. Being informed of the specifics for a particular procedure is necessary, not just being informed of the general risks of medical procedures.

In the same way, GDPR requires informed consent about the specific use of data by a specific data controller. From https://gdpr-info.eu/issues/consent/ :

> For consent to be informed and specific, the data subject must at least be notified about the controller’s identity, what kind of data will be processed, how it will be used and the purpose of the processing operations as a safeguard against ‘function creep’.

The proposed browser-based solution that sends an automated acceptance on behalf of the user would not qualify as informed consent in the context of the GDPR, because the consent was given prior to the human being informed about the specific use by the specific site.

Post reply on HN