Live data from Hacker News

Europe's cookie nightmare is crumbling. EC wants preference at browser level

theverge.com

1–10 of 99 posts

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#2
Related: https://news.ycombinator.com/item?id=45667866

Personally, I find this a move in the wrong direction where hostile behavior by websites is normalized and hidden. Cookie banners show web site true colors. When someone asks me to share data with a thousand of "partners", I leave.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#3
This was the correct decision and could have been made a decade ago. An .. institutional deficiency was trying to make the GDPR as completely general as possible rather than doing a technology mandate. But this had two consequences: bad actors could circumvent it, and good actors just trying to comply ended up horribly confused (e.g. is logging an IP address in an Apache log "personal data"?).

DNT header. Legally binding. Out of the way of the end user. Unambiguous for enforcement purposes. Probably the end of targeted advertising, but that was always the logical conclusion of GDPR.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#5
post #3

This was the correct decision and could have been made a decade ago. An .. institutional deficiency was trying to make the GDPR as completely general as possible rather than doing a technology mandate. But this had two consequences: bad actors could circumvent it, and good actors just trying to comply ended up horribly confused (e.g. is logging an IP address in an Apache log "personal data"?). DNT header. Legally bin…

Cookie consent banners and such come from the ePrivacy Directive, not the GDPR. The banners themselves were never mandated, but lacking any other standardized opt-in signal, that's what everyone converged on anyway.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#8
post #4

> This is not a real choice made by citizens This is something which courts should consider more about other things, such as EULA and Terms and Conditions. Same reasons.

The choice citizens would make every single time is to see the website without ads. Of course, publishers aren’t happy about that, since they would have to close shop. Maybe the EC should consider both sides of the equation.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#9
post #3

This was the correct decision and could have been made a decade ago. An .. institutional deficiency was trying to make the GDPR as completely general as possible rather than doing a technology mandate. But this had two consequences: bad actors could circumvent it, and good actors just trying to comply ended up horribly confused (e.g. is logging an IP address in an Apache log "personal data"?). DNT header. Legally bin…

I agree cookie banners were the wrong solution, and sometimes made things worse (it make a cookie whitelist extensions I used to use unusable because you have to allow the cookie that stores your cookie preferences).

However, this bit concerns me:

> This key change is part of a new Digital Package of proposals to simplify the EU’s digital rules, and will initially see cookie prompts change to be a simplified yes or no single-click prompt ahead of the “technological solutions” eventually coming to browsers. Websites will be required to respect cookie choices for at least six months, and the EU also wants website owners to not use cookie banners for “harmless uses” like counting website visits, to lessen the amount of pop-ups.

That implies there will be "harmless tracking" allowed, and it removes choices. The latter might restrict dark patterns, but it might also encourage "allow all cookies or you cannot read the site at all" approaches.

Re: Europe's cookie nightmare is crumbling. EC wants preference at browser level

#10
post #3

This was the correct decision and could have been made a decade ago. An .. institutional deficiency was trying to make the GDPR as completely general as possible rather than doing a technology mandate. But this had two consequences: bad actors could circumvent it, and good actors just trying to comply ended up horribly confused (e.g. is logging an IP address in an Apache log "personal data"?). DNT header. Legally bin…

Would there have been cookie banners if DNT was respected?
Post reply on HN