5 ms·
Cookies are integral to the operation of every modern website. They offer security in the form of features like csrf protection or maintaining login state betwe
by Kequc 11y ago
Cookies are integral to the operation of every modern website. They offer security in the form of features like csrf protection or maintaining login state between visits. There is sufficient protection for cookies in the form of encryption and a laundry list of further details which have been added over the years.
There are far larger security related concerns on the web. The cookie warnings are on par with if you had to agree with Javascript running on any page you visit in the EU. So, yes, I want to auto-accept.
As a developer I feel like I'm not going to make special considerations that ensure you can use forms on my website without cookies enabled. And I'm not going to find another way to detect and re-instate your login state.
- prodmerc 11y agoYeah, from a technology point of view, they're necessary. The law is half baked and passed only to appease people who worry about their privacy. And it really doesn't do much...
- cornewut 11y agoActually the law cares only about tracking not cookies. And there are a lot of ways to track users even without cookies.
- blub 11y agoThis law aims to protect users from being tracked across multiple websites. There are exceptions in place and most websites would not need to display any message, unless they are in fact helping track their users. If they include services like Google analytics they should absolutely display the message.
- Asbostos 11y agoIt almost sounds like the law is too weak. Despite all the cookie notices I've seen, I never knew they were only asking permission to track me across sites. If that's what the law is for, then perhaps the warnings need to be even more obtrusive to deter sites from doing such tracking.
- blub 11y agoIt probably is. For instance, third-party social plug-in content-sharing might be quite a big loophole (http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm).
- scrollaway 11y agoIt's a misconception that you need to show this warning if you use cookies. You only need to show it if you use tracking cookies. Which means Google Analytics. Don't use GA and you don't need to show it. Your login cookies etc and anything "essential to the operation of the website" are all explicitly excluded. The law is absurd, but it's not braindead.
- Kequc 11y agoI honestly wasn't aware that was the law. I thought it was all cookies, that's what the warning messages are worded to sound like they are saying, thank you for correcting me. My question then is, websites are phoning home through use of iframes? Because those cookies aren't accessible on different domains than the ones they were issued. Am I to understand companies are loading their own domain in hidden iframes that phone home when I visit a website? Like it checks the iframe's top window location and tracks what pages I'm on? Now you have me feeling paranoid. What can be done about that. Google analytics arguably is a very useful service.
- scrollaway 11y agoI don't understand how you make that logical jump? You can look at how GA tracks users with a bit of googling: https://developers.google.com/analytics/resources/concepts/gaConceptsTrackingOverview?hl=en https://developers.google.com/analytics/resources/concepts/g... https://support.google.com/analytics/answer/2992042?hl=en https://support.google.com/analytics/answer/2992042?hl=en