6 ms·
> The EU approach to privacy (eroded by lobyying and lack of control over US companies) is that citizens have a right over their information. They can ask what
by wfunction 10y ago
> The EU approach to privacy (eroded by lobyying and lack of control over US companies) is that citizens have a right over their information. They can ask what personal information a company has on them, ask that it be corrected or deleted. This has resulted in companies that are more careful with data.
More like, this has resulted in things like nonsensical "Cookie warnings" that only waste the user's time.
- DonHopkins 10y agoNot entirely. I've learned to read the word "cookie" in many different languages.
- Semaphor 10y agoIt has resulted in a lot of good things. Cookie consent is most certainly not one of them.
- EvilTerran 10y agoIMO, the intent was good... but yeah, the implementation is a grand demonstration of what you get when legislators don't understand the technology they're regulating. It would be far better if they'd required browsers, not websites, to show the notifications - much like they already do when a site wants to access your webcam/mic/location/etc[0]. That would mean much less implementation work (once per browser instead of per site), no way for underhanded sites to use cookies without the user being notified or despite the user declining them, consistent UI across all sites... Such a thing could provide significantly more useful information, too - I envisage a notification with "This site wants to use a cookie on your computer" at the top, "allow/deny, now/always" buttons and a "What are cookies?" link at the bottom, and a user-friendly breakdown of this particular case in between, things like: • "only visible to this site" vs "visible to ad.doubleclick.net" etc - maybe including, say, the Organization Name from the cookie domain's SSL cert, at least in the case of cookies set to "Secure" (maybe only if the cert's EV) • "until you close your browser" vs "for a week" etc - perhaps with a way for the user to force session-only if desired • possibly some kind of warning about snooping risk if the cookie's not marked secure, or not HTTP-only & 3rd-party scripts are on the page, etc • for the case of 3rd-party cookies, it'd be possible to list which other sites have used the same cookie in the past And so forth. The most importantant point being that you could actually trust this information - your browser has no motivation to lie to you about it, but any random site might. [0] eg, https://i.imgur.com/NcxWz8zh.jpg https://i.imgur.com/NcxWz8zh.jpg
- kuschku 10y agoThe issue is: What about technical cookies? The law allows storing session info, config options, etc without prompting. The browser couldn’t reliably test that. Unless you’d also let login to sites be handled by the browser, akin to Mozilla’s Persona. Damn, that’d actually be a much nicer web.
- EvilTerran 10y agoYeah, that could work. Or, to look at it another way... so what if the browser pops up notifications more often than the law requires? Might encourage people to make less use of cookies for functionality that doesn't really need them, which would be no tragedy. And if your site really can't do without them, you could pop up a message explaining the situation & politely asking to be unblocked. I suppose there'd be a danger of alert fatigue... maybe some heuristic analysis of the cookies themselves would be in order, to at least tentatively classify them as "tracking" vs "other". Eg, Google Analytics & Piwik cookies could be identified pretty reliably.
- Semaphor 10y ago> I suppose there'd be a danger of alert fatigue... But that's happening with the current solution as well (not to mention all those crappy sites with their modal popups that teach you to close anything opening asap anyway)
- codedokode 10y agoSingle Sign-on can be implemented without third-party cookies and therefore without the cookie warning.
- blub 10y agoThat cookie warning is just a friendly reminder that you are being tracked everywhere. Of course, websites that don't track their users are exempt: http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm I guess the EU didn't expect websites to cling to tracking cookies like their lives depended on them.
- Isinlor 10y agoCookie law is one of the stupidest laws that EU forced. I had to install additional rules to adblocker to get rid of this nonsense and it still doesn't catch everything and keeps irritating me... I don't care, damn it! http://nocookielaw.com/ http://nocookielaw.com/
- kuschku 10y agoIs it truly? The law is pretty simple: If you track users, or transmit information to third parties which could track the user, you have to get the user to opt-in. The original intention was to get rid of Facebook’s shadow profiles, which it did – in the EU, websites don’t embed Facebook’s like button anymore, but have a two-click solution, where you have to click it, then it’s actually loaded, then you can like. That alone is worth such a law.
- Isinlor 10y agoIt is not worth it. I would really want a good way to protect myself as an Internet user from this law that the EU is enforcing on me. To protect myself not from Facebook, not from Google, but from the EU. It also gets in my way as a web developer. The law is not simple. 100 words sentences of law jargon are not simple. Many, many pages of such sentences is the opposite of simple. To be honest I have never really understood the law and I don't think I ever will. Even keeping track of it is far from simple. But according to this website: http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm Cookies clearly exempt from consent according to the EU advisory body on data protection- WP29pdf include: (...) third‑party social plug‑in content‑sharing cookies, for logged‑in members of a social network. So, I think what you say about Facebook is not true.
- codedokode 10y agoCookie warnings are an indicator showing that a website takes part in a global spying network. But I think instead of warnings browser developers should just disable third-party cookies by default. Sadly, the most popular browser developer by conicidence owns a popular tracking service so that is not going to happen.
- lewiseason 10y ago> global spying network Or maybe they want to persist session information? Maybe browsers should prompt, instead of each website, but it's too late for that now.
- kuschku 10y ago> Or maybe they want to persist session information? That’s specifically exempt from the cookie law: Any technical cookie – session information, config options, etc – is allowed without any request. The Cookie law only requires opt-in for tracking. Such as Google Analytics.
- lewiseason 10y agoYeah, good point. I couldn't recall if it was third-party cookies, or if it were tracking cookies that the requirement stated.
- deleted 10y ago[deleted]