10 ms·
Cookie policy notifications have ruined user experience on the web
- SteveNuts 8y agoDo these notifications actually help with GDPR compliance or are they just a CYA for the websites?
- gruez 8y agothey were around before GDPR: http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm
- Cthulhu_ 8y agoDefinitely cover your ass, given how the fines are instant bankruptcy for a lot of companies. I'm inclined to believe this + the cookie banners are also a lot of "well site X did it like that, we probably should do that as well" instead of reading and understanding the actual rules. The easy way out would of course be to not violate the GDPR, but with 3rd party advertisers that's a bit painful. I still don't know why big publishers don't just own the ads themselves, that is, have an ad department, have them approve ads and return statistics to the advertisers, have tracking all on the same domain, etc.
- Rjevski 8y agoGDPR compliance requires opt-out, so cookie notifications are useless as far as compliance now. If you don't/can't comply, then you might as well not mention cookies at all - in both cases you're in breach of GDPR but at least you won't be ruining your UX.
- PeterisP 8y agoGDPR compliance can not be done by opt-out, if consent is required, it requires opt-in - recital 32 (https://gdpr-info.eu/recitals/no-32/ https://gdpr-info.eu/recitals/no-32/) "Consent should be given by a clear affirmative act [...]", "Silence, pre-ticked boxes or inactivity should not therefore constitute consent." No matter what your notifications and T&C says, the default UX path where the user clicks "meh, whatever, go on" until the popup disappears won't give the site any legal consent to use data because informed, specific, freely given opt-in consent didn't happen.
- xg15 8y agoGiven that (from my IANAL understanding) the GDPR requires opt-in and forbids "click I accept or leave our service" style forced opt-in, I'd say this is not even CYA - it's closer to magical cargo cult incantations.
- etatoby 8y ago> the GDPR requires opt-in and forbids "click I accept or leave our service" That's an asinine law if I ever saw one. Telling me how I should run my business? Really? From what vantage point, if I may ask? If I had a company, I would ignore the whole thing and invite them to cross the pond and try their crap in my jurisdiction, under my laws. Or just block them altogether. If they want to go back to the middle ages, let them.
- xg15 8y agoIt's called "regulation". Yes, I think, the GDPR is quite opinionated in that they want to discourage "pay with your data"/"surveillance capitalism" type business models - the reasons have been discussed enough in the last years. I guess the authors understood that without that clause, there would be an obvious loophole that would indeed lead to nothing more than annoying pop-ups and reduce the desired consumer choice to name-only. So they took the logical step to close the loophole. Of course many businesses are trying to counter with a pop-up anyway. But then, that's not the fault of the regulation.
- PeterisP 8y agoIMHO not really, GDPR isn't really about (and thus can't be satisfied by) notifications and click-OK-to-continue "consent". For the common use cases of data by random websites, there really are two common scenarios GDPR-wise: 1) Whatever you're (not) doing with the user data falls under one of the multiple GDPR valid reasons for use that do not require user consent: in this case a clear and informative description in an easily accessible privacy policy is sufficient, and the notification/"agreement" isn't needed for GDPR compliance, the popup is useless. 2) Whatever you want to do with user data requires user consent, but you're not going to get GDPR-valid (informed, specific, freely given and opt-in) consent. There are specific sites that can get meaningful consent because users really want it (e.g. genealogy sites come to mind), but for the random "we want to track you for advertising purposes and share it with 200 third parties", it's not realistic. And the popups don't (can't) help you with that. A popup that allows you to opt out... well, if it's not opt-in, the consent isn't valid in the first place; if the user goes "meh, whatever", then that doesn't count as opt-in consent. If the user is required to "agree" to continue, then that doesn't count as freely given consent. If the user isn't clearly told everything before they intentionally opt-in to every single use case because they want you to do that particular thing, then that doesn't count as specific, informed consent. If you do implement all these things properly, then most users aren't going to opt-in in the "ad-tracking" scenario (which is the GDPR intended result), so companies don't want to implement it properly. So the nasty popup doesn't really grant you consent anyway (the process is inevitably missing at least one of these key criteria for valid consent), so GDPR-wise it's useless anyway.
- jasonkostempski 8y agoHA, this made it to the front page right as I was composing this Ask HN submission about picking a de facto standard element CSS class so that ad blockers could just start including a simple rule to get rid of them: https://news.ycombinator.com/item?id=17679932 https://news.ycombinator.com/item?id=17679932
- NSAID 8y agoIt'd be even better if my user agent could simply indicate my acceptance (or lack thereof) for me
- kylel 8y agoThis is what Do Not Track was supposed to be. Unfortunately it never got much momentum. Google, Facebook, Twitter, etc. ignore the DNT header.
- jasonkostempski 8y agoAnother useless attempt at reducing tracking I wish would be banished from the web. The amount of pollution in web standards; official, legal, or accidental; is becoming just as annoying as the annoying things they're trying to fix.
- deleted 8y ago[deleted]
- y0ghur7_xxx 8y agoThere is an adblock filter list for cookie warnings: https://github.com/r4vi/block-the-eu-cookie-shit-list https://github.com/r4vi/block-the-eu-cookie-shit-list
- jasonkostempski 8y agoI figured, but maintaining that is such a waste of human life and parsing the list is a waste of my CPU time. Since no one on either side of the fence wants the notices to exist, web developers could just use a de facto standard element class and ad blockers can add a simple rule.
- rasz 8y agoworks for most: javascript:(function()%7Bvoid([].forEach.call(document.querySelectorAll('body *'),e=>/fixed|sticky/.test(getComputedStyle(e).position)&&e.parentNode.removeChild(e)))%3Bdocument.body.style.overflow%3D'auto'%3Bdocument.body.style.height%3D'auto'%7D)()
- modzu 8y agothen there's reddit and its giant full page ad for the app before finally redirecting me to the content once i find the tiny link to continue instead of opening the app store... yes reddit and fb and gmail and the like are intentionally crippled when viewed on mobile. why? maybe because the data an app can suck up off your phone is much more valuable. no pesky same-origin policies! i digress :(
- imron 8y agoDon't worry about trying to click the 'continue' link, just keep scrolling down and it disappears. It's still annoying, but not as annoying as trying to click the tiny link.
- deleted 8y ago[deleted]
- Bartweiss 8y agoI noticed that reddit now has three separate "use our app" prompts, which don't seem to communicate so they can all appear on the same page. There's the loading-in system popup, the bottom-of-screen one, and the internal popup with a picture and two choices. And then the bottom-bar one, instead of having two buttons, makes the entire field open the app store except for a tiny 'x' in the top right. Talk about unsubtle dark patterns.
- mercer 8y agoThe reddit redesign feels a lot like the Digg changes before everyone moved away. I think reddit still has a lot more going for it, and being able to opt out solves the problem, but I'm still every so slightly worried.
- Bartweiss 8y agoIt hasn't been pushed very hard, but the new 'chat' feature - on a website that already had private messaging - strikes me as a fundamental misunderstanding of what reddit's value is, one bad enough that it makes me doubt for the future design of the site as a whole.
- Shank 8y agoI'm a really big fan of geotargeting these notices only to the EU. If the EU wants cookie notices, give the EU cookie notices. Don't give anyone else cookie notices, because they're garish and few people reasonably care.
- stingraycharles 8y agoBut what if your geotargeting doesn’t work as expected, and has a few false negatives? Will that hold up in court?
- Shank 8y agoPolicy is all about how it gets enforced and acted on. An imperfect cookie targeting scheme could probably fall down in court, but there isn't much caselaw about the cookie law right now. I can't recall any major cases where website operators were taken to court over it.
- littlestymaar 8y agoYou can't do geotargetting here, because to perform geotargetting you need the user consent to use his location (which is a personal data ;) ) if he is european.
- Shank 8y agoIs IP geolocation included in that? I'm genuinely curious, actually. That's how most websites do content filtering (even BBC iPlayer uses server side geolocation to filter people out).
- fasteddie 8y agoThis isn't true. You can use cookies for necessary operations of the website, which this almost certainly is. Also, country level location data isn't PII, and also doing a geoip lookup that you don't store anywhere also isn't in violation.
- 8y ago
- gruez 8y agoWe wouldn't be having this discussion if cookies were opt-in rather than opt-out. I don't sign into 90% of websites I visit, but why are all of them allowed to track me? If cookies were opt-in, then the legal issue of "consent" would be cleanly resolved, and the interface can be handled by the user agent rather than through obtrusive modals.
- SyneRyder 8y agoYou can already do this. In Firefox: * Go to your Cookies And Site Data preferences * Select "Block Cookies And Site Data" * Click on "Exceptions" * Add the address of the website you opt-into * Click "Allow For Session" or "Allow" as you choose.
- sib 8y agoYou visited them and you didn't turn off your browser's cookie requests; therefore you decided to accept the files that the site offer to your browser.
- ballenf 8y agoYou make a fair point -- it's popular to take the same tack with web servers and ad blocking (a server makes content publicly available -- users can decide which parts to view). Not a stretch to apply the same logic both ways -- just because a server offers a file to you, doesn't mean you are forced to store and give the file back on demand. If this view were more widely adopted, it would maybe pressure browser vendors into being more transparent with users on cookie management and proactively ask them how they want to handle them.
- krapp 8y agoThe problem is, the purpose of cookies isn't tracking, they're a hack to maintain state between requests for what's supposed to be a stateless protocol (and until HTML5 came along with session storage and local storage, they were the only way to do that in the browser.) So cookies are useful (and often used) for purposes besides tracking and advertising. Having cookies be opt-in by default would just punish anyone using cookies for benign purposes.
- pupppet 8y agoThey’re terrible. Who are we kidding, no one has backed out of the website after seeing one of these notices.
- craigsmansion 8y agoOf course people have. They don't state it clearly, but every cookie means: "By accepting this cookie you agree to be tracked on the Internet, and allow that data to be sold." (or, "We don't really understand cookie-law, and we didn't actually need to put this up".) Once you know that, it's easier to ask yourself: "Do I really need to read this? Also given that it's likely a sub-par publication, because tracking usually implies layouts and techniques optimised to keep you on the site and optimise data collection."
- mrec 8y agoI back out of them all time. Particularly the egregious dark-pattern ones: "Click this giant green button to let us track you out the wazoo, or click this tiny misleadingly-named link to drag you through a six-hour hell of settings dialogs which will drop you out without actually changing anything the instant it thinks it can get away with it."
- littlestymaar 8y agoHow ironic, websites have been breaking user experience for years by embedding always more trackers that took forever to load. If a publisher doesn't want to display a GDPR notification to its users there's a simple trick : just don't collect and monetize personal informations!
- thrill 8y agoNotifications should be for exceptions that require action.
- cookiePuss 8y agoAction, like "close your browser and clear your cookies, disable cookies, and then block further cookie dropping from that site as well"? Exceptions like when you're being ratted out, to many other companies that perform surveillance on you, by a company you have no particular affection for?
- iKevinShah 8y agoEven if we use cookies for basic sessions (absolutely no personal tracking, just session ID) - Isn't it mandatory to show "Cookie bar" on the said site?
- pjc50 8y agoNo. http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm (Perhaps surprisingly there is an exemption for "third‑party social plug‑in content‑sharing cookies, for logged‑in members of a social network.")
- tremon 8y agoThe operative phrase in that last one is "for logged‑in members", because in that case the cookies fall under the earlier provider of an information society service explicitly required by the user to provide that service. For a user logged-in to a social network, the user clearly consents to the social network providing a service. Note that it is not allowed if the user is not logged in to the social network.
- aaronarduino 8y agoHere is an idea: instead of a cookie policy notification, have a setting in the browser with the user's cookie setting. That way a website can look at that setting and store cookies or not.
- detaro 8y agoYou can already have your website check for the Do Not Track header, don't set non-essential cookies and don't show a notice when it's set. Basically no website does that.
- andrethegiant 8y agoWhat happens if you use cookies and don't show any banner? Does this also apply to localStorage and other offline storage methods?
- aarongray 8y agoIt would be cool if we could develop a protocol where users could flip a setting on their browser that tells every website they visit that the user has consciously, legally opted-in to all cookies. Heck, it would be cool to also have an option that says I accept all your Privacy Policies and Terms of Agreement, so don't show me any banners related to those either.
- joobus 8y ago> a setting on their browser that tells every website they visit that the user has consciously, legally opted-in to all cookies IMO, you do this when you open the browser. Why does every website need to explain how the internet works?
- PeterisP 8y agoMany websites legally need opt-in permission to put (and use) a tracking cookie, so unless the user intentionally chooses to do opt in, they're not legally permitted to do so even if the internet technologies enable them to make it happen. There are many things that are technically easily possible, but prohibited unless certain nontechnical conditions are met. Tracking cookies is one of them. Opening a browser doesn't constitute freely opting in to your specific use of data; at most it constitutes not opting out, but that's not legally sufficient.
- weinzierl 8y agoAre Cookie policy notifications a thing outside of the EU? I always assumed that websites geo target these notifications and life with the small risk of corner cases (like EU customer in the US). If anyone has experience, or numbers I’d find that highly interesting. One datapoint from Germany: We were largely unaffected by cookie notifications before GDPR, because of a local law (TMG) that superseded the EU “cookie law”. Since GDPR we are in the curious situation that every small and medium sized business plasters it’s website with extravagant opt-in notification pop-ups while the worst privacy offenders, like the nations largest newspapers, bombard you with all kinds of cookies with no notification at all. Just one example I tried a few moments ago: spiegel.de one of the most widely read German-language news sites set 54 cookies from lots of different domains plus local storage usage. No cookie notification whatsoever. Another example: bundesregierung.de, the official government website, states in it’s privacy policy that they set a web analytics cookie (Matomo) but they don’t show a notification either.
- JeanMarcS 8y agoThe « funniest » part is that Spiegel probably made several news article about GDPR. In France it’s the same. Sad thing for them, they won’t be able to pretend they didn’t knew (which will be a good lesson taught)
- weinzierl 8y agoHeise is even worse. They covered GDPR extensively, yet don't do any notifications on their own websites.
- mobilehnuser 8y agoNot just cookie policy notifs but all bottom or top aligned overlays present on page load... like the one on this reddit page begging me to install a mobile app so they can get my advertising id
- jokoon 8y agoI can't count how many times i right clicked to hide element thanks to u block origin
- Bromskloss 8y agoI wish we could converge on a way to tag such notifications, so that those who want to can filter them out.