6 ms·
The whole cookie consent thing is a joke. We need rules that stop data collection, not rules that make us have to navigate arcane menus.
by NohatCoder 7y ago
The whole cookie consent thing is a joke. We need rules that stop data collection, not rules that make us have to navigate arcane menus.
- Jestar342 7y agoIANAL, but it is my understanding that those arcane menus are actually breaking the law (with respect to GDPR in the EU, at least). The default position should always be "No", and combined with that the "exit route" for anyone that opted-in should also be really, really easy. Like single-click easy. But business gonna business and bend the rules, I guess.
- bad_user 7y ago> But business gonna business and bend the rules, I guess. Until some lawsuits will happen and the EU has been more than happy to collect fines.
- Nextgrid 7y agoThe reason a majority of websites doesn't comply is because data protection agencies are doing fuck all and there has been no enforcement of the regulations. It doesn't help that reporting non-compliant websites is a pain, at least in the UK. It's as if they're not actually interested in collecting all that "free" money from the fines.
- icebraining 7y ago> data protection agencies are doing fuck all Why do you say this? At least ours is just swamped, so it'll take a while. Plus big cases take up a lot of resources. But there have been GDPR fines issued, and many many more warnings that might lead to fines if the company doesn't comply.
- nihonde 7y agoI’ve been a lawyer practicing in this area since the mid-90s. Nothing meaningful has changed since then. They pass laws and regs, consultants and lawyers get rich by scaring their clients about upcoming rule changes, and the regulators hand out completely ineffectual slaps on the wrist while the big players openly violate the rules.
- Nextgrid 7y agoBeing swamped shouldn't prevent them from at least starting somewhere, and Google and Facebook are violating it so badly it should be a very easy case... yet none of the data protection agencies dare to go anywhere near it (there have been cases against but they seemed to hinge on minor violations as opposed to the elephant in the room). Plus, the swamping problem will stop because the first high-profile case will scare everyone else into compliance.
- icebraining 7y ago> Google and Facebook are violating it so badly it should be a very easy case... Not really, because Google and Facebook will also fight any accusation tooth and nail in the courts and through lobbying. The case must be very well documented and defended. I'm not saying you're wrong, but it's too early to tell.
- Jestar342 7y agohttp://enforcementtracker.com/ http://enforcementtracker.com/ may be of interest to you.
- reaperducer 7y agoThat's an interesting list, but almost none of the fines on it have anything to do with cookies or pre-checked forms. It's more like this gem: "The fine was imposed on a soccer coach who had secretly filmed female players while they were naked in the shower cubicle for years." I think the previous poster's point stands: GDPR enforcement is doing almost nothing about improper cookies and internet tracking.
- the_snooze 7y agoPretty much none of those dialogs are compliant. https://twitter.com/random_walker/status/1187391482401038336 https://twitter.com/random_walker/status/1187391482401038336
- NohatCoder 7y agoThe laws have grown muddy due to lack of enforcement. The notion that there is such a thing as opting in creates a huge gray area, and that has made law enforcement hesitant to open any cases as they are likely to take a lot of time, and probably won't lead to any big victories.
- tennislord 7y agoDamn, very real.
- alpaca128 7y agoAgreed, there should be much stricter rules around tracking. And instead of the cookie popups it would have been much better to solve it the same way localization and notifications work: the browser asks users with an integrated dialog and the user can set it to not even show that popup in the settings. If the browser doesn't support that feature the website has to assume the user doesn't consent.
- redprince 7y agoThe amount of stupidity surrounding this legislation is appalling. The obvious solution could have been: - Use or make something similar of the ill fated Do Not Track header for anonymous users. The user decides on his stance regarding privacy. His machine makes it known to the server, the server acts according to the users wishes. No further user interaction required. - Decide what to do if the user authenticates. Use the method above or offer a more granular way to control privacy settings to be configured by the user in his account settings. Though that would basically kill analytics. The reasonable default for such a Header is no tracking. The controversy around the existing DNT header and the attempts of at least Microsoft to set it to "no track" on default, is "enlightening". https://www.fastcompany.com/90308068/how-the-tragic-death-of-do-not-track-ruined-the-web-for-everyone https://www.fastcompany.com/90308068/how-the-tragic-death-of... I the meantime I installed the Firefox Add-on "I don't care about cookies" which does a reasonably good job to remove these annoyances.
- hrktb 7y agoThe legislation proposed the most obvious solution: - just don’t collect anything, don’t even require cookies From there every significant actors of the industry, short of firefox and Apple (perhaps Microsoft ?) just went on looking for the other ways, workarounds, anything to keep their business as close as it is now. That going as far as completely cutting off whole swaths of users just to not bend to the rules. Blame the players cheating and conspiring to bend the game and ignore or weaken any attempt to limit their reach.
- icebraining 7y agoI agree the cookie law was a failure. The EU does too, so it's being revised. The GDPR is a different matter altogether, it doesn't specify technical solutions at all, and covers all personal data, not just tracking.
- alkonaut 7y agoThe only compliant way to show tracking ads is to first ask the user if they can, where the default in case of non-response must be NO. You can't have it default on, and you can't condition access to the site on accepting non-essential cookies (where "essential" is for the actual site function, and not "essential because our business model means tracking ads keeps the servers running"). Once this is enforced properly, the web will be a better place. Right now it's a mess of cookie banners with no real function, that people just click OK to.
- indigochill 7y ago>Once this is enforced properly Which simply can't happen. There's a reason websites aren't manually indexed. And that same reason means you can never fully enforce these laws. What you can do, though, is score political points for selectively applying them to large unpopular players. It's always going to be a mess everywhere else, though.
- icebraining 7y agoObviously they can't literally apply it everywhere, but it's absolutely not true that they just go after large players. I've had complaints against very small players for relatively minor violations[1] enforced by my national privacy commission. The GDPR opened the floodgates, but the wheels are in motion, and I know of multiple SMBs who got warnings to cut out their practices. [1] The part-time manager of a three story building posted a "list of debtors" on the lobby (which contained false information, though that wasn't relevant for the commission, which focuses on the privacy aspect)
- alkonaut 7y agoYou just need to set some examples. I'd pick a few violators and apply some reallyt painful fines with lots of publicity. Other actors realize that noncompliance is more expensive (when multiplied by the risk of being caught) than compliance. Done. No need to process thousands of violations. All that's needed is a few dozen with lots of publicity.
- jka 7y agoThe user experience should improve significantly once the new EU ePrivacy regulations are effected; these will make browser settings (for example, your settings could be: 'accept first-party cookies, reject third-party cookies') the source of consent. There's a decent summary here: https://www.i-scoop.eu/gdpr/eu-eprivacy-regulation/#The_EU_ePrivacy_Regulation_and_cookies https://www.i-scoop.eu/gdpr/eu-eprivacy-regulation/#The_EU_e... Perhaps this will lead some advertisers to attempt sketchy things like server-side application integration so that their cookies 'appear' to be first-party; either way, the policy has teeth and can apply fines the same way GDPR can, so any advertisers (or services themselves) found to be storing cookies without consent which are not strictly for site functionality may find themselves in hot water. I'll be willing to bet that less scrupulous marketers who make a decent chunk of their revenue from users who they mislead into clicking / purchasing goods (i.e. targeting less skeptical users) will also attempt to get their audiences to lower their cookie settings. Think banners with content such as 'to get access to this special deal, we need you to update your settings'. Note that it's completely possible to build rich web applications that don't use any cookies at all, especially nowadays with localStorage and all the infrastructure for progressive web applications. It's also worth noting that cookies were controversial when they were originally introduced - it's not like they're some fundamental infrastructure that we've always relied upon. Here's some privacy and cookie advice from 1998, for example: https://web.archive.org/web/19980210083135/http://internet.junkbuster.com/cookies.html https://web.archive.org/web/19980210083135/http://internet.j...
- BeniBoy 7y agoWell, publisher and advertiser made it a joke, by trying for the last ten years to extorcate unappropriate consent from users (and bothering them as much as possible in the process). And regarding the option to set your preferences at the browser level, of course this is the best possible solution, but if you are following the ePrivacy reglement discussion, the article 10 (permitting browser to obtain consent for website with a standardized interface) is pretty close to getting killed.. Money talks.
- mtgx 7y agoYes, one thing I've been proposing for the past couple of years around here is that we need rules that make most data gathering a liability. And even then some data should become non-liable only if it's encrypted client-side/end-to-end.