7 ms·
The problem is the false alert - you HAVE to press yes all the time to get NORMAL work done. Same with cookie acceptance popups - supposedly this is allowing t
by privateSFacct 7y ago
The problem is the false alert - you HAVE to press yes all the time to get NORMAL work done.
Same with cookie acceptance popups - supposedly this is allowing the user to know the website uses a cookie blah blah, but you HAVE to press yes in most cases to go forward - so everyone has now been trained to auto click yes all the time. At this point those popups could say anything and at least 10% of users would still click yes.
I like the other approach. NO popup / warning unless something meaningfully unexpected.
The problem is there are bunch of warriors on the net and elsewhere that do things like claim that users hate cookies and won't accept them, so need to be warned of them by every website (which can still technically set cookies regardless of any popup). If users don't want cookies they can block them at the browser level - that's how you have actual control BTW - a scam site may not put up the cookie notice and may still be able to set the cookie.
Meanwhile - no notice required when your ISP tracks your every move AND is the monopoly provider. The internet folks have priorities totally backwards - so much focus on evil google it is ridiculous. The reason many people give google their entire search / email history is that they trust google more than the Chinese phone folks, the samsungs, the comcasts etc.
Some real actions to improve the net:
We need actual criminal prosecution and responsibility for websites distributing malware, browser exploits or downloadable.
Owner goes down even if it was their ad network, they can then sue the ad network and if they can recover from them great, if not they still pay for picking a crappy ad network. If their webhost was hacked they still pay for picking stupid web host, they can then sue webhost to recover.
We need to ban and criminally prosecute sale of info by places like ISPs and DMV's that are monopoly providers that have strong paid revenue streams already.
- saagarjha 7y agoUsers don't want cookies. It's just that websites have made their tracking apparatus dependent on them, so they force users to accept them if they'd like to access the site. > Meanwhile - no notice required when your ISP tracks your every move AND is the monopoly provider. Yeah, no. Nobody likes their ISP, it's just that it's a lot harder to enact change here.
- cortesoft 7y agoI mean, I want cookies on lots of sites... like any one that I login to. How else are they supposed to track access to my account?
- saagarjha 7y agoThat's fine under the EU cookie law, no popup for permission required.
- lostlogin 7y agoCouldn’t that happen from your side?
- bdamm 7y agoHTTP is stateless so, no.
- coldtea 7y agoObviously no. What it would make it different than another user accessing the same account then?
- scarmig 7y agoIndeed! Someone should make a browser API that lets services direct the user agent to set domain-scoped key value pairs that are passed back to the service on subsequent requests. That would let the client automatically prove that they're authenticated while maintaining the server-side statelessness.
- kbenson 7y ago> The problem is there are bunch of warriors on the net and elsewhere that do things like claim that users hate cookies and won't accept them, so need to be warned of them by every website (which can still technically set cookies regardless of any popup). If users don't want cookies they can block them at the browser level - that's how you have actual control BTW - a scam site may not put up the cookie notice and may still be able to set the cookie. Tracking was being targeted, cookies were conflated with tracking (they are, but not really at the level that's being talked about), and some ineffectual legislation was passed to target cookies instead of tracking. It's almost as if the whole process was steered to that point to avoid any useful change with regard to online tracking...
- saagarjha 7y agoIf you're talking about the EU cookie law, that explicitly targets cookies that have nothing to do with the functionality of the site.
- kbenson 7y agoI'm just saying that it's 90% visual and 10% effectual (and I think I'm being generous), and likely makes the average person think good strides have been taken towards the problem of line tracking, which I don't think it really helps. It's the perfect level of highly visible and almost useless that it may in fact be counter-productive.
- ratww 7y agoImplementations where there's only an "Accept" option are not following law, though. The user must opt-in of their own volition, must be able to reject the tracking cookies (or any kind of tracking) and must be able to opt-out later as well. Btw: Functional cookies (colours, session, login, cart, language) don't need consent, just disclosure (and it doesn't have to be an ugly cookie bar).
- klausjensen 7y agoWhat do you mean? If I have a website and ONLY use a single cookie to save a setting for the user for the background color - I still have to get the user to accept the cookie, right?