4 ms·
Finally! EU should have required browser vendors in the first place to handle the intent of the privacy regulation on GDPR, to avoid having this discussion...
by peterhil 6y ago
Finally! EU should have required browser vendors in the first place to handle the intent of the privacy regulation on GDPR, to avoid having this discussion...
- M2Ys4U 6y agoThe extant ePrivacy directive is from 2002. So... maybe you should go back in time and tell the EU back at the turn of the millennium that...
- peterhil 6y agoOh, so why it didn’t happen so that browser vendors and W3C did not add some HTTP header to disallow tracking, and browsers did not represent users options to manage their privacy, instead of these mandatory annoying popups?
- PeterisP 6y agoA law requiring websites to honor 'do not track' header would be sufficient and require no big changes to internet protocols or browsers. People say that DNT failed because it was selected by default - but no, it failed because compliance was voluntary. The EU principles require explicit opt-in confirmation, so a browser setting that's set to "not track" by default is a reasonable way to do it, it only needs enforcement to ensure that websites (in EU jurisdiction) treat the DNT header as binding instruction to not track that user.
- contravariant 6y agoThere are plenty of laws that would have been sufficient. One of them would be to make browsers responsible for providing sensible defaults. And while the public perception might think the webpages are at fault it was the browsers that were responsible for storing and broadcasting private data. Arguably without clear and informed consent. Of course there are problems with requiring software to have sensible default settings, but I reckon most problems with any legislation are due to the fact that none of them address the fact that cookies are a perfectly private system (with the user in full control of their own data) provided browsers don't send this data with every request without permission.