13 ms·
I hate the standard wording on Cookie banners. Most of them should read: "The site uses cookies. Actually it doesn't - you are not logged on and we don't need
by AndrewStephens 6y ago
I hate the standard wording on Cookie banners. Most of them should read:
"The site uses cookies. Actually it doesn't - you are not logged on and we don't need to maintain state. But our advertising partners, their partners, and their partner's partners all love to set tracking cookies. Click here to consent to three dozen cookies from around the globe."
- Spivak 6y ago“And we would rather not have this crap but nobody pays for content are there only two types of ad networks: privacy preserving and paying so we’re stuck. Please call your congressperson to complain [here].”
- Privacy846 6y ago”Businesses are the real victims.” —Another fake quote
- gfxgirl 6y agoI'm confused.... AFAIK the biggest ad company, Google, doesn't share your private info. It's not in their interest to do so. Instead they keep it to themselves and then offer ads by categories so as a 3rd party I can say "Please target this ad at 'video game players'" but I can't ask "give me the names of video game players"
- Macha 6y agoThe issue is by including google tracking on their web page, then from a legal point of view the publisher is sharing your information with Google
- chungus_khan 6y agoGoogle is the company that your info gets shared with. Google being the biggest ad company does not give them the right to surveil all that walks the earth.
- s14ve 6y agoThis wording should be required by GDPR. :) If that would be the case, maybe more sites would follow GitHub here.
- mirekrusin 6y agoYes, like on cigarette boxes with mandatory, non-dark pattern, visible without scrolling 3 meters button to choose "Don't agree, Continue".
- Macha 6y agoCCPA tried this with the "Do Not Sell My Personal Information " requirement, but it was about as ignored as GDPR
- reaperducer 6y agoYes, like on cigarette boxes with mandatory, non-dark pattern, visible without scrolling 3 meters button to choose "Don't agree, Continue". And then Facebook takes out full-page ads attacking your company for allegedly hurting "small business."
- random5634 6y agoGood lord, everyone needs banners and popups? Why not just let browsers controls who sets what cookies? I'm tired the endless cookie popups, can we come up with an "allow cookies if the browser accepts them" standard as long as that guarantees no cookie popups? Then browser vendors can ship a delete all non same origin cookies on tab close or something.
- tsjq 6y ago>"allow cookies if the browser accepts them" isn't that the 'allow 3rd party cookies' setting ?
- thomascgalvin 6y agoThis is (mostly) based on EU law; entities that set cookies and track user data are required to get opt-in permission from users before doing so, and if the user declines, the entity cannot offer a degraded service. At least that's the idea. In practice, almost everyone just throws up a banner that says "fuck you, we're selling your data as hard and as fast as we can," with no opt-out available, but they pretend that this is compliant with the law.
- kixiQu 6y agoYeah, I always wonder why this can't be handled like "prefers-dark-mode" and then the answer is always "because then who would let them do it"
- lez 6y agoWhat keeps back Mozilla to implement this setting and lobby for a general Web API for expressing cookie consent? As far as I can tell, their users would be extremely happy about that.
- munchbunny 6y agoThat existed. https://en.wikipedia.org/wiki/Do_Not_Track https://en.wikipedia.org/wiki/Do_Not_Track It failed horribly because it was voluntary. But now that it's a GDPR requirement, perhaps that might have a snowball's chance in hell of succeeding.
- merb 6y agowell most sites still generate at least some kind of csrf cookie. multi language site sometimes even have tz/lang
- Macha 6y agoTZ/lang preferences do not require consent, a CSRF token for a logged in user seems to me to be legitimate interest too, but I suppose you could see it as an identifier that can be linked back to the user. I still think if you're using it just for security purposes it counts, but the fact that the same identifier could be used for tracking based on differences on the backend is one of the reasons why this isn't just based on browser cookie settings.
- merb 6y agowell it's legal to create a hash and save it inside a database to count unique users. if the hash is not connected to any info that would identify a user (btw. user agent is some kind of identifing stuff) it is fine. what I wanted to say is that cookies are not illegal by gdpr means and gdpr does not make a lot of stuff illegal, it's just that SAVING personal information or information that could identify somebody needs explicit permission. edit: another thing ip addresses, by german law you are required to save it, when a user can register on your site and your site allows users to submit data. because authorities force you to give them out when a user did something illegal. (§ 7 Abs.1 Satz1 Nr.4 TKÜV, https://www.gesetze-im-internet.de/tk_v_2005/__7.html https://www.gesetze-im-internet.de/tk_v_2005/__7.html) In germany it's basically: fuck the privacy if they harmed our law! or at least you need a way to "activate" saving ip addresses.
- Macha 6y agoHow do you create the hash? If it's based on something that you can derive from the user (let's say sha1(IP address + User Agent), that seems pretty clearly identifying. If you generate a random identifier but save that identifier in their cookies and send it back next time, also pretty clearly identifying.
- Blikkentrekker 6y agoSo what happens if one consent to it, but also have third party cookies disabled in one's browser settings? Is disabling it there globally æquivalent to not accepting on such banners?
- Nextgrid 6y agoConsent often involves more than just cookies. Consenting essentially allows them to use other tracking technologies beyond cookies such as IP addresses or browser fingerprinting. This is also why the GDPR requires consent forms instead of relying on browser cookie settings, as it covers the intent of tracking itself as opposed to any technical means by which it is achieved (and this is why functional cookies such as for logging in or shopping carts don’t actually need consent at all).
- Blikkentrekker 6y agoThe wording of these banners rarely suggests as much. They talk about cookies, and little more.
- interestica 6y agoI hate the implication that those banners are some sort of consent. They're so commonplace now that people blindly click 'okay' or close them just to be able to read the site. If the wording was something else ("you agree that we can take your first born child") would it even hold up? The worst is when the banner says: "This site uses cookies. Agree / Disagree" -- it's not even asking for consent.
- swyx 6y agodisagree button is the "Close" button unfortunately.
- type0 6y agoand often it works like - please leave the site nothing here for you button. Amazing how irl businesses use such types of third party booking systems with ads and other crap showed down your throat, that's for anything from hairdressers to carpenters, one would think at least they don't require you to login via fb, ah waaaait, some of them do. The web dystopia is here now, enjoy it.
- reaperducer 6y agoThe worst is when the banner says: "This site uses cookies. Agree / Disagree" -- it's not even asking for consent. Some sites don't even give you a "Disagree." Liberty of London has no way to opt-out: "By closing this box or by clicking accept and close, you agree to our use of cookies." https://www.libertylondon.com https://www.libertylondon.com
- thewebcount 6y agoI have never once in my life clicked on any of these banners. In no way have I given them my consent. I simply ignore them. If they track me, they're breaking the law.
- dorgo 6y agothe law requries either consent or legitimate interest ( there are even more options - but not relevant here ). So they can track you without consent and not breaking the law.
- llaolleh 6y agoI find these pop ups weird. Shouldn't we get an option to say, "Disable tracking"? These pop ups don't really have any utility because a banner won't stop them from reading the article.
- reaperducer 6y agoYou sound like the guy who wrote this: "We're not going to lie to you. Your privacy isn't our priority. It's not even close. Not because we want to track your every move. But because we simply don't care. We'd rather spend what limited time we have actually improving the web site. We're into taking pictures and adding content, not obsessing over what your dog had for lunch so we can sell it to MegaEnormousBigCo. We're not tracking you. We're not tabulating you. We're not folding, spindling, or mutilating you. Seriously, your personal life is not important to us. However, you may or may not be of interest to the people who advertise on this web site." https://www.chicagoarchitecture.info/privacy.php https://www.chicagoarchitecture.info/privacy.php
- tt433 6y agoGotta love some good customer flattery
- mewpmewp2 6y agoThis honesty is refreshing.
- visufo 6y ago+1
- Privacy846 6y agoThe last sentence is the key part. I could respond in kind: No one cares if you care or not. We only care about the people who are willing to buy that stuff from you.
- morelisp 6y agoThe thing is, that's bullshit. Here's the other perspective: Data brokers don't really want your data if you don't want them to have it. It's a legal liability for them, and most of them are struggling to work at the scale their customers demand already. But publishers want high advertising rates and that means advertisers want to make good bids and that means both actually want a data broker involved to deal with the technical (collection, filtering, aggregation, ETL) and legal (GDPR) bullshit. But then publishers and advertisers don't do their due diligence or decent engineering and just shovel illegal shit to data brokers on the backend. The ones that shut up and launder it do well; the ones that actually try to do a good (technical, legal) job drown in account management and data processing overhead. So fuck that site. They are the ones that care about your data, they're just making a show of keeping their hands clean while they pay someone else for the dirty work and hiding behind their (half willful half stupid) ignorance of how their own industry works.
- gowld 6y agoWhy does that matter? If the advertisers delivered cookied via the main site server, would that change your experience?