5 ms·
What if the EU had a tech team which produced widgets that were mandatory to be used by companies rather than every company creating their own custom cookie pro
by eberkund 5y ago
What if the EU had a tech team which produced widgets that were mandatory to be used by companies rather than every company creating their own custom cookie prompt filled with dark patterns?
Kind of like the standardized Facebook like buttons which used to be so popular. But instead it's a JavaScript snippet or web component provided by the EU that Google would be legally mandated to integrate into their site?
Alternatively, could we just go back to using the DNT header? I liked this solution a lot better anyways, just set it once and forget about it. The problem was that sites would just ignore it, but if the EU adds some legal weight behind this functionality it could actually be meaningful.
- qwerty456127 5y agoWe don't need damn widget. All we need is every web site to respect the standard do-not-track flag. And this can only work if the flag is off by default so only those who actually care set it. Things like Google Analytics should also check and respect the flag. Requiring every webmaster to ask every visitor if they don't mind Google Analytics being injected is nonsensical. We should also exclude remembering a user which has signed in from the tracking definition. It's absurd to warn the user about cookies when they sign in. I also don't want classic (no-choice) cookie warning banners, regardless to whether I am tracked or not. Almost everybody already knows cookies are always there (and we can just introduce a browser extension indicating cookies usage for those who don't). The banners serve no purpose other than annoying people.
- rhn_mk1 5y ago> this can only work if the flag is off by default so only those who actually care set it. As the effort in the article is attempting to establish, this can also work when there is a legal stick against those who don't comply. All we need is companies to stop tracking people by default. A side benefit is that webmasters don't need to ask about Google Analytics if it's not being used.
- qwerty456127 5y agoThis is utopian. I want this but don't believe this is possible. Perhaps they might agree to stop tracking a portion of users who opt out but forcing them to stop tracking anybody is unlikely to succeed, and even if it succeeds they will just track everybody secretly. I also am not confident in total elimination of tracking being a good idea from the economical point of view - many small businesses rely on precise targeting today.
- pieno 5y agoWhat a dystopian world we live in when people/companies can just plainly and publicly say that they don’t agree and won’t comply with a binding law with supervision mechanisms and penalties, and still have the general public believe that there’s nothing we can do about it... And mind you: we’re not (just) talking about the top-5 tech companies and 0.01% here. This attitude is shares by almost every other company out there, and I have a feeling (based on anecdata) that the issue is even worse in smaller companies who think they don’t have to comply because they’re small or because they’re a startup or because they just need to “move fast and break things”… and we seem to accept that…
- xg15 5y ago> many small businesses rely on precise targeting today. And many businesses relied on CFCs as coolants before they got forbidden. they found a solution. Regulation can also be a source of innovation if it forces businesses to think of alternative, less harmful ways to solve a problem.
- belorn 5y agoI wonder if there suddenly would exist a bunch of google analytic competitor if google could no longer offer analytics as "free" by monetizing user data. Google analytic is a prime example of why we need data protection. The web developer who uses it are not the one paying for it, and they might not even know that google are tracking users for monetizing purposes. It create a market with broken incentives and information asymmetry, with the buyer having relative no power. Requiring every webmaster to ask every visitor if they don't mind Google Analytics is annoying, but fixing that market is a difficult job. Maybe the solution is more targeted regulation specific to website analytic software.
- qwerty456127 5y agoA don't think of Google Analytics as a problem for users - it's very easy to block, there is a number of ways and even an official way to opt out. The problem is AFAIK Google forces the actual webmasters to use it - I am not 100% sure but I've read sites without Google Analytics show worse in the search results.
- pieno 5y agoThat’s actually the entire point: this should not be standardised. That would make it useless. The purpose of GDPR is that, in principle, you need consent to process personal data. The consent must be specific both in terms of what data is processed, and in terms of why it is processed. The consent must also be explicit (no opt-out or implicit consent by browsing a site) and voluntary (no coerced consent by refusing service for not giving away personal data that is not specifically required for the service you’re asking for). Standardised widgets are exactly the opposite of all that. In a way it’s very frustrating to see all these nonsense cookie banners that absolutely do not comply with GDPR at all. Why nag visitors with annoying cookie banners when your website is just as “illegal” as when it wouldn’t have a nag screen at all. This is really the worst of both worlds. Then again, it’s perfectly understandable for companies to comply just a little, as they can then start long arguments with regulators on whether their implementation is compliant or not and whether they are getting valid, specific, express and voluntary consent (rather than just getting fined right away because there’s clearly no consent being asked at all which would make it too easy for the regulator). So I’m really glad to see someone picking up this battle to actually enforce GDPR and call out the complete joke/smokescreen that most companies have made of it…
- withinboredom 5y agoI think what they mean is a standardized end-user interface with some drag-drop/easy configuration on the dev side. Every site on earth doesn't need to develop their own modals/UI to gather consent.
- pieno 5y agoBut why ask for consent right away when someone just visits your website for the first time? Imagine that you walk into a shop and the owner starts harassing you right away, blocking your path and your view and nagging you whether you consent to them following you around the shop tracking what you’re looking at, what you touch, what you actually purchase, and then give the shop next door a call to tell them all about your visit so that they can all “improve your shopping experience by giving you personalised recommendations”. Pretty sure almost no one would keep shopping there. In fact, this is pretty clear from Apple’s new do not track option where Facebook said in their quarterly report that it’s really hurting then (contrary to their statements that all of their users already happily consented to tracking and that they’re actually doing their users a favour by tracking them). What should really happen is that sites just stop asking for bullshit consent to being tracked. No one will consent to being tracked if given an actual, clear and explicit opt-in choice, if there’s absolutely no downside in refusing consent and no one is tricked into giving consent by dark patterns. Websites should just abstain from processing personal data until the visitor does something that actually requires personal data (e.g. sign up, make a purchase, …). In those cases, most obvious processing of personal data can be done based on other grounds (performance of contract, legitimate purposes, …) so really there should not be any consent nag screens needed at all except for some very specific exceptional cases…
- ajford 5y agoI fully second the DNT header. Perhaps even some common set of headers, like DNT/FirstPartyOnly/Performance) I like what GDPR did for privacy, but I absolutely hate it's impact on web browsing. Now _every_ damn site has a cookie banner covering the bottom third of the page. Plus many sites have a fixed nav or another damn banner at the top. Mobile browsing has gotten painful.
- g_p 5y agoCalifornia seems to be trying to pass (or succeeded in passing?) some new legislation which aims to get sites to honour some new version of DNT. The problem I have is that DNT is "good enough". Websites need to accept the law (opt in is needed, defaults must be to assume a user is opted out unless/until they do so of their own accord, and can't apply coercive pressure or try to force them to agree). DNT fell down when websites said they wouldn't honour it if browser makers made it enabled by default, or made it too easy for too many users to enable it, and it was "voluntary". We now see CCPA privacy statements required to state whether they honour a DNT opt-out... If the next step is to require sites to honour the preference, It just seems to me that adding a new header achieves very little, and using the existing one could achieve more in a shorter time! If we aren't careful, we'll end up with fingerprinting of the new privacy browser headers, based on the granularity of privacy choice information being conveyed in headers due to the various disparate attempts at applying more sticking plasters to the wound. Heck, fingerprinting just DNT and a couple of other proposed privacy headers alongside user agent would probably at least give enough information to distinguish multiple users sharing an IP via NAT... (!)
- M2Ys4U 5y agoNoyb have developed a new spec which would make handling this stuff easier called "Advanced Data Protection Control"[0] [0] https://www.dataprotectioncontrol.org/ https://www.dataprotectioncontrol.org/
- M2Ys4U 5y agoNoyb have developed a new spec which would make handling this stuff easier called "Advanced Data Protection Control"[0] [0] https://www.dataprotectioncontrol.org/ https://www.dataprotectioncontrol.org/