3 ms·
It deeply saddens me that for all of the greatness humanity is capable of we're still dealing with pop-ups and "cookies" when the solution is obvious and should
by aboringusername 5y ago
It deeply saddens me that for all of the greatness humanity is capable of we're still dealing with pop-ups and "cookies" when the solution is obvious and should have been in place years ago (and the current situation has ruined the modern web because "senator we sell ads")
All you need is to build this in to devices sold in EU - iOS, Android, Windows...Each give you privacy controls at the OS layer that applications must respect, on the browser level, this may be a "reject tracking and cookies". Boom. Done. All EU websites will be required to check for this API and their JS code must be plain to see for any visitor using the "view source" option. Going forward, we can build privacy controls at the technical layer, so regardless of the'stack'/'layer' software and hardware is built with GDPR in mind. We are still a long, long way away from that reality and truthfully, we will likely not be there for many decades.
Sadly, it seems this "cookie" debacle is one that is more society based than technical, and it's obvious cookies should probably be replaced by now with better solutions.
Maybe the GDPR might finally yield some positive changes but I remain doubtful. The industries it wants to disrupt have powerful lobbyists (hence why most right to repair legislation doesn't dare challenge Apple, for example).
- tomjen3 5y agoWe already have that: Browsers should be required to ask for permission to set cookies and websites should respect that. If you do that today, you will never get past the GDPR popups.
- Nextgrid 5y agoI guess the misconception about GDPR and cookies is still around. Presumably it's due to the earlier ePrivacy Directive (aka "cookie law") which I agree is completely stupid, but GDPR covers more than just cookies. The GDPR mandates that data subjects provide informed consent before you are able to collect and/or process their personal data for non-essential purposes (ads & analytics don't count). The technical means you use doesn't matter. It can be cookies, but it can also be browser fingerprinting or IP addresses (which you can't deny as the remote server needs to know your IP to communicate with you), or it can even be information you manually enter (such as name & address for payment processing). A purely technical solution will only cover the black & white case of "provide the data or not", it will not cover more nuanced cases where you need to provide the data for essential purposes (the IP so you can load the website, personal details for payment processing) but do not wish this same data to be used for other, non-essential purposes. A legal solution here is needed and that's what the GDPR is about.
- AshamedCaptain 5y agoThe point of the cookie warning was not to give users the option to disable cookies (although giving the option to users that are not familiar with their UA is also a nice side effect). The point was to force websites using cookies for "dubious" tracking purposes to be forced to show the banner as a mark of shame so that users would naturally migrate to websites not spying on their users and therefore not showing such banners. Obviously, this universe being the dystopia that it is, every website started showing these banners overnight and users started ignoring them anyway. If you just enforce all browsers to ignore cookies period, then you have another X-Do-Not-Track-Me scenario (or whatever it was called), where everyone just sets this flag and therefore tracking continues, just using other methods.
- ascorbic 5y agoCookies are a tiny part of what the GDPR is about (and it isn't even the main regulation that covers them). It's what people associate with it because adtech companies have made cookie banners deliberately obnoxious for that very reason. The vast majority of things covered by the GDPR are about the day-to-day protection of everybody's personal data, whether that's medical records, CCTV, employment records, insurance etc. Most of the provisions in it were already the law in most of Europe: it just standardised the rules and enforcement procedures. The main problem with the GDPR is the lack of enforcement, which is largely down to the lack of resources in the national privacy regulators in member states.