16 ms·
Well, it's basically malicious compliance. They're supposed to be super annoying because the people which need them do things which have been deemed unacceptabl
by y4mi 5y ago
Well, it's basically malicious compliance. They're supposed to be super annoying because the people which need them do things which have been deemed unacceptable from the legislature. Instead of complying, they choose this obnoxious practice so they could continue with what they've been doing for years, which is monitoring every action a visitor does.
You don't need a cookie banner to be allowed to create Cookies. You only need them if you're using them for something like tracking.
A session cookie, selected theme etc is all fine without that banner
- jameslk 5y agoNot malice, just lazy ass covering. It's easier to throw up a cookie banner and not get fined rather than reading laws and changing business practices instead and potentially get fined. Also lawyers are expensive and many of them will just tell you to add a cookie banner to your site. They're also lazy and just trying to cover their asses too.
- _Microft 5y agoThis is the correct answer. Nobody needs to ask for cookies that are required for providing the service. They choose to annoy people.
- dageshi 5y agoNobody is thinking about it that hard. Half the sites don't need it but they don't know for certain they don't need it, so they stick it in to be on the safe side because throwing a plugin on that adds it is about a 2 minute job and actually figuring out if they need it requires a lot more work. Path of least resistance wins.
- rendall 5y ago> Half the sites don't need it but they don't know for certain they don't need it, so they stick it in to be on the safe side... That's a pretty bold claim, even steel-manning it. I personally only ever see it on sketchy sites. If you're right, then it would just take a campaign of education to halve the annoyingness rate of the internet.
- dotancohen 5y agoOK, so where is this education? I've read this entire thread and I still don't know when I would need to prompt for cookies, or even if I need to prompt if I store everything serverside and id the visitors with a session token in URLs. There is no easy-to-understand definitive answer for the common use cases.
- rendall 5y ago> I've read this entire thread and I still don't know when I would need to prompt for cookies... Well that's the problem, right there! You're reading random HN threads to get this information. Why not go to the source? https://ec.europa.eu/info/law/law-topic/data-protection_en https://ec.europa.eu/info/law/law-topic/data-protection_en The law itself is fairly easy to read and understand if you're a software developer. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679#d1e1374-1-1 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... Here is what looks to be pretty respectable commentary on when it triggers. Essentially, if you collect any sort of personal data whatsoever: https://gdpr-info.eu/issues/personal-data/ https://gdpr-info.eu/issues/personal-data/ If you store information that can identify the user, e.g. if you collate a user's IP address, you are almost certainly collecting personal data. Don't, if you can help it. If you must, that same site has some general guidance on how to collect consent: https://gdpr-info.eu/issues/consent/ https://gdpr-info.eu/issues/consent/ Read there more info on how to comply with the data collection. Essentially, if it is personal data, you must give the person informed control over their data, including the ability to withdraw consent at any time, in which case you must delete it.
- dotancohen 5y ago$ wc cookie-regs 4198 54871 354380 cookie-regs 54,000 words? Significant fines for non-compliance, even in the form of errors? And this is a legal spec, not a software spec, so there's no validating my implementation? And the terms are subject to possible change and different interpretations as one could get sued in any country? Or just put up the cookie notice and not worry.
- dane-pgp 5y ago> Well, it's basically malicious compliance. Agreed. I can't think of a more widespread and effective campaign by an entire industry to gaslight their customers into hating a regulation more than the invasive practice that is being regulated.
- bsanr2 5y agoTangentially-related, but it's funny that you should say that, and in as many words. https://youtu.be/hX2aZUav-54 https://youtu.be/hX2aZUav-54
- mhaberl 5y agoExactly. We should attack the core issue here; tracking is a form of invaison of privacy and should be banned in general.
- quest88 5y agoThe core issue is people want free shit.
- tomcooks 5y agoYou're posting this as a HN contributor or as a freeloader?
- mam4 5y agoHese right tho
- mhaberl 5y agoNothing is free. So people pay with their privacy, some because they are tricked into it, some because they don't care. Point is that invaison of privacy is bad and you should not have even an option to trade it for "free shit".
- atoav 5y agoNo, the core issue is that advertisments are not enough for them, they want personal data too. Giving someone with a website an image that they put up there is simple and requires zero cookies. If your goal is to have people see that banner this is literally all you need to do. But of course advertisers want targeted ads, they want to get metrics (they don't care how truthful those metrics are, but who cares right?).
- ckastner 5y agoExactly. My favorite example are sites which require you to opt out of hundreds of third party processors individually (advertising partners who may receive data). That's as dark a pattern as it gets. It's also in clear violation of how opt-out is actually supposed to work, at least in the EU. And with the Do Not Track header, I shouldn't even have to opt out in the first place. A GDPR decision to that effect could solve this banner madness once and for all.
- Nursie 5y agoDo Not Track was a joke from the word go. "Let's ask these bad actors to play nice, I'm sure they'll respect that, I mean, they probably think we all want to be tracked so let's just tell them we don't and it'll all be fixed. And make sure the option isn't obvious enough that normal people start to use it and ruin the whole thing".
- necovek 5y agoIIRC, DNT header was such a failure that not even Firefox has it anymore: I think it's an abandoned feature.
- ugjka 5y agoNo, Firefox still has it
- necovek 5y agoThanks for the correction! At the very least, I've stopped setting it since no website respects it.
- jffry 5y agoWith DNT on, Medium actually behaves differently! When viewing an article with embeds (like an iframed YT video), each embed is replaced with a small privacy warning, then clicking it loads the embed.
- 5y ago
- tlamponi 5y ago> Well, it's basically malicious compliance. I get what you mean but technically its not compliance, as the law requires a simple yes no option. Definitively malicious though.
- camillomiller 5y agoUnfortunately in Germany that’s not true. Putting anything in someone’s computer without their approval is now considered illegal. Therefore even if you’re just using Matomo stats or anything that isn’t tracking and just functional you need to ask for permission. That is idiotic and doesn’t solve the issue at hand at all
- karol 5y agoThat sounds nonsensical, when people visit your website they run your code using their CPUs and electricity. You also get their attention and may even influence their heart rates and breathing patterns.
- rad_gruchalski 5y ago> Putting anything in someone’s computer without their approval is now considered illegal. Citation needed.
- enumjorge 5y agoAgreed that doesn’t make a lot of sense. You need to “put” html, css, images in the visitor’s computer just as much as you do a session cookie. How is one allowed and not the other?
- number6 5y agoIt doesn't make a lot of sense. Now we have to interpret what was intended with the law. What about In Browser databases? Or Javascript? It's much more than just cookies that are stored on computers.
- number6 5y agoArt 25 TTDSG "The storage of information in the end-user's terminal equipment or the access to information already stored in the terminal equipment shall only be allowed if the end-user has consented on the basis of clear and comprehensive information. The information to the end-user and the consent shall be provided in accordance with Regulation (EU) 2016/679."
- fumar 5y agoThe consent data collected by the cookie preference pane may not be GDPR compliant. IAB who created the TCF protocol appears to be losing the battle. https://techcrunch.com/2021/11/05/iab-europe-tcf-gdpr-breach-belgium/ https://techcrunch.com/2021/11/05/iab-europe-tcf-gdpr-breach...
- nielsole 5y ago"we value your privacy" I am offended every time I read that.
- jefftk 5y ago> You don't need a cookie banner to be allowed to create Cookies. You only need them if you're using them for something like tracking. That is a common misunderstanding of the ePrivacy Directive [1][2]. It applies to all cookies (and "similar devices") that are not "strictly necessary in order to provide an information society service explicitly requested by the subscriber or user". And "strictly necessary" is quite a high bar. (not a lawyer) [1] https://en.wikipedia.org/wiki/Privacy_and_Electronic_Communications_Directive_2002 https://en.wikipedia.org/wiki/Privacy_and_Electronic_Communi... [2] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058&from=EN https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... See especially (25).
- raverbashing 5y agoYeah, item 25 is interesting, but the way I read this it's more about the informative links instead of the click-to-allow ones > strictly necessary in order to provide an information society service explicitly requested by the subscriber or user". Sounds to me then that login/customizations are allowed
- snek_case 5y agoI've been wondering about that. I have a simple web app and I'd like to gather some basic statistics about what users do, which pages they visit... Not to spy on people, not to share with anyone else, just to have some insight on how to make the app better. The app is just a toy program people use for fun, you couldn't possibly argue that any stats I'd be collecting could be used maliciously. It seems to be difficult to do that while respecting the GDPR and without some annoying pop-up though?
- number6 5y agoDo you really need cookies for this or could you also use your server logs for this? Per default you could not gather statistics but ask inside you app if people are willing to participate in making the app better and if they would agree to accept some cookies for this reason.
- 5y ago
- nulbyte 5y ago> You don't need a cookie banner to be allowed to create Cookies. You only need them if... You don't need a "banner." The requirement, as I understand it, is to be conspicuous. Conspicuous just means visible, easy to notice. Contrary to the industry's apparent position, conspicuous and obnoxious are not synonyms.
- karaterobot 5y ago> choose this obnoxious practice so they could continue with what they've been doing for years, which is monitoring every action a visitor does. You're right, but I'd like to mention that, in pretty much every jurisdiction with laws like this, you cannot set or retrieve information from a user's computer without getting their consent first. Which means that accessing cookies on page load, then showing a consent banner, is no more protection then just not having a consent banner. I would always tell clients this, and even send them the relevant wording, but I don't believe it ever made the tiniest bit of difference because, as you say, they just want to keep tracking users.
- trappist 5y agoMost if not all legislation comes with unintended consequences, if it has any consequences at all. Usually they are entirely predictable. Then, when people adapt their behavior to stay out of trouble by doing objectionable but legal things, we don't blame the careless legislators, we blame those we knew or should have known would respond this way to the legislation as it was written. And so it marches on - most legislation ends up making things worse instead of better, and there is no accountability because we blame the wrong people for it.
- bradgessler 5y agoThis could have easily been a requirement for web browsers. Imagine if instead of the obnoxious cookie banner, browsers ship with a default “don’t accept cookies” or “don’t accept 3rd party cookies” setting. When a website needs to establish a session, the browser would prompt the user, “this website uses cookies to track…” If the user gets annoyed with that setting, they could change the default to let any website use cookies. It’s really obnoxious how this issues was pushed into website operators and not browsers.
- jokoon 5y agoI'm not a lawyer, but I bet those buttons are legally binding. Clicking "I accept" means you can't sue a website if they have your data. I'm not sure but I don't see why those websites would annoy users.