4 ms·
I don't believe it makes sense to have every website in the world implement this in a half arsed JavaScript implementation when it could be done once per major
by VBprogrammer 5y ago
I don't believe it makes sense to have every website in the world implement this in a half arsed JavaScript implementation when it could be done once per major browser. Same with the cookie nonsense.
- jakear 5y agoThe only real explanation is that the cookie laws were explicitly designed to wear users down into blindly accepting whatever prompts get thrown at them on website load. Anyone with half a brain and a real intent to reduce tracking would have mandated websites abide by the existing Do not Track toggle. Unfortunately the law was instead introduced by politicians with strong lobbying from media industry. So no brain, and no intent to reduce tracking.
- sofixa 5y agoThe GDPR isn't a "don't track" law, it's a "tell me what data you collect on me, what you're going to do with it, who are you going to share it with, and allow me to refuse that, retroactively if need be" law. Vastly more nuance than an on/off toggle.
- jakear 5y agoOn paper, sure. In practice, it’s a quick path to “yeah whatever I accept all your stuff just show me the damn content I came here for”. The web would be much better off if the law was implanted with normal consumers and sane defaults in mind.
- munk-a 5y agoI think ideally the web would be much better off if the law was implemented bilaterally with the US so sites had to make a much more important consideration of whether they want to tick off their users or not. It's not like third party cookie usage is required - websites choose what pieces of tech they'll utilize and they have, on the whole, made a choice that is extremely unfriendly to the consumer.
- jakear 5y agoWebsites make the consumer unfriendly choice because it makes them money, the law allows it, and their competitors are already doing it. They’d be fools not to. If the law was instead “no non-essential cookies may be stored when the do not track flag is set”, consumers would be far better off. But that’d cause significant financial impact to the media companies that lobbied for the current wording, so now the whole world is screwed.
- orangecat 5y agoVastly more nuance than an on/off toggle. Yes, and the result of that nuance is less privacy and more annoyance. It's an open invitation for sites to use dark patterns to get you to "agree" to tracking. (In fact they "have" to use dark patterns because they specifically aren't allowed to offer you anything in exchange). Either banning tracking outright or requiring sites to obey the DNT header would make much more sense.
- sofixa 5y agoIt's not an open invitation, in fact those dark patterns are explicitly forbidden in that law :) And many of them have been ruled to be against the law, but compliance is a bit slow.
- sofixa 5y agoHow is the browser supposed to know what information the website collects, who is it shared with, and manage consent and revocation thereof?
- bryan_w 5y agoThe browser is the one actually opening up the connection in this case. That's why there's so much disagreement in this thread. Your browser opens the connection to the original website and downloads the base page. That base page references images and js and fonts hosted elsewhere, so your browser opens a connection to download those images. At this point the browser could pop open a dialogue box that says "Hey you said you wanted to communicate with foo.com but I need to grab a pic from bar.com is that cool?" At no point in this use case does foo.com send anything to bar.com
- mananaysiempre 5y ago> At this point the browser could pop open a dialogue box that says "Hey you said you wanted to communicate with foo.com but I need to grab a pic from bar.com is that cool?" IE 6 in the default configuration did something like that with its yellow bar, IIRC, and all it amounted to was the fastest known method (minutes, for me) to provoke warning fatigue and make people vulnerable, seeing as the same UI was used for installing ActiveX controls. (Could be it did that all additional resources, though, not just those from a different origin? I don’t remember since I disabled the whole thing near-immediately even when I did actually use IE 6.) This is unworkable from a usability perspective for as long as hotlinking to external resources is so commonplace. And a user permission might not be an effective way to do this, anyway, given the imbalance in bargaining power, as already seen with adblocker-blockers and such. (See also the 2006 paper, “A pact with the devil”[1].) [1] https://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-666.pdf https://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-666.pdf
- tremon 5y agoWhy should the browser be supposed to know all that? It only needs to know if the user has authorized the 3rd-party connection, not why.
- zuzun 5y agoThe easiest fix would be to have reasonable privacy laws in the US.