5 ms·
> Did we consider that if everyone is breaking the law, the law itself might need a rework? Agreed - IMO, make cookie banners illegal and make 'minimum cookies
by throwaway_sb666 5y ago
> Did we consider that if everyone is breaking the law, the law itself might need a rework?
Agreed - IMO, make cookie banners illegal and make 'minimum cookies' the default. Done?
- whatshisface 5y agoWhat's the definition of minimum cookies?
- robin_reala 5y agoObviously there’s no definition, but I’d say a reasonable baseline is when a user expects a stateful interaction on the stateless medium that is the web. So for example, a multistage checkout process.
- throwaway_sb666 5y agoThose that don't require opt-out according to the law. Too lazy to look up the legal definition right now. Edit: by law I mean the GDPR. Edit2: Get rid of the "cookie banner law" entirely, actually make it illegal, but require easily found links to privacy statement
- andai 5y agoNecessary site functionality, without the spyware. Unfortunately, most websites sites are funded by spyware, so the minimum cookies to keep the internet economy running would have to include the spyware.
- deleted 5y ago[deleted]
- throwaway_sb666 5y agoDisagree. Let it burn, it's the only way. (change my mind?) This made me think of the Ukraine war, and how the sanctions may turn out to be a bigger help to climate crisis than any political entity could muster on the basis of the impeding climate snafu. Sometimes radical action is the right course of action; for democracy-(pre)serving reasons our governance systems often inhibit change unless most of the population is rallied around a specific cause as we see with Ukraine. That is the time for radical change to happen, or democracies would never progress. End of sidetrack :) EDIT: I mean, Strong agree with "Necessary site functionality, without the spyware. ", but disagree with last part
- andai 5y agoI was just asserting out that a law that banned spyware-based advertising would harm the current website ecomomy which is largely based around spyware. I would like to see an end to mass spying, and therefore the creation of a different kind of funding mechanism. That could indeed be brought about by law, but that seems a bit too violent to me. I think what we're missing is a better alternative. I read an interesting article (from the mid 2000s? Will update if I can find it) arguing that microtransactions will never work due to the cognitive burden of paying for hundreds (or thousands!) of tiny things a day. Brave's BAT seems to solve this part of the problem by automating the payments based on how much time the user spends on each site. It would require everyone to switch to Brave and use their crypto thing to make it work, so it's obviously "suboptimal".
- throwaway_sb666 5y ago> I was just asserting out that a law that banned spyware-based advertising would harm the current website ecomomy which is largely based around spyware. I think that largely, the website economy is based around advertising. I honestly doubt the advertising-centered business model would disappear even if large-scale tracking did. Would it be less targeted and less efficient on a micro-level - yes probably. But less abusive advertising would also have upsides for website owners: Privacy conscious people are increasingly blocking all ads, losing them eyeballs. Privacy friendly ads may be given a pass. Right now it's mostly impossible for privacy-conscious people to support a website the like by looking at their ads. The adtech industry is to blame for this for data-raping people. Website owners would benefit from a sustainable advertising model, where users don't have to make the choice between not contributing financially, vs sacrificing their privacy to data leeches. All the websites crying over ad-blockers would instead be forced to use legal ad networks that don't rely on illegal tracking, and people might again be willing to look at ads for content. Brave is an interesting take, but I think the more optimal solution is to just ban the practice of tracking and shadow-profile building. Problem solved, and I don't need to encourage people to install ad-blockers anymore.
- andai 5y ago
- alkonaut 5y agoShowing an ad next to a news article is not fundamental to the function of a news site, even if it's how the bills are paid. You can't degrade the experience because visitors reject cookies. So you can't do a "we'll show you the article but only if you agree to ads". And you have to make the reject-all-cookies the default choice and easier than accepting. It's pretty simple.
- zeruch 5y agoAs close to none as possible.
- zelphirkalt 5y agoAnd, to make it even more precise, I would call cookies, which are for login, also as non-essential, unless a visitor really wants to log in, meaning they navigate to the login page. This means, that be default, I don't need any cookies, because I don't want to log in to most websites I visit. Only if I want to log in, I have need for such cookies.
- zeruch 5y ago...hit the nail on the head. By 'as close to none' I pretty much meant "any cookie that isn't about authentication and/or holding state of something as an authenticated user that would matter"
- teawrecks 5y agoFor each cookie present, an independent third party expert would be willing to testify that the cookie is required in order for the website to operate as the user expects.
- rcgs 5y agoAs much as this may really damage the sector I work in, I’d cherish the clarity a stance like this could provide. There are many businesses trying to be compliant whilst maintaining access to metrics their business depends on. Compliance is very difficult at this time as the legal advice is shifting in different territories and there is conflicting guidance when you start to dig into it. Id rather see a selection of activities and tactics entirely banned/regulated rather than this directive which is clearly too open to interpretation.
- throwaway_sb666 5y agoAppreciate the sentiment. Policy changes will probably always hurt somebody. The expectation is the the economy will realign around new goals. In this case it's even simpler since a software company would like be able to develop a new product with hopefully more value to society than the vast majority of data collecting companies provide. I'm also not too afraid for tech workers being able to find other jobs, although I'm sorry for any other collateral damage.
- zauguin 5y agoIsn't this already the case? Does anyone actually think that you give voluntary informed consent to something by being annoyed into pressing a button? No, if you show a cookie banner your users do not opt-in. So a cookie banner is pointless since it doesn't actually give you permission to store cookies you couldn't store before. So we already have the law, we just don't enforce it.
- throwaway_sb666 5y agoI agree that a cookie banner is pointless. But they are even on government websites, so obviously something has gone terribly wrong along they way (hint: lobbyism). My thinking goes like this: 1. The law explicitly talks of requesting consent. 2. Incentives will drive actors to request additional permissions if possible (you always get some legal, can claim ignorance, etc) 3. People get constant intrusions wasting our collective time and attention on an enormous scale. The current law is encouraging this type of user-hostile behavior. This is stating an objective fact, since the current situation is clearly a result of the current law. If any type of consent-banner or opt-in method is allowed, industry groups will lobby for loopholes they can use to trick users using whatever mechanism the law leaves at their disposal. Just outright ban the use of cross-site tracking and user profiling. We don't have a societal need for this to be legal.
- anaccountexists 5y agoThe most common use of “tracking” cookies is just to be able to count unique views for your site, which I think is a perfectly reasonable thing to want to do. Knowing the impact of your site is something pretty much every website producer (including governments, individuals, and businesses) wants to do. Other examples of where cross-site tracking is useful is for preventing online payments fraud. You have a similar IRL version of this where your bank will freeze your card if it sees purchases being made in different countries simultaneously. Somewhere along the line, counting views or helping reduce fraud for customers turned into “store full demographic information about someone who never signed up for our service”, which is where everything went wrong in my mind. The cookies themselves aren’t the problem, it’s how they’re being used.