6 ms·
What's wrong with cookies? No tracking, no needed.
by InCityDreams 3y ago
What's wrong with cookies?
No tracking, no needed.
- CrLf 3y agoAlso, non-tracking cookies (e.g. load-balancing, settings selected by the user) don't require consent. Still, many websites put cookie popups in place for those, adding to the noise.
- lofaszvanitt 3y agoBecause everyone mindlessly copy everything they see on the net.
- sam_lowry_ 3y agoPopups everywhere that waste people's time.
- mschuster91 3y agoThat's not the fault of the GDPR. The point of the GDPR was to force companies to expose just how much they sell your data, and thus incentivize people to vote with their wallet and choose services that value protecting your data. Unfortunately, corporate greed was too high, and the result are cookie banners listing sometimes >1k third-party entities.
- jstummbillig 3y agoThat is not unfortunate. That is bad design.
- ben_w 3y agoDeliberate bad design by the websites; I'm not sure how the law could be rewritten except to just say "you had your chance to do this right, now you're all just banned from collecting anything unless it's strictly necessary, just as if every user had said 'deny'."
- mcv 3y agoWell, it is informative to see to just how many entities they're going to sell my data. My big question with those banners is: what the hell does "legitimate interest" mean? The toggle for normal cookies is generally off by default or easy to turn off, but then there's another tab, or other toggles, listed as "legitimate interest", and it lists all the same stuff I don't want: ad personalisation, tracking, etc. What's the difference? Why do they consider that legitimate interest?
- mschuster91 3y agoThat's a GDPR term. "Legitimate interest" should only be what is necessary to provide the service to the user (e.g. load balancer cookies, session cookies for logins). Everything else is abusing the term and should be reported to the responsible data protection authority.
- p_l 3y agoAnd cookies that are necessary to perform service required by end user don't require consent.
- piva00 3y agoThere's a pretty comprehensive answer in the official EU's Commission Q&A section [1]. [1] https://commission.europa.eu/law/law-topic/data-protection/reform/rules-business-and-organisations/legal-grounds-processing-data/grounds-processing/what-does-grounds-legitimate-interest-mean_en https://commission.europa.eu/law/law-topic/data-protection/r...
- dspillett 3y ago> My big question with those banners is: what the hell does "legitimate interest" mean? There is a definition in the regulation, which IIRC basically amounts to a rewording of "strictly necessary". This definition does not cover what companies use it to excuse. The way the phrase is actually used, for much wider tracking, what it has come to mean is "we see your preference not to be logged and stalked for the benefit of our business plan, but fuck you and your preference we want to do it anyway". This is why the legitimate interest check boxes are often hidden in nested concertinas or other UX nightmares, to make it extra difficult to opt out of what should be an opt in. Once a body has gone this far to try engineer an accidental opt-in they are _definitely_ not to be trusted IMO. Though it is likely too late if you really care: they may have already dropped their payload & sent at least some information back to base, and will "accidentally" not remove it later or find some other excuse as to why they shouldn't.
- jansan 3y agoThe popups make things even worse, because people automatically click on "Agree to all", which permits far more than would be permitted without a cookie banner.
- psychoslave 3y agoDo they? On my side, when Consent-O-Matic don’t deal with it all automatically, I look for the "deny all" button and just go elsewhere to find the information I need.
- cbeach 3y agoI'd love to install Consent-O-Matic but when I try, my browser warns me that the extension can read and change all my data on all websites. So, the EU makes laws that supposedly protect my privacy, and in order to deal with the awful practical consequences of those laws, I'd need to give an unknown third party access to all my data on all my websites?
- pipo234 3y agoI believe a German (?) court recently ruled that sending a do-not-track header in HTTP request is sufficient. So essentially, a website showing a cookie banner despite a visitor already expressing her/his preference using DNT, is a malfunctioning website. Now all we need is some carrots or sticks to nudge companies to fix their websites. Like fines or decreased search ranking.
- jansan 3y agoYes, they do. Maybe some nerds don't, but 90% of people do.
- piva00 3y agoThat's because the implementation is illegal, it should show "Agree to all" and "Refuse all" in the same context, the implementations have decided, as a strategy, to bury the refusal which goes against even the text of the law which states it should be as easy to give as to remove consent.
- chaoz_ 3y agoI think the idea is that after certain tech piece is getting regulated, giants will use this as opportunity to push for some replacement which they will get to influence. https://www.theverge.com/2023/7/20/23801435/google-chrome-privacy-sandbox-cookies-api-release-enabled https://www.theverge.com/2023/7/20/23801435/google-chrome-pr...
- pipo234 3y agoRegulation "failures" are mostly about the wording, the how; less about what and why. I guess rather than regulating cookies, they meant to regulate tracking. Or maybe even regulate targeting, rather than tracking. The cookie banners are mostly a tragedy, everyone agrees that modal, blocking cookie banners were never the intention. But the giants definitely had something to gain by suggesting they "were forced" to harass visitors.
- piva00 3y agoAnd the forced harassment is very likely illegal, the law is pretty clear that refusing/removing consent should be as easy as giving consent. Very few sites have both "refuse all" and "accept all" on the same pop-up, even worse are the "legitimate interest" ones which hide a second layer of refusal under that tab. I hope the EU cracks down on it at some point, the harassment is very much a strategy to manufacture discontent in the public about the regulation, and it works (as you can see in multiple replies anytime this topic shows up in HN), and the strategy is illegal.
- troupo 3y ago> I guess rather than regulating cookies, they meant to regulate tracking. Or maybe even regulate targeting, rather than tracking. When I see statements like this, I wonder: have people ever read anything besides what the industry feeds them? Or the echo chambers of HN and twitter? Here's GDPR's text: https://gdpr.eu/tag/gdpr/ https://gdpr.eu/tag/gdpr/ Please show me where exactly it talks about browsers. Or cookies. You could start with Subject Matter and Objectives: https://gdpr.eu/article-1-subject-matter-and-objectives-overview/ https://gdpr.eu/article-1-subject-matter-and-objectives-over... > But the giants definitely had something to gain by suggesting they "were forced" to harass visitors. Indeed. They redirected the ire from themselves to the law and the EU. Spreading FUD works.
- jonplackett 3y agoI mean the pop ups on every single site I visit now. I wish they’d just ban them rather than force the pop ups. My point is just that the corporations just find loopholes. Like how Apple have technically allowed out of app AppStore’s but mad it so horrible that no company would ever do it.