3 ms·
Note that this isn't a cookie law, it's also the EU's main anti-malware law. The principle is that no piece of third-party controlled software should write inf
by flipbrad 3y ago
Note that this isn't a cookie law, it's also the EU's main anti-malware law. The principle is that no piece of third-party controlled software should write information to your computer/phone, or read info from it, over the Internet, without your prior informed consent (with narrow exceptions for storage/reads that are needed to provide a service you've asked for, or equally narrow functions like load balancing). This isn't just about browser cookies, but also your webcam, your mic, and the contents of your Documents folder.
The principle seems sound, but the EU is deadlocked over reforms to create some extra exemptions, e.g. for security scans/mandatory updates, or privacy-respecting audience metrics. EU regulators are already sort of turning a blind eye to those, so it's fair to say the EU isn't great at regulating - it's not fixing what society mostly seems to see as bugs/overreach in the original (now decades-old) law.
- is_true 3y agodid they try to make it a standard for browser? I tried searching but I couldn't find anything
- tpm 3y agoThe standard for browser was called Do Not Track [0], but of course adtech killed it, there is another one now, but unless this is mandated by law or courts it won't go anywhere. Note there seems to be a court decision upholding DNT as rejection of consent [1], but this would have to be much more powerful and broadly adopted to work. [0] https://en.wikipedia.org/wiki/Do_Not_Track https://en.wikipedia.org/wiki/Do_Not_Track [1] https://dig.watch/updates/german-court-affirms-legal-significance-of-do-not-track-signals-in-linkedin-case https://dig.watch/updates/german-court-affirms-legal-signifi...
- toyg 3y agoWhat do you mean by "the original (now decades-old) law" ? The GDPR is 8 years old.
- PinguTS 3y agoThe ePrivacy directive, mostly referred to as "Cookie law" is from 2002. https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A32002L0058 https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A...
- flipbrad 3y agoYes. Although in fairness, the "cookie rule" part has been updated since then. But not anytime recently. And the GDPR's subsequent entry into force created the current emphasis on how actively (and individually) you need to consent to things, and how much you have to be told about them first. Stuff like "clicking anywhere on this site, tells us you consent" was a lot more common, pre-GDPR
- aleph_minus_one 3y ago> Note that this isn't a cookie law, it's also the EU's main anti-malware law. The principle is that no piece of third-party controlled software should write information to your computer/phone, or read info from it, over the Internet, without your prior informed consent So it is a responsibility of the browser vendor to implement this.
- flipbrad 3y agoNo moreso than the OS itself. The real responsibility actually lies with the people causing the remote access (e.g. the website operator, the remote hacker, etc).
- lesuorac 3y agoI mean it currently isn't. The Cookie banners aren't from the browser they're really from the site. That said, it seems fair to require the browser vendor to implement it. The browser is the one that exposes a method to store data on the machine (ex. Cookies, LocalStorage) so it seems fair that they should know the user wanted data to be stored.