11 ms·
>, Paul Graham came up with the thought, that the EU forces companies to have cookie banners. There is no law for cookie banners. [...] Companies could easily
by jasode 3y ago
>, Paul Graham came up with the thought, that the EU forces companies to have cookie banners. There is no law for cookie banners. [...] Companies could easily avoid any cookie banner. Just don’t track.
KingOfCoders/amazingcto, of course you are technically correct but Paul Graham wasn't talking about the letter of the law.
Instead, you have to interpret his complaint with the lens of game theory. I.e. The Law of Unintended Consequences that takes into account what companies actually do in response to laws instead of what we hope they will do.
Your blog post focused on good intentions of the law. PG's tweet focused on actual outcome.
- n4r9 3y agoDoesn't that argument work both ways? If you interpret the EU's regulation with the "lens of game theory", it is an unintended consequence of aggressive corporate data collection. Not sure why it makes sense to complain about the EU and not the companies.
- polygamous_bat 3y ago> Not sure why it makes sense to complain about the EU and not the companies. Unfortunately a non-negligible number of people in tech also have libertarian leanings, with a default “gubmint bad!” position, which makes them easy prey for adtech propaganda.
- gred 3y ago> Unfortunately a non-negligible number of people in tech also have libertarian leanings Why is this unfortunate? Because you don't agree with us? The "they would agree with me if they were smarter" trope is tired and gets us nowhere.
- Kbelicius 3y ago> Why is this unfortunate? GP answered your question, for some reason you decided to cut the quote right before the answer. Here is the part that is missing from your quote which answers your question: '[...]with a default “gubmint bad!” position'
- gred 3y agoPretty clearly implying the diminished mental capacity which prevents us from agreeing with him, no? I addressed this above: > The "they would agree with me if they were smarter" trope is tired and gets us nowhere.
- FredPret 3y agoSome people have a default “gubmint gud business bad” position and assume that disagreement is only possible if you’re a brainwashed bootlicker. I say that’s unfortunate
- Gormo 3y agoPerhaps you should consider the possibility that the reason why libertarians assume a default "gubmint bad!" reaction to new policy interventions is that they are sensitized due to decades of experience seeing multitudes of government interventions both (a) to achieve their intended outcomes and (b) create unintended consequences, often worse than the problems they are meant to solve, instead. Personally, I find it very very strange that many of the people who call for regulation as a remedy to perverse incentives manifest in commercial markets seem unwilling to recognize the existence of even more perverse incentives in the political realm. If people seeking profit sometimes do bad things to get it, why would people seeking political power be expected to behave differently?
- fauigerzigerk 3y agoThat's beside the point. If you are in favour of government intervention you should be all the more interested in good policies that have the intended effect. Bad laws boost libertarianism.
- ZeroGravitas 3y agoAlso, lying about good laws boosts libertarianism. At least until you realise what they're doing, then you think they're skeevy corporate toadies with no morals.
- FredPret 3y agoHow arrogant to assume your position should be the default one, and people who don’t agree with you are - of course - easy prey for propaganda.
- hallway_monitor 3y agoSeems to be a common tactic from a certain faction currently in power in the United States.
- FredPret 3y agoNot just a US phenomenon - it's gone global
- fauigerzigerk 3y agoNo, it does not work both ways. The roles of governments and corporations are not symmetric. Good regulation is regulation that has good outcomes. If a law has bad outcomes it is a bad law. You can separately complain about what companies are doing but that doesn't change the fact that it's a bad law. It is of course debatable whether GDPR as a whole has bad outcomes, but if we're talking about cookie banners in isolation then it certainly does.
- zanellato19 3y agoExposing the fact that the entire internet is tracking is actually a good outcome.
- ragnese 3y ago> No, it does not work both ways. The roles of governments and corporations are not symmetric. > > Good regulation is regulation that has good outcomes. [...] You don't seem to explain what the role of corporations is or what a good corporation looks like. If these things are not symmetric, you need to finish your explanation of why or how they aren't. Corporations and the whole of property rights only exist because of government protection, so it would be pretty audacious--in my opinion--to assert that corporations have no duty to behave to the benefit of society. I'm not saying that's your claim, but I'm curious as to how close you're willing to get to that claim...
- fauigerzigerk 3y agoGovernments are supposed to represent the whole of society. The justification for their policies is ideally based on democratic legitimacy. No entity outside of government can possibly have that legitimacy. In my opinion it is not audacious at all to reject the idea that corporations should intentionally pursue societal goals or claim to act out of a sense of duty. Of course we want the effect of what corporations do to be of net benefit to society as a whole. But this cannot be based on their intentions or sense of duty. It has to be based on the systemic effects of them pursuing their own (possibly enlightened) self interest within the framework of the law. It is for governments to make sure that these effects are beneficial and to intervene when they are not. So the asymmetry I see is that capitalism is a tool of society, not the other way around.
- CipherThrowaway 3y agoOf course not. Only titans of industry and the landed gentry of the executive class are allowed to "move fast and break things", "ask for forgiveness rather than permission" and take "imperfect action rather than perfect action." It's more morally permissible for corporate decision makers to install a global surveillance complex than for civil servants to attempt to regulate it.
- sshine 3y ago> It's more morally permissible for corporate decision makers to install a global surveillance complex No, it's more transparent. Unlike cookie banners. If only cookie banners protected the consumer, but shadow cookies work fine.
- Tarq0n 3y agoThat's a misuderstanding of the banners. The requirement is to get consent to track someone and/or process their personal information in a way that is not strictly necessary or covered by contract. The mechanism that does the tracking is irrelevant.
- edanm 3y agoBecause the companies are getting what they want (data on users), but the regulation is not getting what it wants (no tracking or informed tracking). I don't know if this mini-competition between regulators and companies is truly zero-sum, there could be some way to get everyone something they want. But with the current regulation, it is zero-sum, and the companies are winning and the EU is losing. And the EU "works for you", so of course you can complain to them.
- n4r9 3y ago> the regulation is not getting what it wants (no tracking or informed tracking) That's an overstatement of the purpose of the regulation IMO. The purpose is to give the user control over the tracking of their data.
- edanm 3y agoOK, fair enough. pg's point still stands I think - I believe that most users have zero idea what that popup is and don't bother doing anything but clicking on it immediately even if they do have some idea.
- n4r9 3y agoI find it pretty difficult to be sure what point pg is making, because he uses an ambiguous phrase "good at regulation". What does he mean by "good at regulation"? According to the UK's Institute of Chartered Accountants [0] good regulation satisfies five criteria: * Transparency * Accountability * Proportionality * Consistency * Targeting I'm not certain that the GDPR laws fail any of these. I'm guessing pg is getting at something more nebulous to do with how annoying the UX is as a result of the regulation, and whether it encourages civil engagement. But if he'd simply said "EU regulation has made UX annoying" then he wouldn't have such a snappy tweet. [0] https://www.icaew.com/technical/trust-and-ethics/better-regulation/better-regulation-briefing/1-principles-of-good-regulation https://www.icaew.com/technical/trust-and-ethics/better-regu... EDIT I googled some more and found a brochure from the National Audit Office titled "Principles of Effective Regulation": https://www.nao.org.uk/wp-content/uploads/2021/05/Principles-of-effective-regulation-SOff-interactive-accessible.pdf https://www.nao.org.uk/wp-content/uploads/2021/05/Principles... It does have a statement in there: > Good regulation maximises the benefits while minimising compliance costs and unintended consequences. The benefits of regulation can be both to wider society (such as improved environmental or safety standards) and to regulated (for example, through increased consumer confidence), but not all of the benefits are necessarily easy to quantify. Put that way, I can get on board with what pg's saying.
- semi-extrinsic 3y agoI consider it a good outcome when I can clearly identify shitty websites and just click the back button.
- klabb3 3y agoI’m not surprised. This is a “hot take-centric” platform issue, and a laziness in trying to understand him too. Or.. two people on the street yelling at each other but not listening.
- hikingsimulator 3y agoThe blog clearly works from the actual outcome lense. It's repeated. Several times. The companies could just not track. The actual outcome is that they do want to track, and use adversarial patterns and malicious compliance to twist your arm and "force consent." Paul Graham is still wrong.
- jasode 3y ago>The blog clearly works from the actual outcome lense. [...] The companies _could_ just not track. No, you've inadvertently stated a contradiction. Your use of the word _"could"_ is literally a hope/wish/intention of the law. In contrast, the actual outcome is that the companies didn't stop tracking. We _wish_ they would stop tracking. (I.e. "The companies _could_ just stop tracking us!") But that hope still doesn't change the observation of reality.
- hikingsimulator 3y agoThe law is not code. Equating hope with the intention of the law is a poor way to think about it. The law is to protect users against opaque companies and to enable them making informed choices. If companies act maliciously to contort around the law and force users back to making uninformed choices, it is the companies' fault and not the law's. Companies could have followed the interpretation of the law unobstrusively. But they didn't. Invoking "reality," semanticking a position, do not make Graham's position justified. Neither does it make the blog wrong.
- itishappy 3y agoBut companies have stopped tracking (or they've started lying). I can now opt out. I could not before.
- voxic11 3y agoCan you really say that confidently? I think a lot of these companies would go out of business if they didn't track users so it seems like under the law they have no option but to show cookie banners. Or are you claiming the law exempts companies in such circumstances?
- GTP 3y agoI see your point, but then to have a constructive conversation Paul Graham should also give his two cents about how the law could be improved. I don't know him, so I'll ask here: did he do that?
- jmathai 3y agoIt’s unfortunate, if companies are okay not tracking you, that they care little enough about their user experience to use cookie banners.
- KingOfCoders 3y ago(author here) I'm a fan of second-order thinking and unintended consequences, so I'm with you there. How would you frame a "don't track people without consent" without unintended consequences? The article tries to make the point (perhaps fails), that companies do this intentionally to get the "consent" of people against their will, therefor running the tight line of breaking the law without breaking it.
- gizmo 3y agoThe problems with the current law are: - no fines for non-compliance (or malicious compliance) - no legal liability for data leaks of PPI When businesses believe (correctly or incorrectly) that the benefit of tracking outweighs the cost (annoying users, regulatory noncompliance) they will do it. The fix is to make tracking too costly for businesses.
- pella 3y ago> - no fines for non-compliance (or malicious compliance) "The Biggest GDPR Fines of 2023" 1. Meta – €1.2 billion (Ireland) 2. Meta – €390 million (Ireland) 3. TikTok – €345 million (Ireland) 4. Criteo – €40 million (France) 5. TikTok – €14.5 million (UK) 6. Axpo Italia Spa – €10 million (Italy) 7. Tim S.p.A. – €7.6 million (Italy) 8. WhatsApp – €5.5 million (Ireland) 9. EOS Matrix – €5.5 million (Croatia) 10. Clearview AI – €5.2 million (France) "GDPR fines are designed to make non-compliance around data security a costly mistake and they can be separated into two tiers. Less severe infringements can result in a fine of €10 million or 2% of a firm’s annual revenue from the preceding financial year, depending on which amount is higher. More serious violations can result in a fine of up to €20 million or 4% of a firm’s annual revenue from the preceding year, depending on what is higher." via https://www.eqs.com/compliance-blog/biggest-gdpr-fines/ https://www.eqs.com/compliance-blog/biggest-gdpr-fines/
- gizmo 3y agoWhich ones of those fines were because of inappropriate use of cookie consent popups? You just copy-pasted a list of GDPR fines.
- VeejayRampay 3y agoPaul Graham focused on whining about regulation as he always does
- gizmo 3y agoExcept many companies respond to the cookie law with a cookie consent popup that violates the law (by making opt-out harder than opt-in). Could we really have predicted from the "Law of Unintended Consequences" that companies would respond not by tracking less nor by giving people an easy way to opt out, but with a cookie consent popup that is not compliant and also really annoying to their visitors? This is better explained by business operators being ignorant of the actual law and being ignorant of the UX impact.
- sputr 3y agoThe actual outcome is, from my experience, that tracking has reduced, a lot. When this law was enacted, *we all removed "like on Facebook"* buttons. Remember those? Yeah, we don't see them anymore. Google Analytics also was forced to change, at least a little. Is there still tracking? Sure. But it's not so blatant anymore. There are hoops one needs to jump through. And that was the point - to make tracking a harder. None of my projects have cookie banners. Why? Because I use a first party tracking system (Matomo), I anonymize all visits and I respect DNT. It's that easy.
- FredPret 3y agoIt’s not the difficulty level that people object to. It’s a combination of two things: 1) the law comes to the rest of the world from Europe. We (rest of the world) didn’t vote in the people who brought it. We’ve had quite enough of Europeans making rules for the rest of the world in the past few centuries thank you very much. 2) GDPR encodes an expectation that may or may not be common in the EU, but certainly isn’t common elsewhere. I don’t have any expectation of privacy when I walk in public or when I give any information at all to a business. My solution to this is: a) I wear pants outside, and b) I don’t give out private information. Whether the business ecosystem knows their age and purchasing patterns is largely immaterial to virtually everyone I’ve ever met. And don’t show me a survey showing people don’t like it - if you prime people with the question, of course they will respond that way. They know their info is being gathered, and they just don’t think it’s as big a deal as GDPR would like it to be.
- sputr 3y agoSo, I get your point. I can see how (1) can be aggravating. Can't really say anything to defend it, that's the Brussels effect for you. From the point of view of your own sovereignty, it's a bad thing, period. From the point of view of an effect on the lives of average people, I'm not so sure, it's so cut and dry. Now, point (2) is, unfortunately, in the same vein as smoking, pollution, seat belts etc. Uninformed people (uninformed because they have better things to do) are not protected from their lack of knowledge. They suffer the consequences just the same. And while I agree that and informed person, making a self-destructive choice has (in most cases) the right to do so, there is something to be said about the very, very powerful exploiting the uninformed. And this is where GDPR comes into play. It's protecting normal people, from a very, very big threat, that is not that obvious and is being wielded by the powerful. GDPR is one of those laws restraining western corporations from going full dystopian future on us all. I said restraining, to be honest, I think it's just slowing them down. And as far as surveys go - it used to be the same here. Europeans didn't care and said exactly the same things (i.e. the famous "i didn't do anything wrong, so I have nothing to hide") and then activists worked for years to educate them that, at the very least, it's leading them to buy things at higher prices. Now most people are extremely sensitive to their data.
- CipherThrowaway 3y agoEveryone knows that bad actors will continue to behave badly in the face of the law. This isn't the insight you seem to think it is. Really, PG's tweet has little to do with game theory or anything else. It is a first-world-problem whinge about having to click through cookie banners. Assessing the "actual outcome" of complex regulation and legislation is a task beyond the scope of a single tweet. It might be useful for Graham to determine what claim he is trying to make in the first place. Is he rebutting a particular EU representative for boasting about how good they are at regulation? Or is the idea that the EU shouldn't have the audacity to attempt to regulate in the first place?
- ryandrake 3y agoThere are a lot of ridiculous things a company can choose to do in response to any given law. Those choices are not mandated by the law. Horrible consent UX is not the only option to choose from. Government can, and should, analyze likely (or unlikely) unintended consequences and use those to further shape the law, but at the end of the day, those consequences come from choices that people who are subject to the law make. I think the big mistake the EU made is they probably thought: “Surely no company would choose to abuse their customers with horrible UI just because they don’t like the law and want to take their collective frustration out on their users!” The EU was obviously wrong about the extent to which companies would throw their users under the bus while maliciously complying.
- karmakaze 3y agoThe outcome would be much better if the law explicitly stated that the initial cookie banner must have a "Necessary cookies only" opt-out one-click option. And that this option means truly necessary, not the Internet Explorer is needed by the operating system 'necessary'.