4 ms·
> I do not know what was the reason to get rid of session cookies. Maybe the fear of GDPR violations Just to clarify, GDPR has nothing to do with cookies. GDPR
by Zanfa 2y ago
> I do not know what was the reason to get rid of session cookies. Maybe the fear of GDPR violations
Just to clarify, GDPR has nothing to do with cookies. GDPR applies exactly the same whether you use cookies, JWTs in local or session storage, some magic session id tacked at the end of every URL or device fingerprinting.
- mbmjertan 2y agoI am not surprised. A lot of people conflate GDPR with the well-intentioned but misdirected cookie directive. A lot of people blame the EU for “forcing cookie banners onto the web”, while the GDPR solely demands that you ask for consent before storing data that’s outside of your core functional needs to operate the app/website. The UX of those dialogs is largely a dark pattern because the law did not demand implementation details, yet people blame GDPR because businesses designed them to be a nightmare to use. Yet people applaud for App Tracking Transparency dialogs. It’s ironic how the GDPR is painted as a villain.
- Propelloni 2y ago> The UX of those dialogs is largely a dark pattern because the law did not demand implementation details, yet people blame GDPR because businesses designed them to be a nightmare to use. Yet people applaud for App Tracking Transparency dialogs. True, it does not mandate specific implementation details but in Recital 32 of the GDPR [1], it demands "request[s] must be clear, concise and not unnecessarily disruptive to the use of the service [...]" which is mostly not given with dark pattern implementations. [1] https://gdpr.eu/Recital-32-Conditions-for-consent/ https://gdpr.eu/Recital-32-Conditions-for-consent/
- Zanfa 2y ago> The UX of those dialogs is largely a dark pattern because the law did not demand implementation details, yet people blame GDPR because businesses designed them to be a nightmare to use. IMO the law was clear enough as highlighted in the sibling comment. It is poor enforcement that's been a major issue. If a company registered in country A flouts GPDR, even in country B, there's nothing country B can do, other than delegate to country A's data protection / privacy authority. If country A then drags their feet and takes no action, we arrive at the current situation.
- Cthulhu_ 2y agoThe problem there was that the GDPR was dumbed down by either the legislators behind it or the media to "the cookie law" or "the cookie banner", but nobody, especially not the decision makers, seem to have looked into it. It's a huge cargo cult, in that people put up the same banners they saw the early adopters do and think that's complying to the regulations.
- lmc 2y ago> Just to clarify, GDPR has nothing to do with cookies. Not strictly true, they are highlighted as a potential source of PII. https://gdpr.eu/cookies/ https://gdpr.eu/cookies/
- pjc50 2y agoBut as others have pointed out, the law is extremely technology-agnostic. Sticking the same information in a JWT makes no difference either way.