6 ms·
Except that it’s seemingly impossible to prevent against prompt injection. The cat is out the bag. Much like a lot of other legislation (eg cookie law, being re
by deanc 1y ago
Except that it’s seemingly impossible to prevent against prompt injection. The cat is out the bag. Much like a lot of other legislation (eg cookie law, being responsible for user generated content when you have millions of it posted per day) it’s entirely impractical albeit well-meaning.
- lcnielsen 1y agoI don't think the cookie law is that impractical? It's easy to comply with by just not storing non-essential user information. It would have been completely nondisruptive if platforms agreed to respect users' defaults via browser settings, and then converged on a common config interface. It was made impractical by ad platforms and others who decided to use dark patterns, FUD and malicious compliance to deceive users into agreeing to be tracked.
- deanc 1y agoIt is impractical for me as a user. I have to click on a notice on every website on the internet before interacting with it - often which are very obtuse and don’t have a “reject all” button but a “manage my choices” button which takes to an even more convoluted menu. Instead of exactly as you say: a global browser option. As someone who has had to implement this crap repeatedly - I can’t even begin to imagine the amount of global time that has been wasted implementing this by everyone, fixing mistakes related to it and more importantly by users having to interact with it.
- lcnielsen 1y agoYeah, but the only reason for this time wasteage is because website operators refuse to accept what would become the fallback default of "minimal", for which they would not need to seek explicit consent. It's a kind of arbitrage, like those scammy website that send you into redirect loops with enticing headlines. The law is written to encourage such defaults if anything, it just wasn't profitable enough I guess.
- deanc 1y agoThe reality is the data that is gathered is so much more valuable and accurate if you gather consent when you are running a business. Defaulting to a minimal config is just not practical for most businesses either. The decisions that are made with proper tracking data have a real business impact (I can see it myself - working at a client with 7 figure monthly revenue). Im fully supportive of consent, but the way it is implemented is impractical from everyone’s POV and I stand by that.
- ta1243 1y agoWhy would I ever want to consent to you abusing my data?
- user5534762135 1y agoThat is only true if you agree with ad platforms that tracking ads are fundamentally required for businesses, which is trivially untrue for most enterprises. Forcing businesses to get off privacy violating tracking practices is good, and it's not the EU that's at fault for forcing companies to be open about ad networks' intransigence on that part.
- bfg_9k 1y agoAre you genuinely trying to defend businesses unnecessarily tracking users online? Why can't businesses sell their core product(s) and you know... not track users? If they did that, then they wouldn't need to implement a cookie banner.
- deanc 1y agoRetargetting etc is massive revenue for online retailers. I support their right to do it if users consent to it. I don’t support their right to do it if users have not consented. The conversation is not about my opinion on tracking, anyway. It’s about the impracticality of implementing the legislation that is hostile and time consuming for both website owners and users alike
- 1y ago
- tcfhgj 1y agoJust don't process any personal data by default when not I inherently required -> no banner required.
- 1718627440 1y agoI don't have to, because there are add-ons to reject everything.
- jonathanlydall 1y agoI recently received an email[0] from a UK entity with an enormous wall of text talking about processing of personal information, my rights and how there is a “Contact Card” of my details on their website. But with a little bit of reading, one could ultimately summarise the enormous wall of text simply as: “We’ve added your email address to a marketing list, click here to opt out.” The huge wall of text email was designed to confuse and obfuscate as much as possible with them still being able to claim they weren’t breaking protection of personal information laws. [0]: https://imgur.com/a/aN4wiVp https://imgur.com/a/aN4wiVp
- tester756 1y ago>The huge wall of text email was designed to confuse and obfuscate as much as possible with It is pretty clear
- johnisgood 1y agoOnly if you read it. Most people do not read it, same with ToSes.
- octopoc 1y agoIf you ask someone if they killed your dog and they respond with a wall of text, then you’re immediately suspicious. You don’t even have to read it all. The same is true of privacy policies. I’ve seen some companies have very short policies I could read in less than 30s, those companies are not suspicious.
- 1718627440 1y agoThat's true, because of the EU privacy regulation, because they make companies write a wall of text before doing smth. suspicious.
- johnisgood 1y agoI do not disagree. It could indeed be made shorter than usual, especially if you are not malicious.
- mgraczyk 1y agoEven EU government websites have horrible intrusive cookie banners. You can't blame ad companies, there are no ads on most sites
- lcnielsen 1y agoBecause they track usage stats for site development purposes, and there was no convergence on an agreed upon standard interface for browsers since nobody would respect it. Their banners are at least simple yes/no ones without dark patterns. But yes, perhaps they should have worked with e.g. Mozilla to develop some kind of standard browser interface for this.
- mgraczyk 1y agoThis is actually not true. I just read the European commission's cookie policy. The main reason they need the banner is because they show you full page popups to ask you to take surveys about unrelated topics like climate action. They need consent to track whether or not you've taken these surveys Their banner is just as bad as any other I have seen, it covers most of the page and doesn't go away until I click yes. If you're trying to opt out of cookies on other sites, that's probably why it takes you longer (just don't do that).
- cultureswitch 1y agoYou don't need cookie banners if you don't use invasive telemetry. A website that sticks to being a website does not need cookie banners.