10 ms·
Exactly. If they indeed only use the cookie for essential functionality, this kind of joke banner only makes their choice to respect visitors' privacy equally a
by ttiurani 1y ago
Exactly. If they indeed only use the cookie for essential functionality, this kind of joke banner only makes their choice to respect visitors' privacy equally annoying.
Even worse: because it makes it seem like the EU law is just meritless pestering of people, they are actually fighting for the right for worse sites to spy on their visitors.
It's baffling.
- xp84 1y ago> EU law is just meritless pestering of people It is that. It has done literally nothing to improve anything whatsoever, in any country. And most of the "cookie management" scripts that people use, barely even work. Both the law and the way it's complied with in practice are a dumb solution to a problem that the EU should have forced browser vendors to solve. Only the user's browser can choose not to send back cookies, and it would be trivial for the user to be shown a dialog when they navigate to a previously-visited site in a new session saying: Last time you were here, the site stored information that may help them recognize you or remember your previous actions here. < I want to be recognized > / < Forget Everything > [ ] Also keep these third-party cookies <Details...> [x] Remember my choice and don't ask again for ycombinator.com
- ttiurani 1y agoHow would that prevent sites from selling their users' data to third parties without consent server-side? GDPR is not about third party cookies, but about requiring informed consent.
- vouwfietsman 1y agoThough I agree with your point, the idea that cookie banners in any sense contribute to "informed consent" is very debatable.
- kiicia 1y agoIt’s because those were made to be bad solution by very advertising companies wanting people to be denied their rights and making it look like law is bad instead of implementation being bad
- xp84 1y agoThe 'selling of data' is separate of course, but the banners do nothing to actually ensure that they aren't collecting data you don't know about. They're honor system, which is dumb when you could have browsers not send that data back without opt-in. In other words, of course Facebook knows you like bacon if you've followed 5 bacon fan pages and joined a bacon lovers group, and they could sell that fact. But without cookies being saved long-term, Facebook wouldn't know that you are shopping for a sweater unless you did that shopping on Facebook. Today they undoubtedly do know if you are shopping for anything because cookies exist and because browsers are configured to always save cookies across sessions. Also, I always point this out when this topic comes up: Of all websites I visit and have to click stupid banners on, almost none of them are in the market of "selling data" or building dossiers about individuals ("Steve Smith bought flowers on June 19th. Steve is 28 years old. He has a Ford Explorer. He lives in Boston."). They just want to get metrics on which of their ads worked, and maybe to know aggregate demographics about their audience. My local water utility, Atlassian, and Nintendo to pick 3 sites at random, have never been and are not in the business of data brokerage. But they do need to show cookie banners to not be sued for imaginary harms under CCPA or GDPR (unless they want to not make any use of online advertising or even aggregate analytics).
- gf000 1y ago> They're honor system, which is dumb when you could have browsers not send that data back without opt-in. Given that there is no objective way to differentiate between functional and tracking cookies, your "technical" solution would also boil down to honoring marking certain cookies as such by the website owner, effectively being the same as what we have today. (Though I do agree that the UX would be nicer this way)
- swiftcoder 1y agoWell, I mean, we could go the route Safari has, and just blanket-disable 3rd party cookies by default. It's... quite effective (if a tad annoying for folks implementing single-sign-on)
- 1y ago
- fmbb 1y agoIf you like things the way they were before the law, just answer yes to all cookie banners you see. It does not take time if you don’t care to read it. Yours click yes, and they will remember you want to be tracked.
- koliber 1y agoThat’s in theory. In practice these banners regularly break. They are hard to click on certain devices where the button is off screen. If they use JavaScript and there is an error elsewhere, you can’t hide them. And I regularly see them over and over again on the same sites because for some reason they can’t track me effectively for this purpose. In short they are a regular minor annoyance that does take time and effort.
- diggan 1y agoSeems like it's working then? Because the website chose to (optionally) track you, you need to go through a minor annoyance to accept it. You're effectively making a choice that you're fine with this annoyance (since you keep using the website) and since you're accepting it, you're fine with being tracked. Other people already get two choices to make here which they didn't get before, which is a win in my book. Seeing the banner, you can decide to avoid the website and if you still wanna use the website, you can chose if you allow them to track you by PII or not.
- koliber 1y agoI get the choice, but I make the choice I like less because it is more convenient to make it. If we only look at the positives, then the situation is better. But we have to look at the cost, and there is a cost, in terms of time and mental effort, to read the banner, figure out what the choices are, and if I am not accepting all cookies, how to go through the process of rejecting some of them. Sometimes it's very involved. Also, I am an educated consumer and understand what a cookie is. Most people do not and do whatever is necessary to make the consent screen go away. Because of that, effectively they don't get this choice. As one of the parent posts said, if it was implemented on the browser level, I would get the choice, and the cost of making the right choice would be smaller. If the defaults were to "reject unnecessary cookies" then most of the population would get the benefit. The way it is right now feels like a net negative. Most people don't know what the consent is about and will not spend the time to learn it. Companies still find ways to track you that agrees with the letter but not the spirit of the law. I have friction whenever visiting a new website (or an old one that forgot my choice). The only winners are people who don't value their time and are smart enough to understand cookie consent. That's a small percentage of the general population.
- digitalPhonix 1y ago> It has done literally nothing to improve anything whatsoever, in any country That’s because of malicious compliance from all the websites/advertisers. I guess that is partly the lawmakers’ fault for not pre-empting that; but much larger blame lies on the industry that refuses to grant user privacy. As an example for a site that followed the intent of the law instead: https://github.blog/news-insights/company-news/updates-to-our-privacy-statement-and-terms-of-service/ https://github.blog/news-insights/company-news/updates-to-ou... Github removed excess tracking so they didn’t need to show a cookie banner and that’s what GDPR’s intent was.
- CamouflagedKiwi 1y agoBlaming the industry for it doesn't change the reality that the law has done very little to improve the thing it was aimed at and made the internet worse for users (and developers) with all the banners. By any objective measure its outcomes are terrible - lawmakers should do better than just throwing out things like that.
- omnimus 1y agoVery little? The norm used be to slap google analytics on everything. Suddenly everybody thinks about compliance — especially those who didn't even have idea there was something wrong. Many sites ditched tracking altogether so they don't have to have banners. Everybody is aware of GDPR so you can be pretty confident that when european site has no banner it doesn't track you. Could the law be better? Sure I would love to ban tracking altogether. But this was lobbied to hell by AD companies. Everybody was kicking and screaming because they want all the data. And we still got something that helps. That is a win. And you can see how industry hates it in way they implement the banners. It is annoying and confusing on purpose. You could comply in nice way but when you need to share the data with your 141 ad partners and each one gets their own checkbox… good luck. Same reason nobody was respecting the dont track me flag. The industry is absolutely and exclusively to blame here.
- odie5533 1y ago
- Cthulhu_ 1y agoThe EU law is fine, the implementation used isn't. But never blame the EU laws for cookie banners; the law does not mandate banners at all, let alone the ones full of dark patterns to nag you into accepting anyway. That's all the industry. The industry could have come up with a standard, a browser add-on, respect a browser setting, etc but they chose the most annoying one to pester you, the user.
- Doxin 1y ago> let alone the ones full of dark patterns to nag you into accepting anyway. In fact the law pretty explicitly disallows dark patterns like that. Of course tech companies have a loosy-goosy relationship with the law at the best of times.
- Cthulhu_ 1y agoYeah, and only when (I think) Google got a hefty fine did the banner implementations start to add an instant "opt-out" button. The tech companies really try to skirt the rules as closely as possible. I'm glad I'm not in EU legal, it's gotta be like dealing with internet trolls ("I didn't ACTUALLY break any rules because your rules don't say I can't use the word "fhtagn"")
- theshrike79 1y agoThe #1 problem with the cookie law is that it's not enforced. Start fining sites with dark pattern banners and they'll start going away.
- AlienRobot 1y agoI feel like the #1 problem with the cookie law is that the vast majority of websites need to do something in order to comply while keeping their business model and the law hasn't provided a clear direction for how to comply with it. If they had done that, nobody would be making cookie banners wrong.
- hnbad 1y ago> In fact the law pretty explicitly disallows dark patterns like that. Yes. For "cookie banners" the law in fact forbids hiding "Reject all non-essential and continue" to be given less visual weight than "Accept all and continue", let alone hiding it behind "More details" or other additional steps. It also requires consent to be informed (i.e. you need to know what you're agreeing to) and specific (i.e. you can't give blanket consent, the actual categories of data and purposes of collection need to be spelled out) and easily revokable (which is almost never the case - most sites provide no direct access to review your options later once you've "opted in"). One good example I can think of for a "cookie banner" that gets this right is the WordPress plugin from DevOwl: https://devowl.io/wordpress-real-cookie-banner/ https://devowl.io/wordpress-real-cookie-banner/ (this is not an ad, but this is the one I've been recommending to people after having tried several of them) because it actually adds links to the footer that let you review and change your consent afterwards. EDIT: Sorry, I first misread "disallows" as "allows". I've amended my reply accordingly.
- fifticon 1y agoI don't agree. It is the main way I am being informed that some sites I attempt to use, share my data with thousands of external partners, for no relevant function. I do not believe this information would be divulged to me and the public, if voluntary. The public is mistreated in innumerable ways, starting by not letting them know it is happening.
- thwarted 1y agoPlatform for Privacy Preferences Project (P3P) has existed for over 20 years and no one wanted to implement it. https://en.wikipedia.org/wiki/P3P https://en.wikipedia.org/wiki/P3P
- Tor3 1y agoI read an interview with a bunch of different young people. They all basically said "I just click 'yes' or 'accept' automatically". It sounded like they all believed that this was something they had to do in order to get to the content. Bad implementation of the EU law indeed, as another comment said. It fails the purpose completely and just create more problems for nearly everyone.
- cjpearson 1y agoIn many cases it is required to access the content. Courts have allowed "Consent or pay" for sites such as newspapers.
- Tor3 1y agoIn some cases is how I would state it. It's actually very rare that you have to consent to 'accept all cookies' to read content, I've never actually seen it myself. 'Pay if you want to read more' is common, for certain types of sites.
- hnbad 1y agoThe law is fine. The industry has just decided that dragging its heels and risking fines is better than actual compliance. Most of the "cookie management" scripts that people use aren't compliant. EU law requires "Accept All" and "Reject All Non-Essential" be both equally easy to access and given equal weight (or rather: the latter can't be given less weight and made more difficult to access, which almost all of these scripts blatantly ignore). Browser vendors can't solve this because the question isn't technical but legal. It's not about first-party vs third-party cookies (let alone same-origin vs cross-origin) but about the purposes of those cookies - and not just cookies but all transferred data (including all HTTP requests). You don't need to (and in fact can't) opt into technically necessary cookies like session cookies for a login and such. It's plausible that these might even be cross-origin (as long as the other domain is controlled by the same legal entity). If they're provided by a third party, that would indeed be data sharing that warrants a disclosure and opt in (or rather: this can only happen once the user acknowledges this but they have no option to refuse and still use the service if it can't plausibly be provided without this). The GDPR and ePrivacy laws (and the DMA and DSA) have done a lot for privacy but most of what they have done has happened behind the scenes (as intended) by changing how companies operate. The "cookie management" is just the user-facing part of those companies' hostile and dishonest reactions to these laws as well as a cottage industry of grifters providing "compliance" solutions for companies that can't afford the technical and legal expertise to understand what they actually need to do and think they can just tick a box by buying the right product/service. Heck, most companies don't even provide legally compliant privacy policies and refuse to properly handly data access requests. The GDPR requires companies to disclose all third parties (or their categories if they can't disclose identities) your (specifically your) data has been shared with and the specific types of data, purposes of that sharing and legal basis for sharing it (i.e. if it required consent, how and when that consent was given) - and yet most will only link you to their generic privacy policy that answers none of those questions or only provides vague general answers or irrelevant details ("We and our 11708 partners deeply care about your privacy").
- renewiltord 1y agolol this is what it used to be like back in the day. We have forgotten the old ways and now we yearn for them. Every tutorial instructed old people to just click Always Allow or else they would not be able to read their webmail.
- ketzu 1y ago> the EU should have forced browser vendors to solve. Only the user's browser can choose not to send back cookies This is only an option if you limit tracking to using cookies. But neither tracking technologies, nor the current EU law, are limited to tracking via cookies. It also kills functionality for many web applications without also accepting all tracking. Some browser-flavors went to extreme lengths to prevent tracking through other means (eg fixed window size, highly generic header settings, ...). Maybe I am mistaken, but it seriously frustrates me how much people within the relevant field make this mistake of conflating tracking and cookies and come to this "it would be so simple" solution. A welcome update to the law would be to allow a header flag to opt out/in (or force the do-not-track header to have this functionality) preventing the banner from showing.
- boomlinde 1y agoThe pessimist in me thinks a legally enforced header and corresponding browser setting (so that the user wouldn't have to make an explicit choice per website) would have met enough pushback from businesses for the EU to back down to something with the infinite stupidity of the current solution. Maybe we could move towards that end in small steps. The EU should start by banning irrelevant non-sequiturs like "We value your privacy" and other misleading or at best distracting language. It can then abandon the notion that users are at all interested in fine-grained choice, and enforce that consent and non-consent to non-essential statekeeping are two clearly distinguished and immediately accessible buttons. No one wants to partially block tracking. It seems as though the EU is operating under the notion that this is all a matter of consumer choice, as though any informed consumer would choose to have tabs kept on them by 50 trackers if not for the inconvenience of figuring out which button stops them.
- xp84 1y agoI know it'll be considered a hot take, but I'd argue that people don't even know what "tracking" in the Internet context even means enough for their supposed "preferences" about it to be valid. 90% of non-tech-nerds have this simple of an opinion about it: 1. Retargeting ads are "creepy" because ... "they just are" 2. Retargeting ads either annoy me because I think they're dumb in that particular instance ("I already BOUGHT a phone case last week, it's so dumb that it keeps showing me phone cases all day!") or because they're too good ("I gave in and bought the juicer after I kept seeing those ads all around the web") and I don't like spending money. The rest of "tracking" they don't even know anything about and can't verifiably point to any harms. Data brokers acquire data from thousands of different sources - many of which aren't stemming from Internet usage - and most of the browser data relevant here isn't tied to their actual name and permanent identity (and doesn't need to be to serve its purpose which is usually "to show relevant ads" and the more specific case of "to get people to come back and buy things they saw"). Honestly, just like people are annoyed by pushy car salesmen, and being asked for a "tip" at a self-order kiosk counter-service restaurant, they are going to be annoyed about aspects of the commercial Internet, and it doesn't automatically mean that they're being victimized or that they need regulations to try to help.
- bxsioshc 1y ago[dead]
- AshamedCaptain 1y agoThe entire point of the law was to make websites using extraneous cookies and trackcing annoying to use. It's not something that can be solved in the browser _at all_. What I guess no one expected is that most websites would just decide to go on and pester their users rather than stop the tracking -- and that users would still continue using those websites.
- arghwhat 1y agoNo, it is not that. It highlighted an issue, and it makes it painfully obvious when a particular page is being extra ignorant about your privacy and trying to sell it to thousand vendors instead of a handful. What I don't like about cookie popups isn't the popup (which isn't something the EU law dictated btw), it's that someone thought it was okay to have hundreds of advertisement vendors and data brokers on a single news article, and it's better to know so I can just close the tab and never interact with that webpage again if they're being excessive asshats. They have failed at enforcing this properly though, in particular with the recent proliferation of "legitimate interest" abuse (it is only legitimate interest if it an implied component to a service I am directly requesting), and the general issue of popups illegally making rejection different from acceptance, intentionally making rejection slow, or even requiring payment to continue without cookies. And yes, the occasionally completely defective prompt. I do agree that it would be neater if the browser handled this though. Would also be neater if the internet wasn't entirely sponsored by privacy violations. :/
- viccis 1y ago>this kind of joke banner only makes their choice to respect visitors' privacy equally annoying Their name is "PostHog", a dirtbag left joke from years ago. If they were trying to make joyless scolds happy with their humor, their site would be very different.
- pjmlp 1y agoMan, I am always required to use this seatbelt even though I haven't had a car accident in decades, it takes me seconds to put it on and off, makes this pestering sound when I forget it, that gets into my nerves, another useless law that need nothing to improve security. /s /s
- auggierose 1y agoIf the EU was a serious entity, they would just forbid cookies that are non-essential. Simple as that. Either you take your responsibility as a law maker serious, or you refrain from making laws entirely.
- dgb23 1y agoOr they would enforce it via the (unfortunately deprecated) do not track header.
- troupo 1y agoAs we all know, tracking is only reliant on cookies. And not things like "storing your geolocation for 12 years" https://x.com/dmitriid/status/1817122117093056541 https://x.com/dmitriid/status/1817122117093056541 People ranting against cookie banners and GDPR literally never read the regulation itself and they literally never read what these banners are supposed to trick you into
- sylware 1y ago"EU law"... you mean "regulation", that to prevent some "abuse". Here, EU is not quite doing the right thing: the web need "noscript/basic (x)html" compatibility more than cookie regulation. Being jailed into a whatng cartel web engine does much more harm than cookie tracking (and some could use a long cryptographic URL parameter anyway). Basically, a web "site" would be a "noscript/basic (x)html)" portal, and a web "app" would require a whatng cartel web engine (geeko/webkit/blink). I do remember clearly a few years back, I was able to buy on amazon with the lynx browser... yep basic HTML forms can do wonders.
- Al-Khwarizmi 1y ago> makes it seem like the EU law is just meritless pestering of people Which it is? I am from the EU and I don't see what this law has accomplished apart from making the WWW worse, especially on mobile. I remember back when Opera was a paid browser, last century, it already have options to accept all cookies, refuse them, or set fine-grained preferences per website. No need for handling it at the website level if the client can do it.
- lucideer 1y ago> making the WWW worse You can argue that the law might not have improved things (at least not as much as intended), but nothing about this law has made the WWW worse. If you believe that, you've fallen for the concerted efforts of the advertising industry spreading misinformation about who's idea the annoying consent popups were & (like this website) perpetuating the myth that they're a legal requirement. None of the new annoyances on the modern web that you're thinking about are mandated by EU law. It benefits the ad industry massively to scapegoat the EU for these annoyances.
- Al-Khwarizmi 1y agoThe objetive, observable outcome is that before the law, websites don't have cookie banners. Since the law passed, they do. And they make the user lose time, and make navigation much more cumbersome, sometimes even impossible (not even 5 minutes ago, I had to go back on my phone because a newspaper article went into an endless loop after accepting the cookie banner). It doesn't matter much what happened behind the scenes to cause that outcome. From a black-box perspective, it could be that (a) the EU mandated the cookie banners, (b) the EU mandated to provide cookie settings in some generic form, and websites decided to use banners because it's easier, more lucrative, or even to put people against the EU, in spite of having other options that were better for the user. (c) the EU mandated a different thing and the annoying banners don't even comply with the law. No matter what the case is, the fact is that the EU made the WWW worse with the law. Either due to an outright harmful law, or to a well-intentioned law with too many loopholes, or to a good law but lack of enforcement. Doesn't matter much for the end user. When you make laws that affect people's daily life, good intentions aren't enough.
- whywhywhywhy 1y ago> because it makes it seem like the EU law is just meritless pestering of people The law should have been just a browser setting sites had to follow, making it a "banner" has made it meritless pestering while pretending it's for my own good and allowing the worst offenders to make convoluted UI to try and trick you every site visit.