7 ms·
Bold of you to assume that lawmakers have any common sense when it comes to technology legislation. It could have taken 3 interns 3 hours at each browser compan
by lxe 4mo ago
Bold of you to assume that lawmakers have any common sense when it comes to technology legislation. It could have taken 3 interns 3 hours at each browser company to implement a cookie consent standard 15 years ago, yet here we are in cookie banner hell.
- Bender 4mo agoI was referring to the intern being able to add the header. Politicians need financial incentive. I don't have the resources to lobby them. I think that might require a philanthropist should there happen to be one that lurks on HN. There are some interesting people that lurk here that we sometimes learn about. They can't do anything today as it is a federal holiday but they could do something tomorrow.
- gsich 4mo agoDNT exists, not even that is honored by websites. There is no need for a cookie banner for technical cookies.
- kube-system 4mo agoDNT is deprecated by W3C, and browsers have been removing it
- daemin 4mo agoCookie banners exist because it is a dark pattern companies use to get you to opt into marketing cookies by making the easiest thing the worst choice. This could all be handled by settings in the browser, only if the sites themselves listened to the users' browser preferences.
- vincnetas 4mo agoAgree. Its like in some countries you put a sticker on the mail box "no advertisement, please" and its illegal tor postman to deliver you ad brochures. Same could have been possible with browsers, but oh no, now you have to go out to each postman ant tell him explicitly that you do not want ads, and postman has no memory, if you tel him that you don't want ads. He can come back ten minutes later and you have to tell him again.
- tyre 4mo agoFun fact: in the US, the Supreme Court ruled that postal workers cannot filter out mail by the owner’s request. It makes a bit of sense, since the mailer had already paid, but the main justification (iirc; it was years ago that I read the opinion) was that a postal service should be neutral and trusted to deliver.
- tardedmeme 4mo agoFair enough. Most advertising isn't individually posted to each address because that's expensive - they hire their own guy, who isn't a postal worker, to go around and put it in everyone's mailbox. It's like paying one cent per email to prove it isn't spam.
- Geezus_42 4mo agoNo, 99.9% of the mail I get is trash and is delivered by USPS. You can't even recycle most of it because of the paper they are printed on. It's a huge, disgusting waste of resources on multiple levels.
- dessimus 4mo ago> It's a huge, disgusting waste of resources on multiple levels. The companies on the ads wouldn't do it that way if they were not getting a positive ROI from it. They probably only need to get 2 maybe 3 new customers to offset the cost of mass mailings.
- tardedmeme 4mo agoThis isn't true. Proctor and Gamble cancelled $200m of advertising and saw no change in sales. And companies using AI are costing more money to produce worse quality stuff more slowly. Facts don't matter, only how well you can convince a CEO.
- 4mo ago
- olalonde 4mo agoLawmakers should have foreseen this would be the consequence of the law and not have gone through with it.
- shakna 4mo agoThe law does mandate that opting out should be as easy as opting in. The choices are meant to be equal. It is simply that no one is actually compliant.
- olalonde 4mo agoThey could and should have foreseen this as well.
- jabwd 4mo agoIt is all in the law, the problem is enforcement. 99% of the cookie banners on the web you'll encounter are in fact illegal.
- theknarf 4mo ago"Do Not Track" (DNT) is already a browser setting. It just doesn't enforce anything, nor does anyone respect it.
- bragr 4mo agoTo be fair, some cookie banners do automatically opt you out if you send DNT, but is not the standard for sure.
- whywhywhywhy 4mo agoIf sites don’t listen to user preferences why would the cookie banner listen to my consent. Ultimately there’s no good excuse for the banner solution.
- daemin 4mo agoBecause the site (or marketing agency in charge of the ads) has plausible deniability for the user opting into marketing and tracking when they show a banner, whereas if it's a browser setting automatically applied then there's no such chance. Same sort of thing when you log into Wizzair and the check box below the password field is not "remember me" but "subscribe to our marketing emails".
- arendtio 4mo agoYes, the data protection people are always blamed for the banners when, in fact, the marketing people are responsible. If you build a website without all that tracking stuff and without 'free' services from the data collection companies Google and Facebook, then you have a pretty good chance of not requiring a banner at all, because for logins, etc., you are allowed to use cookies et al. without requiring an opt-in. But I never saw anybody at the OMR being proud about the state of cookie banners they created...
- kqp 4mo agoThis is misinformation stemming from disinformation propagated by organized industry retaliation to the law. Cookie banners are not and never have been required by law, they are intentional harassment designed to make users oppose laws that actually just say “you may not track users without their consent”. A good faith implementation would be simply nothing, because no explicit consent is required when you’re actually using cookies for honest purposes.
- AnthonyMouse 4mo agoAll of the cookie banners have separate categories for strictly necessary, functional, performance and marketing, because those come from the law. The problem is that people generally want functional and often performance cookies, and then you end up with the stupid cookie banner regardless of marketing cookies.
- kqp 4mo agoStrictly necessary cookies don’t require explicit consent, and generally can’t be rejected. Functional cookies don’t require additional explicit consent if you actually use that function. “Performance” actually refers to analytics, probably rebranded because users did not want it. Making you think they had to ask for the reasonable cookies, too, is the whole trick being pulled here.
- AnthonyMouse 4mo ago> Functional cookies don’t require additional explicit consent if you actually use that function. To not be indistinguishable from "strictly necessary" there would have to be a case where the "functional cookie" actually required consent, right? What case is that and how would you solicit that consent other than some kind of cookie banner? > “Performance” actually refers to analytics, probably rebranded because users did not want it. It refers to statistics, but sometimes you do want that, e.g. so the site can tell you how long it took you to do something compared to the average user, or provide those analytics to you. And the fact that this is ambiguous is an obvious problem -- if you get access to the data they collect is that "analytics" or "functional"? In the face of an ambiguity, most corporate bureaucrats are going to take the risk-averse option, which is to ask for consent in case it turns out to be adjudicated as required ex post facto. The result is quite predictable. If you pass a poorly drafted law, businesses have a general preference for doing something stupid/wasteful/annoying over something that could get them sued or fined.
- SoftTalker 4mo agoTech companies could have headed off this legislation 15 years ago by just solving the problem as Bender suggested. But they wanted to pretend they had no social responsibility to not deliver filth to children, and so now the legislators are involved and they get to deal with that. I have no sympathy.
- deleted 4mo ago[deleted]
- ClikeX 4mo agoHere's one thing Apple did well on. Their screentime settings also work in the browser. It could be better, but at least it's something if you set up your kids device properly.
- compass_copium 4mo agoI had a teen whose main device was an iPad 4ish years ago and now a tween whose main device is a Windows laptop. I like Windows' implementation better--it's more granular when it comes to site access on Edge, and allows time limits in specific programs rather than categories of apps. I remember some apps that were clearly games had themselves listed as education apps.
- ClikeX 4mo agoYou can do specific apps on Apple too, though. You can select the entire category, or expand it and select individual apps.
- redsocksfan45 4mo ago[dead]
- LtWorf 4mo agoMost of those banners are in violation of GDPR. The law isn't necessarily the problem, although it could have been done better.
- LtWorf 4mo agoAs always, downvoting me doesn't change the legality of those banners. The law clearly states the "deny all" button must be as prominent as the accept button, and the banners employ all sort of dark patterns.
- d1sxeyes 4mo agoI don't think 'the law' does clearly state that, although I'd be happy to be proved wrong, and honestly it's a point of pedantry, the enforcement indicates that you're right about the actual expectation, and definitely you're right about the actual usage.
- deleted 4mo ago[deleted]
- 1718627440 4mo ago> 8. When authorities were asked whether they would consider that a banner which does not provide for accept and refuse/reject/not consent options on any layer with a consent button is an infringement of the ePrivacy Directive, a vast majority of authorities considered that the absence of refuse/reject/not consent options on any layer with a consent button of the cookie consent banner is not in line with the requirements for a valid consent and thus constitutes an infringement. Few authorities considered that they cannot retain an infringement in this case as article 5(3) of the ePrivacy Directive does not explicitly mentioned a “reject option” to the deposit of cookies. https://www.edpb.europa.eu/system/files/2023-01/edpb_20230118_report_cookie_banner_taskforce_en.pdf https://www.edpb.europa.eu/system/files/2023-01/edpb_2023011... Also the law doesn't require anything to be done by the user to reject cookies, to begin with, as that is the default state. I often just delete the cookie dialog from the DOM.
- ClikeX 4mo agoLike how browsers made a do-not-track feature that got ignored by websites because there was no consequence?
- olalonde 4mo agoBrowsers can literally chose not to store cookies... There is no need to bring trust in the equation.
- freehorse 4mo agoCan browsers know which cookies are necessary for a site functioning, logins, etc and which are for tracking, ads etc? There are many ways one can eg block third party cookies and that helps and rarely causes issues, but tracking can also be done with first party cookies, let alone fingerprinting. For example, firefox's "strict tracking protection" setting also breaks a bunch of websites.
- 1718627440 4mo agoThere are some browsers, that implement it like it was originally intended and asks the user for each cookie individually: Do you want to store "PHPSESSIONID=12345"? -> Yes. Do you want "AdTRackingID..." -> No. Do you want "AWStelemtry..." -> No, and reject all further. Midori is an example for a graphical one, while there is Lynx for the terminal.
- miki123211 4mo agoMost laws make a distinction between cookies stored for "technical purposes" and those stored for marketing / tracking. The former are things like "does the user want dark mode", the language you chose to use the website in, the contents of your cart, your login info etc. The latter are for tracking. Typically, the former don't need consent, the latter do. Browsers have no way of telling the two apart.
- axelthegerman 4mo agoAlso should have been easy to design an OAuth like flow where the government that seems to care so damn much about age verification to attest someone's age in a privacy respecting way - only yes/no if the person is of the desired age. But then again if it was to protect children, better support for voluntary age control would be so much more useful as most minors use devices managed/owned by their parents. But then similar to cookie banners it is just about enabling surveillance
- akdev1l 4mo agoYou can brute force the real age this way. Do binary search and you don’t even need that many calls. 1. Is person older than 50? 2. Older than 25? 3. Older than 18? 4. Older than 9? 5. Younger than 14? 6. Older than 16?
- Joker_vD 4mo agoYeah, that's why the EU-designed API doesn't work that way.
- no_wizard 4mo agoIn the US all the age verification legislation is written by data broker companies that want to mine this data. The government also wants to be able to have access to this information by proxy. It’s not written the way it’s written because they’re oblivious it’s written the way it’s written because it’s plain lobbying writing the bill. For example, there’s little in the way of protections in how the age verification would be protected or prevent the analytics from being sold
- miki123211 4mo agoHow do you know?
- vetrom 4mo agoTake the volume and mass of lobbying by all of data broker companies, data collection companies, and executive agencies. Combine that with the character of practically every law written involving data privacy, use, IP, and associated regulation of activity around these since the 1990s. It becomes painfully clear that the interests of private citizens have not had a seat at the table, and the Constitution has been taken as an inconvenience to bypass, not a guiding document.
- mentalgear 4mo agoThere actually is/was a "Do not Track" header in browsers, but due to failing or toothless legislation, websites and ad-tech companies never honored it. It's our duty as informed persons to educate the general population to exert pressure on policy makers to act in the common good - otherwise indeed nothing will change but increasing corruption.