4 ms·
A lot of UK sites (Reach local news stuff) now explicitly say take cookies or pay, which tbh I always thought was illegal.
by thom 2mo ago
A lot of UK sites (Reach local news stuff) now explicitly say take cookies or pay, which tbh I always thought was illegal.
- roelschroeven 2mo agoIt is illegal, but compliance is not enforced to the degree that it should. Companies get away with a lot of GDPR infractions, unfortunately.
- dredmorbius 2mo agoThe UK is somewhat famously no longer part of the EU (you may have heard of a thing called "Brexit" a few years back). However the UK does have its own GDPR regulation (see: <https://www.gov.uk/data-protection https://www.gov.uk/data-protection>), though my understanding is that it may be less strict in requiring equivalence between "accept" and "reject" actions. (I may be wrong on this.) UK sites accessed from the EU would have to be under EU GDPR compliance.
- xp84 2mo agoIt's wild to me that anyone thinks that would be a reasonable law (whether or not it is law, I have no clue, I don't live in UK or EU). If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway." Note that I used "sign any name" as the metaphor, not "show ID," since it is trivial to not allow any important information exchange if you simply delete the cookies yourself, which is easy to configure a browser to do. The end-user has the choice, if it's so important to them, to configure their browser. Even Chrome can be configured for which sites to allow cookies, which to disallow, and which to clear when the browser closes (the smart choice, since accepting them and throwing them away soon after is the undetectable option that accomplishes your main aim).
- thom 2mo agoAllowing bad actors to act badly against all but the most sophisticated users is exactly where lawmakers should be stepping in. Sorry you find that controversial.
- xp84 2mo agoWe ask more sophistication of drivers to understand the rules of right of way than we would be asking of users to hit Settings -> Privacy and Cookies and read the plain language there. Sorry that you need the government to "help" people in this way, by forcing other people to give them free things.
- kalleboo 2mo agoAre you proposing a licensing scheme to use the internet?
- xp84 2mo agoNo, I'm just saying that it's okay to burden humans with the responsibility to learn a few basic ideas about how to operate their own computers if they want to control their data privacy. Simple, easy tools are already there, such as the Clear Browsing Data menu item in Chrome, Edge, and Safari. For more complicated intents, the browser settings are no more complicated to navigate than the actual customization UI in the CMPs, anyway.
- kalleboo 2mo agoThen I don't understand the driver analogy. Drivers are forced to take lessons and get licensed for the precise reason that we know people can't take the responsibility on their own. Clearing browser data is anything but easy for people who aren't certain what is "browser data". Is this going to delete all my google sheets? Those are in the browser. And it's not a bad question, some apps actually use IndexedDB or whatever to store user data.
- 2mo ago
- kalleboo 2mo agoYou're fooling yourself if you think clearing cookies does anything. Everyone is doing browser fingerprinting instead these days.
- tripzilch 2mo agoThis is a false analogy. The cookie banner stuff is explicitly about sharing data with third parties. If that were the case in your example, it'd be a different thing, right.
- ben_w 2mo ago> If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway." More: "To view the private content on my website, you have to either pay me, or let more businesses connect the dots between this content and the rest of your internet browsing habits, than there were students and teachers combined in your high school." Yes, it is technically possible to fake this content, or to auto-delete it. But https://xkcd.com/2501/ https://xkcd.com/2501/ applies. "It's easy to forget that the average person probably only knows the privacy settings for Safari and one or two Chromium derivatives." (Real world user familiarity with software is much, much worse; this is an old survey now, but look at the chart near the bottom: https://www.nngroup.com/articles/computer-skill-levels/ https://www.nngroup.com/articles/computer-skill-levels/)
- xp84 2mo agoI'm in agreement with you that most computer users haven't bothered to learn anything about how to use their browser or computer. But still, let's say I agree that there's even an important problem to be solved. We can (A) regulate the browser to dumb this down for these ignorant people, and have the problem guaranteed solved, or (B) we can burden every single company that operates a website, and rely on enforcement since otherwise it's all honor-system. The EU and so far multiple US states, have chosen the stupid option B.
- ben_w 2mo agoOption A is insufficient, as cookies are a mere implementation detail about how tracking is done, and the tracking is the concern.
- inigyou 2mo agoThey're in UK, not EU, and it has a different law.
- account42 2mo agoUK GDPR is simmilar to the EU one and German news websites do the same thing in the EU.