6 ms·
it's an example of malicious compliance by some, and herd mentality by others. I had a discussion with my CFO about removing the cookie banner from our website
by dijit 2mo ago
it's an example of malicious compliance by some, and herd mentality by others.
I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.
- Achterlangs 2mo agoI have had the same discussion multiple times at multiple companies. Luckily most of them were fine with dismissing the popup with a timer.
- bonoboTP 2mo agoThat reasoning isn't wrong, though it seems ridiculous when looked at with techie-brain. But if there is a standard expectation of what serious company websites are like, it makes business sense to look like that too. It's like dressing up appropriately to cultural expectations. You can deviate somewhat but you have to strategically spend your weirdness points.
- naravara 2mo agoHow nice of the EU to have determined for the rest of the world that the “cultural expectation” should be that every business do the design equivalent of wearing clown makeup.
- bonoboTP 2mo agoI don't care about this. I explained why for an individual business trying to project seriousness, it makes sense to adopt a banner in the current environment. I didn't say it's nice of the EU or anything of the sort. It's an incentive pressure that exists on an individual company in the current situation. That's all I said.
- Arainach 2mo agoThe EU doesn't require banners. Companies could stop selling and storing your data. They could only use cookies when absolutely essential. They could use lots of kinds of UX. This is the equivalent of businesses who put a big visible "20% the state says we have to give our employees healthcare" fee on their bill to throw a hissy fit and hope customers get angry at the government for protecting them instead of the business for exploiting them.
- nonethewiser 2mo agoBanners exist to eliminate EU regulatory risk. You can try to convince people they aren’t required but its not going to remove any banners.
- Insimwytim 2mo agoThis is misinformed. As many have said before: it's basically malicious compliance. They're supposed to be super annoying ... Instead of complying, they choose this obnoxious practice so they could continue ... monitoring every action a visitor does. You don't need a cookie banner to be allowed to create Cookies. You only need them if you're using them for something like tracking. [1] Regulators didn't enforce cookie banners. Cookie banners are a form of malicious compliance. When you complain about them, you are doing the lobbying work of ad companies for free. The correct solution is to just not spy on people, and the problem is that the EU didn't go far enough and just ban the behavior altogether. [2] Cookie pops are malicious compliance to regulations that legitimately protect consumers. You’ve cherry picked one bad side effect to throw out all the ways the EU is way ahead of anyone else in protecting consumers [3] [1] https://news.ycombinator.com/item?id=29529148 https://news.ycombinator.com/item?id=29529148 [2] https://news.ycombinator.com/item?id=38299135 https://news.ycombinator.com/item?id=38299135 [3] https://news.ycombinator.com/item?id=46552795 https://news.ycombinator.com/item?id=46552795
- YetAnotherNick 2mo agoWhy does static site of Europe's parliament need big cookie banner? Or is that the parliament which created this law doesn't know what you know or they are doing "malicious compliance". [1]: https://www.europarl.europa.eu/portal/en https://www.europarl.europa.eu/portal/en
- danillonunes 2mo agoIt's more like a cultural expectation that business do shady things and the "clown makeup" is a compromise that government found between making those shady things illegal (utopia) and don't intervene at all and let the corporations set their rules (dystopia). It's like those warnings in cigarettes packages saying they will kill you. I know cigarettes are bad, but the warnings also make me believe there's at least "some" control in how bad they are. Now if I buy one without the warnings, I will worry those in particular are extra-shady and likely to kill me even faster.
- encom 2mo ago>warnings in cigarettes packages Oh how I miss those warnings. Nowadays the packages are covered in graphic body horror pictures. And there's no branding on them any more, just white text on a black background, so I have to carefully check that the illiterate teenagers at the store gives me the correct ones. Do anyone else hear circus music?
- inigyou 2mo agoI think the point is to make you stop smoking, without actually making it illegal to smoke. Have you considered stopping smoking?
- alexpotato 2mo agoReminds me of the early days of the CANSPAM act. One of the best indicators that something was not spam was the unsubscribe button.
- quruquru 2mo agoMany years ago, I used to make informational websites for small, local businesses and they all wanted the cookie banner "just to be safe", even after explaining they didn't need it.
- Xirdus 2mo agoThis website contains chemicals known to the State of California to cause cookies.
- zippyman55 2mo agoThe Irish Republican Army, even at the height of their conflict, would never have stooped to such a website.
- forgotaccount3 2mo agoBut are you a software developer or a lawyer? Do they 'not need it' because the government provided a way to ensure it's not needed or because your interpretation of the law indicates it's unnecessary? Are you willing to indemnify them for legal costs if your guidance was wrong? Most small business owner's I've spoken to are keenly aware they are only one bad lawsuit away of closing down. Almost no one care's about the cookie banner. Most just mindlessly click to allow cookies and go on with their life. There's almost no cost to having it.
- mrandish 2mo agoThe 'better safe than sorry' calculation of small businesses skews almost 100% toward 'safe' because almost all govt regulations contain no reasonable size scaling cap on penalties. Any penalties on a website that are per-occurance could be almost infinite.
- inigyou 2mo agoGDPR actually has one. It's 3% of global revenue.
- pbhjpbhj 2mo agoYou could have a 'no cookies' badge that links to your cookie policy - 'we use no tracking cookies and so are compliant with EU law ... then list any cookies/local-storage used and explain what they're for.
- tempest_ 2mo agoBest we can do is a full screen model or annoying toast telling users we dont use cookies and click 4 to 7 check boxes to agree.
- Xirdus 2mo agoBut then you can't have tracking cookies.
- bborud 2mo agoThat would make you sound a lot more professional too. And trustworthy. (As long as that's actually what happens). When I see these dialogs listing they have 1289723 gazillion vendors they share data with, I know that whoever is in charge of analytics, privacy or both at the company is incompetent.
- bborud 2mo agoI'd say just remove it. Don't ask people who don't actually understand the cost of having it there because you will get the wrong answers. Sometimes people just have to do the right thing, take some heat and then everyone can move on. If it has severe consequences then that's probably a good reason to leave anyway. Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they couldn't deny that it cost a fraction of what we were paying our supplier and that things took minutes to set up rather than weeks. And that they worked a lot better. Yes, there was shouting in meeting rooms. And yes, people said "you can't do this". Turns out they were wrong. A few years later I mentioned this to Werner Vogels. During a meeting. Where my CEO and CTO were present. And where everyone was feeling very good about us being one of AWS' biggest customers in our region. So when someone says "you can't do that", sometimes you should make them prove it. (At the time AWS was a good idea. Today dependence on a US service provider is a harder sell in Europe. The _first_ question you get today is if we can host it ourselves if we need to or if we can use a local service provider.)
- docjay 2mo agoI have the same mindset and often did the same thing, but then I thought about my doctor sneaking into my house while I’m sleeping and injecting me with the “good medicine” I had refused in their office.
- 2mo ago
- vovavili 2mo ago>it's an example of malicious compliance So how would you do ePrivacy Directive compliance/risk avoidance in a non-obnoxious way?
- dghlsakjg 2mo agoDon’t use a bunch of unnecessary tracking cookies? Completely eliminates the need for a cookie permission bar.
- pie_flavor 2mo agoThe law does not say 'tracking'. It says 'strictly necessary'. If you remember the user's light/dark theme preference in a cookie, that requires notification. (Or rather, what it requires in practice is that you hire a Highly Paid Consultant.)
- dghlsakjg 2mo agoOkay, but it doesn’t require notification for every user that hits your landing page. If you want to remember dark mode with a cookie, then you can just gate that setting behind a “allow functional cookies” toggle. Getting consent for functional cookies doesn’t have to be done with an intrusive cookie bar on landing. You can request consent as it becomes needed. There’s other ways of complying that aren’t dark patterns.
- inigyou 2mo agoCan you please tell me what part of this law requires any sort of notification or toggle whatsoever for remembering your dark mode setting: https://gdpr-info.eu/art-6-gdpr/ https://gdpr-info.eu/art-6-gdpr/
- dghlsakjg 2mo agoYou're replying to me, but I'm not the one asserting it. The GDPR law doesn't require it specifically, but the earlier ePrivacy regulation does and it is considered to be the guide for GDPR on this specific issue. Lex Specialis is the term for one regulation being applied within a different one. In any case here is a plain text interpretation from the EU (https://gdpr.eu/cookies/ https://gdpr.eu/cookies/): "Strictly necessary cookies — These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookies. While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user. Preferences cookies — Also known as “functionality cookies,” these cookies allow a website to remember choices you have made in the past, like what language you prefer, what region you would like weather reports for, or what your user name and password are so you can automatically log in." Farther down: "To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must: Receive users’ consent before you use any cookies except strictly necessary cookies. ..." So a preference cookie is categorized differently than "strictly necessary" by the ePrivacy rules predating, but now part of, GDPR. But elsewhere in this thread someone asserted that a cookie that is placed and the data never sent back to the server is exempt, so if you handle dark mode entirely client side you might be ok? I'm beginning to understand why the lawyers in the EU just say "fuck it, put a banner up"
- Aurornis 2mo ago> and he said "yeah, but it makes the site seem less legitimate. He may be right, sadly. I’ve seen the lack of a cookie banner used to suggest that a site was doing something shady or not complying with the law. Most people don’t have knowledge about the finer details of cookie laws. They’ve been trained to believe that legitimate sites who comply with the laws will implement the cookie banner, and not seeing it feels suspiciously unprofessional.
- inigyou 2mo agoWho suggests that? I've never seen it. I've never seen anyone who would even notice if there wasn't a cookie banner. They'd just think they'd been there before, and already accepted it.
- kermatt 2mo ago> but it makes the site seem less legitimate I have yet to head that cookie prompts are a sign of legitimacy. What business has customers that would think that way?
- TheOtherHobbes 2mo agoNot customers. Owners. Although if you've ever worked retail, you'll know that plenty of customers are idiots. Whatever "Surely no one is that stupid!" assumptions you make will be proven wrong no matter what you do.
- patwolf 2mo agoI built an ecommerce site long ago, and even though the UI was fairly modern for the time, they insisted we use antiquated styling on the billing forms of the checkout page to help exude trust. As a developer it bugged me because I knew it was just styling, but they probably weren't wrong.
- 0xbadcafebee 2mo agoGood point. The page should have 200MB of assets so that it loads slowly, making it look like there's serious engineering going on.
- nonethewiser 2mo agoNo one is tanking UX to stick it to the EU. It would be better for them to simply not piss off their users. They are covering their ass. The obvious conclusion is that when you try to regulate something like this you arent going to get the behavior you want.
- deleted 2mo ago[deleted]
- wat10000 2mo agoThey're not covering their ass, they're making a deliberate tradeoff. It's trivial to make a site that doesn't need a cookie banner: don't set any cookies. Modern web devs have probably forgotten, but this is actually the default behavior. Cookies don't get set unless you do something to make it happen. And cookies that you actually need for functionality don't need a banner either. If you're setting a session cookie for logged in users so they stay logged in when navigating between pages, you don't need one. Why, then, does practically every site in existence now have one? Because they set unnecessary cookies. Because they choose to set unnecessary cookies in order to track you for purposes that are not necessary to the actual functionality of the site. Every single cookie banner you see is a big sign that says, "We value our ability to track you for marketing purposes more than we value your time." Apparently they're willing to say that. I still see it as a win. No tracking and no banners would be ideal, but at least the regulation forces them to be honest and up front about what they're doing. I'd rather have tracking and cookie banners announcing it than tracking with zero indication of tracking.
- aquentinn 2mo agoEvery site needs analytics no, unless you're going to walk in the dark, and they need payment processors. If it was just about ads, they could have limited it to ads, like 'tracking for the purpose of advertising,' though even then is a press release advertising, and every serious company is going to have press releases. They could have instead targeted it, and applied it, to third party ad providers only, like Google. And, btw, Google is big enough they could have just outright named it. They're worth as much as the GDP of Germany. Why not just make a Google law? So yeah, maybe good intentions but it clearly shows the EU parliament is still too young and inexperienced.
- Mistletoe 2mo agoCFO should be fired immediately.
- bigbuppo 2mo agoIn my experience, most people come in two camps: 1) they just click to make it go away because they click everything and would agree to sell their own mother to organ scrappers just to get past the annoyance, and 2) they understand what it's asking and are immediately suspicious.
- Insimwytim 2mo agoYou may float an idea to describe what you've just said in the banner, and have just a "close" button. E.g. "we don't set any tracking cookies, so we're already compliant with the law even without banner, so there's nothing to decline or agree to".
- bot403 2mo agoI would hate that more than an actual cookie banner. You didn't have to popup but you chose to anyway just so I could give you a pat on the back?
- deleted 2mo ago[deleted]
- SilasX 2mo agoIt's not malicious compliance when the very governing authorities for this in the EU do the same thing.
- inigyou 2mo agoTo whom??? Literally nobody thinks that way. You should convince him to let you do an A/B test.