8 ms·
It should be noted here that the Evil Bit proposal was an April Fools RFC https://datatracker.ietf.org/doc/html/rfc3514 https://datatracker.ietf.org/doc/html/r
by MiddleMan5 1y ago
It should be noted here that the Evil Bit proposal was an April Fools RFC
https://datatracker.ietf.org/doc/html/rfc3514 https://datatracker.ietf.org/doc/html/rfc3514
- Y_Y 1y agoWhile we're at it, it should be noted that Do Not Track was not, apparently, a joke. It's the same as a noreply email, if you can get away with sticking your fingers in your ears and humming when someone is telling you something you don't want to hear, and you have a computer to hide behind, then it's all good.
- cma 1y agoDo Not Track had a chance to get into law, which if it did would be good that the code and standard were already in place.
- sebstefan 1y agoThere should be a law against displaying a cookie consent box to a user who has their Do Not Track header set.
- MaxBarraclough 1y agoNot all that far-fetched, Global Privacy Control is legally binding in California. https://en.wikipedia.org/wiki/Global_Privacy_Control https://en.wikipedia.org/wiki/Global_Privacy_Control https://news.ycombinator.com/item?id=43377867 https://news.ycombinator.com/item?id=43377867
- vbezhenar 1y agoHow is "Do Not Track" is a joke, but website presenting a button "Do not use cookies" is not? What's the difference?
- anamexis 1y agoFor one, Do Not Track is on the client side and you just hope and pray that the server honors it, whereas cookie consent modals are something built by and placed in the website. I think you can reasonably assume that if a website went through the trouble of making such a modal (for legal compliance reasons), the functionality works (also for legal compliance reasons). And, you as the client can verify whether it works, and can choose not to store them regardless.
- zeroxfe 1y ago> And, you as the client can verify whether it works How do you do that? Cookies are typically opaque (encrypted or hashed) bags of bits.
- anamexis 1y agoJust the presence or absence of the cookie.
- echoangle 1y agoI would assume most websites would still set cookies even if you reject the consent, because the consent is only about not technically necessary cookies. Just because the website sets cookies doesn't tell you whether it respects you selection. Only if it doesn't set any cookies can you be sure, and I would assume that's a small minority of websites.
- GuB-42 1y agoIt is ridiculous, but it is what you get when you have conflicting interests and broken legislation. The rule is that tracking has to be opt-in, so websites do it the way they are more likely to get people to opt in, and it is a cookie banner before you access the content. Do-not-track is opt-out, not opt-in, and in fact, it is not opt-anything since browsers started to set it to "1" by default without asking. There is no law forcing advertisers to honor that. I guess it could work the other way: if you set do-not-track to 0 (meaning "do-track"), which no browser does by default, make cookies auto-accept and do not show the banner. But then the law says that it should require no more actions to refuse consent than to consent (to counter those ridiculous "accept or uncheck 100 boxes" popups), so it would mean they would also have to honor do-not-track=1, which they don't want to. I don't know how legislation could be unbroken. Users don't want ads, don't want tracking, they just want the service they ask for and don't want to pay for it. Service providers want exactly the opposite. Also people need services and services need users. There is no solution that will satisfy everyone.
- odo1242 1y agoThe goal with Do Not Track was legal (get governments to recognize it as the user declining consent for tracking and forbidding additional pop-ups) and not technological. Unfortunately, the legal part of it failed, even in the EU.
- deleted 1y ago[deleted]
- 2OEH8eoCRo0 1y agoI like the 128 bit strength indicator for how "evil" something is.