9 ms·
The cookie thing, I assume it's EU-only, is an example of the EU policy making process being fundamentally broken in some way. If you create a flawed policy and
by RivieraKid 1mo ago
The cookie thing, I assume it's EU-only, is an example of the EU policy making process being fundamentally broken in some way. If you create a flawed policy and don't fix it many years after it's very visibly obvious that it's a bad policy, something is really wrong.
- sghiassy 1mo agoIt’s an EU law, but it impacts us all in America as well… because you know, every fucking website
- mnewme 1mo agoIt is not an EU law. Nowhere in GDPR are cookie banners mandated. Actually big tech is to blame: https://killthecookiebanner.eu/ https://killthecookiebanner.eu/
- mr_mitm 1mo agoThe cookie disaster is thanks to the ePrivacy Directive, which came before GDPR: - https://www.edps.europa.eu/data-protection/our-work/subjects/eprivacy-directive_en https://www.edps.europa.eu/data-protection/our-work/subjects... - https://en.wikipedia.org/wiki/EPrivacy_Directive https://en.wikipedia.org/wiki/EPrivacy_Directive
- mnewme 1mo agowe could have settled on privacy compliant tracking without cookies, which is possible or use browser preferences and respect those (which would be perfectly legal)
- dijit 1mo agoit's an example of malicious compliance by some, and herd mentality by others. I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.
- inigyou 1mo agoTo whom??? Literally nobody thinks that way. You should convince him to let you do an A/B test.
- Achterlangs 1mo agoI have had the same discussion multiple times at multiple companies. Luckily most of them were fine with dismissing the popup with a timer.
- bonoboTP 1mo agoThat reasoning isn't wrong, though it seems ridiculous when looked at with techie-brain. But if there is a standard expectation of what serious company websites are like, it makes business sense to look like that too. It's like dressing up appropriately to cultural expectations. You can deviate somewhat but you have to strategically spend your weirdness points.
- naravara 1mo agoHow nice of the EU to have determined for the rest of the world that the “cultural expectation” should be that every business do the design equivalent of wearing clown makeup.
- bonoboTP 1mo agoI don't care about this. I explained why for an individual business trying to project seriousness, it makes sense to adopt a banner in the current environment. I didn't say it's nice of the EU or anything of the sort. It's an incentive pressure that exists on an individual company in the current situation. That's all I said.
- Arainach 1mo agoThe EU doesn't require banners. Companies could stop selling and storing your data. They could only use cookies when absolutely essential. They could use lots of kinds of UX. This is the equivalent of businesses who put a big visible "20% the state says we have to give our employees healthcare" fee on their bill to throw a hissy fit and hope customers get angry at the government for protecting them instead of the business for exploiting them.
- skrebbel 1mo agoBullshit. There’s no need to track every visitor. Just stop tracking and you don’t need a cookie banner. The only mistake EU policymakers made was underestimating how willing companies were to deface their websites.
- zigzag312 1mo agoThe policy is both, good, but also flawed. For example, you cannot persist settings, because one policy says that website settings should be ephemeral unless user agrees to persist them.
- dgellow 1mo agoThat’s not true, it’s even explicitly called out by the EU guidelines. Copy pasting an older comment because it’s really coming up all the time… https://news.ycombinator.com/item?id=49060456 https://news.ycombinator.com/item?id=49060456 === That's not true and is a very common misinformation people repeat online. You can save user preferences in cookies without any consent banner, if the cookie isn't used for tracking. See here[0], page 6: > As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’ 0: https://www.edpb.europa.eu/system/files/documents/2024-10/ed https://www.edpb.europa.eu/system/files/documents/2024-10/ed... As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen
- zigzag312 1mo agoThe guidelines you linked state: "These Guidelines do not address the circumstances under which a processing operation may fall within the exemptions from the consent requirement provided for by the ePD". Let's check what "Opinion 04/2012 on Cookie Consent Exemption" [0] says under section 3.6: """ 3.6 UI customization cookies User interface customization cookies are used to store a user’s preference regarding a service across web pages and not linked to other persistent identifiers such as a username. They are only set if the user has explicitly requested the service to remember a certain piece of information, for example, by clicking on a button or ticking a box. ... These customization functionalities are thus explicitly enabled by the user of an information society service (e.g. by clicking on button or ticking a box) although in the absence of additional information the intention of the user could not be interpreted as a preference to remember that choice for longer than a browser session (or no more than a few additional hours). As such only session (or short term) cookies storing such information are exempted under CRITERION B. The addition of additional information in a prominent location (e.g. “uses cookies” written next to the flag) would constitute sufficient information for valid consent to remember the user’s preference for a longer duration, negating the requirement to apply an exemption in this case. """ See that you need to provide provide "information in a prominent location (e.g. “uses cookies” written next to the flag)" to be able to store user preferences in persistent cookies. You don't need consent banner for that (which I didn't say you need), but you need to clearly inform the user. The act of setting a preference together with clear information about persistence counts as a valid consent. [0] https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2012/wp194_en.pdf https://ec.europa.eu/justice/article-29/documentation/opinio...
- ganzsz 1mo agoThe most used banners at least have a quick way of dismissing without opting in. When the cases against too obvious dark patterns started that fixed itself at least.
- gdcbe 1mo agoI have yet to see an actual part of that policy which requires a cookie banner though. Seems more to me that it's a combination of (a) websites allowing all kind of fcked up use cases of cookies on their site (most sites do not even need cookies for real) and (b) not respecting http headers that ask to not be tracked... They much rather have a very confusing popup that kinda forces you to accept all :) How convenient. Just like websites also give zero fcks about accept-language header... sure do geoip lookup, so much easier... not
- devmor 1mo agoI have always seen the cookie banner as a sort of punishment to the public for daring to have demanded better treatment. “Oh you want consent involved in this interaction? Then we’ll annoy you about it constantly instead of respecting the intent of the regulation.”
- dd8601fn 1mo agoI’m certain it’s often just the California “literally everything is known to cause cancer” problem. It’s simplest just to put the bullshit everywhere and the dipshit bureaucrats will leave everyone alone.
- zetanor 1mo agoThe EU said "you have to ask for permission before forcefully sodomizing your users", and webdevs thought "let's ask for permission" rather than "let's not forcefully sodomize our users". Of course, the law could have said "don't forcefully sodomize users", but it seems the west is still under the impression that some people will do the right thing, just because, sometimes. (maybe 20 years ago they would have, just because, sometimes, but they won't now)
- nirava 1mo agoNot web devs per se, I’d be hard pressed to find a serious web dev who wanted to “forcefully sodomize users”. Thats a management thing
- zetanor 1mo ago"No." If every webdev who would say no can be trivially replaced by webdevs who won't say no, then yes, it is webdevs.
- edoceo 1mo agoIt's silly to blame the individual who doesn't have the authority or power at the business making these choices.
- bonoboTP 1mo agoYou can try to put the blame on the grunts, like trying to focus on the engineers in the VW Dieselgate, etc, but that is very weak leverage. You have to intervene at the root cause of the incentive. But of course the higher you go, the more there is a blur between legislators and business owners and they won't be harsh to themselves.
- mingus88 1mo agoMost US sites are giving the cookie bag to US users. It may simply be easier for leadership to say add the widget than it is to say we won’t accept traffic from the EU or risk the consequences It feels similar to how CA environmental regs become the national standard simply because the market is so large it’s not worth splitting on it. So they just slap a cancer warning on everything
- qurren 1mo ago1. It's also a piece of cake to just not display the cookie banner for non-EU IPs 2. If you are a purely US entity with no actual business presence in the EU, you only need to comply with US laws and nothing else. If the EU doesn't like a purely-foreign website, it's on them to set up a national firewall and block it. Case in point 1: It's not on you to comply with China's laws, it's on them to block it if they want to Case in point 2: China's local businesses with no EU presence do not follow GDPR and do not display cookie banners even if accessed from the EU
- dgellow 1mo agoGDPR applies to EU citizens data. It doesn’t matter where your business is located in the world, if you process European personal data you’re on the hook. Of course you can decide to ignore and argue the EU doesn’t have jurisdiction
- qurren 1mo agoExactly, they don't have jurisdiction outside their borders. If you don't have a presence there, they cannot subject you to their laws. 1. When is the last time you saw China enforcing its laws outside their borders? Why would EU be any different? 2. China has laws that are directly contradictory to GDPR laws; you may be required to retain data regardless of consent; if your website is based in China you have to follow local laws first before you follow contradictory foreign laws that have no jurisdiction over you.
- frollogaston 1mo ago
- mnewme 1mo agoActually cookies are not mandated by the EU, but this was the solution the big companies agreed on and now Google and Co try to lobby against better solutions. Check out: https://killthecookiebanner.eu/ https://killthecookiebanner.eu/
- logseman 1mo agoDo Not Track was the right implementation (browser-based, activate only once) and it was sabotaged by ad peddlers. It is bad policy that has been reached after every better alternative was rejected.
- dgellow 1mo agoDo not track has been used by ad companies to track users, it’s one of the datapoints that can be used to identify your fingerprint
- frollogaston 1mo agoThe idea is that it'd be illegal to do so. Same as how with GDPR it's illegal to track users who denied tracking, even though the "don't track me" setting is a cookie and nothing technical stops them from doing fingerprinting.
- Havoc 1mo agoPolicy making assumed good faith actors - specifically that tracking outside of necessary for website to function to be minimal. Because like…not necessary. It’s only broken to the extent that it collided with a messed up world where websites track even when they don’t need to and then send that to 2000 partners for more profit extraction on top of what the website does commercially. Something is deeply fucked up there and it’s not the EU part. They just make a good scapegoat because the banner is what users see
- f6v 1mo ago> Policy making assumed good faith actors Let's not paint the policymakers naïve when they're in fact incompetent.
- mnewme 1mo agoThey are not incompetent in general. Most stuff works pretty well in Europe and better than in most of the world. We just focus on the bad regulations
- vovavili 1mo ago>Most stuff works pretty well in Europe Bold thing to say. t. European
- mnewme 1mo agoNot really Bold, yes GDP per capita is lower in many countries than the US, but top tier in almost every other index: low crime rates, clean cities, high quality of living, childfriendliness, longevity, access to healthcare, liveable cities, culture, etc.
- Havoc 1mo agoLet’s not paint the policymakers incompetent when they’re in fact naive
- 1mo ago
- mmillin 1mo agoI see a lot of people below arguing that this isn’t the fault of the EU policy but the companies. I think that’s being overly charitable to the policy. While you can be rightly upset with the companies behavior, ultimately policy has to work with the incentives it creates. The policy in its current form allows for meeting requirements with annoying cookie banner opt-outs while keeping the lucrative business of tracking. If we don’t want that, the policy should be changed. Don’t expect companies to go against their interests here, even if some will actually be thoughtful and find a way to do so. The “Purpose Of a System Is What It Does” principle applies, and the purpose of the EU policy seems to be cookie banners for most sites.
- naravara 1mo agoI’ve long believed that making companies liable for paying damages if PII is leaked in a data breach would be the best way to stop excessive tracking. If you force them to have to manage user data like they’re handling radioactive waste then the expense and overhead involved is a natural drag on the business logic that drives the bottomless appetite for data collection. They’ll collect it if they actually need it, and they’ll take great pains to secure it.
- mnewme 1mo agoActually having worked in big companies,many of them just track everything, but don’t actually use the data, which is even worse.
- Aurornis 1mo agoThe most valuable data breach content isn’t your advertising tracking data, though. It would be your payment information, which is orthogonal to most of the tracking data. The black market demand for leaked advertising-related tracking data is basically nil, except maybe in cases where it’s related to something else exploitable or usable for blackmail like if someone frequents cryptocurrency exchanges or porn sites. Nobody cares to pay for black market data about you shopping for towels on Amazon or things like that.
- 1mo ago
- 4ndrewl 1mo agoIt's not a cookies banner. It's a request to harvest your data and share it with third parties for purposes that are not required for the service you're offering. No harvest data to 936 partners? No need for a banner!
- 4ndrewl 1mo agoDownvote all you like, if you're just using purely functional cookies, you don't need a banner.
- inigyou 1mo agoPeople all over this thread are just making up wildly speculative guesses about what the law says. Here's what it actually says: https://gdpr-info.eu/art-6-gdpr/ https://gdpr-info.eu/art-6-gdpr/ Note that cookies aren't even mentioned. (You're in the right)
- umeshunni 1mo agoIt's the EU equivalent of the California Prop 65 warning that tells you that every building causes cancer: https://en.wikipedia.org/wiki/1986_California_Proposition_65#Controversy_and_abuse https://en.wikipedia.org/wiki/1986_California_Proposition_65...
- nathell 1mo agoNo it’s not, it’s a testimony to how broken the Internet is. There’s a perfectly valid and simple way to comply with the EU policies, including GDPR, and not impose annoying popups on your users: just don’t set cookies (if you need to have a login, you can ask for permissions at login time) and don’t collect personal data. That a lot of sites elect not to do that is an indication of how they treat the user, not of the brokenness of EU law.
- 6510 1mo agoYou are free to set cookies if you need them for site functionality.
- iwontberude 1mo ago[dead]
- charles_f 1mo agoOnce again, as everytime I see this, the policy only dictates that you ask for consent to track personal information from people. The problem is not the cookie banner, it's that every fucking website extracts your pants size to sell it to Facebook.
- TZubiri 1mo agoWhat is the consequence of not complying with the cookie thing? Assuming you sell out of a jurisdiction outside of the EU
- inigyou 1mo agoNone, it's the same as calling the Kim dynasty a bunch of poopyheads and never travelling to North Korea. You could still travel to the EU though. Only your business would have to comply before doing business there.
- buildsjets 1mo agoWARNING: Reading his post can expose you to photons, which are known to the State of California to cause cancer. For more information go to www.P65Warnings.ca.gov
- LastTrain 1mo agoThe banners force sites to divulge that they are tracking you in a very obvious way. It’s fucking great and site owners can make it go away any time they want by choosing not to tack their users.
- deleted 1mo ago[deleted]
- deleted 1mo ago[deleted]
- frollogaston 1mo agoSafari + Firefox ignoring 3P cookies did more for privacy than GDPR ever will, and with fewer side effects. It didn't go very far, but it was evidently a threat to Google because they refused to do it in Chrome.