9 ms·
The stupid cookie law is dead at last
- morphics 14y agoThank goodness for that. Countless hours have been lost debating how best to implement this pointless law, and the amount of business lost due to unsightly and confusing consent banners must have been huge.
- petercooper 14y agoI think it might have been Derek Sivers who wrote a great essay about how in business the best policy is often just to ignore silly rules and regulations (except the really serious ones) until someone pulls you up on it. I took that to heart, and that was ultimately the best policy with this. The ICO had dropped enough hints that they'd be lenient and go after the big boys and most evil violators first that 99% of sites were wasting their time panicking about implementing this stuff.. yet panic they did.
- walshemj 14y agoyes given that my employer a FTSE 100 publisher must have spent a huge amount time and money on this stupid law - can we claim this back against our tax bill.
- kintamanimatt 14y agoWell, yes. Generally and imprecisely speaking, expenses are deducted from revenues and the net is what's taxable. Your employer will end up paying a little less corporation tax because of it. Whether it's a net loss for the government is another matter, as what isn't paid in corporation tax might be paid in national insurance and individual income taxes. Could your employer sue the government for their compliance costs? Almost certainly not.
- Dylan16807 14y agoYes very cute but that only gets a $TAXRATE percentage refund on the wasted money. The rest is gone.
- robotmay 14y agoWell at least they realised they were being a bit thick; they could have just kept on blindly enforcing it. I think it really hit home when they lost a serious percentage of their analytics data.
- panacea 14y agoA "serious amount of their analytics data" was already lost to US.com
- UnoriginalGuy 14y agoBrowsers already have the ability to ask the user if they want to accept a cookie. So all this law did was reproduced browser functionality that has existed all the way back to Netscape. That all being said however, I'm not entirely sure it is "dead." The current legal standing from my understanding is a grey area...
- kintamanimatt 14y agoNo, the law also prohibited use (without permission) of such things as flash cookies and cookie-like things stored in HTML5's web storage, HTTP ETags, IE userData storage, Silverlight isolated storage, etc. The browser has no control over these things, only standard HTTP cookies for which it is responsible.
- lucian1900 14y agoThe browser has full control over HTML5 storage.
- samastur 14y agoYes, but browser's user generally doesn't (in easily accessible way).
- onemorepassword 14y agoNo it doesn't. It's impossible for ordinary users to distinguish between privacy invading tracking cookies and regular functional site cookies. Also, this doesn't form "informed consent". Users have no idea what the data is used for, and this is the key to this law. It's not about "cookies", that is just FUD. It's about being able to opt-in to very specific forms of gathering personal data. Browser functionality is neither opt-in nor informed.
- lucian1900 14y agoAt least on Chrome, they are displayed precisely in the same manner as cookies.
- polshaw 14y agoThe cookie law is in no way dead, the ICO is just doing what every other 'compliant' site has always done. New policy for the ICO site: > Cookies set on arrival to the site. New cookies banner displayed. Banner explains that the website uses cookies and that cookies have been set, tells users they can change their cookie settings (via a new cookies page), or continue to use the site. I always thought the "set first and offer the user to kindly f' off if they don't like it" method was not in the spirit of the law, but that is the one that sites have adopted. There was never any realistic possibility of prosecution in that scenario, so i see this move as just the ICO accepting reality.
- radiac 14y agoRather than what Silktide are saying, this change just seems to be bringing their own website into line with their last-minute clarification (or rather u-turn) on implicit consent. The ICO spent a year banging on about how you need explicit consent, and lots of people ran around implementing various solutions that make people click buttons and are generally incredibly annoying. Then, about 12 hours before the law came into effect, the ICO said "Actually, you know what? Implicit consent is fine." On the off-chance anyone is still interested in this sort of thing, I wrote a small implicit consent script after the ICO clarified their position: http://radiac.net/projects/cookieuse/ http://radiac.net/projects/cookieuse/
- grabeh 14y agoI was wondering when another sensationalist blog post would pop-up from Silktide. Last May, the ICO acknowledged that in certain cases, implied consent would be appropriate and this is judged on the basis of the type of cookies that a site is looking to set plus the information that is made available to a user on its site regarding cookies. The ICO considers that due to having had explicit consent on their site for a number of months, and due to the information generally available on their site, it was ok to switch to an implied consent approach. The cookies that are set when you go on the ICO websites do not include any third party advertising cookies. For other sites, it is not guaranteed that an implied consent will be appropriate where for example third-party advertising cookies are set and very little information is provided generally (for example in a specific cookie policy). As such, it is still for each website to consider whether in their own specific circumstances, it is appropriate to have an explicit consent or whether implied consent is ok. I appreciate that this creates ambiguity but as I understand it, it reflects the present position. I still think the overall aim of the policy in terms of educating users as to the nature of cookies is a good one. That aim is one that is of course not particularly aimed at anyone who browses this website I wouldn't have thought.
- alanctgardner2 14y ago> the type of cookies The ones with text inside them, or the other ones with text inside them? I don't understand how you decide between good and evil cookies. > The ICO considers that due to having had explicit consent on their site for a number of months, and due to the information generally available on their site, it was ok to switch to an implied consent approach Why is there a temporal component ( a couple of months ), surely new visitors come all the time? Why is the content relevant? According to their stats, 10% of the users explicitly consented. Switching to implied consent on that basis makes no sense. > it is not guaranteed that an implied consent will be appropriate I'm pretty sure it's not OK to say 'You might be breaking the law, but we'll let you know once we decide to prosecute'. 'Very little information' is a terrible metric; there's an implication that quality is also necessary. If I populate my user-tracking page with mathematical proofs, I've encoded information on that page - potentially a lot. It doesn't mean anything. > I appreciate that this creates ambiguity I appreciate that you didn't create this law (I hope). Ambiguity is bad. And expensive. All this backtracking they've been doing, it wastes my time, it wastes some civil servant's time, and it accomplishes nothing. It seems like these policies should be like trademarks; subject to dilution if they aren't suitably enforced. If Disney decided to give everyone two years to use their logo free and clear, or they only prevented 'content-free' uses, they would lose that mark.
- gvido 14y agoA similar law is still going strong in The Netherlands. As of this year, most Dutch sites greet you with an annoying pop-up.
- panacea 14y agoAnnoyance, related to privacy. I vote for being "annoyed".
- sjmulder 14y agoShame is that at many sites it’s not really opt-in. If you disagree, you get a lecture on why the site is obliged to track you and then you can accept anyway or leave. A cookie wall, if you will. Examples: * http://tweakers.net http://tweakers.net * http://nos.nl http://nos.nl * http://uitzendinggemist.nl http://uitzendinggemist.nl NOS (public news broadcaster) and Uitzending Gemist (public television catch up) are interesting cases because apparently they’re actually required by law to collect user statistics.
- deleted 14y ago[deleted]
- jules 14y agoIn the abstract, I agree. Only somebody who does not understand cookies would say such a thing in this context however (like our Dutch politicians). You, the website visitor, are running a program called a browser. This browser sends and receives data from servers that host the web sites you visit. Some of that data contains a request to store a piece of information on your computer. Your browser stores that piece information, and later when you visit the site again, it sends the same piece of information back to the site. Note that cookies are not some evil technology created by website owners to track you. It is YOU who is running the software that stores the cookie. If you don't want cookies, DON'T STORE THEM. This is easily done in any competent browser. By analogy, if you don't want people to store things in your basement, don't give them the keys to your basement! The current Dutch law is: after you already gave them the access to store cookies on your computer, the law forces that person to ask you again if they are allowed to store cookies. Not only does it not keep any bad people out and thus gives a false sense of security, it's also annoying. The correct action to take is to educate people on the existence of cookies, and how to disable them completely or disable them for specific ranges of sites. This is less annoying for both the users and the site owners, and more importantly it also works for foreign sites that the Dutch law has no power over, like Google analytics & Facebook like buttons that track you all over the internet (which is a much bigger privacy concern than uitzendinggemist.nl or nos.nl). While they're at it they might as well sponsor efforts to make browsers less identifiable through other means than cookies, and support projects like Tor. Of course that's not going to happen, because the current security theater reminds millions of Dutch citizens every day that they are being protected by their politicians through messages in annoying popups.
- LTheobald 14y agoI'm sorry but hasn't this been the case for a good while now? I remember seeing this on the Guardian last year: http://www.guardian.co.uk/technology/2012/may/26/cookies-law-changed-implied-consent http://www.guardian.co.uk/technology/2012/may/26/cookies-law... And isn't that why sites like The Guardian, BBC etc. have been using a banner anyway?
- oliveremberton 14y agoIt's significant because they're the regulator, and now they're changing to do what everyone else is, instead of telling everyone else to do what they've been doing.
- onemorepassword 14y agoThis is just more disinformation and FUD from the anti-privacy marketing clowns at Silktide. Nothing has changed when it comes to the EU rules on tracking cookies. Of course it doesn't help that the UK's authority tasked with enforcing the law is utterly incompetent.
- oliveremberton 14y agoHow exactly am I spreading Fear, Uncertainty or Doubt here? (I wrote that article, and run Silktide). We have no problem with privacy - quite the opposite, I wish it were being taken seriously - but this law is not remotely about that. If you look at the ICO's latest report they say their audit of sites like Facebook and Google was done purely "visually". They are literally evaluating privacy by looking for banners or legal pages, and not at say the technology or intent behind it. This event is newsworthy because their site - which is clearly going to be looked at as an exemplar of best practice - is changing from explicit opt-in to implicit. Essentially we're now back to 2009, when sites were expected to include privacy policies that explain if they use cookies.