Brutal. I have gone 100% autopilot to “cookie consent buttons”. I’m curious how many people are. That’s a very clever place to click jack.
Brutal. I have gone 100% autopilot to “cookie consent buttons”. I’m curious how many people are. That’s a very clever place to click jack.
What should really bother you is that rather than putting up these stupid cookiewalls the intended effect of the legislation was to get websites to stop tracking everything and everybody and this was the result.
Self regulation didn't work, then there was a soft push, which resulted in a lot of wriggling to get around the laws intent and now we will see the hard push.
I wonder how many parties will have the guts to try to wiggle out of the hard push, and I'm quietly hoping for one of the larger offenders to be hit so hard they have to shut down, which might send a useful message to the rest.
Analytics is fine but this wholesale profile building is really across the line.
Edit: More info: http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm
Maybe regulation would work better if there weren't such a disconnect between what lawmakers think people want and the way the technology works.
That's a pretty strong claim. Citation needed.
I always thought it was a combination of slow legislative process, legislators not understanding tech, and industry pushback. I somehow doubt underfunded government IT departments had that much pull.
Hell, let's repurpose Do Not Track for it; it's not like it's being used for anything meaningful otherwise.
I think it's more likely that most tracking companies ignore do not track.
And well, DNT could have had legal bearing, since most legislations in the world require you to stop tracking when the user tells you not to.
So, if the user goes and sets up this general purpose opt-out, you'd have to have some sort of argument why you're different than what the user had in mind when they turned DNT on.
Could have had that legal bearing. Microsoft as well as Google and Facebook killed it off pretty well.
Microsoft by turning it on by default in Internet Explorer. Meaning that there were now lots of instances where the user had not explicitely gone into the settings to turn it on (nor did they perform some other action that serves as reasonable sign that this is what they'd want, like going into InPrivate Browsing, or specifically installing a privacy-focused browser / operating system.)
Google and Facebook killed it off by saying right away that they would not respect it. With how many webpages bundle a Facebook Like button or Google: Analytics, ads, GStatic, ajax.googleapis.com, JQuery, fonts, ReCaptcha, Maps, YouTube etc.
As such, there were very few webpages left that could have chosen to respect it and no judge would have just ruled that everyone has to respect it. It would have killed the internet for a few months.
Anyway, now with GDPR consent buttons on their way (at least in Europe), there's a fresh new opportunity for black hats to click jack their whole population of visitors all over again.
(Firefox for Android supports extensions, I don't know if there are any Webkit-based browsers that do.)
I wonder how that applies legally if they happen to collect data on you and you haven’t given consent.
It is an instance of a much broader issue, where contracts are no longer the result of any negotiation, but are a take it or leave it option.