Same with cookie acceptance popups - supposedly this is allowing the user to know the website uses a cookie blah blah, but you HAVE to press yes in most cases to go forward - so everyone has now been trained to auto click yes all the time. At this point those popups could say anything and at least 10% of users would still click yes.
I like the other approach. NO popup / warning unless something meaningfully unexpected.
The problem is there are bunch of warriors on the net and elsewhere that do things like claim that users hate cookies and won't accept them, so need to be warned of them by every website (which can still technically set cookies regardless of any popup). If users don't want cookies they can block them at the browser level - that's how you have actual control BTW - a scam site may not put up the cookie notice and may still be able to set the cookie.
Meanwhile - no notice required when your ISP tracks your every move AND is the monopoly provider. The internet folks have priorities totally backwards - so much focus on evil google it is ridiculous. The reason many people give google their entire search / email history is that they trust google more than the Chinese phone folks, the samsungs, the comcasts etc.
Some real actions to improve the net:
We need actual criminal prosecution and responsibility for websites distributing malware, browser exploits or downloadable.
Owner goes down even if it was their ad network, they can then sue the ad network and if they can recover from them great, if not they still pay for picking a crappy ad network. If their webhost was hacked they still pay for picking stupid web host, they can then sue webhost to recover.
We need to ban and criminally prosecute sale of info by places like ISPs and DMV's that are monopoly providers that have strong paid revenue streams already.
> Meanwhile - no notice required when your ISP tracks your every move AND is the monopoly provider.
Yeah, no. Nobody likes their ISP, it's just that it's a lot harder to enact change here.
What I might not want is cookies from OTHER sites like Google being set and/or accessed by non-Google sites. But having worked at web startups, I know firsthand how important google analytics were, so I don’t know.
GDPR allows that, and you don't need consent, only disclosure, and you don't need an ugly cookie-bar.
Tracking was being targeted, cookies were conflated with tracking (they are, but not really at the level that's being talked about), and some ineffectual legislation was passed to target cookies instead of tracking. It's almost as if the whole process was steered to that point to avoid any useful change with regard to online tracking...
The user must opt-in of their own volition, must be able to reject the tracking cookies (or any kind of tracking) and must be able to opt-out later as well.
Btw: Functional cookies (colours, session, login, cart, language) don't need consent, just disclosure (and it doesn't have to be an ugly cookie bar).
Only cookies that are used to track user behavior, and can be tracked back to that particular user are disallowed. So things like Facebook like buttons would require consent (since Facebook will use the info gained to target you with ads in another context) while basic Google Analytics or similar is fine as it only presents aggregated data to the site owner and does not leak data cross-site. Some GA features do require consent though (like demographics tracking) as it requires Google to cross-reference between sites. You can generally turn these off (I think they even are off by default?)
Note that implementation of the law also differs between EU countries. So a few are more strict. It is up to the national privacy agency to set exact rules.
If you think of the wasted power of a billion warning / notifications a day, you realize how little folks will pay attention to these warnings, it's the only way to get on with your life is to tune these warnings out.
SERIOUSLY - can't someone do a study in the EU showing that their constant warnings mean folks have totally tuned them out?
Here's how the GDPR options of an European website looks like: https://imgur.com/a/ckOivi7
That "Analytics Advertising Feature" MUST be unchecked by default. Only users that actually want to be tracked are tracked.
Every "tracking feature" (cookies, fingerprinting, IP tracking, whatever) must be hard opt-in, and the website has to provide an option for the user to opt-out if they change their mind.
If a website only use functional cookies (colours, session, login, cart, language) they don't need consent, just disclosure (and it doesn't have to be an ugly cookie bar).
This is the official EU website.
EVERYONE is being trained to click I accept.
And then they do a nonauthenticated javascript scrip insert into a secure page ON THEIR HOMEPAGE. You gotta love it.
<script type="text/javascript" src="http://ec.europa.eu/wel/surveys/wr_survey01/wr_survey.js"></script>
What would provide users some actual security is if their browser would block this unauthenticated insert of javascript if its in a secure page. In other words, DON'T trust the website to do the right thing, just take control at the browser level.Look again.
There's a very clear "I refuse cookies" button, which I can click and continue to the website. [1]
The point of those things is that I can refuse cookies or tracking without retaliation and without loss of functionality. Remember: functional cookies don't require consent.
They are doing it right.
It is all the non-compliant companies with only the "Accept" button that are training users to click on it. Those cookie bars are not compliant with GDPR at all.
"Here's how the GDPR options of an European website looks like: https://imgur.com/a/ckOivi7 "
False, the EU website has an ugly cookie bar with a button called "I accept" that everyone has been trained to click yes on.
"That "Analytics Advertising Feature" MUST be unchecked by default. Only users that actually want to be tracked are tracked."
False, users can be presented with an accept / reject button on a standard cookie bar, clicking accept can opt them into tracking - please LOOK at the EU website example I provided.
"Every "tracking feature" (cookies, fingerprinting, IP tracking, whatever) must be hard opt-in."
This can be done though an accept button on a website that users have been trained to click yes on. My earlier suggestion that folks do a study on how many users navigate into these policies for every website they visit to make fine grained selections if such options are even available stands as well.
"If a website only use functional cookies (colours, session, login, cart, language) they don't need consent, just disclosure (and it doesn't have to be an ugly cookie bar)."
I gave you an example of an ugly cookie bar on an EU website subject to GPDR - I can find many more.
This is the problem with these folks messing the net up. Everyone should do this / shouldn't do that, but no attention to what is actually happening.
I want to be clear, billion of pages are showing I accept buttons, some without reject buttons if they are disclosure only, some with reject buttons that kick you off the site, and some with reject buttons that opt you out of tracking, and users are being / have been trained by the EU alert notices / disclosure only notices (which generally DO have an I accept button) etc to waste their time clicking I accept everywhere.
This is bad for actual user choice, actual privacy.
Making money is not functionality to me. (Also, note that your website doesn't have to make money: I run my personal blog at a monetary loss, just like many other people.)
> The EU law says I have to disclose lots of stuff and get your consent before tracking you. So every website added a disclosure and consent button, and every user clicked on it.
Right, what they didn't realize that everyone would just make it super annoying in an attempt to lampoon the law instead of actually changing their behavior because they'd just make usage of their website conditional on it. Hence GDPR, where now users can actually click "no" and not be penalized for it.
- make money via advertising
- make money via advertising that tracks the user
- make money via advertising that tracks the user and hands over that data to a third party
- make money via advertising that tracks the user, hands over that data to a third party, and opens a security hole in doing so
I’m increasingly annoyed as I go down that list, but I might be willing to accept some of the behaviour at the top of it.
Most websites made it about cookies, but it does not contain that language.
This is also why if you access a website with a self-signed certificate, the browser will not give you a “yes” button to go through. You have to jump through a few hoops somewhere else (depending on browser) to accept the self-signed certificate, and then you can see the site.
I think this is the right choice!
I think a list of permissions with detailed explanations as to what they mean, and a Yes button, is a better approach.
Although there needs to be an option to disable or even mock certain permissions.
There is also no log what tells how the app uses the permission. It would be nice if there was a log of each use of the granted permission.
Dropbox, for example, was recently in the news for silently granting itself accessibility permission, and Apple had to update the OS to prevent them from doing it. They still beg users to grant them this, even lying (EDIT: misleading users) on their web page about the purpose of the permission [1].
1: https://help.dropbox.com/installs-integrations/desktop/mac-p...
[EDITed instead of replying because HN limits the number of posts I can make for whatever reason.]
1: The first sentence in Apple’s accessibility API docs[2] is: “Accessible apps help users with disabilities access information and information technology.“ I think they are very clear about the purpose of these, and it’s not “to do cool innovative things missing from the regular API”.
2: https://developer.apple.com/library/archive/documentation/Ac...
> I think they are very clear about the purpose of these, and it's not "to do cool innovative things missing from the regular API".
It's certainly a powerful ability, and I can completely understand not wanting to grant it, but realize that the need is legitimate (and non-malicious) in a lot of cases.
The button doesn't say "yes", but at least on FF there's a way to bypass the warning with one or two clicks from the error page itself. I think you might be confusing this with HSTS, where a certificate failure on an HSTS-enabled website will not let users bypass the warning (and for good reason).
The UAC prompt is essentially "sudo" - it grants root to whatever program is running. You really can't really implement a more granular permissions system without significant engineering effort, because you need to ensure that granting one permission doesn't result in privilege escalation. For instance, granting permissions to modify Program Files/Windows directory can be abused to get steal permissions from other applications, by replacing existing executables with malicious ones.
>Android permission prompts are way better.
Not really comparable because "regular" Windows programs aren't sandboxed. So they kinda already all the android "permissions" already (eg. contacts - they can simply read off disk). A better comparison would be root, which essentially has the same ux as Windows UAC.