I found a loophole to prevent those pesky cookie notices
ma.ttias.be
ma.ttias.be
I’m sure that works great for this guy’s blog, but I’d guess that it would hobble a startup’s ability to understand/optimize their customer funnel to abandon tracking entirely.
> Want to know why I don’t have a cookie notice on this site? It’s because I don’t track you.
Obviously doesn’t work for any website that requires creating an account and logging in.
Thanks everyone for upvoting a nothingburger to the top of front page.
Edit: Okay, I didn’t know cookie notice isn’t required for login cookies (apparently I never used a cookie banner on my sites anyway, cookie law be damned). Anyway, the nothingburger point still stands.
You don't need explicit consent to provide functionality. When an user logs in, their consenting to storing cookies on their computer is implicit.
when a user sends a http request to a remote server with a client that saves cookies on their behalf, it's not consent?
not arguing with you, per se, I just don't understand how sending a request to someone else has somehow become "involuntary" under the law. the server didn't come looking for you, your program asked it to send you the cookie.
When I say "GET /some-information-on-topic" I did not ask you to track me, I asked you for information on "topic".
When I say "POST /login", I want you to log me in.
if you walk into the local deli and there's a sign-up sheet to receive updates about the store, is that coercion?
Doesn't it? Once you're logged in, presumably because you've created the account you've consented to some kind of privacy policy?
The point of the cookies notice is to let you know that the site tracks you even if you're just using it passively.
Many people might not be aware of this; few outside of the types that frequent HN are aware of the scale of it.
That's the point.
Perhaps you people should read the GDPR instead of looking at alarmist reinterpretations?
The goal is to say, as an individual:
- I am not ok anymore that so much sensitive data are collected
- I know data collection had negative impacts on individuals and society
- I can, and we should live without collecting so much data
- Individuals and society should come before companies
And I definitely relate...The ability to track doesn't really add that much value to most ads. The only time it is helpful is if you want to get a specific person across many different platforms. If you have a niche product that is useful, but niches generally have better ways to get their target (ie the forums frequented by their target). When someone advertises a car they don't need to track - they need to get everybody in the world because that is their potential customer base.
Not long ago there was a front-page HN post about Smart TVs. From a lot of the comments I gather that, at least for TV, they now do. Possibly for some forms of radio too.
There are surely other uses. For instance, I might want to know if my ad is being shown again to a return visitor or for the first time to a new visitor.
However, the next issue is using Cloudflare or similar front ends. For example, I use their free tier on most of my websites. These reverse proxying services / DDOS mitigators / TLS terminators tend to set identifying cookies which website operators have little to no control over.
My point is that the web ecosystem contains lots of integration points that could lead to operators being liable in the eyes of the law, even if they're not actively tracking their users themselves - the services they use, do.
My website is also 'bare-bones'. What do we need all that extraneous crap for? People who want to look at it will. People who don't want to look at it won't.
Want more eyes on your site? Make it more interesting.
But, big - huge - businesses exist (often exclusively) on the internet in 2020, and suggesting that nobody should worry about collecting metrics on traffic/usage is really not feasible when your bottom line depends on making sure those numbers are moving in the right direction.
Don't get me wrong: those companies collect too much. There's no need to do some of the deep, cross-site data sharing that most big web sites do. But analytics? Advertisements? Seems like fair game. Even if you run a boutique blog, you're going to want more real-world feedback than "hit me up on Twitter."
The larger complaint here (at least in the first half of the article) seems to be the lack of elegant ways to present this compliance. Nobody seems to do it in a way faithful to the law without ruining your browsing experience. Maybe that's the point.
Seems like moving it into the browser permissions model could be a good way - in a similar way to websites can ask for permission to show notifications or use your camera, and the browser handles prompting the user etc.
At the very least, it'd be more consistent across websites, you could see in your browser settings at any time which sites you have allowed to store cookies, probably set a global allow/reject etc.
I'm sure there are various reasons why this hasn't been done though
... like requiring explicit consent :)
Really interesting human behaviour occurs when the subject isn't being watched. There's numerous headings for this in various fields: "hawthorne effect", "panopticon", "heisenberg effect" etc.
Of course, in principle the "cookie banner" should alert you to this, that's the point. But after a while people just get used to them. At least it's better than them not being there though ... can't say you weren't warned!
I don't see how it's different?
However it won't work for any site that uses client log in.
Businesses don’t have an inherent right to your data. There’s countless bans on much more nefarious practices that “didn’t work” at the time.
install the extension 'i don't care about cookies' if you don't care
https://chrome.google.com/webstore/detail/i-dont-care-about-...
https://addons.mozilla.org/fr/firefox/addon/i-dont-care-abou...
Now if I were to send this article to the business team at my company in order to make a point about privacy I’m sure it would result in one way.
They’d be pissed I wasted their time telling them not to track based on the views of the author who clearly doesn’t understand and hasn’t fully articulated the business implications of not tracking which are numerous.
No track is like security regulations in healthcare. Yes it makes sense but when you think about the implications to the system as a whole there will be negative impact.
1. Loss of jobs (lack of data collection in business)
2. Loss of lives (greater security requirements in healthcare)
Why loss of jobs? Because guys like Jeff Bezos will lay-off staff before impacting his and his shareholders wealth in any significantly negative way.
Tell me why I’m wrong.
With pleasure. Not having one's fundamental human right to privacy¹ undermined trumps the wants and needs of the business team at a certain company.
¹ Art. 12 UDHR, also mentioned in over 150 national constitutions
Yes, not using cookies is a way to avoid it. To be useful for anything but personal satisfaction the function fulfilled needs to be solved as well. Even if it is a niche and highly qualified solution like "a low bandwidth largely plain HTML website with lower yielding non-tracking ads or a donation page can actually yield more money per hosting cost but results in far smaller websites" would still be infinitely better.
Is it? You can buy fanless computers of various kinds, and it may make sense to do so in certain scenarios. One shouldn't put a fan in a computer "because computers have to have fans", but that's the approach a lot of companies take to tracking. Data gets hoarded and never looked at.
The Dutch personal data authority even published a guide for Google Analytics explaining exactly what to do: https://www.autoriteitpersoonsgegevens.nl/sites/default/file... and they ruled that you don't need permission to enable the cookies when you do. You do need to have a privacy policy however.
Stop. Wanting. Money. All. The. Fucking. Time.
In case it’s not obvious, the article is a publicity stunt.
https://law.stackexchange.com/questions/30739/do-the-gdpr-an...
Why annoy your users if your are not compliant anyways?
IANAL.