For users it was as awful then as the experience is now.
The people who made this law seemed to be under the impression that sites would react by removing cookies. This is naive or plain stupid. Instead what we have now is that every single site has a popup saying "Lorem ipsum" (nobody reads this), and you have to click "fuck off" to get to the content.
I would LIKE to say that all this law does is annoy people. I would like that, but no. Instead what it does is train literally billions of people to click "fuck off" (actual text is usually something like "I agree", but what the user means is "fuck off, I'm trying to read the article"), without reading what the box says.
ACTUAL security problems now, or ACTUAL choices, now cannot be warned about. Because if users were not good at reading actual meaningful warnings before, they sure as hell don't read them now.
So not only is this law (1) not helping, people still have cookies. It's also (2) annoying absolutely everyone every day, with up to four "fuck off" buttons users need to click per page load, and (3) actively hurting via huge externalities, as described above.
Oh, and for extra bonus on a weekly basis I run into websites that chose to simply block users from EU IPs, presumably after a ROI calculation. Thanks, EU.
Are you in Europe?
Yes, I remember. Back in the 90s you could always choose another browser that didn't do that, and we didn't yet have the rampant data collection and exploitation that we have seen since. Back in the 90s it was a novel thing when $known_company got a website at all. In the intervening years a huge amount of our life and identity has moved online.
> The people who made this law seemed to be under the impression that sites would react by removing cookies. This is naive or plain stupid. Instead what we have now is that every single site has a popup saying "Lorem ipsum" (nobody reads this), and you have to click "fuck off" to get to the content.
Where there is no way of opting out of the data collection I leave, and I have taught my family to do the same.
It is possible to run a website that doesn't use cookie popups. Amazon UK sets 3 essential cookies (i18n prefs and two session cookies) on first page load. https://basecamp.com/ doesn't set any.
> ACTUAL security problems now, or ACTUAL choices, now cannot be warned about. Because if users were not good at reading actual meaningful warnings before, they sure as hell don't read them now.
Sorry, which websites were warning users of potential security issues before? What choices were users being asked to make? I am not sure we were browsing the same web.
> So not only is this law (1) not helping, people still have cookies. It's also (2) annoying absolutely everyone every day, with up to four "fuck off" buttons users need to click per page load, and (3) actively hurting via huge externalities, as described above.
Remember that this law isn't about cookies. It's not a cookie law, it's a law about data privacy and control. Cookies are just one part of it. The law also deals with the safe and appropriate handling of user data, and when a website does pop up a huge hard to use banner that uses dark patterns to get you to click it then it's not the EU being annoying and forcing users through this annoying process, it's forcing websites to effectively tell users that they want to do extra things with their data. It's like forcing bank robbers to dress up in stripey shirts and use bags labelled "SWAG".
Any website that is doing that is basically being forced to wave a big red flag "I AM DOING DODGY THINGS WITH YOUR DATA" when you visit. You can at that point blindly click the "Accept" button if you want, I choose to leave.
The web industry, and avertisers in particular, have had over 20 years to pull their shit together to avoid this, but they didn't, so now we have this.
> Oh, and for extra bonus on a weekly basis I run into websites that chose to simply block users from EU IPs, presumably after a ROI calculation. Thanks, EU.
I've hit very few of those, and to be honest it's not been a particularly big deal. It's also their choice. Don't want to stick to the EU speed limit? Don't drive on the EU roads.
> Are you in Europe?
For now.
Not just websites, but applications too. If you had to click "fuck off" to 100 cookie popups today, then when your email client pops up "exe files are dangerous", or your browser says "this website is not secure" you won't even read that, but just press "fuck off, make it happen".
> Any website that is doing that is basically being forced to wave a big red flag "I AM DOING DODGY THINGS WITH YOUR DATA" when you visit.
But since that's every website, it's meaningless. Especially since nobody looks at that red flag because of popup fatigue.
I'm not saying there's no problem. I'm saying this doesn't even close to address the problem, and it makes everything much worse.
Instead, we have a banner you have to interact with as the price to visit pretty much any website.
If the roads are bad, we need to fix the roads, not just tell everyone to drive better cars.
You can track people with all sorts of other means other than cookies, you would also need to get people's permission to do this.
The issue is handling of PII, tracking users and the hoops companies are jumping through to try to trick users into agreeing to allow this. In reality forcing users to select through the myriad of cookies that many sites set isn't practical, and doesn't get round the fact that you still would have to "Receive users’ consent before you use any cookies except strictly necessary cookies."
A better technical solution would be to enforce that web applications respect a client header that specifies the level of cookies the client will allow (see https://gdpr.eu/cookies/).
An even better solution to this would be to stop the invasive tracking and profiling of users that has brought us to this point at all.
The user agent is free to do so, reject it, or ask the user (as Konqueror did).
It is not the responsibility of everyone responding to HTTP requests to ask to ask “I ask you if I can ask you to keep this cookie”.
Remembering that HTTP is a format of messages being sent between people, it’s clear to me that this law is unwise. Likely written by Eurocrats who don’t understand HTTP.
Forcing those who reply to HTTP messages to ask if they can send a header asking if they can save a cookie does not change that - the user who clicks the cookie popup may still now understand what they do.
Many do understand things like private mode though, which is nice.
Say I have a dress code at my club. You don't have the right to a "meaningful choice" of wearing flip flops and shorts and still enter my property.
I don't have the right to a meaningful choice of bypassing paywall either.
The law seems to make no distinction. As a user, I view every cookie notice as pointless and annoying -- obviously you use cookies, and obviously I'm okay with it. If the notice were specifically about cross-site tracking, that would be a meaningful notice, and opting out would make sense. Session cookies, though? You're warning me about session cookies?
If I could set a blanket "I accept cookies" in my browser settings and have those notices all go away,. I would in a heartbeat.
And, in fact, I DO have a blanket "I accept cookies" setting in my browser. Sadly, I'm still forced to manually opt-in on each stupid website.
Ideally, we would distinguish between different "types" of cookies (and I believe the law requires you do this), and we would have settings specifically for these in browsers (which we sort of do in a limited fashion), and we would simply make it a setting defaulted to "ask". show notice only if the user has manually changed the setting from "ask" to "accept" for the types of cookies used on a site. Boom, useful and non-annoying cookie notices.
Until we do that, it's a bad system, and a useless law.
What do you mean by this? The law does make a distinction between essential and nonessential cookies (cookies that are necessary for the function of the website/app, i.e. session cookies, and not necessary, i.e. analytics IDs) and requires you to get consent for nonessential cookies, while allowing essential cookies. If a website doesn't set any nonessential cookies then it doesn't need to ask for consent.
Session cookies, e.g. are fine. As best I can tell, "remember me" / "remember my email" checkboxes still do require a banner, though I'm not sure. Preference cookies in general seem to. That strikes me as silly.
Facebook's tracking me on thousands of unrelated websites; Wikipedia is remembering that I X'd out the donation banner last week and don't want to be shown it again[0]. These are entirely different use-cases with entirely different privacy implications. As far as I can tell, both require a banner, and while the banner allegedly has (or links to) details about which is occurring, I've never, ever paid enough attention to those banners to see those details.
Part of this mess may be due to the fact that our client software is dominated by the largest advertiser, but I'd prefer regulations that address that by demanding privacy-respecting settings and setting defaults, not by showing me banners that I've never found useful.
I use uBlock Origin and Firefox' tracking protection. I don't use the consent banners. I think most people automatically click "yes" on those, yet given the option to block tracking cookies en masse, would enable that option.
[0] Okay, seems as if Wikipedia ISN'T storing that info, but I wish they did.
I think that the fact that a lot of websites nag you with endless lists of cookie consent checkboxes, even for functional cookies, is not entirely innocent, and contributes to the idea that cookie notices are terribly annoying and pointless.
Is there a difference between remembering this "for the current session" vs. "for several weeks"? (The idea of a session is awfully vague given how HTTP works, but seems like one we use anyway.)
> I think that the fact that a lot of websites nag you with endless lists of cookie consent checkboxes, even for functional cookies, is not entirely innocent, and contributes to the idea that cookie notices are terribly annoying and pointless.
One thing I can add is that when I searched for info about the law, I got a bunch of results from cookieyes.com, which told me 1. that I need a cookie banner for any cookies at all and 2. we'll provide you with a cookie banner if you pay us.
So there's definitely some incentives to push unnecessary cookie banners going on. :-)
1. it’s not hidden. open dev tools, see what the page does.
2. someone has got to pay. either a subscription or with your data, the salaries need paying once per month.
1. That's still hidden. "read the code" has never been an acceptable answer to how to inform users, and wouldn't even get close to being allowed under the current GDPR or ePrivacy directives.
2. If you want me to pay then you have to tell me how much I have to pay. It's why there are laws on the clear display of prices in restaurants, and that bars in the UK have to have the prices of drinks listed.
If you want me to pay the price to enter your wensite then tell me what that is and let me make he choice.
Over the last 20 years or so companies have been playing fast and loose with people's data, they could have not done that, but the continued, and now this is what they have to deal with. Forgive me if I don't feel sorry for them in the slightest bit
(more text here: https://news.ycombinator.com/item?id=25028296)
Most popular user agents just keep all cookies by default, but it’s by no means given.