Cookie Consent Speed Running Game
cookieconsentspeed.run
cookieconsentspeed.run
"You opted out of our cookies, but we're going to say we need them anyway, but you can still opt out of that".
It's somewhere between underhand and downright disturbing ("our interests override your lack of consent"? Eww)
Hint: columns are sortable.
I'm not opposed to GDPR. I just think it's ridiculous how they boasted about fines up to 20 million or 4% of annual worldwide revenue, and then we get an interpretation of "up to" that we otherwise only know from ISPs. I mean, a "fine" of 0 Euro, and 100 Euro for a bank? That is not how you make organisations respect user privacy.
At this rate we're going to have three different any% categories of this speedrun before we can hope for an announcement of a plan to tighten restrictions in an unspecified amount.
Just because your country doesn't take advantage of the new tool doesn't mean it isn't useful.
Here's marriot being fined over €20m because they decided to save money by not having a secure computer system.
https://tietosuoja.fi/en/what-rights-do-data-subjects-have-i...
Objection itself may or may not stop the processing of data. Usually it should, but there are some situations where it would still be allowed (e.g. "a task in the public interest that requires scientific or historical research or the compilation of statistics")
https://tietosuoja.fi/en/controller-s-legitimate-interests
Now I don't know if there has been any decisions or not based on what kind of tracking would actually be legitimate interest (the text on the website is very ambiguous)
No, that would be necessary interest, that's case (b) of the processing grounds [1] of Article 6 GDPR.
Legitimate interest is case (f). Basically, processing that is not strictly necessary, but beneficial to the processor.
Article 7 "Conditions for Consent," paragraph 2:
> If the data subject’s consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters[...]
https://gdpr-info.eu/art-7-gdpr/
Most regulators have taken this to mean that requests for consent must be distinguished even from other noticies required by GDPR. I.e. it must be a separate request from the Privacy Notice itself.
To process data under GDPR, you need a Legal Basis. Consent is one Legal Basis. Legitimate Interest is a different Legal Basis. There are four others.
Consent is opt-in. That's the defining feature of Consent as a Legal basis, since that's what "consent" means. It can also be revoked.
Legitimate Interest is opt-out, as is Public Interest.
If your Legal Basis is one of the other three, then there isn't even an opt-out requirement. Which makes sense, because those cover essential or non-optional processing: Legal requirements (e.g. retaining credit card records), processing necessary to perform a contract the Data Subject has signed, and "Vital Interests" which means "literally life-or-death situation."
Note that cookies are regulated by the ePrivacy Directive in addition to GDPR. The ePD requires consent for cookies and does not have a concept of Legitimate Interest. If a company invokes Legitimate Interests for their cookies, they are Doing It Wrong.
What you describe makes sense, but the way it's implemented everywhere seems like a complete breach of GDPR. If I understand it correctly, "legitimate interest" would be the processing of data necessary to perform the service in question, of which extent must be properly informed?
If I can turn the "legitimate interest" options off, and the service / product remains the same, then... isn't that a clear indication that the grounds for it being "legitimate" don't hold up? For example, I'd consider a service feedback functionality to be "legitimate interest". It's obvious that for it to work, there is a legitimate interest for processing the data transmitted.
A company can also decline opt-out if they have an "Overriding Legitimate Interest." This is true regardless of whether the original legal basis was Legitimate Interest or Consent. However the company must restrict processing only to that particular overriding interest.
"Fraud Detection" is the canonical example of an (Overriding) Legitimate Interest. To my knowledge, that's the only example that's actually given in the text of GDPR itself. Telemetry is generally believed to be another example, and in that case it's probably not Overriding.
Processing necessary to provide a service is kind of weird. If the service is part of a contract, then you use Performance of Contract as your Legal Basis. But if the use of the service doesn't actually form a contract, then you can't use that Legal Basis and have to use either Consent or Legitimate Interest. There are arguments for and against either.
When it's for marketing, telemetry or similar purposes, it's tangential data, which need not be illegal or immoral to be an "illegitimate" interest. It becomes more of a dark pattern when they present a selectable option for "legitimate interests" - at best malicious compliance. They might think it's legitimate because it makes them money?
Similarly in the vein of malicious compliance is offering a cookie consent banner. As far as I know, they only need to do that if they're tracking you or storing TMI/PII. Worse is, it works, too, because now everyone is complaining about the law and not the companies engaging in these dark patterns.
Similarly, you can't just legitimize anything with consent (opt-in) – the consent must be valid, and of course can't override more specific laws. You can't consent to something illegal.
So no, failing to use legitimate interest doesn't mean it's illegitimate or that consent could always be used. It could also mean that the balancing test failed, or that laws prescribe a different legal basis. E.g. the “cookie law”prescribes consent for non-necessary cookies and similar technologies.
„Processing shall be lawful only if and to the extent that at least one of the following:
(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.“
I would argue that this loophole is for conveniency and was not a hot topic anywhere. How it used now however is a different thing.
This use-case was already covered by letter b) of the same Article 6.
„b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;“
Maybe that business should fail.
Seems like many commenters want the businesses to both fail and provide them with expensively produced content for free.
In fact, its quality was better, and they did live mostly on advertisement.
[0] https://ico.org.uk/for-organisations/data-protection-advice-...
No, it's not. If you need it to fulfill a service, then you are covered by (b) of Article 6 GDPR I cited earlier:
processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
Legitimate interest under (f) would be something that is not strictly needed to provide the service but (1) beneficial to the processor and (2) does not unduly negatively affect the data subject.
I think it's like this:
Legitimate interest means you've signed up to use the product. It then is assumed that you understand that by signing up/logging in/buying something that you want to be tracked and known (otherwise, how will they know you are the same person who signed up just now?).
Consent doesn't require you to sign up for anything, just click "OK".
But as a result, if you have Legitimate Interest, then companies don't need to ask your permission to track you.
Another example, I bought a car recently that defaults to stealing my personal information and sending it to the manufacturer. I had to call, and provide more information to them, to opt out (and I can only assume they are still stealing information they have deemed critical in some way)
Anyway, I'm reminded of all of this because I think the obfuscated cookie consents are just one facet of how hostile consumer tech has become to users. Aided by complex and ambiguous regulations, companies are able to stay within the letter of the law while making it impossible to just be left alone with your purchase and not be tracked and marketed to.
If there is a regulatory solution, it has to focus on clarity and spirit, not on just more rules. I'm not aware of an example of something like this working elsewhere.
One idea is a heavy tax on advertising. I've argued before that there is a lot in common between environmental pollution and the effects of advertising on the public value of the internet, and I would say this extends to tech generally. Charge a 25-40% tax on ad revenue, and make it less economic for companies to pollute.
10minutes for something like 5 questions?
>and shifted into finding more ways to steal data
if they wanted to steal your data, then they'd ask you about it?
I don't have screenshoot of those newest windows, but I found one of older quetsions
Diagnostic data - send all basic diagnostic data along with info about websites you browse and how you use apps and features plus additional info about device and its health and enhanced error reporting
You could chose
FULL or probably Minimal(?)
What is 'device'? In moder parlance, device is a phone/tablet type of something. I've personally never heard of a computer being refered to as a device. What is 'enhanced error reporting'? What is 'basic'?
My natural instinct would be to have clicked no to everything, but just taking that approach screws you when it is worded like some of the options in the TFA 'Disable all basic diagnostic blah blah'. If you quickly select no for everything, then you just said no to disabling, thereby granting permission to do what you thought you were just disabling. These are the things to be looking out for.
Because if they don't meet a bare minimum of decency and regulatory requirements, they will be fined a substantial % of their revenue.
They ask questions because if they didn't they wouldn't have a defense in court.
When collecting usage data, the data is different each time you collect it, and its not a one-time event, it happens over and over.
I'm not condoning copying games, just saying its not a fair comparison to gathering your usage data.
And with respect to the gp comment, this is actually different than copyright infringement, where the infringer is not depriving the copyright holder of anything, except potentially a business model based on withholding information. There is obviously a lively debate about the appropriate reach of copyright law, but imo at least, copyrights are more abstract that the privacy rights that are being infringed through surreptitious data collection
It's not always black and white as the OP demonstrates. Store owners memorize their customer's preferences or habits in hoping of their return; waiters do so to please their customers for tips. The customers weren't consented but that still isn't stealing. Scaling it up, small mom and pop stores compete with big box chain by providing better customer services. They can't do that without knowing their customers. That isn't stealing either.
So where is the line? I'd argue collecting customer's information en mass for the purpose of reselling being the line and that isn't perfect either.
Why would the uniqueness matter?
Again, a dollar bill is a widely-available for sale finished product.
There's your mistake. Partitioning works just fine from the installer, or if the installer provides any live environment on the second virtual console, with gdisk or parted.
Also, even if you toggle "everything off" there is stolen data going through which you don't even have an option to disable.
Maybe some websites just add a ad-blocker penalty whether you opt in or out.
"We can't be bothered to not load trackers without consent so we're going to make calls to all their endpoints and trust they'll respect that and not use the calls themselves to track you"
with a mix of:
"Hey, if we put a sleep(1) every 5 entries it's going to be slow and annoying and less people opt out"
The people doing it just know you won't like the explanation so they're not going to.
While I have seen less of the "30 seconds to save" issue recently (I dunno if it was a ublock origin update or the ad companies actually fix their scripts). The issue causing it was ublock origin. Looking at the network activity when it was happening (it pissed me off too), the script was sending a request to each of the partners with your prefence and the script had to wait for the timeout on the request (as ublock was blocking the request) before moving onto the next batch. this scaled over all the partners listed in their ad/tracking partners added up for a piss take of a long time.
But as I said for me personally when I see that particular opt in/out modal these days it saves almost instantly, so someone somewhere fixed it :-)
EDIT: thinking about it, it might of even been the addition of FireFox's built in tracker protection that "fixed" the issue for me. I can't recall extactly when I stopped seeing the TRUSTe modal take forever to save my prefs.
> Compared to accepting cookies, opting out causes an additional 279 HTTP(S) requests to 25 domains, which amounts to an additional 1.2 MB / 5.8 MB of data transfer (compressed / uncompressed).
[1] https://informationsecurity.uibk.ac.at/pdfs/HWB2020_Consent_...
I'm still not seeing the advantage. This isn't me arguing with you and telling you that you're wrong - I just genuinely don't see the difference and would like to understand better. This hypothetical service will still have the same amount of information on you either way (just stored service-side rather than in cookies), right? Unless you're claiming that the service wouldn't associate your various sessions with one another, which seems both incorrect (they certainly would, if they possibly can - as you say, via IP address, etc.) and undesirable (almost all moderately-sized-or-larger web services would feature some kind of persistent settings, at least).
Firefox does the "synchronize the authentication data across devices" thing too.
I would probably use such thing too, and not only for privacy reasons. Bonus if it deleted stored data, cache, and everything else related to the site.
Along with this we have a browser API we can call Authentication with something like Authenticate.prompt() and Authenticate.clear(). prompt() would bring up the standard browser UI for logging in and the parameters to it would dictate how the authentication should happen: username and password, 2FA options, private/public key, client certificate, etc. Registration could be handled in the same UI or have a separate API. clear() lets you have an internal logout button or mechanism on the site. The same APIs should be available via HTTP headers for non-JS usage.
As a bonus, we can then develop a mechanism for creating a session ID based on me having a private key that has an associated identity with with. So when I am prompted with a login UI instead of entering usernames and passwords I can simply choose from a drop down which identity I want to use for this site. Of course the problem of syncing private keys across devices is hard, but not any harder than what password managers currently do with my passwords.
I suspect the reason Chrome doesn't do that already is that user tracking is essentially Googles business.
The downside is that I always see the cookie banners, which I mostly try to ignore but some of them block most of the page.
All courts have to do is request server logs and look for this header. If it's present and the company is found to be violating people's privacy, they are obviously guilty and should be condemned and fined.
The biggest takeaway from this is the dark patterns sites aggressively use to trick you into accepting all their cookies, by making use of creative language that might take a while to parse for the impatient reader or setting buttons to common colours that might confuse someone into clicking.
I really wish there was just a setting in the browser that just says
- Accept 'functional/mandatory' cookies (with exclusion support for sites that abuse this...)
- Reject advertising cookies
- Reject personalisation cookies
- Reject analytics cookies
- Reject tracking cookies
etc. and this config is available for these GDPR banners to query and apply the appropriate settings.
people want their fix and they want it now and many are just apathetic to the idea of privacy on the net to the point we need a better solution.
Sure, I could tail someone for two weeks, flash their email and SMS data, and flip through publicly available images of them. Or I can get a bunch of digital data points like GPS, wireless APs, and the actual emails and SMS data. Computers and databases make it trivial to sift through this data.
The average person likely doesn't understand how deep digital profiles can go. They think that because they use incognito to look up birthday gifts and porn, everything that's private stays private. What about when screen sharing a work presentation and there's a banner ad for cancer or addiction treatment? What about months of funeral care ads after searching for what to do after a parent or child dies?
People think that advertisers are wasting money since they see ads for the same purchase made a week prior. They'd be devastated if health insurance providers partnered with Visa or a tracking network to extract a "health risk" profile.
In modern times, we hang a lot of hats on explicit contracts. If contracts don't work well, we're stuck for ideas.
The reductio ad absurdum is that contracts are supposed to be a flexible solution. Meanwhile, almost every implementation is a rote ruleset.
See "EasyList Cookie". https://easylist.to/
Or if you prefer to block social media junk too (as I do), Fanboy's Annoyance list includes both cookies and social blocking.
What would be there harder end level, the google or the facebook out out screens?
But the effort is to fight tracking and protect privacy at all cost. Even if this destroys foundations of the internet.
Moreover it gives the false belief that clicking NO will protect you from tracking, that companies protect your data.
But it is not a true belief. People should be aware that every password and everything transmitted through the internet can be tracked and may become public one day. And act accordingly.
It is just like data protection. You can have firewalls, antivirus and so on. But what you always really want to have is a backup.
The same goes for privacy and tracking. You can use some measures to protect, but you should act as you are tracked and everything can become public one day.
But such laws ensure people they don't need to act in such a way, what makes them less safe in the end run, rendering these laws to making people surprisingly less safe contrary to the intention of law makers.
"Clear cookies on departure" feels like it goes too far -- I do want the ability of the site to remember my login, etc., as a default thing, and once you open that door, they can link any browser identification to whatever they want on the backend; cookies just give an easy way for them to not talk to their own backend, but introduce no new security or privacy issues as far as I'm concerned.
I'd love to know similar sites for other EU countries.
One thing that I particularly dislike (and seems to be a uniquely US take on the EU GDPR rules) is "you must consent to access our site" banner. Not give _or refuse_ consent, but actively agree to the marketing crap or be redirected to a "bugger off commie" wall. An example would be healthline.com
I think this explicitly violates article 7, paragraph four of the regulations that states:
> When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
But then -- I am not a lawyer. But if any HN readers are lawyers, I'd love to hear your take on it...
I guess that makes too much sense.
I recommend enabling the EasyList Cookie blocking list in the adblocker of choice (i.e. uBlock Origin). Its not enabled by default, so check your settings (Edit: This will block the consent popups, not the cookies).
I personally would prefer to accept all cookies, and take responsibility for keeping separate cookie jars as needed.
I'd rather something that auto-rejected, so I don't use it, but it exists.
This bit is actually the opposite. All tracking _must_ be opt-in, therefore by blocking the pop-up and not opting-in the website cannot track you.
It's only for the websites which are broken when not opting-in that it accepts the policy (which AIUI is itself a violation of the GDPR).
The lack of the header should indicate that the user denied consent to be tracked.
How should a Transparency & Consent String be stored?
In version 1 of the TCF Specifications the consent string was specified to be stored as either a 1st party cookie for service-specific consent or a 3rd party cookie for global consent. In version 2 of the TCF Specifications, the storage mechanism used for service-specific TC Strings is up to a CMP, including any non-cookie storage mechanism. However, global TC Strings must still be stored as cookies under the consensu.org domain.[0]
Pretty much no website uses it.
[0] https://github.com/InteractiveAdvertisingBureau/GDPR-Transpa...
EDIT: gumroad sets the cookie, not bigdatagirl. Does that make it better?
I may be completely off, but would love to get this resolved.
The Cookie Law is circa 10 years ago, I think, and is widely considered to be poorly implemented. The GDPR is newer (implemented in 2018) and is widely considered to be a good idea. AFAIK, the GDPR didn't subsume the Cookie Law, but I may be wrong about that.
You are correct. GDPR repealed and replaced the Data Protection Directive (DPD) from 1995. The "cookie law" (ePrivacy Directive, ePD) was an extension of the DPD, and made heavy reference to it. As part of replacing the DPD, GDPR includes a provision that any law referring to the DPD now refers to GDPR instead, which affects the ePD.
So ePD is still in effect, and by reference uses GDPR's new stricter definition of consent. This is a problem. The ePD was dumb but mostly ignorable. The "upgrade" has made its dumb-ness actually impactful.
Such a shame do not track got ignored so hard.