The bait-and-switch hidden in today’s cookie announcement
webdevlaw.uk
webdevlaw.uk
I see so many websites – even club websites or private blogs – that have a cookie consent banner, but which wouldn't actually need one if they'd just turn off Google Analytics. I just don't get it.
Isn't one of the incentives for Analytics, that by knowing your audience Google will be able to suggest your site to their search engine users?
I've heard more than once something in the lines of "we can't disable analytics as we'd lose traffic".
I've been in SEO for a while and there are a lot of myths but I've never heard anything quite this wrong before.
I mean, the burden is on both sides here but one has "been in SEO for a while".
Besides, GA data is easily faked. I can give a site a low bounce rate or make it look like people spend a long time on a page. Google can't trust their own Analytics data because of this since it is client provided.
Sounds like a myth non-SEO people believe because, again, I've never even heard this before. And SEOs believe a lot of myths but this one is just too stupid
People will do an update on their site, which includes removing GA, then blame GA exclusively for tanking their rankings. All of which is probably coincidental to an algorithm change that was going to de-rank them anyways
Urban legend clearly benefiting Google.
Also, my understanding is Google pretends like they don't really look at your traffic data and use that for search.
The cookie-blocking features in modern browsers (except Chrome, probably, haha) effectively make tracking opt-in anyway, don't they? The cookie pop-ups are pretty redundant today.
Not to suggest that this makes all the down sides of Brexit worthwhile, but it does make me happy that this can now be addressed. Cookie popups seriously harm the usability of the web and have been one of the most highly visible and ill-conceived pieces of EU legislation.
If you're using a menstruating-cycle app, GPDR will protect you against the app owner publicizing your name that you're pregnant, and thus protect you against anti-abortion mobs, if you wish to abort. A cookie banner wouldn't do that. Because GPDR is NOT about the cookies.
If we were to speak exclusively about tracking (which is, again, a very very small part of GPDR), even simply dismissing as a browser-side "feature" is yet another brainwashing win from anti-GPDR marketing. The number of ways to track people in a browser is infinite. From canvas rendering, to DRM, from cache leakage to window size. Hell, even the GPDR banners explicitly say so! Most GPDR banners now contains an option to allow site owner to fingerprint your browser to track you.
Considering the way we went with browsers (was it right adding so many features? I don't know. But the effects are there), we CAN NOT put this on browsers, it is technically impossible. If Google wants to prove the world that it is possible, fine, I'll grab popcorn. But at the moment they are not even trying.
So no, history has proven again and again that those privacy issues can not be handled technically. Only through regulation can privacy be preserved.
Absolutely. I'm not arguing against GDPR, which includes many important rights and protections that don't have much to do with cookies. I'm arguing against intrusive and pointless cookie pop-ups.
Browsers are generally only working on stopping cross-site tracking, but cookie banners are needed even for first-party cookies (ex: local telemetry, shopping carts).
And every browser offers a private browsing mode which is more or less the same effect.
See this earlier discussion: https://news.ycombinator.com/item?id=29530890
Mechanically if you add something into a physical shopping cart it will remain there forever until you take it out. But legally the pdf has the claim "a merchant could set the cookie either to persist past the end of the browser session or for a couple of hours" [1] and to me that means indefinitely or a few hours.
[1]: https://ec.europa.eu/justice/article-29/documentation/opinio...
Tories need this because of two reasons:
1. Brexit is hurting the UK economy
2. They need to distract from the Partygate scandals[0]
As for Google Analytics... I've talked with multiple clients who have wanted to improve site performance on their stores. The first thing I usually point out is the multiple overlapping analytics packages downloading multi-megabyte JavaScript files. Those are, of course, absolutely untouchable for whatever reason, and we just have to work around the most obvious performance flaws in their site.
The reasons why someone might tank their site performance with a bunch of conflicting ad trackers is not just because "data is valuable". We're conditioned to think of ad tracking as solely interest targeting[1] and remarketing[2], but a huge part of it is also just attribution. Advertising is paid for on a per-click or per-conversion basis, and nobody trusts nobody in this industry, so everything needs to be tracked or the people buying ads get gamed out of their money by the people they buy ads from.[3] So even if you just want to buy ads, you often also need to have tracking on your website purely so that the ad network can either protect you from click fraud, or if you're paying per conversion, actually track how much you owe them.
[0] For those who are not in the UK, like me: The scandal is the fact that the PM and his staff were running a bunch of illegal parties while the whole country was on COVID lockdowns.
[1] When ad networks track your interests to serve more relevant ads. As the ad buyer you can purchase ads based on these specific interest categories; i.e. "I want this ad to be served to 40-year-old men with an interest in cars"
[2] When ad networks track your history to serve ads based on what sites you've visited recently. This is actually a different thing from interest-related ads; it's more like "I want this ad to be served to anyone who has just gone car shopping".
[3] This is also why on-domain advertising will never be a thing outside of the big social media networks.
Thanks. I think this is severely understated. Ad people managed to force the debate to "customized ads" vs "privacy", saying that websites could make money exclusively with customized ads. We've seen here on HN a lot of examples of people realizing that was bullshit (I would guess there are some cases where customized ads can be beneficial, but overall they seem little).
Apple showed how to make attribution privacy-friendly (I have no idea whether there implementation works and scale), yet debates still manage to ignore that totally.
That being said, solving attribution doesn't actually... solve attribution problem. The reason being for the case where I search Nokia D3500 on Amazon, then I go on random website, which will show me ads for Nokia D3500 on Amazon, and I click on this ad to buy what I already planned to buy. In that case, the random website will get money, with current unprivate ads, while they won't with the private one. I didn't change my consumption based on that ad, so the ad has literally 0 value, "private-friendly ad" properly reflects that, however the migration from not private to private ad will reduce the revenue for websites (even though this didn't have any impact on my purchasing behavior).
Edit: It does solve attribution for "proper meaningful" ads: If I'm reading camera reviews on some websites, and they have affiliated links for those reviews, then they'll rightfully get money for it, whcih is good!
I want to know how many people visited my website. So does every website. It's something that websites need to know. We use Analytics to handle that for us, and because of this silly EU rule we're all technically breaking the law by not bothering every single visitor with annoying popups.
Now there are in fact bad companies collecting data on individual people, correlating it between sites on the backend, and using it for nefarious purposes. Those are presumably the reason these stupid laws were passed in the first place, and it would be nice if they actually did need to show a button for you to click.
But since the law says that everybody needs to show that button or lose the ability to know how many people saw their site, you never know whether you're getting the button for an evil site or just one of the millions of other sites you visit every day.
I don't blame the evil companies even a little bit for this mess. It's the people who passed these terribly thought out laws. They'll keep passing more of them until we stop letting them.
Apart from being a... very interesting take, how do propose to do this?
You can do that easily without third-party tracking cookies.
(Disclosure: I used to work on ads at Google)
You're talking about the https://developers.google.com/analytics/devguides/collection... section, right? That's only for sites that are already using third-party cookies for advertising, has to be specifically enabled, and doesn't seem very applicable to our "know how many people visited my website" discussion? But my comment above was too broad, and I've edited it to point here.
> moving from third-party to first-party
GA, back to the Urchin days, has always been built around first-party cookies though.
I am assuming you need to do client side tracking for static pages though or you need to self host your static page.
But Google Analytics is a 30 second setup, whereas setting up a log analyzer (or even getting logging going in the first place) is a much bigger hassle. Some of my stuff is on wacky Cloud Function hosting that I wouldn't have the first idea of how to go about logging.
Thus, nearly 100% of us just use Analytics. If they had an "evil" checkbox that I could uncheck to stop it doing whatever you're worried it will do, then I'd happily do so.
Frankly, I'm not sure what GA could do that would bother anybody. All it does is tell me how many people saw what page and how long they stayed there. It certainly can't tell me anything about you personally.
I don't have time to screw around with figuring out what uses third-party cookies, what uses browser fingerprinting, what correlates information across sites, and/or what tracks what how in general, nor to check all the time to see if any of that has changed. I'm just gonna block all of it, because it's not worth the investment of my time to make such distinctions. The most I could get out of it would be slower page loads.
Actually, I'm not even bothering to make THAT decision. My ad blocker blocks GA by default, and I'm not going to worry my pretty little head about unblocking anything unless something breaks.
It puts tracking cookies on your visitors which means you need a cookie banner.
And of course it invades the privacy of your users and slows down your site.
If you do it right, a high proportion of your site visits leave no trace in your logs that they were ever there.
Not sure where you got this from. But GDPR absolutely does not require this.
I see so many websites – even club websites or private blogs – that have a cookie consent banner, but which wouldn't actually need one if they'd just turn off Google Analytics. I just don't get it.
He asked why we don't turn off GA. I explained.
Ultimately, some of these alternatives that avoid the cookie law are simply finding tech work arounds. I have no doubt in my mind that the gov would find a way to require popups for those services if they were more prevalent.
That's because it is the most evil one of all.
Just because you're only using it for one piece of info doesn't mean you aren't violating your users' privacy by handing over a complete record of every site they visit to a company that uses it exclusively for evil.
Actually, most are probably not even correctly following the law since the cookies will probably be set before the popup is accepted. For most, people just assume they need a cookie banner. I'm pretty sure I've seen cookie banners on sites that had no cookies.
There have been non-binding votes to split it up. And they can tell them to split up or be banned from operating within the EU.
Each passing day the govnement becomes more and more deceptive
For other sites though, if the this passes into law I suspect it will have a much more intense cooling effect on the availability and access to sites. For the unpaid service sites I run, I'm certainly not going to pay for identity verification or allow that garbage on my sites. I'm much more likely to hide or disable any user generated content, or just serve a static page to users in the UK saying the site isn't available in your region.
They're really doubling down on removing themselves from the world community...
> The UK is also planning to legislate to remove the EU-derived requirement for the Data Protection Officer, as the person responsible for safeguarding an organisation’s users’ privacy rights, while simultaneously demanding under the OSB that companies appoint named individuals who are subject to personal arrests and criminal sanctions for failing to prevent bad things from happening on the internet.
*subject to personal arrests and criminal sanctions* seems like the limited liability companies no longer limit the liability.
I have a legal entity registered in Scotland. Seems like it might be time to wind that up and move it to another country. Where is a good company within the EU to registered?
Just to be clear, some poor sod is going to end up getting a criminal conviction because someone at the company they work for but don't own fucked up. You get a so-so paid job at a mega corp and end up with a criminal record because some guy in an office you've never been to did something. That is nuts.
There are plenty of other positions in companies that come with similar personal criminal liability. They mostly only exist in finance industry, but the roles of CEO, CRO, MLRO etc in most financial institutions come with personal criminal liability.
The liability in these cases is usually tied to competence and knowledge. It’s illegal to be incompetent at your role, and it’s illegal to be ignorant of the activities of your company that fall within your roles responsibilities. The expectation is that individuals in this role will setup policy and monitoring frameworks to make sure that nobody is doing any stupid, that might result in them going to prison.
All of these requirements came into existence after the 2008 financial crisis, after it became apparent that senior leaders in financial institutions we’re keeping themselves deliberately ignorant of the misbehaviour of their companies, and creating a situation where nobody could be held responsible for the mess.
I’m not sure that age verification for website meets the bar needed for applying this approach here. But there are certainly places where it makes sense.
The law is changing so that the liability isn't limited to the company. That has all to do with the companies limited liability.
If you commit an act of murder as a company agent, limited liability isn’t going to protect you. This law is simply saying that failing in your legal responsibilities as a specific company officer is a criminal offence. Just like committing fraud as a company officer, or failing to produce accurate accounts will also expose you to personal criminal liability.
GDPR, Data Protection Act, etc all exist. These are all leveled againist the company.
> If you commit an act of murder as a company agent, limited liability isn’t going to protect you. This law is simply saying that failing in your legal responsibilities as a specific company officer is a criminal offence. Just like committing fraud as a company officer, or failing to produce accurate accounts will also expose you to personal criminal liability.
Comparing data protection with murder is silly. The law is simply stating if you breach data protection laws it's now a criminal matter againist a person instead of againist a company, Massive difference. Especially, if you registered a company to make sure you're not personally liable for data protect breaches.
And that's your mistake right here. A limited liability structure never protected you against wilfully breaking the law, or being criminally negligent, not when it came to murder, and not when it came to data protection. Just ask any engineer who signed off on a design that later turned out to be insufficient according to specification.
Data protection criminal charges used to be levied against random people within the company - and now they are focussed on the data protection officer (who criminally neglectfully abandoned their function if there is a breach).
If you are still confused about this concept, before you do more in the business structure world, it might be a good idea to talk to a lawyer and make them explain the difference to you.
The goal is to hold the company accountable, but it sounds like they just created legalized paid-fall guys.
If the government wants to pierce the limited liability veil, they should either go after the persons in the company either directly or ultimately responsible (eg the direct manager, or the C-suite). Letting the company decide who takes the fall just means they're going to foist it on some uniformed schmuck.
You get paid more for being on-call - now wait until you see the legaly-liable-for-the-entire-company bonus!
Estonia for sure. Their e-residency scheme is fantastic and designed for people all around the world to register virtual companies, even if you don't have any presence in Estonia.
* https://www.w3.org/TR/powder-use-cases/#cpA
* https://www.w3.org/2007/powder/
* https://en.wikipedia.org/wiki/Protocol_for_Web_Description_R...
It could be much easier if the major web browsers (at this point Chrome, Safari (mobile), Firefox) were able to read the metadata and if parents (or corporate IT departments) wanted to filter content they could using 'built-in' technology rather every web site having to potentially re-invent the wheel.
Movies and video games self report their rating not sure why web content needs to be any different.
The problem with the top down approach of the government deciding which topics are taboo is that it removes agency from parents. Different parents, different kids, and different ages all lead to different values and levels of acceptibility.
My tin foil hat catches my eye every time I see government trying a heavy-handed, slippery-slope approach to clamping down on a problem instead of just providing society with a common set of tools to accomplish a relatively simple goal.
But if I'm reading this right, this takes the cake for the worst one yet, or certainly up there.
my number one is the Australian AABill mandating any Australian citizen working for a tech company can be forced to create backdoors in code and altering their employer about it is illegal. This one is so bad, that if it were China, we'd no longer hire any Chinese nationals anywhere in the world.
But what worried me was that it was actually written quite coherently, I felt like it had been well considered by some people of technical background, but the bill still had ill intent. So I'm not sure what's worse, legislature misunderstanding technology so much that it's harmful, or people using a good understanding of technology to be more precise and underhanded in their abuse.
Or does Australian government also supply some handbook about how to do it properly?
What the fish?
> This one is so bad, that if it were China, we'd no longer hire any Chinese nationals anywhere in the world.
Heck if it was China implementing something like GDPR and the rest of the world was seeing those annoying popups, then:
* for 3 months the rest of the world will hate-tolerate it
* then somebody will figure out how to get rid of the popups for the rest of the world
Are you willing to hire armed and trained goons to make them stop their ways and kill, maim and/or kill them? Because they are willing to do the same to get their way.
And that's why we let this pass. The so-called "monopoly of force" was not given by a "social contract", as Hobbes postulated - it was taken by them through superior force.
* For some value of "we" which differs by jurisdiction:
Are you saying that there are literally no policy differences between major political parties in countries like the UK? What about countries that have voting systems that make the legislature more representative of voters' preferences?
The only way I can think to steel-man your position is that you're saying "Some unspecified power would intervene to stop a government relinquishing its monopoly on force even if the population overwhelmingly voted for the government to do so". That's hard to imagine though; not because the unspecified power is so vague, but because no country would ever vote like that to remove the protections that a state provides for them.
In the context of my parent's comment: "Government trying to legislate things that they do not understand", no, there is no distinguishable difference between the Tories, Sinn Fein, the DUP, the LibDems, the SNP or Labour. The Raving Loonies at least have the introspection that they consider themselves incompetent, so ... more power to them, I guess?
The fact that politicians can make rulings over things they don't understand in the slightest is bad, the fact that nobody even cares is tragic.
(To be clear, I dont consider the fact that he had to "sweat a bit over it" in any way justice, or a sign of a fair society, but at least its something)
I feel like this whole post, (notably this section) makes bad faith assumptions, then elaborates on the strawmen/bad assertions.
> ...no matter what they’re trying to put right in the world – to know the ages of all their visitors or users
That's not what it says, explicitly. I interpret it as "it will require most every useful online service to be account-based with hoops at that level, not just some random visitor or on every page".
Most of the sections are making reference to having to know the age of users as a pre-requisite to any web activity, in the UK, and I don't see it. Did I miss something or did she?
This was certainly the case for that nationwide opt-out porn block that they brought in a decade ago, then quickly slipped under the rug when it became clear that they too would have to either learn to use a VPN or call up their service providers expressing their desire to watch porn
> that nationwide opt-out porn block
That's still there; ISPs just made it very easy to switch off the block from apps and websites.
Tories ask for 100, bag 20, then ask for 200 and bag 80 - result: they get 100. And there is no recourse now, because those pesky supranational voices of reason have been jettisoned.
Johnson is the one who keeps pushing these crazy schemes just to keep people riled up against the "bureaucracy-mad EU" he invented so many years ago. He will stop at nothing to stay in power, and will happily sacrifice all your freedoms to that effect - he doesn't respect the law anyway, so anything put on the book is just for you and me to be beaten down, not for him and his mates.
> it's still better than Cameronism
That's a false dichotomy. There is life outside the Tory ideological landscape.
> If an uproar comes, which it hopefully will
If the uproar comes from the "wrong" sector of the electorate, the Tories will just double down on it.
>That's a false dichotomy
right now the options are Boris or a Cameronesque Tory. Sure in 2 years better options will be available, but that's in 2 years time. it is not a false dichotomy. besides, the longer Boris stays in power, the more he damages the Tories as a whole
>If the uproar comes from the "wrong" sector of the electorate, the Tories will just double down on it
this is an exaggeration, especially under the populism of Boris. yes they largely listen to their base, but they don't seek to actively antagonise others. they're a centre-right party that seeks a wide base without a high degree of polarisation. they're not the GOP or UKIP. given your comment, I suspect you may assert that they are more like the GOP or UKIP than I think. if so, I will agree to disagree on that
it seems like you have a lot of emotion and anger about this, and that's fine, but I don't think it's helping your objectivity about actual outcomes and intentions. I also don't like him or his party, but in the short-term he's better than a right-wing ideologue that doesn't care what you think
> 2 years better options will be available, but that's in 2 years time
You assume the Tories can produce a majority after the current "Brexit coalition", held together by Johnson, collapses. That's not a given. It's also not a given that whichever cabinet a new PM could produce, will be strong enough to enact big policies.
> but they don't seek to actively antagonise others.
Policies like Rwanda deportations and the return of imperial measures are absolutely designed to produce outrage, and I challenge you to prove otherwise.
The basic Johnson strategies are directly copied from the US playbook: they deliberately provoke the left in order to consolidate the right by defensive reaction, playing the victim and distracting from failures and scandals. And it works, for a while at least.
Is the entire party like that? No, but the people who are, are currently running the show.
> they're a centre-right party that seeks a wide base
They were. They stopped being that when absolute power went to the likes of Reese-Mogg. They attracted radical Northern votes by acting extremist on issues where the Labour party refuses to do. This is not your dad's Tory party.
Second point, do I assume that? I cannot see how you've read that from what I've said. I'm a dyed in the wool labour voter, and last I checked the Tories were down by about 15% in the polls.
The rest is opinion that I disagree with. I'm not here to change your mind. It's fine to be emotional and shouty and take the worst possible view of everything, but I'm completely unconvinced by it, especially when you challenge me to prove a negative
Hate to break it to you but we have no laws for them in the US and we have the stupid popup on almost every site.
Sold. I am all for returning to standard boring web 1.0. Lets do this thing!
I presume I will have to log into hacker news via a VPN because obviously this place isn't going to implement anything other than geo blocking for UK IPs (like 99% of websites will); it certainly isn't going to be paying 10p+ for every user here to prove they are over 16/18?
Do we know under what terms young people will be allowed to interact with the Internet?
It doesn't have to, it just has to follow up by making VPNs illegal, and then selectively enforcing that law against its political opponents.
Besides, don't plenty of despotic countries already ban VPNs around the world, to limited effect? A large, liberal country like the UK banning them would I'm sure drive improvements to VPN protocols to make them even harder for ISPs to detect.
Maybe I'm too hopeful for the future...
A lot of people said that in 2015. And in 2016. And again in 2019. And here we are.
Ordinary voters want this stuff. They don't know any better, and the UK press does its best to keep them that way.
Why do the commenters here don’t think they want to be able to control and bully opponents on the Internet too?
Nahh, they'll just ignore UK law just like they ignore other countries laws. I mean, do you really expect every website owner to be versed in every single country's laws? There's no way!
Unless they "do business" in a specific country (e.g. selling goods/services) there's not really any downside to just ignoring that country's laws (when it comes to website/data stuff).
I don't plan to ever sell stuff to say, Guyana and never plan to go there. Why should I care what their laws are regarding websites/data collection? It's completely irrelevant.
Besides that, it is hard to argue against any law that is couched as protecting innocent children. Obviously, having to verify with ID the age of every website visitor is impractical right now. The logical solution is for government to mandate and issue Internet IDs that must be used to access any web service. This bait-and-switch leads down a slippery slope that erodes anonymity on the Internet, not that there is much left.
And the targeted demographic that should be protected - children - will find plenty of ways around it. Reddit and Twitter are easily accessed, Youtube has tons of soft porn that won't get filtered out, VPNs are everywhere - even free ones, like in Opera, and they Know about it - Tiktok has tons of soft porn, the list goes on.
Step 2: roll it out for all sites
Step 1 could be seen to have some justification. But any lawmaker with a functioning brain would immediately realize that Step 2 will cause a radical change on the Internet.
They aren’t saying that you get an unlinkable verifiable claim (Web3) that you’re over 18, to access ALL SITES. That would be somewhat reasonable. No, they say you’ll get an ID that is linked to you and all sites will be able to know who you are and cross correlate all data on you, to save the children. I mean… who needs third party cookie blocking at that point haha
Step 2 could conceivably happen a la boiled frog.
https://bills.parliament.uk/bills/3137
so, a long way to go.
the new Data Reform Bill has not even been submitted yet.
If companies weren't actively spying on their users, if the didn't collect every last bit of data they can, there would be no need to put up a banner. If the website needs cookies for core functionality (essential cookies) only, there' no need to inform, ask or badger the user for anything. The websites/data collectors are the bad guy here (from where I'm standing) and now that they have to ask us if they can please spy on us, the EU is evil because they force them to ask?
The main presented point of this bill is "We will eliminate the obligation for the spies to ask you if they may spy on you" and even the author of this piece is celebrating that.
I don't think so. Read the last part of that sentence which I've emphasised in italics.
"So if you work in any sort of tech or digital related role, and the work you put into the world can be viewed, or accessed, by anyone of any age in the UK, and you are (rightfully) celebrating the loss of the cookie popups, I need you to do me a favour and drop the balloons and party streamers and sit down."
If the end-result of the law + standard human behavior is that you made web browsing a crappier experience then you made a crappy law.
That's not a very good way to figure out if a law is "crappy". Building codes make for a crappier construction experience (can't just do whatever TF you want) but that doesn't mean they're bad.
Laws requiring designated handicapped parking spaces make parking a slightly crappier experience for non-handicapped people. That doesn't mean they're crappy laws.
No one cares about you enough to "spy" on you.
Would you mind telling them that? Maybe they'll stop sending me personalised spam offering me discounts since I haven't shopped there in a while, or paying to send me phyisical advertisements through the post. From your tone, that must be giving me an inflated sense of my own importance.
> "You really think that basic web analytics is "spying on you""
No, I think web analytics is spying on me. A HTTP log is one thing, a JavaScript library which probes my browser, tracks available APIs and versions and mouse movements and sets EverCookies and behaves insidiously, is spying. If I visit example.com and example.com know I went there, that's understandable. If there's a deliberately invisible Facebook pixel telling Facebook I went to example.com, which is only vaguely disclosed in some "and our trusted 3rd parties" legalese, that's not fine.
An access method based on rss (of some sort), in the way "start pages" did it ages ago.
So instead of going to a website to get information, the information comes to my website where I make the rules (as I'm the provider and the sole user). And instead of only receiving plain text information, I can also interact and communicate with other people (the content provider and other consumers), if I choose to.
It took them 15 years to fuck up the Web, we can pull the rug underneath them and perhaps get 20 more.
When I hear about strange Brinternet rules, I just think why should I care about a single country and their strange and costly laws. If UK users want to reach my site, change your laws or use a VPN.
This is to say that "killing pop-ups" should not be a point of a legislation if there isn't one that requires these pop-ups.
Isn’t the simpler answer that the EU like most governments is incompetent and didn’t think through their legislation even though it’s 99 sections and 11 chapters?
It was websites and businesses that chose cookie walls over data minimisation. Most websites don't need a cookie wall or even a popup. Even ad supported websites can use context based advertising without any tracking whatsoever but the choice is clear.
It's not always a political statement to add a cookie wall. Some companies are too lazy to consider alternatives, others don't care enough about their users. This stuff has been coming for years and nobody cared until suddenly everyone was "surprised" and now years later everybody is still acting like this is a recent development.
The message is always clear: your convenience as a customer is worth less than your data.
Apple did more for privacy with a 30 line rule change on the App Store than the GDPR. As evidence by every company dependent on tracking admitting during earnings that they are losing money by the change. No company announced any effects by the GDPR.
Imagine that a private technology company knowing more about technology than the EU.
Some examples (obviously not problem-free, but just to show that a solution space exists):
* No tracking even with permission
* No tracking unless the user mailed you hard-copy permission
* No popups
* No popups unless user testing shows that a user who hates popups, doesn't care about privacy and is just clicking stuff to get to see the site, will decline tracking at least 80% of the time
The reason behind it is privacy (lol, considering their total failure and unwillingness to enforce the GDPR) and yet they are totally fine with the tax office having the same database and information (which is no doubt accessible to law enforcement).
Did you just call the US underdeveloped? :P
But seriously, the US does not have a standardized "ID card" either. They have things like passports (which not that many people have), state-issued driver's licenses (so 50+ different ones, not sure how it's handled in all the non-state areas like Guam or Puerto Rico), social security numbers (which aren't exactly ID either), birth certificates, voter id cards (for people without a driver's license), and a slew of other things the government and businesses will accept under certain circumstances. What they do not have is a nation id card.
You mean State ID cards? They're used for much more than voting.
And no I'm not talking about govt ID or a card. I'm talking about a digital identity you log into and then oauth into other govt services like the tax office or healthcare systems.
This is exactly the issue, and the most important point that people and small businesses should be focused on. Especially when dealing with organizations that want to use the "consumers with contracts" model. Stop using the word "Consumer". People are not consumers, they don't consume things. People and Individuals purchase things with their own purchasing power as "Customers". We are not apart of a mindless machine, where businesses are the engine and we are the gears. Its the other way around, and the more that people promote this in the work place and other areas of life, the better. Words are like magic, they can empower, or enslave us. Don't let the few, who want to control public perception, make the calls.
And that's all one needs to know about that announcement.
The Great Firewall on the Thames.
The PROPER mechanism for this would be a certificate issues by a trusted authority (or a few) that would somehow prove with a zero knowledge proof that you have one of the certificates, but every time it would be different and unlinkable to you. It wouldn’t leak an identifier that can be used to track you.
Google GROUP SIGNATURES, that is what we want to achieve. How? Is there a well-known software library in crypto, besides a mixer like Tornado.Cash or rings like in Monero? Something like openssl so we don’t have to “roll our own”?
The technical name for what I want is Group Signatures, starting with this seminal paper by Chaum in 1991: https://chaum.com/wp-content/uploads/2021/12/Group_Signature...
But what is the latest State of the Art in Group Signatures? What is used today, that can work at scale for groups of MILLIONS of people, and still be anonymous? Chaum’s conception is linear in the number of group members and the group has to be fixed in the beginning, and can’t be dynamically changed. That means issuing new certs once a year year to people who have come of age at 18, or registered to vote etc. That proves your age so they’d have to actually create larger groups by aggregating these together with previous groups (they could also remove people from the rolls if they haven’t retegistered for a while, eg for a driver’s license again).
This is the latest work I could find and it’s from 2003… why is no one making progress in this field, or implementations?
What we've got now is a physical mixing where you "prove" your identity to a clerk at the assigned polling location, you are issued a physical token which you fill out in privacy, and then the token with the voting information on it is mixed with all the others from that polling location. By having opposed auditors watching vigilantly, we get some confidence that ballots are not altered or replaced.
Let's say that you have a system which has a single account for every citizen (fine in theory), which can issue an anonymous bearer token that can be used for voting later. That bearer token is now vulnerable to being sold, confiscated, copied (but only usable once, so there's a race), forgotten, and can go unused.
Is there any way to provably opt out of this latter feature, so we can be sure NO ONE can link signatures to users? That’s Chaum’s original 1991 conception.
The alternative is to use ZK mixers on distributed ledgers that have solved the double spend problem, but the jury is out on just how anonymous and unlinkable they really are in practice: https://arxiv.org/pdf/2201.09035.pdf
Having users manage cryptographic secrets seems like an absolutely terrible idea. Developers and system administrators are incapable of renewing certificates in time, it'll only slow everything down.
None of these technical measures solve the core issue, though, which is that kids will lie about their age online. They'll find a friend/family member/random guy over the required age and copy the super privacy friendly secret token to their devices and boom, everyone is 18. Cryptographic age requirements raise the bar but ultimately they'll never be enough.
It isn’t just for kids.
The hardest part is to make sure that the certificate issuing authorities aren’t corrupted (eg by having a self regulating organization like FINRA) when they give out certificates — since those represent free cashflows or outsize voting shares.
For example, iOS has pretty good parental controls, where parents can limit time in certain apps, etc. It's just a much more scalable and flexible solution.
Sure, some laws for companies could make sense, e.g. forbid them to run ads tailored to children below a certain age. Or label their products appropriately.
But I think it's basically the same thing as "video violence" and any reasonable set of parents shouldn't have any trouble making sure that their eight year old isn't watching Saw 3 (or some other violent film) with her friends.
If this becomes UK law and I continue to run onionisafruit-forum.net without age verification or blocking UK traffic, these are what I consider the possible outcomes from most to least likely:
- It never comes to the kingdom's attention, and everything continues as before.
- Some vigilant Brit reports it to their government. An email is sent to the support address. I do nothing, and the matter is dropped.
- My site gets reported and is added to a blocklist for UK ISPs.
- My site gets reported and Her Majesty's government convinces my ISP to cut me off.
- My site gets reported. Her Majesty's government puts in the effort to identify me personally and issues an arrest warrant. I never get to fulfill my lifelong dream of drinking warm beer in a London pub for fear of arrest.
All those bribes must have made them forget their fight for freedom.
And it's not clear to me that those two sets of rules would be compatible, rather than mutually exclusive.
What a clusterfuck!
If you host non-adult content and there's no way for randos to upload it you don't need to verify.
What is safe for underaged is not defined and can change on a whim. Therefor, any sane person running a website that is not "explicitly for underageds" will verify and eject said underageds. Especially since the one in charge (hired by the company) can be personally liable for any "harm" comming to the underaged.
Websites that seem they need to track users immediately and across their entire web space implemented popups because it's the only way to get consent before showing content, but that's the website's choice, not a consequence of the law.
« in their professional experience, age verification is only ever invoked in discussions around what we might call explicit adult content: pornography, alcohol, tobacco, and firearms. So that’s what they assume this discussion is about, here, in the UK. They don’t realise, until I explain it to them, that the UK legislative discussion is not just about preventing children from accessing those four kinds of content. It’s about mandating age verification for anything and everything, for every user, of every age, in front of access to all topics, all subjects, all sites, all service providers, all opinions, and all content. The whole public open web. Everything. »
Although i can't find any clear statement of pronouns [1] https://webdevlaw.uk/about/ [2] https://twitter.com/WebDevLaw
Sometimes, you must call a spade “a spade”
Do you have some information to contribute to the discussion or are you suggesting that the author should lie instead?
Furthermore the British government is planning to force all websites to verify their visitors’ age (allegedly using government approved providers), which is orders of magnitudes more onerous than GDPR (me: which is actually almost free unless you abuse your users’ data).
The entire reference feels like an overreach, however, not just because of the Reductio ad Hitlerum, but also because it begs the question on the inherent evil of any use of craniometry.
> But for the slow VCs at the back who do need to be told:
>> Concluding, Dr. @Abebab notes, "It took Nazi-era atrocities, forced sterilizations… for phrenology,
Anyway, measuring age with e.g. just a webcam is quite feasible. It's not perfect. I mean: I was well in my 30s when people were still asking for my student id, so there's an error margin. I do suppose these methods cannot circumvented by holding a picture in front of the camera or judicious application of some make-up. Adolescent boys looking for porn are not going to give up just because an age filter declines them access.
It's not phrenology, not in a technical sense, nor in the sense which the article appeals to. And that appeal is a bit pathetic, indeed, but more born from despair than the will to kill of a few million people.
Given that this ludicrous legislation was, undoubtedly, pushed for by the Home Office and shadowy security apparatus, it seems plain to me that those same groups will have access to all the data the age verification companies hold - they will know the identity of every user accessing these websites, and there is absolutely zero chance it won't be abused. There is also zero chance it won't be used as a springboard to escalate the scope.
This is yet more mass-surveillance via the handy back door of "think of the children". One of the main reasons I voted against Brexit was exactly because of shit like this - put simply, I trust the EU more than my own government. Honestly, I found the phrenology comparisons rather apt.
You're not the only one. This was also my own number one (but not sole) reason for voting against Brexit, and that's a really sad thing to have to say.
[1] - https://twitter.com/clancynewyork/status/1535686305438478339
The UK government have been hopelessly out of their depth legislating the internet, since, forever.
The site is called "webdevlaw.uk" and the article footer "This is my personal site, and the opinions on it do not reflect the views of any current or previous employer." seems a bit dishonest, but everywhere does it these days (putting "news" at the end of your twitter handle somehow makes you a journalist apparently).
This is both the good and the bad of this legislation. Bad, for obvious reasons, but good because usually they're so unbelievably out of their depth that it never actually comes to pass.
We're now, what, 5 years is it delayed on a bill that was supposed to require an ID for adult websites? I remember it started up before May was in power and still nothing has been done about it, and that was far less "ambitious" than this.
They need some crazy headlines to try to win the next by elections. When the pensioners will realise that they have to identify themselves to watch porn, the bill will be retracted.
The question we should be asking is how much that we value for other good reasons we are willing to give up in exchange for the possibility of improving the protection of our children, when there is no crystal ball that tells us either how much of an improvement any given measure would actually make or how much of the potential harm from giving something else up would actually be realised.
Until we view these kinds of rights and protections issues as a balancing act with legitimate arguments on both sides but also genuine concerns from both sides it's impossible to even have an intelligent debate on the ethics, never mind write good laws with all the extra practical concerns that legislation and enforcement introduce.
1. I don't believe children will really be "saved" from viewing/reading harmful content - if they really want to see something, they will simply find a way around it, but also remember this is a *UK-only* thing!
2. I don't believe for a second that the security apparatus won't have unchecked access to the dataGiven who the government here currently are it's hardly surprising that they resort to attention-grabbing soundbites. With a bit of luck the Tories will boot Boris before too long and that'll take many of his current Cabinet out of the picture as well since they were seemingly chosen more for their expected loyalty to Boris than any particular expertise or competence. Then at the very least there is a mini-reset in government and some of the more headline-grabbing but questionable policies of the Johnson administration might be quietly sidelined while whoever takes over desperately tries to steady the ship before the next general election. Although of course they quietly passed legislation earlier this year that pushed the latest possible date for that election all the way back to January 2025...
So instead of parents actually installing and/or configuring and/or actually using all of the different parental controls that are already available to stop their kids seeing stuff they shouldn't, they want all the rest of us to deal with the bullshit, while not solving the problem.
It establishes the age and id of UK children to websites and services. However, unless all these services children use are siloed off from the rest of the internet and UK only, bad people from other countries (and those in the UK savvy enough to mask themselves behind some kind of VPN/TOR) will still be able to use these services without having their ids established the same way, and will keep trying and sometimes succeed to groom and abuse children.
Everybody who is actually an expert will have an opinion.
Therefore almost anything that "reads like a neutral analysis" will be worthless drivel. If you want such drivel, it's available in unlimited quantities from various press outlets. Of course, they're not "neutral", either, but they buy their biases wholesale rather than actually doing that whole tedious "understand the issue" thing.
And some opinions are right, while other opinions are wrong. Reality is not "neutral".