What is the end game here, it's like watching dumb and dumber. I want a great web experience just like the next person, but not at the cost of jeopardizing the successful freemium model of the internet that has given billions of people access.
What is the end game here, it's like watching dumb and dumber. I want a great web experience just like the next person, but not at the cost of jeopardizing the successful freemium model of the internet that has given billions of people access.
This is simply automating the process of ignoring the request for consent to track you. The result is (legally) that the website may not track you because it did not receive affirmative consent. That really is the end goal, to stop companies from tracking consumes like this while still allowing for legitimate business deals.
Everyone in the industry tracking the privacy moves in GDPR acknowledges that far from improving privacy, they are intended to blunt US tech companies' success in the continent. And . . that's perfectly fine, i guess positioning it as a moral defense of privacy just doesn't sit well with me.
No, this is by far the minority view and is held purely by people who are ignorant about the requirements and functionality of GDPR.
EU doesn't enforce popups that take half page space though, web sites added them.
> followed by browsers like brave programmatically defeating the ability of companies to seek consent?
followed by the choice of the user to automatically deny consent to those asking for it using annoying popups.
FTFY
it's like ad blocking, I don't want to consent to data collection or see ads and I automatically deny the permission and block ads.
It's a default, chosen by users, you can opt out, which in this case means you're opting in for choosing to which site give your consent.
I don't want to consent to any tracking and there's no need to ask me.
- drastically reduced free content (see the rise of paywalls on most news sites)
- an arms race to find other ways to track (see rise of cookieless tracking and retargetting approaches, first party cloaking, etc)
Not to say the latter wouldn't always be there, and but fact is a good chunk of the web is free and stuffed with ads because that's the only way to stay afloat, people simply don't want to pay for content.
You act as if this is a bad thing. I’m all in favor of business models where I give them money and they give me goods and services
If this state was the normal, and later they were to stop blocking cookie banners that you explicitly chose to always reject, it would be seen like a huge harrassment from companies to the user.
Maybe the end game is that we managed to realize what practices were beyond acceptable, and finally forbid them via legislation.
So, in your estimation, which side am I on - Dumb, or Dumber?
(Except, possibly, for automatic bug tracking; but even then, the value is in the stack trace, not the personal info).
I'd rather poke my eye out than stick up for them. What i'm calling out is the dangerous series of events over the past few years which have been rooted in good intent to preserve privacy, that seem to be having the fallout of destroying the web experience.
[edit] I can't believe HN has turned into a reddit style downvote brigade so i'll just post my response to the below comments in this edit since i can't reply anymore <shrug>
And you've made my point exceedingly clear[1] That pretty much is the ambiguity left up to the whims and fancies of the EU bureaucracy to enforce.
According to noyb.eu , the entity behind famous decisions at the CJEU, consent IS INDEED required[2] for ANY cookies to be stored on a users device. It isn't about data collection , if some rando agency or court finds Github or HN use fingerprinting of user preferences (as an example) or are LIKELY TO. . . it is considered a breach.
A French agency fined Google and Facebook heavily for merely providing a more complex refusal flow for cookies than the accept flow.
[1] https://www.cnil.fr/en/cookies-cnil-fines-google-total-150-m...
[2] https://noyb.eu/en/project/cookie-banners#:~:text=Cookie%20b....
No, consent banners are a consequence of scummy companies trying to vacuum up your personal data for nefarious reasons. They are not required by any regulation, aside from in cases where a company is asking to use your data in non-essential ways.
The GDPR doesn't require consent pop-ups. Companies choose to add consent pop-ups when they exceed the minimum amount of personal data collection.
* "Started with" implies that there were no motivating factors for the GDPR, nor a situation being responded to. Online surveillance is a clear harm being done to users, to which the GDPR is a clear response.
* "Ignorant lawmakers" implies that the law was poorly crafted with little subject matter knowledge. This hasn't been my experience in reading it, that the GDPR is well-crafted to make certain unethical business models be infeasible, while avoiding impact to data collection that is essential to a service.
* "Made web browsing worse" implies that the current state in which surveillance must make itself known is worse than the previous state in which surveillance could be done silently. I would argue that it is a better state, as knowledge of a hostile act is the first step in preventing it.
1. The law was passed
2. Websites complied with the law
3. Web browsing got worse
Has “surveillance capitalism” subsided at all after the GDPR? Did any company announce that it affected their revenue negatively?
How many people are saying “we are so glad we have cookie banners everywhere”. I’m also sure that every small business is glad to have to decipher the huge law.
* Explicit claim: "Websites complied with the law" The GDPR does not allow a refusal of consent to take more steps than an acceptance of consent. I have only seen a scant handful of websites where this is the case. Instead, refusal requires following additional links, sometimes disguised as "privacy policy details", disabling each pre-selected consent box, etc.
* Implicit claim: "Websites complied with the law" implies that the websites took the only method by which they could be compliant. This is incorrect. Websites had a choice, and could have stopped surveilling users instead. This is a breakage in the causal chain between the passing of the GDPR and the omnipresent cookie banners.
* Explicit claim: "Web browsing got worse". Appeals to a majority are not sufficient. A user-hostile website being required to announce itself as such is an improvement.
As far as appealing to the majority, if the majority don’t like the consequences of a law, in a democratic society isn’t that prima facie a bad law unless the law is to protect the minority from the majority?
If the websites complied with a law in a form that made web browsing worse and didn’t achieve its intended purpose - isn’t that yet another sign of a badly written law?
2. Enforcement corps complied
3. Hitmen's job got harder
Are the two sentences completely uncorrelated? Yes, so is the effect of the GDPR on websites.
[citation needed]
I wonder why Facebook tried to bypass GDPR if it's of no use
https://noyb.eu/en/irish-dpc-removes-noyb-gdpr-procedure-cri...
Did they announce a decline in revenue caused by Apple’s ad tracking transparency - yes by the tune of billions and they called that out as the reason,
classic non sequitur.
What would have happened without it?
Do you have hard numbers?
No.
Anyway, looks like looking for the data was too difficult, with the whole Internet at your disposal.
So I did it for you.
https://techcrunch.com/2022/04/27/facebook-leaked-ads-docume...
If web sites of those tracking us got worse, good!
That was the point.
You really think the GDPR stopped the US government from tracking anyone?
it hasn't stopped homicides
but it made them illegal
if your point is that nothing ever changes so there's no point in doing anything, I beg to differ.
The only thing that GDPR did was annoy users.
https://www.enforcementtracker.com/
anyway, as many have already pointed out, GDPR does not annoy users, web sites owners do.
Hacker News, ditto.
No.
Hacker News has no banners and no shields is used by Brave, because they do no track you.
It's that simple.
I don't believe in consent banners but that doesn't remove my legal requirements. I've got to stick to the law whether I like it or not.
They don't care about the tracking/ad blocking side of things.
Brave is popular for ad blocking.
only because you're asking for something that is not necessary.
besides, you could assume no consent and let the user change the setting autonomously.
It's called opt-in.
Nobody asked you to display a giant popup asking for users' consent.
Consent !== cookie-banners. Hey, you don't have a legal requirement to track people at all; it follows that there's no legal requirement to get consent to track. Tracking must be opt-in, so just provide a menu option or something, that lets your visitor opt-in to tracking, if they love being tracked (let us know how many people opt-in to tracking, if you haven't gated the entire site on a consent banner).
Maybe your site provides features that depend on tracking? No prob - gate those features with a consent dialog.
Maybe you don't want any visitors you can't track? Well, that really means that your homepage should be an opt-in dialog, returning a 404 if you opt out.