They are more akin to the "Do not eat" warnings on silica packs... except on the internet everyone swallows.
Don’t track people for non-essential reasons, then you don’t need to ask for consent, which means you don’t need a cookie banner.
HN being an American company probably violates some section of the GDPR (not having someone labeled as the privacy officer or some other technicality) but I doubt anyone cares. If you feel your privacy is getting violated, you can try contacting your local DPA.
In terms of cookies and data processing, I don't think HN is breaking the law anywhere, unless the privacy policy is full of lies and dang is secretly selling our personal info on the site (he isn't).
It's okay, though. No DPA will go after HN.
To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must:
Receive users’ consent before you use any cookies except strictly necessary cookies.
Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received.
Document and store consent received from users.
Allow users to access your service even if they refuse to allow the use of certain cookies
Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place.
If you want to save a person's login to make it easier for them to log in when they come back? That's not strictly necessary - consent is needed. If you save settings to a cookie - that's not strictly necessary - consent is needed. And then there's the "using a cookie to track a session to determine page bounce rate - even if it's not Google Analytics" - consent is needed.And of course, consent is needed if you are using cookies for marketing.
The consent is implied in login functionality. Literal example from same article you cited but apparently didn't bother to read in full:
> These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookie
Essentially if cookie is effect of user action that would directly indicate it needs storing state (cart, login, stuff like switching themes on page) it is "essential" to that feature and doesn't need consent.
> Preferences cookies — Also known as “functionality cookies,” these cookies allow a website to remember choices you have made in the past, like what language you prefer, what region you would like weather reports for, or what your user name and password are so you can automatically log in.
> When people complain about the privacy risks presented by cookies, they are generally speaking about third-party, persistent, marketing cookies.
Nothing is helped or solved by insisting first party "site preferences" cookies need consent. There's obviously room for interpretation in regards to what is a "strictly necessary cookie" when it comes to site preferences, account tokens etc.
Analytics and marketing tracking cookies require separate consent, that’s correct. I would prefer websites to refrain from attempting such tracking completely.
Theoretically websites could choose to do better, but the EU should absolutely have predicted this outcome.
tracking pixel ? Are you sure you know what you're talking about ?
I just check some web pages from diffrent organs of the EU:
https://commission.europa.eu/select-language?destination=/no...
https://www.consilium.europa.eu/de/european-council/
https://european-union.europa.eu/institutions-law-budget/ins...
They all have cookie banners, some of them are super prominent and annoying. So maybe they as well are doing malicious things, maybe they don't understand they own regulation, or it is just impossible to have a non-trivial web page without a cookie banner in 2023. In either case, the regulation is totally dettached from reality and has become just some ritual.
not completely wrong.
ime in the case of the cookie law, most ppl didn't actually bother to go into details and just took the word on the street and some existing 'solution' and called it a day since everybody was doing it this way and sales/executives were pleased.
fact remains: cookie banner is _not_ necessary for logins and most existing banners are outright illegal since 'no' is not an easily accessible option
Yes it is.
You'll quickly learn that what the EU does is very very very good for privacy, I have contacts in a major company and they were shocked at how the US branch operates, they have absolutely no sense of privacy, no anonymisation, no limitation on what is stored or tracked, no consent, &c. they just scrape and store as much as they can for "future use"
I’ve never felt protected or assisted by the cookie banners, just annoyed and inconvenienced.
With the 0.1s it takes to click on a banner I'm sure you're fine. Most people probably visit less than 50 different websites per month, so at most that would be 50s per months, minus the banners you already clicked on, for which your browser already saved your choice (Unless you use incognito, but why would you do that, it's only for people who have something to hide right ? regular people just accept all data collection right ?)
Also the banner, if there is one, must have a 1-Click "reject all" button.
Most sites fail to fully comply, because they want to force (annoy) users into clicking on "leave me alone I don’t care" button to keep selling user data. They make you go to some overly bloated list of things to disable, scroll all the way down to finally "confirm my choices". It’s voluntarily painful and with misleading wording.
These sites want you to believe that all this clunkyness is required by the EU law. It’s not. It’s the good old mislead-into-approval strategy, using dark patterns and blame-the-EU rethoric.
And for the record, if it really takes less than 100ms to read and clear interstitials, I'm more impressed with your button clicking skills than anything. Have you tried Osu?
All the important things such as purchasing habit that used to require indirect guesses are now directly available in their databases as essential functions.
The popups are malicious compliance. They want you to hate the popups, so that you will turn against privacy laws, and fully submit to the unimpeded surveillance business.
And it’s working: people are installing “I don’t care about cookies” extension that agrees to data collection, deanonimization, profiling, and sale of this data.
They should all have 3 buttons: "accept all" or "reject all" or "customize", dead simple. Every time it's a different design, different button text, different options. Usually rejecting = multi layers of options.
A perfect example of good intentions making bad policy.
I'm using uBlock and Consent-o-matic to remove as much tracking as possible already.
There's already the "do not track" header that noone respects.
this is on purpose
if you could commit where the Deny button was to muscle memory, you would click it every time
Even Google has a "reject all" button in their cookie prompt these days. If rejecting takes you through multiple layers, consider reporting the website or their tracking partner to your local DPA.
The ad industry is intentionally making their popups as inconvenient as possible. They childishly point to the EU legislation that they "have" to make your life miserable with those popups but they really don't. They can choose to make your life easier, but that threatens their business model of using you and your browser as a source of revenue.
They can simply stop tracking you at all if you send the do not track header. You wouldn't even see the popups! They can even still serve ads, just not the ones based on the profile they've collected.
- Accept all
- Mandatory for function non-tracking cookies only
- Reject all
There should be a standardised browser accessible interface so browsers can automatically choose the one you want on your behalf based on your browser settings.
If you don't like cookie banners, which are indeed really annoying, you should be turning your ire to the companies that wish to track you. They are fully-functional solutions that allow anonymous tracking without installing cookies on your computer - no banner needed then.
Good for you. Most people are not technical and can't, so why do they also not deserve to not get tracked too?
Are you sure? It starts from simple supercookie-like stuff and ends at TrustPID where the network provider aids in tracking.
Feel free to link to a plugin you trust...
Essentially, now we're at a state where consent banners exist, slowing down all sites, and there are like four states: a) they look compliant, but are ignored by the website provider (the EU itself takes this approach), b) they are flat out ignored (a lot of companies still take this approach) c) they aren't compliant (tiny "no" link, huge "yes, take my firstborn" link) d) they're compliant and are paywalls (buy subscription or accept everything under the sun).
d) is what we're probably going to end up with, so you either pay or you accept tracking. More and more solutions offer that as an option so adoption will grow. Most people accept tracking (stats that I've seen say that those paying are like 1/10,000th), so what have we won exactly by doing this dance?
That would require more regulation, by regulating both browsers and websites, and their technical protocol. Instead the EU tried to minimize regulation by not prescribing the exact technical means by which websites would need to obtain consent for tracking from users.
Browsers could already do most of it, and there are far fewer browser manufacturers than website owners, and they have far more resources than the average website owner, and, at least for some of them (all of them except Chrome), the incentives would be aligned. Right now it's "protect the user (and earn less money)", and the results are unsurprising.
Lastly, cookies aren’t the only way of tracking. Websites can also use local storage, or fingerprinting, and so on, each of which can equally require consent. If the browser consent mechanism is restricted to cookies, websites would have to be mandated to always use a cookie to ask for consent, even when they actually use other means for tracking, and websites would have to explicitly check whether the cookie is stored or not in order to control any other tracking.
Ideally browser should just send "do not track" and site should fuck off with tracking, no questions asked.
However, choosing to respect the users' wishes isn't very profitable. You need to make your ads relevant to the content somehow andtthat requires effort and skills. It's much more profitable to trick people into consenting with tracking so you can sell their information, so the more annoying your cookie popup becomes, the more money you can make. IAB has already been fined for such a popup mechanism.
"Do not track" is not enough to comply with GDPR because you must also be able to request a copy or corrections of your personal information once you have given consent. Then there's the option to allow some companies to track you (say, analytics companies) but not others (say, Google) that needs to be taken into account.
Back in the day, Microsoft's P3P protocol was trying to fix this problem, but nobody used it. DNT headers also aren't really configurable in the browser itself, you can only pick on or off.
A protocol is being developed that may solve this (https://www.dataprotectioncontrol.org/) but I'm sure it won't work until the EU forces company to take such protocols into account. After all, ignoring people's wishes is literally how these ad empires are making money now.
Easy. Clear your cookies. Use a proxy. Use a fingerprint resistant browser. Will protect against >99% of website operators.
> In most cases, it just blocks or hides cookie related pop-ups. When it's needed for the website to work properly, it will automatically accept the cookie policy for you (sometimes it will accept all and sometimes only necessary cookie categories, depending on what's easier to do).
If there was a way to be assured that 99.9% of the time it hit reject all, instead of accept, I would absolutely use it.
[0] https://consentomatic.au.dk/ [1] https://github.com/cavi-au/Consent-O-Matic#compatible-cmps
Except that it does. The law specifically prohibits any form of consent that is not informed and specific. As a consequence, a user cannot just consent - or disallow - cookies globally. He has to tick a box for every single domain on earth; and can only do so after reading the specific information box associated to said domain.
As a user, saying "I am OK with analytics cookies but not with marketing ones" is not something I am allowed to express or setup. I have to do it for every domain because the law explicitly forbids a global solution to be implemented.