However, there is a very real productivity loss with all the cookie prompts - both trying to implement them, getting around them, and the billions of people who have to click on them every single day.
We've got to come up with a better solution.
However, there is a very real productivity loss with all the cookie prompts - both trying to implement them, getting around them, and the billions of people who have to click on them every single day.
We've got to come up with a better solution.
Try accessing Apple.com or iCloud.com. No cookie pop up, yet one of the most successful businesses in history. You don’t have to be annoying
Any personally identifiable information.
GDPR is not a complex law no matter how shady businesses and clueless devs are trying to tell you. It's also been in effect for 7 years. You'd think it's enough time to have at least some clue on what it's about.
And yet we still have these inane threads on HN claiming it's about cookie popups, and people having no idea what info trackers collect.
I highly doubt that. Do give people simpler ways to opt-out of all tracking, and they‘d happily chose that. Currently we have two problems: 1) The consent button is one click for cookies, the other is several clicks away. 2) The layman does not now how to choose a setting to always opt-out of tracking.
I've got an easy one for you: stop embedding google analytics and others. You don't need a cookie banner when you only have operational ones or better yet, none at all.
I also built my own analytics solution that simply shows me my blog article reads per day, week, month, and year (that is all I care about). It's a simple bit of JS that sends a request to my endpoint when the user spends 30 seconds on a page with an article. I also do some light user agent filtering (no "curl" or "python" in the agent string, for example).
I might start logging the referrer in the future to see where my traffic is coming from. However, I am very far from needing cookies or a GDPR notice. I doubt there's a need for cookies at all for most analytics. Even if you wish to track user flow in your website, you can do it with IPs (or hashed IPs to not store the actual IPs) only. An IP is unlikely to change while a user is browsing the website.
It seems to my mind that we only see so many GDPR notices because many websites use dinosaur software like Google Analytics that hasn't been keeping up with the times.
Or maybe has a conflict of interest, and its true purpose is to act as spyware on behalf of Google? Google absolutely has the skills to build a GDPR-compliant version if they wanted to.
The problem is that they aren't in the business of giving away free stuff. GA is only free because they need to give you an incentive to deploy their spyware - they'll happily let you in on (some) of the data they collect in exchange for you spreading it.
As far as I understand (and I could be wrong), the cookie notices exist because analytics providers do not guarantee that this personal data won't be associated with the cookie fingerprint in their systems. Cookies themselves are only mentioned once in relation to this in the GDPR text:
> Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.
If the advertising ID/fingerprint was kept unassociated with personal data capable of identifying a natural person, there would be no need for the cookie notice in my understanding. However, I am not a lawyer.
I guess you may actually make it truly anonymous from a GDPR point of view if you proxy all calls through your own server and strip out anything that can be used to reidentify a user - so no IP addresses, session IDs, etc.
And even then it might not be strictly compliant due to Schrems II ruling
Somehow the industry decided it's better to annoy your users with consent for 50 different trackers with the most in-your-face popup possible to cause users to reflexively hit consent instead.
GDPR actually has provisions against this kind of malicious compliance - the problem is a chronic lack of enforcement, despite it being trivial to detect with a web crawler.
It was promised that things get better with the proposed ePrivacy regulation. Let's see.
In fact, the French data protection authority CNIL has issued orders to around sixty players that do not make refusing cookies as easily as accepting them. They have also fined companies such as Google and Facebook for making it harder to reject cookies than to accept them. The CNIL has ordered these companies to provide a means of refusing cookies as simple as the existing means of accepting them.
Also, under GDPR, it is not legal for websites to make rejecting cookies more complicated than accepting them. In May 2020, the EU updated its GDPR guidance to clarify that cookie walls do not offer users a genuine choice because if you reject cookies you’re blocked from accessing content. It confirms that cookie walls should not be used. Companies such as Google have introduced new options to reject tracking cookies in Europe after their existing dialog boxes were found to be in violation of EU data laws.
Now what I don't know is if users outside of EU get the evil-twin version of those popups when visiting websites. My experience browsing the www is just not as bad as many people describe because I usually get a "reject all" button or when "managing" the cookies, they are all disabled by default and I can simply save the options.
They will see the issue and care about it when something happen. We have a lot of regulation about welding under high pressure because we know from experience what happen when we have no rules (things go boom).
What happen when we have no regulation about tracker ? We get massive data leaks from poorly secured data hoarding company (hello Equifax). This is dangerous in many many ways: Identity theft, scam & spam, identifying people with certain political view, from a minority of some sort, etc... GDPR does not solve all this issue, some company can still hoard massive amount of data about you (it is always scary to ask for a data extraction from Meta, Twitter, ... and how you have a "profile") and have bad security, but it does limit in how many hand this data circulate and how easy it is to gain access to.
> To make this very clear: user/visitor consent is only needed for data going to 3rd parties. All cookie laws, including GDPR and CCPA, allow essential first-party cookies to be exempt from collecting user consent before performing their actions. So your session tracking cookie on your site DOES NOT need a consent popup AT ALL.
Most consent dialogs can be avoided, were it not that the surveillance capitalist services need your data, and shove these dialogs full of deceptive design in your face. In hopes to have as many people as possible complain about the regulations, and use that pressure to lobby them away again.
This is insanity. Their explanation is that users are so accustomed to these cookie walls that a site without one would feel suspicious and unsafe.
I very much blame the EU on this, because the EU policy has solved NOTHING, tracking still happens just as before, except now users just have to go through more friction. Of course I am also pissed at the websites and entities that sell my data, but that is irrelevant to my gripe with the EU.
Businesses: implement rampant dark patterns to trick people into accepting tracking and data collection
Businesses: flood the internet with inane, obnoxious and blatantly illegal cookie dialogs
...
4ad: I blame the EU
(Hint: show me where GDPR says anything about cookies)
It's correct to blame the businesses for creating the banners but also unfair to treat the matter as if the businesses and the EU are on a level playing field. The EU makes laws - it has cheat codes to achieve what it wants.
It's like defensive driving. You may not be at fault if someone crashes into you but you may have had the power to prevent it.
So stop being superficial and read this 7-year old law. I wonder if you could point to me where it talks about cookie banners
Alternatively, the EU could change the laws. Or enforce the existing ones.
Funnily how "7 years of complaining" was, and continues to be, only about the EU. Not about the predatory businesses creating these banners (often in direct violation of GDPR).
> Or enforce the existing ones.
That's definitely the biggest criticism you can level at EU: they are too slow in enforcing this.
I think the tide is very slowly changing. First they started showing reject buttons https://noyb.eu/en/where-did-all-reject-buttons-come There's a report on the cookie banners in the works: https://noyb.eu/en/data-protection-authorities-support-noybs... etc.
https://news.ycombinator.com/item?id=17679596
https://news.ycombinator.com/item?id=25457469
https://news.ycombinator.com/item?id=30982470
https://news.ycombinator.com/item?id=23090393
https://news.ycombinator.com/item?id=29529062
https://news.ycombinator.com/item?id=19381063
All of these links have comments against this sentiment.
This comment from one o the linked discussions sums it up well: https://news.ycombinator.com/item?id=29529190
Regulation, literally: do not collect people's data without their consent if you don't require that data for services you provide. Applies in equal measure to websites, banks, grocery stores, shit processing plants and nuclear power stations.
...
4ad: I still blame the EU, and it's a pointless regulation.
Edit: This comment really says it much better: https://news.ycombinator.com/item?id=35567507
No, when politicians make things worse and absolutely don't solve any problem they promised they will solve then they should be held accountable, removed from positions of power, and replaced with competent people who write better regulation.
Edit to your edit: indeed, the EU is mostly about making people miserable while convincing them it's actually better for them.
No it shouldn't. But it should be criticism and not blaming it for what is 100% the responsibility of the business.
> he EU is mostly about making people miserable while convincing them it's actually better for them.
See, this is not criticism. This is emotionally-charged whining and demagoguery
Most criminal gangs need to steal/rob/etc to survive too.
Of course they don't.
Maybe they're all wrong, but I have doubts.
If you use a cookie for Matomo tracking than yes, you need consent. You are using a cookie for a non essential service (analytics), so you need to ask consent.
But you can use Matomo as cookieless: https://matomo.org/cookie-consent-banners/
If matomo gathers data without a cookie, you can still use technical / essential cookies without consent.
As an example Github.com, owned by Microsoft, does not have a cookie consent popup and sets at least 5 cookies as soon as you open it:
- color mode (dark / light)
- user timezone
- whether the user is logged or guest
- a session cookie
- _octo, that I don't understand.
I'm pretty sure those cookies are non-compliant if you look at them closely, because none of them are necessary for the operation of the service. a) a default value doesn't need to be stored in a cookie -- and it has to be a default value, because you haven't selected a color scheme or a timezone b) login-state does not require a cookie: either you're logged in and have a session, or you aren't, and you don't, c) there's no reason for a session on the public facing side that doesn't contain any private/individualized data, unless you want to use these session cookies to track users -- and it's only about users as bots will typically ignore cookies.
My money is on "Microsoft knows that cookie consent is optional if you're not a small European company".
Edit: And as the sibling said, in many cases it may be restricted to analytics and simple 'reject' suffices, which is at least better than some of the intricate dialog designs.
"We use analytics cookies to offer you a better browsing experience. You have the choice to refuse or accept them. Reject. Accept".
Those analytic cookies are not required for the functioning of the website, and those web sites are required to ask for your consent to gather any additional data.
When presented with "Ask app to not track" on iOS, 96% users clicked "do not track" https://arstechnica.com/gadgets/2021/05/96-of-us-users-opt-o...
If my job relied on people giving up their data privacy I would probably continue telling everyone that line as well.
Cookies/tracking banners on website completely obfuscates the choice. Negative option ( track me ) is presented as the pearly gates to heaven and easy to click. Positive option ( don't track me ) is presented as these mathematical puzzle where you must know what to click or your dog gets executed.
So yeah people care about not being tracked when presented with clear instructions to which one is bad and which one is good.
That is literally the requirement by GDPR
> Cookies/tracking banners on website completely obfuscates the choice.
On purpose. In violation of GDPR.