https://news.ycombinator.com/newsguidelines.html
We detached this subthread from https://news.ycombinator.com/item?id=36341702.
This whole "Don't blame me! Boss told me to do it" attitude is rampant in software.
Is that what they're saying? Because that must be a lie. It's probably more that if you're subscribed and log in, they don't have to ask to set a cookie.
GDPR made a lot of headlines when it was announced and a lot of American companies confused that with the cookie requirements, because that is the time I started seeing a lot of American companies install them, including my own clients asking for them. Despite the cookie requirements being around long before that. It's quite clear that, without enforcement, nobody will ever take these things seriously. The best way to handle it would be something that requires browsers to implement and which cannot be skirted. Maybe we should do away with cookies altogether and come up with something else.
I was once working on a website, we had everything fine, but then a committee of various people from various departments spent days coming up with everything that they thought the cookie banner should conform to.
And then the ad revenue people come in, and say that it should be easiest to just accept all. They quickly backtracked when the EU or France fined one of the big parties; suddenly, the (legally required) reject all button was back on all the cookie banners, which is a good example on how fining large companies large sums bubbles down quickly to smaller companies doing the same thing.
Meanwhile trash clickbait advertising is semantic and psychological pollution that actively makes the internet (and by extension the world) a much worse place for profit. Your priorities need recalibration.
It’s not some hobby site you’re visiting and a web dev likely isn’t the decision maker…. and I doubt a web dev had much to do with the legislation for all these stupid banners.
So third parties specialize in it, and we buy the banner have the company behind them trawl our sites and pull in the info about all the cookies we don't even keep taps on.
And when we've installed them, we all try not to get involved with them again. Because it is the least fun and rewarding area of any web dev day and tinkering with them just might get you invited to a whole series of GDPR review meetings.
Your comment is a good reminder that a median HN opinion has no idea what they are talking about.
This reads almost word for word what one of our execs might have expressed at us 6 years ago when we started doing GDPR compliance.