But I’m also waiting to see how this is torn apart and made horrible by big corps just like cookies was
But I’m also waiting to see how this is torn apart and made horrible by big corps just like cookies was
It's good having the EU as a counterpoint to the US in terms of regulation. It's not always going to work perfectly but it's worked fairly well over all.
But even there I feel like the cookie banner at least offers some benefit to me, whereas all the other modals asking to send me notifications, subscribe to stuff, register here, follow us there, are completely superfluous and we should push back against those first.
Unfortunately, corporate greed was too high, and the result are cookie banners listing sometimes >1k third-party entities.
My big question with those banners is: what the hell does "legitimate interest" mean? The toggle for normal cookies is generally off by default or easy to turn off, but then there's another tab, or other toggles, listed as "legitimate interest", and it lists all the same stuff I don't want: ad personalisation, tracking, etc. What's the difference? Why do they consider that legitimate interest?
Everything else is abusing the term and should be reported to the responsible data protection authority.
[1] https://commission.europa.eu/law/law-topic/data-protection/r...
There is a definition in the regulation, which IIRC basically amounts to a rewording of "strictly necessary". This definition does not cover what companies use it to excuse.
The way the phrase is actually used, for much wider tracking, what it has come to mean is "we see your preference not to be logged and stalked for the benefit of our business plan, but fuck you and your preference we want to do it anyway".
This is why the legitimate interest check boxes are often hidden in nested concertinas or other UX nightmares, to make it extra difficult to opt out of what should be an opt in. Once a body has gone this far to try engineer an accidental opt-in they are _definitely_ not to be trusted IMO. Though it is likely too late if you really care: they may have already dropped their payload & sent at least some information back to base, and will "accidentally" not remove it later or find some other excuse as to why they shouldn't.
That's certainly how I've been reading it.
What I really want is for my browser to automatically block all of it. I know Firefox blocks a bunch of stuff, and ad blockers probably do too, but I have no idea how thorough they are and whether there are ways of tracking they can't block at all. There probably are.
(Except login and preference cookies; those are legitimate. And only relevant for sites where I actually login and set preferences. I'm pretty sure most sites I just visit to read some article, have no reason to set any cookies at all.)
So, the EU makes laws that supposedly protect my privacy, and in order to deal with the awful practical consequences of those laws, I'd need to give an unknown third party access to all my data on all my websites?
Now all we need is some carrots or sticks to nudge companies to fix their websites. Like fines or decreased search ranking.
https://www.theverge.com/2023/7/20/23801435/google-chrome-pr...
I guess rather than regulating cookies, they meant to regulate tracking. Or maybe even regulate targeting, rather than tracking.
The cookie banners are mostly a tragedy, everyone agrees that modal, blocking cookie banners were never the intention. But the giants definitely had something to gain by suggesting they "were forced" to harass visitors.
I hope the EU cracks down on it at some point, the harassment is very much a strategy to manufacture discontent in the public about the regulation, and it works (as you can see in multiple replies anytime this topic shows up in HN), and the strategy is illegal.
When I see statements like this, I wonder: have people ever read anything besides what the industry feeds them? Or the echo chambers of HN and twitter?
Here's GDPR's text: https://gdpr.eu/tag/gdpr/ Please show me where exactly it talks about browsers. Or cookies. You could start with Subject Matter and Objectives: https://gdpr.eu/article-1-subject-matter-and-objectives-over...
> But the giants definitely had something to gain by suggesting they "were forced" to harass visitors.
Indeed. They redirected the ire from themselves to the law and the EU. Spreading FUD works.
My point is just that the corporations just find loopholes. Like how Apple have technically allowed out of app AppStore’s but mad it so horrible that no company would ever do it.
I repeat - the cookie consent popups, and the resulting de-sensitisation of users to genuinely useful warning popups - that's ENTIRELY the fault of the technocratic leadership of the European Union.
"Big corps" have to follow the rules or they will face hefty fines.
---
Edit: the comments about the consent forms protecting against "spying" are disingenuous. Even functionality such as remembering user region, or allowing the website to improve performance and UX using simple analytics requires consent.
In fact it's not a “cookie warning pop-up”, it's a cookie consent pop-up.
And there's an easy way to get rid of that pop-up for companies (big or small BTW): stop using cookies that require user consent: that is, stop harvesting people's data.
This is the problem with feel good laws like this. You always have to write laws assuming that those negatively effected will be bad actors that will try to subvert the law. That's just human nature. People want to keep doing what they're doing.
Okay. I always ask this: what's your solution to this?
It made the web worse because companies decided that making it worse was better than changing their business model. But it did reduce the amount of data collected.
> You always have to write laws assuming that those negatively effected will be bad actors that will try to subvert the law.
But they did. But EU was lobbied into being too business friendly, and relied on nudging them into better behavior instead of forcing them, and the businesses said “no way, we'd rather fuck up our website”.
There's no way the European Commission could have convinced the member states to accept a law that would be too detrimental to business interest. When discussing a law, you must always take into account the political forces that drives it adoption process.
Not a well thought through law and clearly needs an update to restore usability to the web
Yet you are happy enough to stop at "the intention was good".
I imagine you smiling happily every time you have to click "set cookie preferences ... reject all".. ahh good old EU looking out for me, how wonderful they made things.
Show me where GDPR talks about browsers or cookie popups.
> Yet you are happy enough to stop at "the intention was good".
No, I'm not. I want the EU to slap the maximum possible fines on the biggest perpetrators, as defined by the law.
The cookie banners you are complaining about are illegal, read the EU law directive [1], it states pretty explicitly:
> Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place.
It's not the fault of the EU law if companies decide to act illegally. Blame the fucking companies, they are the ones making you miserable.
Or if you insist on regulations that burden every website operator, how about the user ticks a box in their browser once e.g. "I do not consent to cookies regulated by EU Cookie Law" and then that choice is sent in the header of every web request, and website operators are mandated to respect it (and NOT show a banner asking for consent every time the user visits!)
What if the operators don't respect the header? Well, what if operators don't respect the user's responses to cookie consent popups? We're relying on operators doing the right thing in both cases, and the EU cannot guarantee either approach will work.
You seem to be deliberately ignoring the fact that cookies are necessary for normal website functions like logging in to a user account. And also the fact that those types of cookies do NOT require a consent banner.
> how about the user ticks a box in their browser once e.g. "I do not consent to cookies regulated by EU Cookie Law" and then that choice is sent in the header of every web request, and website operators are mandated to respect it (and NOT show a banner asking for consent every time the user visits!)
I agree, that would be ideal. I hope it comes in the next version of the ePrivacy directive.
> What if the operators don't respect the header? Well, what if operators don't respect the user's responses to cookie consent popups?
That's what law enforcement is for. A common critique of new EU laws is that the enforcement is lax at the beginning. However, it ramps up over time and is a one-way ratchet. The EU is like a massive ship with huge inertia. Changing course takes a long time, but once it gets going, you better not be in the way.
By the way, we saw this with those highly infuriating and illegal cookie banners that hide the option to deny cookies behind many clicks. The regulation clearly says it should be as easy to consent, as to not consent. And most cookie banners I see nowadays have an easy opt out button.
Yup, Europe is so lucky to have this stubborn, inertia-ridden juggernaut in charge of dynamic and innovative technology like the Internet
...which you have to click EVERY TIME you visit nearly every website on the web.
What a great success for usability.
Forced onto us by the site operators (directly, or via their "partners"), not the regulations.
It is called malicious compliance. In fact many of those popovers are not even properly compliant in various ways (usually breaking the "as easy to opt out as to out in" mandates, to give the most common example).
If you are angry at "cookie laws" and/or GDPR, you are angry at the wrong target.
I guess that, too, was the EU's fault (and not the industry's).
- EU Cookie Law is "tell people you're using cookies". And with GDPR it became "if you use that data strictly for the operation of your website, you don't need anything at all"
- GDPR is: if you want to collect more data, and track people, and sell/send people's data to third parties, you have to ask for their consent in a clear unambiguous manner, with opt-out being as easy as opt-in.
The industry's response to that [1]?
---
We value your privacy.
1498 partners
We're building a profile on you
GDPR made us do it
Agree to all
---
And the gullible devs gobbled that up and blame the law for their own industry's failing.
no, it does not
"improve performance and UX using simple analytics" I don't see how performance requires persistent analytics. This smells like a flimsy justification or perhaps "we always did it this way" rather than strict technical necessity. You can send events from a current session without keeping state in the client. And if one truly cared about performance, there's a lot of fat to trim from many commercial webpages that shouldn't require any analytics at all, try opening a profiler first and notice how much time is spent on loading all the analytics stuff.
Then the "popups" (which aren't actually popups) aren't actually as onerous to users as the web developers on HN would have us believe.
Seriously, I never hear common people complain about it, only people in the industry who have a commercial stake in tracking people without consent
i profoundly disagree. the cookie law+gdpr did not force the websites to show their obnoxious overlays, they do that in order to confuse a part of the users and make it hard do not opt in. they could have used a simpler way to show the information, or, you know... not sucking every information about you they can, which would have not created the need to show anything.
edit: maybe it's not well known exception, but cookies that are mandatory for the functionality of the website (and are not used for tracking) do not have to pass through the opt in process. for example, the session cookie for the login functionality.
Repeat as much as you like, you're still wrong. Note that this website you're currently using doesn't have one. Neither does github.
> Even functionality such as remembering user region, or allowing the website to improve performance and UX using simple analytics requires consent.
That's the point.
I've seen analytics data. Looks neat. Definitely doesn't need to be granular to the level of individual users.
Also, given how badly I'm categorised by even the giants like FB, I simply don't believe this data is half as useful as it seems from the shiny graphs coming out of most analytics software.