https://www.theverge.com/2023/7/20/23801435/google-chrome-pr...
I guess rather than regulating cookies, they meant to regulate tracking. Or maybe even regulate targeting, rather than tracking.
The cookie banners are mostly a tragedy, everyone agrees that modal, blocking cookie banners were never the intention. But the giants definitely had something to gain by suggesting they "were forced" to harass visitors.
I hope the EU cracks down on it at some point, the harassment is very much a strategy to manufacture discontent in the public about the regulation, and it works (as you can see in multiple replies anytime this topic shows up in HN), and the strategy is illegal.
When I see statements like this, I wonder: have people ever read anything besides what the industry feeds them? Or the echo chambers of HN and twitter?
Here's GDPR's text: https://gdpr.eu/tag/gdpr/ Please show me where exactly it talks about browsers. Or cookies. You could start with Subject Matter and Objectives: https://gdpr.eu/article-1-subject-matter-and-objectives-over...
> But the giants definitely had something to gain by suggesting they "were forced" to harass visitors.
Indeed. They redirected the ire from themselves to the law and the EU. Spreading FUD works.
Unfortunately, corporate greed was too high, and the result are cookie banners listing sometimes >1k third-party entities.
My big question with those banners is: what the hell does "legitimate interest" mean? The toggle for normal cookies is generally off by default or easy to turn off, but then there's another tab, or other toggles, listed as "legitimate interest", and it lists all the same stuff I don't want: ad personalisation, tracking, etc. What's the difference? Why do they consider that legitimate interest?
Everything else is abusing the term and should be reported to the responsible data protection authority.
[1] https://commission.europa.eu/law/law-topic/data-protection/r...
There is a definition in the regulation, which IIRC basically amounts to a rewording of "strictly necessary". This definition does not cover what companies use it to excuse.
The way the phrase is actually used, for much wider tracking, what it has come to mean is "we see your preference not to be logged and stalked for the benefit of our business plan, but fuck you and your preference we want to do it anyway".
This is why the legitimate interest check boxes are often hidden in nested concertinas or other UX nightmares, to make it extra difficult to opt out of what should be an opt in. Once a body has gone this far to try engineer an accidental opt-in they are _definitely_ not to be trusted IMO. Though it is likely too late if you really care: they may have already dropped their payload & sent at least some information back to base, and will "accidentally" not remove it later or find some other excuse as to why they shouldn't.
That's certainly how I've been reading it.
What I really want is for my browser to automatically block all of it. I know Firefox blocks a bunch of stuff, and ad blockers probably do too, but I have no idea how thorough they are and whether there are ways of tracking they can't block at all. There probably are.
(Except login and preference cookies; those are legitimate. And only relevant for sites where I actually login and set preferences. I'm pretty sure most sites I just visit to read some article, have no reason to set any cookies at all.)
So, the EU makes laws that supposedly protect my privacy, and in order to deal with the awful practical consequences of those laws, I'd need to give an unknown third party access to all my data on all my websites?
Now all we need is some carrots or sticks to nudge companies to fix their websites. Like fines or decreased search ranking.
My point is just that the corporations just find loopholes. Like how Apple have technically allowed out of app AppStore’s but mad it so horrible that no company would ever do it.