1. Businesses trying to violate your privacy. 2. A government trying to protect you from said businesses.
Either of these entities could avoid the cookie warning, but there are very different reasons why they do not.
I think there are very, very few people who are earnestly proud of the work the EU did with this regulation every time they waste finite brain cycles on yet another cookie banner. I don't really know why Europeans use this as an example of their system of governance working as hoped.
The anticipated effect of requiring consent is that by forcing companies to shine a flashlight on their own bad behavior, they will instead choose to correct their behavior. That didn't end up happening in practice.
That said, I just looked at it, and this is my idea of a well-made popup: https://gdpr.eu/what-is-gdpr/
[0] But for the Betteridge law of headlines and Gell-Mann amnesia
Which, technically, it isn't.
> Which, technically, it isn't.
That's still a dark pattern, because by definition, dark patterns aren't illegal - just barely legal, and detrimental to the consumer.
not ah yes, let's go back to having no regulation of corps tracking people.
People would be quite enthusiastic to more regulation which required no cookie banners where users had, eg., expressed a preference for no tracking at the browser level. And likewise, to require the provision of such "no-tracking signals".
I suspect something like this is on the horizon, and in part, something google was trying to head-off with its 3rd party cookies stuff.
"more, better!"
this is so true and kind of hilarious to see Americans not understand this. When a regulation happens and it's day to day effects are not working out great. The answer will always be to regulate more, add more rules and restrict things more.
The EU is inclined not to create regulations at first. They prefer to hold meetings, seminars and inform companies of their effects to encourage them to self regulate. If after years this does not help they will either:
A) create subsidies to help companies implement changes. but only if they have shown they are will to interact with the EU governing bodies.
or
B) Add rules and regulations to force companies to act a certain way.
The beautiful disconnect pointed out in the article where Apple thinks the meetings are negotiation and EU is basically showing that their smiles and friendly words are just formalities and change is happening no matter what Apple thinks or not.
While still protecting the “business freedom” of the said business.
They could have forbidden cookies and tracking altogether, but they are too probusiness for that.
I do not care why cookie banners are there. All I know is that they weren't there N years ago and now they are, and they are annoying.
Is there some background reading on this? I would like to use Cloudflare as one of my DNS providers but this issue has always bothered me.
This is false. The GDPR does not mandate privacy - the GDPR mandates the protection of certain kinds of personal data, much of which (e.g. IP addresses) has legitimate reasons for being collected (e.g. abuse protection). Claiming that every business that shows a cookie warning is trying to violate your privacy is not only objectively false, but extremely intellectually dishonest - although that's about par for the course for GDPR enthusiast zealots.
I have seen 500+. Which is like wtf is going on.
I can't even name 500+ companies or websites, who the hell are these companies?
--
[1] which I read as “we see you and your privacy preferences, but fuck you and your preferences we want to stalk you anyway”
Meaning “we've vetted our partners and found their security practises to be seriously wanting, but haven't kicked them to the curb because a very small amount of money is far more important to us than our claims to care about your security and/or privacy”.
If you give companies an easy copy-and-paste way to get around a single regional law then they will do the quickest dumbest thing possible to get what they want no matter who the visitor is and where they're located.
The EU laws are poorly conceived, poorly written, and now we all have to live with them. They can make privacy laws, but they need to make them better.
I truly believe that the EU ruined the web for everyone with their haphazard legislation. And now they're trying to do it again with AI but thankfully they're just getting blocked now instead of everyone trying to comply.
https://ec.europa.eu/commission/presscorner/detail/en/ip_24_...
If that site needs a cookie banner I'm guessing nearly all sites do.
Exactly. And this doesn't surprise me.
The law states: if you collect more data than is strictly required for your site[1] to function and/or send user data to third parties, you have to:
- tell the users about it
- let the users to opt out, where opt out must be as easy as opt in
- if the users opt out, the site[1] must continue working
So yes, that site does send some extra data to third-parties, and informs the user about it. And lets the user know about it. IMO it shouldn't use third-party services, but oh well.
These days it's a source of my constant amazement that 8 years after its publication the people who complain about GDPR the most have not had even the tiniest attempt to read anything about it or understand anything about it.
[1] I simplified this to sites. GDPR is General Data Protection Regulation. All this equally applies to sites, apps, offline businesses, governments etc. To cookies, local storage, offline paper documents, tape records, cloud storage etc.
8 years. The law has been around for 8 years. It has been enforced for 6. It takes about half an hour to read the most relevant parts of it (chapters 1—5). An hour if you're not too familiar with legalese. And yet... "I don't know".
What is there to know? Nearly every website on the western internet has these cookie banners including the EU's own government sites.
The practical consequences of the laws are now apparent.
So what did we all miss that was hidden in the legalese?
Rarely do you see people flaunt their willful ignorance.
> Nearly every website on the western internet has these cookie banners
Well, since you approach is "I don't know and what is there to know", it's no surprise that the industry so easily sold you the lie of "the EU's laws are at fault"
> including the EU's own government sites.
Compare the banner on the site linked above and the usual dark patterns employed by the industry.
are you saying that the explosion of opt-in cookie banners on the web is not the result of the EU's privacy laws?
With AI what I saw in the news mostly made sense and did not hinder development too much. But again I would rather they regulate the use because it will have real negative consequences for many people if they don't
A lot of EU laws have also been bad. VATMOSS (especially with the very low initial limit to register) was initially a disaster. It actually deterred people from trading within the EU! The commission's attempt at chat surveillance was thrown out by the parliament, but they will try again. The new AI regulations look problematic. The draft I saw of the AI one was far too broad (included old tech like expert systems) - not checked recently whether it has changed. There are also issues with a lack of FOSS exemptions in the other current law (forgotten what it is called) imposing greater liability for faults in some categories of software.
I think it is important to acknowledge that many regulations are not perfect and I would push for more revisions on the details (although changes in the law also have a real cost associated) that don't hit their target.
last time I caught up on it, it was a very narrow exemption that was only of use to pure hobby projects.
Where would you find a lawmaker with an ounce of foresight?
https://ec.europa.eu/commission/presscorner/detail/en/ip_24_...
"This site uses cookies to offer you a better browsing experience."
Which of course is total crap. There's no better experience, only a worse experience with the banner.
They seems to use this https://piwik.pro/, which as far as i read seems ok (i did not audit the code personally), i think this data might be legit useful for UX (im really shit a UX, you should ask people working on it though).
Heck, the way the cookie protocol works the server already says ‘hey, may I store this cookie?’ by sending the Set-Cookie header. The user’s browser doesn’t have to do anything if he doesn’t want it to!
It is not a question of cookies per se. You can use localStorage and other techniques to track users without using cookies. But you still have to show the warning if you are tracking.
And there a plenty of legitimate uses of cookies.
I stopped using it because if you blocked websites from setting cookies, that meant the cookie consent banner showed on every page rather than the first you viewed because the cookie consent cookie had been blocked. That made blocking cookies entirely apart from whitelisted sites impossible.
Not every one is tech-savvy and that is why we have regulations.
Even in its worst form, the cookie warning is giving a significant material advantage to the non tracking website over the tracking website, which without the cookie warning the 2 websites would have appeared exactly the same to all users.
None of those are accurate.
The only adverts they've shown which are relevant to my interests are for Babbel, except I already had that years before they started showing me the ads.
In all seriousness so, for all the effort and data companies like facebook have, the product, targeted ads, is just bad. And sometimes hilariously so.
Seriously so, how is something like targeted ads a product worth paying for if the results are, quite often, so incredibly wrong? I get search context ads and such things, but all that targeted stuff is just so pointless. I never got a single one that was relevant for me. Since I aggressively turned off anything ad related on my phone, ad quality actually got better. Still not really relevant for me, but better.
Their purpose is to push you towards working against your own privacy.
Obviously it's a flawed implementation and the powers that be fought hard against an automated flag, but that's what we should be fighting for to fix it.
The correct way to get rid of cookie banners is businesses using cookies in a responsible fashion, and sooner or later this is going to happen.
Also, your framing misses one important point: If I have the choice between mildly frustrating cookie banners that raise awareness for the situation and simply having all your data sent to 500 advertising "partners" the moment you enter a website, like it is in the US, I choose the mildly frustrating cookie banners.
Freedom does come at a cost.
Do not blame regulators for evil forces trying to circumvent those regulations.
It's what the article you are commenting on is all about. Go (re-)read it.
Or you can read what Github has to say about this: https://github.blog/2020-12-17-no-cookie-for-you/
This is how Brexit happened, remain tried to explain this stuff over and over again and no one wants to hear it. They want the cookie banners gone, or the bendy banana rules gone. The EU makes itself an easy target everytime they add more.
If nothing else was learned from Brexit that should have been the thing. There actually isn't a point where you can spend enough money to convince people of this stuff when they don't want to hear it.
European here. I squarely blame the business, and often turn back when hit by a particularly obnoxious banner.
> This is how Brexit happened, remain tried to explain this stuff over and over again and no one wants to hear it. They want the cookie banners gone, or the bendy banana rules gone. The EU makes itself an easy target everytime they add more.
Nah, that's stupid. The bendy banana thing isn't a law, it's a class descriptor. It just says that if you want to sell bananas labelled as "class A" they can't be bent into a pretzel. Because go figure, when a restaurant buys what is advertised as high quality produce, they don't want to get a shipment full of ugly stuff that doesn't look good on the plate.
But you absolutely can sell weird, ugly but still edible bananas. They just have to be described properly.
That's again, what the article is speaking about here.
> If nothing else was learned from Brexit that should have been the thing. There actually isn't a point where you can spend enough money to convince people of this stuff when they don't want to hear it.
Haven't changed my mind in the slightest on that. Brexit was a stupid idea and as far as I can see, the UK failed to profit from it.
You're in the minority. Most people will not think every business is responsible for that, they'll assume they're being forced into it.
> The bendy banana thing isn't a law, it's a class descriptor.
Missing the point. Even with millions of pounds you can't convince a majority of people that is true.
> Haven't changed my mind in the slightest on that. Brexit was a stupid idea and as far as I can see, the UK failed to profit from it.
Continue to miss the point here. It doesn't have to be a good idea, years of meddling made it so people were willing to vote for a bad idea. That's my point.
They've gotten far less annoying as of late, in good part because the EU made it clear annoying the user into acceptance isn't going to fly.
But early on, when websites had the great idea to make me opt out of 78 "partners" one by one, my annoyance was not at the EU, but at the website forcing me to click 78 checkboxes, and a reaction of "WTF? Why are 78 companies being informed I'm reading an article?"
> Missing the point. Even with millions of pounds you can't convince a majority of people that is true.
Did you know the US also has equivalent banana regulations?
> Continue to miss the point here. It doesn't have to be a good idea, years of meddling made it so people were willing to vote for a bad idea. That's my point.
Yeah, to their detriment to the point that it killed pretty much every other eurosceptic movement, and apparently they're not that happy with Brexit anymore themselves either.
You're very much speaking from inside a bubble here. The only people I ever hear blame the EU for this, are on HN.
A bit chicken and the egg, this. Persistent and well funded influence campaigns are precisely how people came to hold the views you describe. I personally wouldn't treat "leave" logic as some kind of particularly organic position. Rather its success demonstrates how one form of persuasion was more effective than another.
This is true. I'm not sure anyone has demonstrated it working the other way though so it seems to be infinitely more effective.
It's happening again now with EVs. "The EU is forcing you to swap your car for an expensive EV with their Euro6 rules." There doesn't seem to be any come back to it at all.
That website basically has an infinite budget and doesn't have to make a single cent. It is also for the group that should have the best understanding of the law. Yet they still give you the cookie popup.
why do you think a banner should not be in this case ? devs are lazy they aren't going to recreate all the service inhouse from scratch. I don't think the dev team has infinite budget either.
- it offers an explanations that cookies are used, and offers a link to read why
- it offers a way to opt out that is as easy as the way to opt-in
- it doesn't prevent the site from functioning
However, I agree that they shouldn't require non-essential cookies to begin with.
It's from a 2002 ePrivacy Directive, which is still in force, but on its way out and therefore less heavily enforced. ePrivacy Regulation is supposed to eventually deprecate it. The initial idea was for both GDPR and ePR to be enforced from the same date, but that obviously hasn't happened.
Yeah it does[0], and no it didn't get updated. ePrivacy Regulation which was supposed to make it deprecated was never voted on.
[0] "Where such devices, for instance cookies, are intended for a legitimate purpose, such as to facilitate the provision of information society services, their use should be allowed on condition that users are provided with clear and precise information in accordance with Directive 95/46/EC about the purposes of cookies or similar devices so as to ensure that users are made aware of information being placed on the terminal equipment they are using. Users should have the opportunity to refuse to have a cookie or similar device stored on their terminal equipment. This is particularly important where users other than the original user have access to the terminal equipment and thereby to any data containing privacy-sensitive information stored on such equipment. Information and the right to refuse may be offered once for the use of various devices to be installed on the user's terminal equipment during the same connection and also covering any further use that may be made of those devices during subsequent connections. The methods for giving information, offering a right to refuse or requesting consent should be made as user-friendly as possible. Access to specific website content may still be made conditional on the well-informed acceptance of a cookie or similar device, if it is used for a legitimate purpose."
Not the ones that the industry has barfed up, and I specifically chose this wording
ePrivacy: "their use should be allowed on condition that users are provided with clear and precise information"
GDPR (among other things): "the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language... It shall be as easy to withdraw as to give consent."
Nothing in any law requires the "accept by default, go through hundreds of checkboxes to opt-out". If anything, those are actually illegal.
Here is another. Work for a company that made a machine used in automation. Designed around US regulations it had a clamping force of 1600 N, same biting force as an adult panda. This thing can take off fingers and arms.
Only know about the 1600 N because it was risk assessed for EU market. After a year of design changes. Moved to fail-safe motors and changed order of operation. The machine no longer leaves someone limbless, it cannot take off a fingernail.
EU requires safety to be engineered into the product while USA allows for deforming machine operators and victim blaming when something goes wrong. Company has discontinued the USA model and only manufacturers the EU model.
EU regulations can help USA citizens when our politicians reject good regulations for personal profit.
Yes, GDPR is absolutely beneficial to citizens. And quite often in invisible ways, since e.g. we never hear about the breach of customer data that didn't happen.
Concretely in this case it seems quite relevant to include GDPR, which consumers seem pretty happy about, and which many Americans look enviously at while their data is slurped up without recourse by credit bureaus and data brokers.
Unfortunately there are only so many GDPR compliance officers around, and they have to focus on the bigger fish to fry.
Me: "No. We are not in the EU. I refuse. I also refuse to abide by Congolese law or Peruvian Navy doctrines. If I break Myanmar PII laws, I will take my chances. EU is no better than anyone else, pushing their crappy laws, I refuse to care about."
Boss: "Ok! Np."
I see you being deliberately antagonistic and strawmanning an opinion you disagree with.
Have you really not noticed how defensive and antagonistic cookie banner supporters become when people say anything negative about it?
Teenagers could have predicted this was the likely outcome.
Whoever wrote it was either incredibly incompetent in not predicting this outcome or intended this outcome.
Actually most popups are already in violation since there needs to be a "no to all" option. Lots of them get fined, but there's just so many.
They should probably make the fine more like: "your domain goes down for 2 months" to be taken more seriously.