Visitor Tracking Without Cookies (or How To Abuse HTTP 301s)
scatmania.org
scatmania.org
http://www.aboutcookies.org/default.aspx?page=3
6. - (1) Subject to paragraph (4), a person shall not store or gain information, or to gain access to information stored, in the terminal equipment of a subscriber or user unless the requirements of paragraph (2) are met.
(2) The requirements are that the subscriber or user of that terminal equipment -
(a) is provided with clear and comprehensive information about the purposes of the storage of, or access to, that information; and
(b) has given his or her consent.
The Dutch minister spoke of (freely translated): "Everything that reads or stores your data on your appliance, without permission, without a functional goal other than tracking".
Some techniques like browser fingerprinting ( https://panopticlick.eff.org/ , but also possible with http://modernizr.com/ ) don't store anything on your appliance, but would still fall under the "reading your data from your appliance" part of our law, if used for tracking purposes.
You would need permission to use the "grey" technique from the article. Even if you were to store that data in aggregated form.
As you can see, these European laws border on absurd.
Also if someone does not consent to storing data on their computer and it's necessary to store it to get it to work, then they cannot use your site. The law doesn't require that your site work fine without local data. That would be silly.
Kissmetrics was actually using it in the wild for a while, but I think they stopped after there was a public outcry.
http://www.wired.com/threatlevel/2012/10/kissmetrics-trackin...
Rather than a bunch of ad networks and analytics companies finding workarounds, I'd rather sites just stand up to this obviously flawed rule. It's ill thought out, and I have no plans to offer one of those annoying "Hey, this site uses cookies, just like every other site on the internet!" alerts.
If your visitors have to log in you might as well show them such a message. If they don't have to log in, there is probably also no reason for them to accept your cookies.
While almost every site on the Internet uses cookies, most of them are of no benefit to a visitor. And yes, technical solutions exist, but they are not really suitable for a vast majority of the population that simply does not know about cookies, and which cookies to accept.
It hasn't significantly improved privacy for anyone but has made the Internet a bit more annoying.
Personally, I get annoyed when I'm badgered by notices, and sometimes even modal windows, for cookie notices. Of course your site uses cookies, it's just like every other site on the web. I shouldn't have to agree to a notice every time I visit a new domain. I have a browser toggle and if cookies offend me for some reason I can disable them.
Look at what cookies websites actually store.
When you go to many sites there are a bunch of other people spying on you and setting cookies that you didn't even know.
I don't agree with the implementation of this law, but I certainly agree with its intent.
Not that you can really tell, anyway - it's impossible to know just by looking at a cookie what it's really being used for, or what data on you is being tracked. There are certainly good reasons to give cookies to users that have not logged in yet, though - one example that springs to mind is a CSRF token.
Lastly, what is this meant to achieve? The aim is to crack down on activity that was already illegal before this law came in. Sites that were doing naughty things and tracking users illegally aren't exactly going to stop because they now have to show a notice about cookies. Before the law came in I said "they'd just not bother showing the notice" but frankly, the could abide by it - users would just click "yes" anyway out of habit!