This could all be handled by settings in the browser, only if the sites themselves listened to the users' browser preferences.
It makes a bit of sense, since the mailer had already paid, but the main justification (iirc; it was years ago that I read the opinion) was that a postal service should be neutral and trusted to deliver.
The user agent should... be an agent for the user, and be able to perform actions on their behalf.
(The legality of those actions is of course assumed by the user here... if I add an automated flamethrower to my mailbox and burn my bills, well the debt collectors may come regardless if I read them or not - we cannot shift blame to the USPS here).
The second argument has the problem that for the whole thing to work the recipient must also have reason to trust the post office, but here their interests are not considered at all.
The companies on the ads wouldn't do it that way if they were not getting a positive ROI from it. They probably only need to get 2 maybe 3 new customers to offset the cost of mass mailings.
Should USPS be required to respect that owners wishes here?
Sensible decision I think.
Ultimately there’s no good excuse for the banner solution.
Same sort of thing when you log into Wizzair and the check box below the password field is not "remember me" but "subscribe to our marketing emails".
If you build a website without all that tracking stuff and without 'free' services from the data collection companies Google and Facebook, then you have a pretty good chance of not requiring a banner at all, because for logins, etc., you are allowed to use cookies et al. without requiring an opt-in.
But I never saw anybody at the OMR being proud about the state of cookie banners they created...
It’s not written the way it’s written because they’re oblivious it’s written the way it’s written because it’s plain lobbying writing the bill.
For example, there’s little in the way of protections in how the age verification would be protected or prevent the analytics from being sold
Combine that with the character of practically every law written involving data privacy, use, IP, and associated regulation of activity around these since the 1990s. It becomes painfully clear that the interests of private citizens have not had a seat at the table, and the Constitution has been taken as an inconvenience to bypass, not a guiding document.
They can't do anything today as it is a federal holiday but they could do something tomorrow.
But then again if it was to protect children, better support for voluntary age control would be so much more useful as most minors use devices managed/owned by their parents.
But then similar to cookie banners it is just about enabling surveillance
Do binary search and you don’t even need that many calls.
1. Is person older than 50? 2. Older than 25? 3. Older than 18? 4. Older than 9? 5. Younger than 14? 6. Older than 16?
The former are things like "does the user want dark mode", the language you chose to use the website in, the contents of your cart, your login info etc. The latter are for tracking. Typically, the former don't need consent, the latter do. Browsers have no way of telling the two apart.
For example, firefox's "strict tracking protection" setting also breaks a bunch of websites.
Midori is an example for a graphical one, while there is Lynx for the terminal.
It's our duty as informed persons to educate the general population to exert pressure on policy makers to act in the common good - otherwise indeed nothing will change but increasing corruption.
https://www.edpb.europa.eu/system/files/2023-01/edpb_2023011...
Also the law doesn't require anything to be done by the user to reject cookies, to begin with, as that is the default state. I often just delete the cookie dialog from the DOM.
It’s a useful guide on how the law is likely to be interpreted, and likely influences the interpretation itself, but my inner pedant is not satisfied.
Yeah, me too, which is why I challenged OP on the claim that it's 'clearly stated'.
The problem is that people generally want functional and often performance cookies, and then you end up with the stupid cookie banner regardless of marketing cookies.
To not be indistinguishable from "strictly necessary" there would have to be a case where the "functional cookie" actually required consent, right? What case is that and how would you solicit that consent other than some kind of cookie banner?
> “Performance” actually refers to analytics, probably rebranded because users did not want it.
It refers to statistics, but sometimes you do want that, e.g. so the site can tell you how long it took you to do something compared to the average user, or provide those analytics to you. And the fact that this is ambiguous is an obvious problem -- if you get access to the data they collect is that "analytics" or "functional"?
In the face of an ambiguity, most corporate bureaucrats are going to take the risk-averse option, which is to ask for consent in case it turns out to be adjudicated as required ex post facto. The result is quite predictable. If you pass a poorly drafted law, businesses have a general preference for doing something stupid/wasteful/annoying over something that could get them sued or fined.
The case is when you don’t use that feature.
> how would you solicit that consent other than some kind of cookie banner?
Using the feature that requires the cookie is considered consent, same as using the website is considered consent to set cookies actually necessary for the entire website to function. For example, if you click “save settings”, that’s consent to save those settings, there’s no need for a “but am I allowed to save settings?” popup.
You might be tempted to dive into the potential grey area here, and sure, one exists, but (a) that’s why the laws go into 1,000 times more detail than this HN comment, (b) most of it’s not in the grey area, and (c) even in the worst case, making 100% sure is as easy as a checkbox before the button that activates the feature, there’s never a requirement for a blanket “can we do whatever we want” before even displaying the homepage.
> It refers to statistics, but sometimes you do want that, e.g. so the site can tell you how long it took you to do something compared to the average user, or provide those analytics to you. And the fact that this is ambiguous is an obvious problem -- if you get access to the data they collect is that "analytics" or "functional"?
The GDPR calls it “statistics”, but in this context defines the word to mean analytics, not statistics shown to users. If it’s shown to users then it’s either strictly necessary or functional.
> In the face of an ambiguity, most corporate bureaucrats are going to take the risk-averse option, which is to ask for consent in case it turns out to be adjudicated as required ex post facto. The result is quite predictable. If you pass a poorly drafted law, businesses have a general preference for doing something stupid/wasteful/annoying over something that could get them sued or fined.
Businesses are generally risk averse, yes, but don’t mistake knowing a force at play for knowing them all. The “cookie consent banner” was invented and evangelized not by the laws they’re commonly believed to have sprung from but by the IAB, an ad industry consortium counting Google, Facebook, and many others as members. The same organization that organized efforts to prevent third party cookie blocking, and that tried to block the GDPR entirely. The banner norms they created did not even comply with the law until changes a few years ago, the EU just took its sweet time on enforcement.
The average small business, of course, is not in on some grand scheme, but this is where your risk aversion comes in: if all the big players are doing something, and everybody around you is doing it, and you Google it and the first 20 results all say to do it, then the risk averse move is of course to just do it and move on. After all, trusting your own judgement is scary, what if you get sued or fined?