| ▲ | RivieraKid 3 hours ago |
| The cookie thing, I assume it's EU-only, is an example of the EU policy making process being fundamentally broken in some way. If you create a flawed policy and don't fix it many years after it's very visibly obvious that it's a bad policy, something is really wrong. |
|
| ▲ | dijit 3 hours ago | parent | next [-] |
| it's an example of malicious compliance by some, and herd mentality by others. I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate. |
| |
| ▲ | bonoboTP 3 hours ago | parent | next [-] | | That reasoning isn't wrong, though it seems ridiculous when looked at with techie-brain. But if there is a standard expectation of what serious company websites are like, it makes business sense to look like that too. It's like dressing up appropriately to cultural expectations. You can deviate somewhat but you have to strategically spend your weirdness points. | | |
| ▲ | naravara 3 hours ago | parent [-] | | How nice of the EU to have determined for the rest of the world that the “cultural expectation” should be that every business do the design equivalent of wearing clown makeup. | | |
| ▲ | Arainach 2 hours ago | parent | next [-] | | The EU doesn't require banners. Companies could stop selling and storing your data. They could only use cookies when absolutely essential. They could use lots of kinds of UX. This is the equivalent of businesses who put a big visible "20% the state says we have to give our employees healthcare" fee on their bill to throw a hissy fit and hope customers get angry at the government for protecting them instead of the business for exploiting them. | | |
| ▲ | nonethewiser 2 hours ago | parent | next [-] | | Banners exist to eliminate EU regulatory risk. You can try to convince people they aren’t required but its not going to remove any banners. | |
| ▲ | Am4TIfIsER0ppos an hour ago | parent | prev [-] | | The EU didn't have to do anything. The User Agent can already handle everything from denying cookies to blocking requests for certain resources. | | |
| ▲ | wizzwizz4 an hour ago | parent [-] | | The user agent can refuse to store cookies, but it can't do much against supercookies (cookie-like features not knowingly implemented by the user agent programmers) or fingerprinting: you need something like legislation to curb practices like that. |
|
| |
| ▲ | bonoboTP 3 hours ago | parent | prev [-] | | I don't care about this. I explained why for an individual business trying to project seriousness, it makes sense to adopt a banner in the current environment. I didn't say it's nice of the EU or anything of the sort. It's an incentive pressure that exists on an individual company in the current situation. That's all I said. |
|
| |
| ▲ | pbhjpbhj 3 hours ago | parent | prev | next [-] | | You could have a 'no cookies' badge that links to your cookie policy - 'we use no tracking cookies and so are compliant with EU law ... then list any cookies/local-storage used and explain what they're for. | | |
| ▲ | bborud 2 hours ago | parent | next [-] | | That would make you sound a lot more professional too. And trustworthy. (As long as that's actually what happens). When I see these dialogs listing they have 1289723 gazillion vendors they share data with, I know that whoever is in charge of analytics, privacy or both at the company is incompetent. | |
| ▲ | tempest_ 3 hours ago | parent | prev | next [-] | | Best we can do is a full screen model or annoying toast telling users we dont use cookies and click 4 to 7 check boxes to agree. | |
| ▲ | Xirdus 3 hours ago | parent | prev [-] | | But then you can't have tracking cookies. |
| |
| ▲ | nonethewiser 2 hours ago | parent | prev | next [-] | | No one is tanking UX to stick it to the EU. It would be better for them to simply not piss off their users. They are covering their ass. The obvious conclusion is that when you try to regulate something like this you arent going to get the behavior you want. | | |
| ▲ | 6 minutes ago | parent | next [-] | | [deleted] | |
| ▲ | wat10000 4 minutes ago | parent | prev [-] | | They're not covering their ass, they're making a deliberate tradeoff. It's trivial to make a site that doesn't need a cookie banner: don't set any cookies. Modern web devs have probably forgotten, but this is actually the default behavior. Cookies don't get set unless you do something to make it happen. And cookies that you actually need for functionality don't need a banner either. If you're setting a session cookie for logged in users so they stay logged in when navigating between pages, you don't need one. Why, then, does practically every site in existence now have one? Because they set unnecessary cookies. Because they choose to set unnecessary cookies in order to track you for purposes that are not necessary to the actual functionality of the site. Every single cookie banner you see is a big sign that says, "We value our ability to track you for marketing purposes more than we value your time." Apparently they're willing to say that. I still see it as a win. No tracking and no banners would be ideal, but at least the regulation forces them to be honest and up front about what they're doing. I'd rather have tracking and cookie banners announcing it than tracking with zero indication of tracking. |
| |
| ▲ | quruquru 3 hours ago | parent | prev | next [-] | | Many years ago, I used to make informational websites for small, local businesses and they all wanted the cookie banner "just to be safe", even after explaining they didn't need it. | | |
| ▲ | forgotaccount3 2 hours ago | parent | next [-] | | But are you a software developer or a lawyer? Do they 'not need it' because the government provided a way to ensure it's not needed or because your interpretation of the law indicates it's unnecessary? Are you willing to indemnify them for legal costs if your guidance was wrong? Most small business owner's I've spoken to are keenly aware they are only one bad lawsuit away of closing down. Almost no one care's about the cookie banner. Most just mindlessly click to allow cookies and go on with their life. There's almost no cost to having it. | |
| ▲ | Xirdus 3 hours ago | parent | prev [-] | | This website contains chemicals known to the State of California to cause cookies. | | |
| ▲ | zippyman55 2 hours ago | parent [-] | | The Irish Republican Army, even at the height of their conflict, would never have stooped to such a website. |
|
| |
| ▲ | bigbuppo an hour ago | parent | prev | next [-] | | In my experience, most people come in two camps: 1) they just click to make it go away because they click everything and would agree to sell their own mother to organ scrappers just to get past the annoyance, and 2) they understand what it's asking and are immediately suspicious. | |
| ▲ | patwolf 2 hours ago | parent | prev | next [-] | | I built an ecommerce site long ago, and even though the UI was fairly modern for the time, they insisted we use antiquated styling on the billing forms of the checkout page to help exude trust. As a developer it bugged me because I knew it was just styling, but they probably weren't wrong. | |
| ▲ | Achterlangs 3 hours ago | parent | prev | next [-] | | I have had the same discussion multiple times at multiple companies. Luckily most of them were fine with dismissing the popup with a timer. | |
| ▲ | Aurornis 2 hours ago | parent | prev | next [-] | | > and he said "yeah, but it makes the site seem less legitimate. He may be right, sadly. I’ve seen the lack of a cookie banner used to suggest that a site was doing something shady or not complying with the law. Most people don’t have knowledge about the finer details of cookie laws. They’ve been trained to believe that legitimate sites who comply with the laws will implement the cookie banner, and not seeing it feels suspiciously unprofessional. | |
| ▲ | bborud 3 hours ago | parent | prev | next [-] | | I'd say just remove it. Don't ask people who don't actually understand the cost of having it there because you will get the wrong answers. Sometimes people just have to do the right thing, take some heat and then everyone can move on. If it has severe consequences then that's probably a good reason to leave anyway. Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they couldn't deny that it cost a fraction of what we were paying our supplier and that things took minutes to set up rather than weeks. And that they worked a lot better. Yes, there was shouting in meeting rooms. And yes, people said "you can't do this". Turns out they were wrong. A few years later I mentioned this to Werner Vogels. During a meeting. Where my CEO and CTO were present. And where everyone was feeling very good about us being one of AWS' biggest customers in our region. So when someone says "you can't do that", sometimes you should make them prove it. (At the time AWS was a good idea. Today dependence on a US service provider is a harder sell in Europe. The _first_ question you get today is if we can host it ourselves if we need to or if we can use a local service provider.) | | |
| ▲ | docjay 2 hours ago | parent [-] | | I have the same mindset and often did the same thing, but then I thought about my doctor sneaking into my house while I’m sleeping and injecting me with the “good medicine” I had refused in their office. | | |
| |
| ▲ | alexpotato 3 hours ago | parent | prev | next [-] | | Reminds me of the early days of the CANSPAM act. One of the best indicators that something was not spam was the unsubscribe button. | |
| ▲ | kermatt 2 hours ago | parent | prev | next [-] | | > but it makes the site seem less legitimate I have yet to head that cookie prompts are a sign of legitimacy. What business has customers that would think that way? | | |
| ▲ | TheOtherHobbes 2 hours ago | parent [-] | | Not customers. Owners. Although if you've ever worked retail, you'll know that plenty of customers are idiots. Whatever "Surely no one is that stupid!" assumptions you make will be proven wrong no matter what you do. |
| |
| ▲ | vovavili 2 hours ago | parent | prev | next [-] | | >it's an example of malicious compliance So how would you do ePrivacy Directive compliance/risk avoidance in a non-obnoxious way? | | |
| ▲ | dghlsakjg 2 hours ago | parent [-] | | Don’t use a bunch of unnecessary tracking cookies? Completely eliminates the need for a cookie permission bar. | | |
| ▲ | pie_flavor 2 hours ago | parent | next [-] | | The law does not say 'tracking'. It says 'strictly necessary'. If you remember the user's light/dark theme preference in a cookie, that requires notification. (Or rather, what it requires in practice is that you hire a Highly Paid Consultant.) | | |
| ▲ | dghlsakjg 2 hours ago | parent | next [-] | | Okay, but it doesn’t require notification for every user that hits your landing page. If you want to remember dark mode with a cookie, then you can just gate that setting behind a “allow functional cookies” toggle. Getting consent for functional cookies doesn’t have to be done with an intrusive cookie bar on landing. You can request consent as it becomes needed. There’s other ways of complying that aren’t dark patterns. | |
| ▲ | rcxdude 2 hours ago | parent | prev | next [-] | | No, it doesn't. If it's reasonably expected as part of the service, you don't need to gather consent. It's not even personal data. | | |
| ▲ | pie_flavor an hour ago | parent [-] | | The law does not say 'reasonably expected', it says 'strictly necessary'. | | |
| ▲ | rcxdude 24 minutes ago | parent [-] | | Sorry, getting my GDPR and e-privacy terms mixed up. The cookie is strictly necessary for the setting to be saved. The user has specifically requested that the setting be saved by changing it. The opinion suggests this should be a session cookie unless you indicate somewhere prominently next to the setting that it uses cookies to store it for longer. This still doesn't require a cookie banner. What's more, if the 'cookie' is entirely local (i.e. it's never sent back to your own server, e.g. you're using the local storage API), like how this would normally be implemented nowadays, then these requirements don't apply at all. |
|
| |
| ▲ | clan 2 hours ago | parent | prev [-] | | Nonsense. You are correct that people keep stating such things. But it is incorrect. That example would be an essential cookie, also known as a strictly necessary cookie. A shame this FUD is still being spread. | | |
| ▲ | pie_flavor an hour ago | parent [-] | | That's not what various references (and AIs) say. Strictly necessary means strictly necessary. They didn't bother defining it in the law. However, user preferences were called out specifically in the WP29 opinion as something that wouldn't count as strictly necessary if scoped any wider than the browser session. So if the plain English meaning and the drafters' opinion contradicts your opinion, why should I risk significant fines to trust it? |
|
| |
| ▲ | vovavili 2 hours ago | parent | prev [-] | | I am obviously referring to a scenario where tracking cookies would be highly beneficial to expanding the business, e.g. e-commerce. | | |
| ▲ | dijit an hour ago | parent | next [-] | | Don't set a tracking cookie, use of IP addresses is allowed for legitimate purposes (Art 6(1)(f)) as long as they're not stored. At least for GDPR... The only ways to actually track without a consent pop-up are: (1) stay off the device entirely and process server-transmitted data under legitimate interests with a privacy notice, or (2) confine any device storage to what's strictly necessary for the service the user requested | | |
| ▲ | vovavili an hour ago | parent [-] | | This goes to show that the assertion that cookie banners are just "malicious compliance" isn't quite correct. These are significant trade-offs here. | | |
| ▲ | dijit an hour ago | parent [-] | | you don’t need to track users by giving them an ID they send with every request. in fact. you probably don’t need to track users. |
|
| |
| ▲ | ranger207 2 hours ago | parent | prev [-] | | tracking cookies are so obviously beneficial to e-commerce that they passed an entire law to disclose them because people... liked them so much? | | |
| ▲ | vovavili an hour ago | parent [-] | | I don't exactly see how these two statements are contradictory. Policy is about conflicting interests. |
|
|
|
| |
| ▲ | 0xbadcafebee 2 hours ago | parent | prev | next [-] | | Good point. The page should have 200MB of assets so that it loads slowly, making it look like there's serious engineering going on. | |
| ▲ | Mistletoe an hour ago | parent | prev [-] | | CFO should be fired immediately. |
|
|
| ▲ | frollogaston 2 minutes ago | parent | prev | next [-] |
| California should start enforcing cancer warnings in the EU |
|
| ▲ | zetanor 3 hours ago | parent | prev | next [-] |
| The EU said "you have to ask for permission before forcefully sodomizing your users", and webdevs thought "let's ask for permission" rather than "let's not forcefully sodomize our users". Of course, the law could have said "don't forcefully sodomize users", but it seems the west is still under the impression that some people will do the right thing, just because, sometimes. (maybe 20 years ago they would have, just because, sometimes, but they won't now) |
| |
| ▲ | nirava 3 hours ago | parent | next [-] | | Not web devs per se, I’d be hard pressed to find a serious web dev who wanted to “forcefully sodomize users”. Thats a management thing | | |
| ▲ | bborud 2 hours ago | parent | next [-] | | Many of them can't help themselves. I used to have long conversations with frontend developers that "no, when I log on I don't want to be forced through a look-at-the-new-feature-we-made" sequences. And then they went ahead and did it anyway. And usually whatever flag they tried to set to make sure you only saw it once would malfunction, so next time you'd get to click through it all over again. (If you want to tell users about new features, show a unread flag on a notification icon and make it a one-click affair to make it go away. Don't get in users' face with stuff they don't want) | |
| ▲ | zetanor 3 hours ago | parent | prev [-] | | "No." If every webdev who would say no can be trivially replaced by webdevs who won't say no, then yes, it is webdevs. | | |
| ▲ | zamadatix 2 hours ago | parent | next [-] | | You don't really need a web dev to add a cookie banner these days, but you probably still want one to build the actual site (unless it's simple enough to be fully site-as-a-service, in which case there is really no webdev at all). Be it the EU for regulating disclosure and consent requirements, users for being "lazy" and usually just accepting all, or the webdev for not staking their livelihood on denying the banner - I'm sure they'll all get blamed before someone sees the ones actually demanding it be done can be the problem. | |
| ▲ | StableAlkyne 2 hours ago | parent | prev | next [-] | | "Damn, I'm being asked to put a cookie into this site that will maybe result in some guy seeing an ad about a toothpaste he might buy at some point in the future. I'm going to risk months of unemployment and explain to my family why this is more important than eating when I get home. The internet is serious business, they'll understand." -- the hypothetical webdev in that scenario, I guess? | | |
| ▲ | zetanor 2 hours ago | parent [-] | | If you can get replaced over something so minor, it means there's dozens of capable bootlickers lined up and ready to do it as soon as you're gone, so yes, there is a webdev problem. | | |
| ▲ | StableAlkyne 2 hours ago | parent [-] | | > bootlickers Mate, it's just a cookie on a site. | | |
| ▲ | clan an hour ago | parent [-] | | Not quite. That would just be boiling the frog. It is an important fight for our future with our tech overlords. But sure - some will be happy owning nothing. This is really one of those "First They Came" moments. Unfortunately convenience trumps all. So for many "its just a cookie". |
|
|
| |
| ▲ | bonoboTP 2 hours ago | parent | prev | next [-] | | You can try to put the blame on the grunts, like trying to focus on the engineers in the VW Dieselgate, etc, but that is very weak leverage. You have to intervene at the root cause of the incentive. But of course the higher you go, the more there is a blur between legislators and business owners and they won't be harsh to themselves. | | |
| ▲ | clan an hour ago | parent [-] | | So morals are good at a certain pay level? Thank god I am just a minion who now can go home worry free. Yay! |
| |
| ▲ | edoceo 3 hours ago | parent | prev [-] | | It's silly to blame the individual who doesn't have the authority or power at the business making these choices. | | |
| ▲ | clan an hour ago | parent [-] | | Unsure if you are saying there is no collective responsibility or think it is time to bring out the pitchforks? |
|
|
| |
| ▲ | 3 hours ago | parent | prev [-] | | [deleted] |
|
|
| ▲ | mmillin 3 hours ago | parent | prev | next [-] |
| I see a lot of people below arguing that this isn’t the fault of the EU policy but the companies. I think that’s being overly charitable to the policy. While you can be rightly upset with the companies behavior, ultimately policy has to work with the incentives it creates. The policy in its current form allows for meeting requirements with annoying cookie banner opt-outs while keeping the lucrative business of tracking. If we don’t want that, the policy should be changed. Don’t expect companies to go against their interests here, even if some will actually be thoughtful and find a way to do so. The “Purpose Of a System Is What It Does” principle applies, and the purpose of the EU policy seems to be cookie banners for most sites. |
| |
| ▲ | mnewme 3 hours ago | parent | next [-] | | Actually the purpose was not to invade our privacy as much, which we do and there is active lobbying (for example by Google) against any better solution:
https://noyb.eu/en/eu-member-states-and-google-suddenly-want... | |
| ▲ | nonethewiser 2 hours ago | parent | prev | next [-] | | Classic over-regulation producing unintended side effects | | |
| ▲ | clan an hour ago | parent [-] | | Really? Because the industry really respected DNT[0]? Regulations are needed when the kids cannot play nice in the school yard. GDPR is actually not that bad if you read it rather than subscribing to much of the malicious compliance we see. [0] https://en.wikipedia.org/wiki/Do_Not_Track |
| |
| ▲ | tempest_ 3 hours ago | parent | prev | next [-] | | Nah fuck the companies and their horse shit. 99% percent of them intentionally turn the "decline" choice into a 5 - 10 step game of dark patterns even though the EU policy says it should be equally easy to decline. They know its bullshit but they also know the chance that someone will drag them through court is low. | |
| ▲ | naravara 3 hours ago | parent | prev [-] | | I’ve long believed that making companies liable for paying damages if PII is leaked in a data breach would be the best way to stop excessive tracking. If you force them to have to manage user data like they’re handling radioactive waste then the expense and overhead involved is a natural drag on the business logic that drives the bottomless appetite for data collection. They’ll collect it if they actually need it, and they’ll take great pains to secure it. | | |
| ▲ | mnewme 2 hours ago | parent | next [-] | | Actually having worked in big companies,many of them just track everything, but don’t actually use the data, which is even worse. | |
| ▲ | dgellow 2 hours ago | parent | prev | next [-] | | That’s already part of the EU regulations people in the comments complain about | |
| ▲ | Aurornis 2 hours ago | parent | prev [-] | | The most valuable data breach content isn’t your advertising tracking data, though. It would be your payment information, which is orthogonal to most of the tracking data. The black market demand for leaked advertising-related tracking data is basically nil, except maybe in cases where it’s related to something else exploitable or usable for blackmail like if someone frequents cryptocurrency exchanges or porn sites. Nobody cares to pay for black market data about you shopping for towels on Amazon or things like that. | | |
|
|
|
| ▲ | mnewme 3 hours ago | parent | prev | next [-] |
| Actually cookies are not mandated by the EU, but this was the solution the big companies agreed on and now Google and Co try to lobby against better solutions. Check out: https://killthecookiebanner.eu/ |
|
| ▲ | mingus88 3 hours ago | parent | prev | next [-] |
| Most US sites are giving the cookie bag to US users. It may simply be easier for leadership to say add the widget than it is to say we won’t accept traffic from the EU or risk the consequences It feels similar to how CA environmental regs become the national standard simply because the market is so large it’s not worth splitting on it. So they just slap a cancer warning on everything |
| |
| ▲ | qurren 2 hours ago | parent [-] | | 1. It's also a piece of cake to just not display the cookie banner for non-EU IPs 2. If you are a purely US entity with no actual business presence in the EU, you only need to comply with US laws and nothing else. If the EU doesn't like a purely-foreign website, it's on them to set up a national firewall and block it. Case in point 1: It's not on you to comply with China's laws, it's on them to block it if they want to Case in point 2: China's local businesses with no EU presence do not follow GDPR and do not display cookie banners even if accessed from the EU | | |
| ▲ | dgellow 2 hours ago | parent [-] | | GDPR applies to EU citizens data. It doesn’t matter where your business is located in the world, if you process European personal data you’re on the hook. Of course you can decide to ignore and argue the EU doesn’t have jurisdiction | | |
| ▲ | qurren 2 hours ago | parent [-] | | Exactly, they don't have jurisdiction outside their borders. If you don't have a presence there, they cannot subject you to their laws. 1. When is the last time you saw China enforcing its laws outside their borders? Why would EU be any different? 2. China has laws that are directly contradictory to GDPR laws; you may be required to retain data regardless of consent; if your website is based in China you have to follow local laws first before you follow contradictory foreign laws that have no jurisdiction over you. | | |
| ▲ | frollogaston 10 minutes ago | parent [-] | | If you have any presence in the EU, you can be on the hook for EU customers visiting your non-bannered US site. |
|
|
|
|
|
| ▲ | logseman 3 hours ago | parent | prev | next [-] |
| Do Not Track was the right implementation (browser-based, activate only once) and it was sabotaged by ad peddlers. It is bad policy that has been reached after every better alternative was rejected. |
| |
| ▲ | dgellow 2 hours ago | parent [-] | | Do not track has been used by ad companies to track users, it’s one of the datapoints that can be used to identify your fingerprint | | |
| ▲ | frollogaston a few seconds ago | parent [-] | | The idea is that it'd be illegal to do so. Same as how with GDPR it's illegal to track users who denied tracking, even though technically nothing stops you from doing it. |
|
|
|
| ▲ | LastTrain 20 minutes ago | parent | prev | next [-] |
| The banners force sites to divulge that they are tracking you in a very obvious way. It’s fucking great and site owners can make it go away any time they want by choosing not to tack their users. |
|
| ▲ | Havoc 3 hours ago | parent | prev | next [-] |
| Policy making assumed good faith actors - specifically that tracking outside of necessary for website to function to be minimal. Because like…not necessary. It’s only broken to the extent that it collided with a messed up world where websites track even when they don’t need to and then send that to 2000 partners for more profit extraction on top of what the website does commercially. Something is deeply fucked up there and it’s not the EU part. They just make a good scapegoat because the banner is what users see |
| |
| ▲ | ryanfreeborn 2 hours ago | parent | next [-] | | Policy should never assume good faith actors. There wouldn't need to be policy if an assumption of good faith was a valid substrate for the policy. The policy is bad because its authors built it in a vacuum, without any thought or care put towards how its compliance would actually instatiate. This is a consistent problem with EU regulators. The 'tax' the policy levies on invasive cookie use (which I agree is broken and horrific) is forwarded to the user, via this terrible, omnipresent popup. The policy has made the problem worse, by further densensitizing humanity at large to this terrible practice. Shameful behavior by EU regulators and they should absolutely be pilloried for the present state. | |
| ▲ | f6v 3 hours ago | parent | prev | next [-] | | > Policy making assumed good faith actors Let's not paint the policymakers naïve when they're in fact incompetent. | | |
| ▲ | mnewme 2 hours ago | parent | next [-] | | They are not incompetent in general. Most stuff works pretty well in Europe and better than in most of the world. We just focus on the bad regulations | | |
| ▲ | vovavili an hour ago | parent [-] | | >Most stuff works pretty well in Europe Bold thing to say. t. European | | |
| ▲ | mnewme 2 minutes ago | parent [-] | | Not really Bold, yes GDP per capita is lower in many countries than the US, but top tier in almost every other index: low crime rates, high quality of living, childfriendliness, longevity, access to healthcare, liveable cities, culture, etc. |
|
| |
| ▲ | Havoc 2 hours ago | parent | prev [-] | | Let’s not paint the policymakers incompetent when they’re in fact naive | | |
| ▲ | dragonwriter 2 hours ago | parent | next [-] | | So, let’s not paint them as <term meaning lacking the combination of knowledge and skill to do a job effectively> when they are in fact <term meaning particularly lacking wisdom, experience, and/or judgement> Are you sure? | |
| ▲ | f6v 2 hours ago | parent | prev [-] | | If you think about it, a naïve policy maker isn't competent. |
|
| |
| ▲ | Xirdus 2 hours ago | parent | prev [-] | | The biggest positive outcome of the whole GDPR affair is that people finally believe me when I say that yes, they are selling your data to thousands of 3rd parties, and no, I'm not making these numbers up or exagerrating at all. |
|
|
| ▲ | buildsjets 43 minutes ago | parent | prev | next [-] |
| WARNING: Reading his post can expose you to photons, which are known to the State of California to cause cancer. For more information go to www.P65Warnings.ca.gov |
|
| ▲ | ganzsz 3 hours ago | parent | prev | next [-] |
| The most used banners at least have a quick way of dismissing without opting in. When the cases against too obvious dark patterns started that fixed itself at least. |
|
| ▲ | umeshunni 2 hours ago | parent | prev | next [-] |
| It's the EU equivalent of the California Prop 65 warning that tells you that every building causes cancer: https://en.wikipedia.org/wiki/1986_California_Proposition_65... |
|
| ▲ | gdcbe 3 hours ago | parent | prev | next [-] |
| I have yet to see an actual part of that policy which requires a cookie banner though. Seems more to me that it's a combination of (a) websites allowing all kind of fcked up use cases of cookies on their site (most sites do not even need cookies for real) and (b) not respecting http headers that ask to not be tracked... They much rather have a very confusing popup that kinda forces you to accept all :) How convenient. Just like websites also give zero fcks about accept-language header... sure do geoip lookup, so much easier... not |
| |
| ▲ | dd8601fn an hour ago | parent | next [-] | | I’m certain it’s often just the California “literally everything is known to cause cancer” problem. It’s simplest just to put the bullshit everywhere and the dipshit bureaucrats will leave everyone alone. | |
| ▲ | devmor 3 hours ago | parent | prev [-] | | I have always seen the cookie banner as a sort of punishment to the public for daring to have demanded better treatment. “Oh you want consent involved in this interaction? Then we’ll annoy you about it constantly instead of respecting the intent of the regulation.” |
|
|
| ▲ | TZubiri an hour ago | parent | prev | next [-] |
| What is the consequence of not complying with the cookie thing? Assuming you sell out of a jurisdiction outside of the EU |
|
| ▲ | charles_f 2 hours ago | parent | prev | next [-] |
| Once again, as everytime I see this, the policy only dictates that you ask for consent to track personal information from people. The problem is not the cookie banner, it's that every fucking website extracts your pants size to sell it to Facebook. |
|
| ▲ | 6510 2 hours ago | parent | prev | next [-] |
| You are free to set cookies if you need them for site functionality. |
|
| ▲ | iwontberude 2 hours ago | parent | prev | next [-] |
| [dead] |
|
| ▲ | skrebbel 3 hours ago | parent | prev | next [-] |
| Bullshit. There’s no need to track every visitor. Just stop tracking and you don’t need a cookie banner. The only mistake EU policymakers made was underestimating how willing companies were to deface their websites. |
| |
| ▲ | PerryUlyssesCox 3 hours ago | parent | next [-] | | "Every time you visit the websites managed by the European Commission, you will be prompted to accept or refuse cookies." https://european-union.europa.eu/cookies_en | | | |
| ▲ | ryanfreeborn 2 hours ago | parent | prev | next [-] | | >The only mistake EU policymakers made was underestimating how willing companies were to deface their websites. Yes and that is a MASSIVE mistake for a policymaker to commit. They should absolutely be pilloried for their incredible lack of foresight and understanding of how internet companies handle compliance. The policy has set back humanity by further desensitizing internet users around the world to the terrible, endemic use of cookies by most websites. | |
| ▲ | NetMageSCW 3 hours ago | parent | prev | next [-] | | That shows the same fundamental misunderstanding of the modern web that led to the ignorance of EU regulations. | |
| ▲ | zigzag312 3 hours ago | parent | prev [-] | | The policy is both, good, but also flawed. For example, you cannot persist settings, because one policy says that website settings should be ephemeral unless user agrees to persist them. | | |
| ▲ | dgellow 2 hours ago | parent [-] | | That’s not true, it’s even explicitly called out by the EU guidelines. Copy pasting an older comment because it’s really coming up all the time… https://news.ycombinator.com/item?id=49060456 === That's not true and is a very common misinformation people repeat online. You can save user preferences in cookies without any consent banner, if the cookie isn't used for tracking.
See here[0], page 6:
> As stated in Article 5(3) ePD: ‘This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’
0: https://www.edpb.europa.eu/system/files/documents/2024-10/ed...
As long as you do not share that info with 3rd party, and the user requested it, you can store via cookies pretty much whatever you want without the need for a consent screen | | |
| ▲ | zigzag312 an hour ago | parent [-] | | The guidelines you linked state: "These Guidelines do not address the circumstances under which a processing operation may fall within the exemptions from the consent requirement provided for by the ePD". Let's check what "Opinion 04/2012 on Cookie Consent Exemption" [0] says under section 3.6: """ 3.6 UI customization cookies User interface customization cookies are used to store a user’s preference regarding a service across web pages and not linked to other persistent identifiers such as a username. They are only set if the user has explicitly requested the service to remember a certain piece of information, for example, by clicking on a button or ticking a box. ... These customization functionalities are thus explicitly enabled by the user of an information society service (e.g. by clicking on button or ticking a box) although in the absence of additional information the intention of the user could not be interpreted as a preference to remember that choice for longer than a browser session (or no more than a few additional hours). As such only session (or short term) cookies storing such information are exempted under CRITERION B. The addition of additional information in a prominent location (e.g. “uses cookies” written next to the flag) would constitute sufficient information for valid consent to remember the user’s preference for a longer duration, negating the requirement to apply an exemption in this case. """ See that you need to provide provide "information in a prominent location (e.g. “uses cookies” written next to the flag)" to be able to store user preferences in persistent cookies. You don't need consent banner for that (which I didn't say you need), but you need to clearly inform the user. The act of setting a preference together with clear information about persistence counts as a valid consent. [0] https://ec.europa.eu/justice/article-29/documentation/opinio... |
|
|
|
|
| ▲ | sghiassy 3 hours ago | parent | prev | next [-] |
| It’s an EU law, but it impacts us all in America as well… because you know, every fucking website |
| |
|
| ▲ | nathell 2 hours ago | parent | prev | next [-] |
| No it’s not, it’s a testimony to how broken the Internet is. There’s a perfectly valid and simple way to comply with the EU policies, including GDPR, and not impose annoying popups on your users: just don’t set cookies (if you need to have a login, you can ask for permissions at login time) and don’t collect personal data. That a lot of sites elect not to do that is an indication of how they treat the user, not of the brokenness of EU law. |
|
| ▲ | 4ndrewl 2 hours ago | parent | prev [-] |
| It's not a cookies banner. It's a request to harvest your data and share it with third parties for purposes that are not required for the service you're offering. No harvest data to 936 partners? No need for a banner! |