←back to thread

332 points vegasbrianc | 10 comments | | HN request time: 1.016s | source | bottom
Show context
diggan ◴[] No.42141994[source]
Correct URL: https://legiscope.com/blog/hidden-productivity-drain-cookie-...

> This situation calls for an urgent revision of the ePrivacy Directive

Shame companies cannot live without tracking cookies, and shame that the blame somehow end up on the regulation, rather than the companies who are the ones who introduce this cookie banner and "massive productivity loss".

You know the best way of not having to put up cookie banners on your website? Don't store PII in cookies. You know the best way of not having to care about GDPR? Don't store PII.

replies(5): >>42142003 #>>42142011 #>>42142019 #>>42142081 #>>42142098 #
Alupis ◴[] No.42142081[source]
> Shame companies cannot live without tracking cookies

Most cookies are entirely benign. Many cookies (or something like a cookie) are required for a website to operate normally. The EU law, while good intentioned, was/is too broad and failed to understand the realities of operating websites. This regulation has caused the entire world to be annoyed with useless cookie banners that 99% of people just reflexively click through - just like all of California's Prop65 warnings are ignored today.

> Don't store PII.

These hard-line statements defy reality. Many websites have legitimate need to store PII.

> You know the best way of not having to care about GDPR?

Don't be in the EU?

Just ignore it. There are no consequences. If you don't have physical presence within the EU - there's little-to-zero the EU can do about it. The EU can think it's laws apply to the world all it wants - but the world disagrees.

replies(2): >>42142125 #>>42142131 #
diggan ◴[] No.42142131[source]
> Most cookies are entirely benign. Many cookies (or something like a cookie) are required for a website to operate normally. The EU law was/is too broad - and has caused the entire world to be annoyed with useless cookie banners.

Give reading the actual implementations a try. You'll quickly notice they actually thought of this. I wouldn't say it's "expertly crafted" by any means, but the banner is for a specific "class" of cookies, not just "abc=123" as you seem to think.

replies(1): >>42142157 #
1. Alupis ◴[] No.42142157[source]
You might try to argue many types of cookies are non-essential - but that would be because you lack experience in this domain.

Website operators have a right to study how people use their website just the same as a brick-and-mortar operator has the right to study how customers navigate their store isles.

The EU law compels a popup for these types of services/scripts and 99% of people just click through them because they are noise.

Lastly - the EU and it's laws don't matter. What are they going to do about non-compliant foreign websites? Nothing.

replies(4): >>42142210 #>>42142220 #>>42142247 #>>42145748 #
2. diggan ◴[] No.42142210[source]
> You might try to argue many types of cookies are non-essential - but that would be because you lack experience in this domain.

I'm not arguing anything, read the directives and implementations yourself, then get back to me. While some might lack experience, others seem to lack reading comprehension. That's fine, we can always learn :)

> Website operators have a right to study how people use their website

In the EU, that depends. As a website operator at a certain scale, you cannot do whatever you want with personal data.

> Lastly - the EU and it's laws don't matter. What are they going to do about non-compliant foreign websites? Nothing.

Yeah, I mean that's cool and all, but maybe you're spending time discussing in the wrong HN submission then? I don't go around in submissions about "Golang is bad" commentating how you wouldn't have those issues if you didn't use Golang in the first place. Not my idea of curious conversation at all.

Obviously EU directives and laws apply in EU

replies(1): >>42142241 #
3. ryandrake ◴[] No.42142220[source]
> Website operators have a right to study how people use their website just the same as a brick-and-mortar operator has the right to study how customers navigate their store isles.

I think reasonable people can disagree about this, and if enough reasonable people think that a web site operator should not have that "right" then they should be able to pass legislation to curtail it.

As a user, I say I should have the right to control what data is collected by what company, and what they should be allowed to do with it. I should be empowered to decide what kind of data is "essential" for a company to collect about me, not the company. Reasonable people could disagree with me, too. These are not laws of physics.

replies(2): >>42142306 #>>42143816 #
4. Alupis ◴[] No.42142241[source]
> Obviously EU directives and laws apply in EU

The EU designed these regulations to be viral and compel the world into compliance. The world does not need to comply, and largely does not. Multinational corporations with physical presence within the EU need to comply - but nobody else does, nor should they.

> read the directives and implementations yourself, then get back to me.

So we're arguing this down-thread of an article claiming our fuzzy European friends wasted nearly 600,000,000 hours last year clicking "I Accept" over and over? Seems like a well-designed regulation that's totally working super-duper well for the EU. Totally cut down on cookies!

5. whstl ◴[] No.42142247[source]
> Website operators have a right to study how people use their website just the same as a brick-and-mortar operator has the right to study how customers navigate their store isles.

This can be done without a cookie banner, as long as no PII is collected for the purposes of that analysis.

6. Alupis ◴[] No.42142306[source]
Why is this different than a brick-and-mortar to you? Do people feel they are "private" when shopping in a retail store with AI cameras tracking patterns and behavior, names and purchases collected at checkout, loyalty "discount" cards to get even more data, etc? Even without your name, they can identify you by recognition alone, aka. an anonymized cookie used to track a specific user's behavior.

Somehow people think visiting someone else's private website grants them privileges to be entirely anonymous - it does not anymore so than shopping in a physical retail store.

If we keep going down this path, websites will require a full ToS/EULA just to access the site...

replies(1): >>42142357 #
7. ryandrake ◴[] No.42142357{3}[source]
For the record, I don't think brick and mortar stores should have an automatic right to surveil and study the personal information of in-person customers without their consent but I agree that ship has largely sailed.
8. what ◴[] No.42143816[source]
You have a right to not visit websites that you think are collecting to much information about you. That’s about it.
replies(1): >>42176510 #
9. BlackFly ◴[] No.42145748[source]
> how customers navigate their store [a]isles.

Sure, physical stores can do that in certain way, certainly they cannot reverse pickpocket GPS trackers into our pockets or stalk us around the city. You can ask your customers how they found about your store but they can lie or simply not answer. Cameras in the store? Fine. Cameras in the store bathroom? Not ok.

It is a legitimate interest to understand where your customers are coming from and this can be done without cookies in an anonymous fashion. Similarly, you can understand what people purchase together in an anonymous fashion. Cookies and PII aren't needed for any of this.

Cookies and PII are only necessary when you are trying to surreptitiously correlate people's purchase pattern with something that you shouldn't legitimately know like their sexuality or any given aspect of their identity.

> Lastly - the EU and it's laws don't matter. What are they going to do about non-compliant foreign websites? Nothing.

Rightly so. But if your third party processor is operating in the EU they will hold them liable for processing the data on EU citizens you send them without consent. That is between the EU and your provider.

10. gljiva ◴[] No.42176510{3}[source]
Yes, and I'm glad I can at least now tell such sites from others. Not allowing such malicious compliance would be better, but this is still an improvement over websites stealing data with no way of telling it happens