logoalt Hacker News

RivieraKidtoday at 2:59 PM21 repliesview on HN

The cookie thing, I assume it's EU-only, is an example of the EU policy making process being fundamentally broken in some way. If you create a flawed policy and don't fix it many years after it's very visibly obvious that it's a bad policy, something is really wrong.


Replies

dijittoday at 3:00 PM

it's an example of malicious compliance by some, and herd mentality by others.

I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.

show 15 replies
zetanortoday at 3:03 PM

The EU said "you have to ask for permission before forcefully sodomizing your users", and webdevs thought "let's ask for permission" rather than "let's not forcefully sodomize our users". Of course, the law could have said "don't forcefully sodomize users", but it seems the west is still under the impression that some people will do the right thing, just because, sometimes. (maybe 20 years ago they would have, just because, sometimes, but they won't now)

show 2 replies
mmillintoday at 3:11 PM

I see a lot of people below arguing that this isn’t the fault of the EU policy but the companies. I think that’s being overly charitable to the policy. While you can be rightly upset with the companies behavior, ultimately policy has to work with the incentives it creates. The policy in its current form allows for meeting requirements with annoying cookie banner opt-outs while keeping the lucrative business of tracking. If we don’t want that, the policy should be changed. Don’t expect companies to go against their interests here, even if some will actually be thoughtful and find a way to do so. The “Purpose Of a System Is What It Does” principle applies, and the purpose of the EU policy seems to be cookie banners for most sites.

show 4 replies
mnewmetoday at 3:05 PM

Actually cookies are not mandated by the EU, but this was the solution the big companies agreed on and now Google and Co try to lobby against better solutions.

Check out: https://killthecookiebanner.eu/

mingus88today at 3:03 PM

Most US sites are giving the cookie bag to US users. It may simply be easier for leadership to say add the widget than it is to say we won’t accept traffic from the EU or risk the consequences

It feels similar to how CA environmental regs become the national standard simply because the market is so large it’s not worth splitting on it. So they just slap a cancer warning on everything

show 1 reply
logsemantoday at 3:06 PM

Do Not Track was the right implementation (browser-based, activate only once) and it was sabotaged by ad peddlers. It is bad policy that has been reached after every better alternative was rejected.

show 1 reply
LastTraintoday at 5:30 PM

The banners force sites to divulge that they are tracking you in a very obvious way. It’s fucking great and site owners can make it go away any time they want by choosing not to tack their users.

frollogastontoday at 5:48 PM

California should start enforcing cancer warnings in the EU

Havoctoday at 3:08 PM

Policy making assumed good faith actors - specifically that tracking outside of necessary for website to function to be minimal. Because like…not necessary.

It’s only broken to the extent that it collided with a messed up world where websites track even when they don’t need to and then send that to 2000 partners for more profit extraction on top of what the website does commercially.

Something is deeply fucked up there and it’s not the EU part. They just make a good scapegoat because the banner is what users see

show 3 replies
buildsjetstoday at 5:07 PM

WARNING: Reading his post can expose you to photons, which are known to the State of California to cause cancer. For more information go to www.P65Warnings.ca.gov

ganzsztoday at 3:02 PM

The most used banners at least have a quick way of dismissing without opting in. When the cases against too obvious dark patterns started that fixed itself at least.

umeshunnitoday at 3:55 PM

It's the EU equivalent of the California Prop 65 warning that tells you that every building causes cancer: https://en.wikipedia.org/wiki/1986_California_Proposition_65...

gdcbetoday at 3:02 PM

I have yet to see an actual part of that policy which requires a cookie banner though. Seems more to me that it's a combination of (a) websites allowing all kind of fcked up use cases of cookies on their site (most sites do not even need cookies for real) and (b) not respecting http headers that ask to not be tracked... They much rather have a very confusing popup that kinda forces you to accept all :) How convenient.

Just like websites also give zero fcks about accept-language header... sure do geoip lookup, so much easier... not

show 2 replies
TZubiritoday at 4:49 PM

What is the consequence of not complying with the cookie thing? Assuming you sell out of a jurisdiction outside of the EU

charles_ftoday at 4:17 PM

Once again, as everytime I see this, the policy only dictates that you ask for consent to track personal information from people. The problem is not the cookie banner, it's that every fucking website extracts your pants size to sell it to Facebook.

6510today at 4:04 PM

You are free to set cookies if you need them for site functionality.

iwontberudetoday at 4:04 PM

[dead]

skrebbeltoday at 3:01 PM

Bullshit. There’s no need to track every visitor. Just stop tracking and you don’t need a cookie banner.

The only mistake EU policymakers made was underestimating how willing companies were to deface their websites.

show 4 replies
sghiassytoday at 3:00 PM

It’s an EU law, but it impacts us all in America as well… because you know, every fucking website

show 1 reply
nathelltoday at 3:57 PM

No it’s not, it’s a testimony to how broken the Internet is.

There’s a perfectly valid and simple way to comply with the EU policies, including GDPR, and not impose annoying popups on your users: just don’t set cookies (if you need to have a login, you can ask for permissions at login time) and don’t collect personal data. That a lot of sites elect not to do that is an indication of how they treat the user, not of the brokenness of EU law.

4ndrewltoday at 3:35 PM

It's not a cookies banner. It's a request to harvest your data and share it with third parties for purposes that are not required for the service you're offering.

No harvest data to 936 partners? No need for a banner!

show 1 reply