logoalt Hacker News

dijittoday at 3:00 PM15 repliesview on HN

it's an example of malicious compliance by some, and herd mentality by others.

I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.


Replies

bonoboTPtoday at 3:02 PM

That reasoning isn't wrong, though it seems ridiculous when looked at with techie-brain. But if there is a standard expectation of what serious company websites are like, it makes business sense to look like that too. It's like dressing up appropriately to cultural expectations. You can deviate somewhat but you have to strategically spend your weirdness points.

show 1 reply
pbhjpbhjtoday at 3:11 PM

You could have a 'no cookies' badge that links to your cookie policy - 'we use no tracking cookies and so are compliant with EU law ... then list any cookies/local-storage used and explain what they're for.

show 3 replies
nonethewisertoday at 3:48 PM

No one is tanking UX to stick it to the EU. It would be better for them to simply not piss off their users. They are covering their ass.

The obvious conclusion is that when you try to regulate something like this you arent going to get the behavior you want.

show 2 replies
Insimwytimtoday at 6:32 PM

You may float an idea to describe what you've just said in the banner, and have just a "close" button.

E.g. "we don't set any tracking cookies, so we're already compliant with the law even without banner, so there's nothing to decline or agree to".

quruqurutoday at 3:11 PM

Many years ago, I used to make informational websites for small, local businesses and they all wanted the cookie banner "just to be safe", even after explaining they didn't need it.

show 2 replies
patwolftoday at 3:43 PM

I built an ecommerce site long ago, and even though the UI was fairly modern for the time, they insisted we use antiquated styling on the billing forms of the checkout page to help exude trust. As a developer it bugged me because I knew it was just styling, but they probably weren't wrong.

Achterlangstoday at 3:02 PM

I have had the same discussion multiple times at multiple companies. Luckily most of them were fine with dismissing the popup with a timer.

bigbuppotoday at 4:57 PM

In my experience, most people come in two camps: 1) they just click to make it go away because they click everything and would agree to sell their own mother to organ scrappers just to get past the annoyance, and 2) they understand what it's asking and are immediately suspicious.

Aurornistoday at 3:27 PM

> and he said "yeah, but it makes the site seem less legitimate.

He may be right, sadly. I’ve seen the lack of a cookie banner used to suggest that a site was doing something shady or not complying with the law.

Most people don’t have knowledge about the finer details of cookie laws. They’ve been trained to believe that legitimate sites who comply with the laws will implement the cookie banner, and not seeing it feels suspiciously unprofessional.

bborudtoday at 3:18 PM

I'd say just remove it. Don't ask people who don't actually understand the cost of having it there because you will get the wrong answers. Sometimes people just have to do the right thing, take some heat and then everyone can move on. If it has severe consequences then that's probably a good reason to leave anyway.

Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they couldn't deny that it cost a fraction of what we were paying our supplier and that things took minutes to set up rather than weeks. And that they worked a lot better.

Yes, there was shouting in meeting rooms. And yes, people said "you can't do this". Turns out they were wrong. A few years later I mentioned this to Werner Vogels. During a meeting. Where my CEO and CTO were present. And where everyone was feeling very good about us being one of AWS' biggest customers in our region.

So when someone says "you can't do that", sometimes you should make them prove it.

(At the time AWS was a good idea. Today dependence on a US service provider is a harder sell in Europe. The _first_ question you get today is if we can host it ourselves if we need to or if we can use a local service provider.)

show 1 reply
alexpotatotoday at 3:09 PM

Reminds me of the early days of the CANSPAM act.

One of the best indicators that something was not spam was the unsubscribe button.

kermatttoday at 3:36 PM

> but it makes the site seem less legitimate

I have yet to head that cookie prompts are a sign of legitimacy. What business has customers that would think that way?

show 1 reply
vovavilitoday at 3:26 PM

>it's an example of malicious compliance

So how would you do ePrivacy Directive compliance/risk avoidance in a non-obnoxious way?

show 1 reply
0xbadcafebeetoday at 3:48 PM

Good point. The page should have 200MB of assets so that it loads slowly, making it look like there's serious engineering going on.

Mistletoetoday at 4:43 PM

CFO should be fired immediately.