Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Using your analogy, I think what ends up happening is that even companies that don't collect hidden fees will put up a banner just in case.

Not only that, I'm not an EU citizen and I'm not browsing websites based in EU but I'm still bombarded with cookie banners non-stop.



Do you have /any/ examples of websites that don't have a bunch of 3rd party cookies that still have a cookie banner?

Middle managers absolutely love anything with charts and graphs because it makes their decisions feel more scientific. That's why they want tracking software included on their websites. And if the law requires disclosure then a cookie popup is the solution.


My company recently announced a game, and we launched a website for the game. There's no ̶t̶h̶i̶r̶d̶ ̶p̶a̶r̶t̶y̶ e:tracking cookies (I didn't make the site, but I do run it).

Our US based legal team told us we needed a cookie banner if we were going to have visitors in the EU. I pushed back, but I lost, and ultimately it's not my fight.


Sounds like your US legal team is covering their asses on topics they are not familiar with instead of acquiring the neccessary competences.


Your legal team is holding the door open for the day they decide to start tracking.

They probably won't tell you that, tho.


Our legal team is following the checklist that they have that they know is pre-approved


OK? Does that contradict what I said?


Which was probably written (even if not by the legal team, but someone they consulted) with an eye towards keeping more data than legitimate interest allows under GDPR.


Thanks for this, it seems a lot of cookie popups are there just due to cargo culting


I don't quite think Cargo Culting is the right label for it. It's not just because everyone's doing it. My experience when legal meets code is that common sense, intent and what is actually allowed go out the window, and cover-your-ass wins. My experience with Legal has been that they default to no "just in case" for every question you come to them with.

It's a battle to get them onboard to not taking the safest possible approach, so you only want to fight that battle when it's a kingmaker of an opportunity.


Yeah, people often approach legal in the wrong way: people often want to ask "is this OK?" and have the lawyers say "yes", but basically no lawyer is going to say that for almost anything. Instead you need to ask them to explain what the risks of different courses of action are and take a view as to whether they are important or not.


That's been my experience, but unfortunately _that's_ where cargo culting comes in. As part of $NEW_WEBSITE_CHECKLIST we have to "check with legal" which inevitably involves a laundry list of stuff like this, and the default is to accept what legal says, unless we _really_ don't like the answer at which point we're going to do it anyway...


Legal counsel is there to advise, not to design product UX. Some companies have bonehead policies like “you must develop whatever Legal advises” but that’s a choice the company is making. Sensible companies treat their in house counsel as advisory, and weigh the risks like they would weigh any other risks.


The funny thing is that most of the CYA cookie banners... are in themselves GDPR violations


It is not about third party or not, but what it is used for. Consent may be required even if there are no cookies at all.


> It is not about third party or not

you're right, I said third party, but I actually meant tracking. I actually went and checked, and our only cookie is the cookie for if you've seen the cookie banner or not...

> Consent may be required even if there are no cookies at all.

For what?


It's not about cookies. Tracking without cookies also requires consent.


See my original post. Our US legal team said that we need the banner if we have visitors from the EU, not if we're tracking them.


>Our US legal team said that we need the banner if we have visitors from the EU, not if we're tracking them.

This actually makes sense - because if you didn't have the cookie banner then some fucking weirdo would come to Hacker News and make a self righteous post about how you're "tracking residents of the EU without their consent and abusing them" (even though you're not). Instant karma. Next thing you know these weirdos and their mob are reporting you to their government and you're dealing with government inquiries and more legal expenses trying to prove your cookie-less web 1.0 site doesn't "abuse people."

The banner placates them.


Do you have any basis at all for such an absurd claim? The law actually works in the opposite direction (kinda):

You may use "legitimate interest" cookies/tracking without saying so, but as soon as you show a privacy dialog you actually have to disclose everything you're doing including legitimate interest.

Basically by having a list of what youre're doing with your user's data you're giving up your right to do anything not listed.


> For what?

GDPR actually doesn't specifically mention cookies at all. Tracking is what's illegal, not cookies.

Let's say you keep website logs with IPs on them, and you do analytics for non-essential purposes. You can do this under GDPR, but you must gain consent from the user before logging this PII.

It actually is completely and totally orthogonal to cookies. Some cookies are fine without consent. Some things that are not cookies are illegal without consent.


It only took two minutes to find at https://www.schwarzkuenstler.com/ and I'm sure I can find a dozen more in half an hour.

Germany is a bit litigious w.r.t. internet or privacy, so the combination---cookie consent---is a doozy. Nearly every German website that does anything will have a consent notification, and the slightest misstep (e.g. using Google Fonts without asking permission) can be punishable.


Their privacy policy states they use Google reCAPTCHA, which requires disclosure.


True, I hadn't noticed that at first glance, and I didn't see that as a third-party cookie in my site data. Nonetheless, I regularly see cookie warnings on sites with purely first-party cookies or even "just" session storage. (Mostly, I have been alert to this for the past year as I've started making non-personal web sites in Europe.)


I think a heck of a lot of smaller sites just cargo-cult the pop-up. Either because they misunderstand the law or because of overly cautious lawyers.


Or because of FUD from people interested in undermining privacy protections.


Aggregate data is not considered personal data by the GDPR.

Managers and everyone else can have charts and graphs without retaining personal data.

The processing of personal data prior to anonymisation to turn it into aggregate data, that part needs protection. But you can do it in a variety of ways that don't require personally invasive tracking.


> Not only that, I'm not an EU citizen and I'm not browsing websites based in EU but I'm still bombarded with cookie banners non-stop.

Again, that's the fault of the companies putting those up, they could make it opt-in to collect your data, they could just put a small notice on the footer with 2 simples links "Accept all/Reject all". But they chose, they decided to pester you with those banners as annoyingly as possible to make you have exactly the reaction you're having.


The fact that companies are doing that says more about the bad law than the companies which is exactly Paul Graham's point.


So the problem is that the legislator did not expect companies to be even worse assholes than they already were...?

Laws are not borne in a perfect state; very much like programs, sometimes you need a few versions to see how the system actually works in practice and fix a few bugs. The fact that v1.0 has such bugs is not a good reason to just give up, nor it's an indication that the programmer is bad at programming.


> companies to be even worse assholes

All companies? Every single company with a website even if without any trackers or ads?! All companies are evil and the single law that triggered their evil behaviour is good. Sure. Ever heard of Occam's razor?


Companies who don't track don't need any banner or popup.

> All companies are evil

No, but many, many companies are sociopathic assholes that exist just to make a buck. Otherwise we wouldn't need these laws.


All companies exist just to make a buck. And in the process they serve us with literally every single product and service we are using every second of every day. They play by the rules we put on them, making their life easier or harder, and in the process making our life easier or harder. Like this bad cookie law.


The law is pretty crystal clear. In many cases the issue is that websites are outsourcing their tracking to ad companies, which in turn apply those banners indiscriminately because that's in their interest.

That being said, all the dark-pattern banners actually break the law. The problem, if anything, is lack of enforcement of the law.


  The law is pretty crystal clear. In many cases the issue is that websites are outsourcing their tracking to ad companies, which in turn apply those banners indiscriminately because that's in their interest.
You think a small company should roll their own tracking software? A mom and pop website that wants to track its conversion rate on its little eCommerce site?

Come on. Be realistic.


It is the companies that suck, and Paul Graham is (quite literally) invested in the suckage, wherefore this dumb tweet. Which, if one wanted to create an ad campaign for that eternal Upton Sinclair quote, couldn't have been done much better.

(Thanks for the site though, Paul)


Paul is very unlikely to be invested in tracking unless he has some shares in Google/Facebook. Startups in tracking aren’t really a thing


I expect most startups "integrate" their regular revenues (if they have any) with some sort of adtech deal.


Any source for those allegations or is it only your imagination?


Or it says more about the manipulative intentions of the companies than anything about a good law.


What exactly is bad about the law that allows companies to do the annoying cookie banner?


"this is what you get for trying to handle us with kid gloves" is an understandable reaction/blowback from advertisers but I don't think it's something we should be giving any real weight or merit.

it's also generally an indictment of the modern neoliberal regulatory approach in general. asking people nicely to follow train safety regulations etc isn't going to get you results. even fines/penalties largely end up just as cost-of-doing-business (even in the EU). if you really want behavior to go away, make it illegal and give people at the top Sarbanes-Oxley-style legal culpability if it happens on their watch.

again, if you want to know the right way to set incentives so that people don't do a thing, you need only look at the way rich people want their money handled. you can bet that ripping off rich people is an ultra-mega-crime and doesn't just get a 1%-of-the-takings slap on the wrist. And lo and behold SOX does actually hold important people accountable as a result, not just some fall guy at the bottom.


what a ridiculous point of view.

do you think the same thing about laws against murder?

about fraud?


I've got to admit, I'm unclear what the equivalent of a cookie banner for murder would be.

This criminal uses murder! If you continue to interact, you consent to being murdered.

Murders you anyway


[flagged]


> Please stop defending the behavior of shitty companies. At the very least, I hope you're getting paid for these comments.

Please don't do this on HN.


For your first point I disagree, my companies don't track and we don't have banner cookies.

On your second point, that is again a choice of said companies, not a problem with the law. The GDPR has proven very well that if they cared, they can segment who is affected or not, and not just big tech lots of random local news site and the likes are doing it just fine.

So again, you're aiming at the wrong culprit.


Just been in Europe last week (I live in US): you have no idea what a nightmare internet is in Europe. You are only seeing a side effect here.


> what a nightmare internet is in Europe

I live in Europe; I don't experience this "nightmare". Would you care to expand?


Sure. The nightmare is that every single time you open the browser on a website you have to go through the data tracking preference for that website. It's a lot of work to avoid being tracked (companies are obviously using dark patterns there) and when you do it 20 times a day it gets frustrating quickly and collectively a big waste of human time.

Now I am not saying the US doesn't have a problem. They just don't have GDPR and most website don't ask you for any permission to track you. So the experience is generally smoother (with the occasional tracking popup).

Ideally there should be a way for me to broadcast my willingness to share my data and not allow dark patterns to try to change my opinion. But the GDPR does not cover that and allows websites to drive you crazy until you click "YES, Track me"


I think your problem is that you're accessing US websites from Europe, since those are what you know. European websites are a lot less annoying, they actually care about the customer base here.


If you are using a browser provided by an ad company surely being nagged to death to provide data they can sell is the expected outcome? You could use Firefox, which can disable most cookie banners [0].

[0] https://community.mozilla.org/en/campaigns/firefox-cookie-ba...


You mean we can use the development version of Firefox, which gets almost daily updates and also breaks things a lot of times. An important caveat.


No, I don't mean that.

The post is dated 2022. The feature became generally available in v120. Stable is v123, so it is available now. It's gated, so you still have to enable it as described in the post.


> every single time you open the browser on a website you have to go through the data tracking preference for that website

This is not my experience. Perhaps the websites you favour are exceptionally abusive.

> a way for me to broadcast my willingness to share my data

That's the opposite of what most people want to broadcast.

> But the GDPR does not cover that and allows websites to drive you crazy

Apparently your view is that GDPR should not allow that, i.e. it isn't strict enough. I'm inclined to agree.


As someone who's lived in both the US and Europe during the past few years... GP is full of shit.


It's really not much different.

Source: Living in Europe


It's crazy how censored the internet is too, you need a VPN to access even piracy adjacent sites in Germany. Unheard of that an ISP would block a website in the US without the FBI itself taking it down.


You don't need a VPN, just a different DNS server.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: