chrismorgan
2 days ago
The other approach to killing the cookie banner is simply to declare that such a thing cannot constitute “informed consent”. (Perhaps: “ticking a checkbox and/or clicking a button cannot constitute informed consent”; and see what they try next.) From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way. Just as shrink-wrap licenses and even simple contracts have at times in some jurisdictions essentially been neutered, so that only terms that a reasonable person would expect to be there are enforceable, at which point it becomes obvious that the whole thing needs tearing down in favour of standard licenses/contracts. In the Australian state Victoria, for example, there are standard rent and property sale contracts; for renting you must use that contract <https://www.consumer.vic.gov.au/housing/renting/starting-and...>, and I got the impression that residential sales practically always use the standard contract.
But of course it’s impossible to convince someone of something when their livelihood depends on their not understanding it.
kleiba2
2 days ago
> it’s well-understood that very few people actually read those things, they just want to get them out of the way.
This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept" on every single cookie banners that pops up, without ever wasting a second even reading what they're accepting. It's mind boggling to me. Sure, I'm in IT, so surely I'm more aware of data mining, profiling, and other privacy-related aspects. But in many cases, you could just click "reject" and the banner would also disappear...
To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
readread
2 days ago
"Accept all" always makes it go away immediately.
Some variant on "reject" takes more effort like 70% of the time. Which is on purpose, of course. The ones that aren't maliciously-complying have a "necessary only" button that insta-closes it, but tons pretend that you might want to allow some spying but not all of it and make you go through another screen if you don't just "accept all".
> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
Then it'd be possible to default it to "nope" (Firefox, and perhaps Safari, might do this) or to allow a "never, anywhere" setting the first time the question is asked, and malware and spyware vendors know that'd mean a much larger proportion of denials.
jackson1442
2 days ago
"necessary only" also tends to have a malicious compliance aspect where they don't store a cookie recording your preference and show the banner on every single page until you click accept.
remus
2 days ago
Perhaps I am overly optimistic in thinking this is just incompetence.
smallmancontrov
2 days ago
Yes, you are. The legislative process around EPD/EPR fully anticipated the malicious compliance and it became a back-and-forth political football long before anything was passed. The legislators were never dumb and the corporations were always greedy+powerful.
whstl
2 days ago
I had one of the providers recommending us that we leave the "Decline All" button out of Europe, since it's not widely prosecuted, buy recommended that we add it to California, since chances are slimmer.
Naturally in a camera meeting with a "don't tell anyone we said that" appended right before.
The marketing people in the meeting were very angry that California was "doing it to them".
Aerroon
2 days ago
If they fully anticipated this then surely they could've fully anticipated how annoying and useless cookie banners are?
There is nothing stopping a website from using cookies regardless of the banner. If they are outside EU jurisdiction then there won't be any consequences either.
The legislators were and are dumb. They have wasted an enormous amount of collective time for no benefit. Big corporations continued doing what they were doing and nefarious third parties could still track you.
smallmancontrov
2 days ago
> surely they could've fully anticipated how annoying and useless cookie banners are
They did. The laws were airtight in this regard. They simply lost -- whether through a last minute "tweak" or undermined enforcement mechanism I do not know, but I do know that the current state of affairs was fully anticipated and headed off at the point where I reviewed the proposal. Your vitriol is bass ackwards -- the lesson is to strengthen the walls between corporations and the legislative process and support enforcement mechanisms, because those were the places where the process failed. Not the intelligence of legislators. Otherwise you will keep losing to the corporations, and you will deserve to.
unscaled
2 days ago
The law is airtight. Acceptance must be informed and freely given (this includes forcing through dark patterns and annoying banners that force you not to read), and withdrawal should be as simple as acceptance.
GDPR article 7 and its various recital already include that. GDPR wisely doesn't get into technical details like "cookie banners" anywhere, but various national agencies did set guidance and it's usually quite explicit: Rejection must be as simple as acceptance and reject buttons or link must be as prominent as the accept buttons and links.
For example, CNIL, the French data privacy authority, clearly says[1]:
"The CNIL has received complaints about dark patterns on cookie consent banners encouraging data subjects to accept cookies.
As a reminder, with certain exceptions, cookies can only be used with the consent of data subjects. Moreover, rejecting cookies should be just as easy as accepting them."
And gives examples of dark patterns such as different button sizes, multiple accept buttons, hidden reject buttons, etc.
The law and specific guidance is pretty unambiguous. This purely an enforcement problem. The regulatory bodies do not have the resources to go and chase most individual companies, and the non-profit NGOs that go after the violators apparently don't have the budget to make enough impact and scare companies into compliance.
[1] https://www.cnil.fr/en/dark-patterns-cookie-banners-cnil-iss...
Aerroon
21 hours ago
>Otherwise you will keep losing to the corporations, and you will deserve to.
I get a cookie pop up on https://europa.eu
This is a website that effectively has infinite funding and has to make zero money. And I still get a cookie pop up.
Is this also the fault of corporations?
The EU isn't some kind of hero saving us from evil corporations. Just look at the recent customs duty that makes things much more expensive for regular people.
soco
a day ago
Sometimes the folks commenting here are exactly those corporations, so there.
inigyou
a day ago
We are on news dot rich corporate billionaires dot com, after all.
tikhonj
2 days ago
Well, maybe it is... but then the PM never prioritizes testing or fixing the problem. They're not intentionally trying to get more people to accept cookies, it's just that there are always more important features to build and fires to fight, and fixing the cookie banner won't move any of the metrics executives are breathing down their necks about, and it won't look good in the perf packet...
But of course, designing the system that pushes people to make this sort of decision was absolutely intentional.
So even when it's incompetence, it's still malicious, just in a way that obscures the explicit decision-making that led to the result.
bshacklett
2 days ago
I don't see that as malicious. Is my consent record "strictly necessary"? No. Don’t get me wrong. I’m sure they love that, but if sites saved that preference when only necessary was selected, I’m sure a bunch of people would be screaming that they weren’t following the law.
jeremyjh
2 days ago
The entire banner is malicious. They don't need consent for necessary or functional cookies. They only need consent to track you - at no benefit to you ever.
novafunc
2 days ago
I don't think anything is actually "necessary" if you want to be strict on definitions.
I think it's absolutely fair and unlikely to be illegal to use a cookie to remember cookie preferences. Unless the cookie value was not yes/no, but something like a precise timestamp that could be used for uniquely identifying.
tremon
2 days ago
Yes, it is strictly necessary to properly honour the user's choice. Not storing a rejection of consent but storing acceptance violates the GDPR because it creates an asymmetry between the effort required to accept vs the effort required to reject user data processing.
flotzam
a day ago
The malicious compliance aspect is that they're not offering a choice between "tracking" and "no tracking", but bundling "no tracking" + "painfully degraded functionality" (like repeating the question on every page) = "strictly necessary cookies only"
Gigachad
2 days ago
There is no legal requirement to ask for consent for first party functional cookies. The cookie banner is only for invasive 3rd party trackers.
PunchyHamster
2 days ago
which they can be sued for as that's not compliant way to handle it. Just that nobody bothers
inigyou
a day ago
IIRC it was ruled by a court that "reject all" must be as easy to use as "accept all", but nobody actually follows it because enforcement is lacking.
xp84
2 days ago
It literally does not matter what you pick on these things - most of them don't work anyway. Think about it: Of course they don't. All the third-party javascript is already on the page. Anything you do inside the sandbox with UI provided by, usually, some other third-party, can't just magically force all that other code to behave in a specific way, unless someone has done a great deal of work to integrate the cookie banner code. If the first-party site were that competent at instrumenting every bit of third-party code the marketing department threw at the website department, they wouldn't even need the third-party cookie banner vendor in the first place.
Clicking those "REJECT!" buttons might make you feel empowered, but it's pointless. Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you.
The whole thing has always been a problem to be properly solved by the browser, and it's probably just the fact that Google makes the only browser that matters, that it's been foisted upon every website owner, who mostly just wants basic analytics and to track conversions from the ads they run, and isn't "selling your data."
The browser is your user agent. If it's sending any information up to web servers on every request that isn't okay with you, why are you using it?
zelphirkalt
19 hours ago
While I don't usually laud Wordpress plugins, I know of at least one WP plugin, that gets it right and that allows one to specify all kinds of scripts and stuff to load after consenting. Of course people still manage to use that wrongly and load third party stuff before consent. What I want to get at is, that one of the most widely used things to make websites, that even businesses use, has all the means to do it correctly, but businesses decide to do a shitty job and do illegal shit. Very often at the behest and nagging of marketing departments, who are chasing pointless metrics and "KPIs".
zugi
2 days ago
> Just set your browser to delete all the cookies at the end of the session except for whatever sites you want to allow to 'remember' you
Exactly. I use the "I don't care about cookies" extension, which rejects most cookies automatically without me having to see the popups. But even accepting cookies is fine - I'll be closing my browser soon anyway and they'll be gone.
tremon
2 days ago
I'll be closing my browser soon anyway and they'll be gone
Sure, your browser cookie will be gone. But you have already allowed the server-side identifiers of your session to be used for whatever purpose, including reconstituting increasingly larger parts of your identity over multiple disconnected sessions. Please don't make the mistake of thinking that clearing your cookies afterwards is the same as rejecting all server-side processing.
zugi
a day ago
Sure, but "rejecting all server-side processing" is basically trusting the website to honor my wishes. I don't put much faith in that at all.
They'll have my IP and browser fingerprint. Using Firefox mobile narrows me down to 1-2% of the world, but also lets me run ad blockers and noscript, to block some of the more troublesome trackers.
It's all tradeoffs...
unscaled
2 days ago
Despite this being called a "cookie banner", this is not _just_ about cookie. When you click "Accept all" you are giving your consent to any form of tracking and information sharing mentioned in the details. The site you visit may share everything they know about you with any third party they mentioned. They can even use fingerprinting (if you've agreed to it) to keep tracking you after you've deleted the cookies.
badestrand
a day ago
And then? What's the practical, concrete, real-life consequence for me? Nothing, not even a bit more relevant ads as these run into my adblocker anyway.
zelphirkalt
19 hours ago
It's not only about you. It is about a practice, that is manipulative and even endangering certain kinds of people. By not caring about these things, we as a society have made the Internet a dangerous place in some regions for journalists and other types of people.
cowboylowrez
a day ago
Yeah honestly I just assume sites fingerprint and track to the extent the visitors allow.
zelphirkalt
19 hours ago
The naming of that extension is misleading then. You do care about cookies ... not ending up on your device. Does it really reject the cookies, or does it just default to accepting everything, because "one doesn't care"?
inigyou
a day ago
Yeah they can, they can also get fined 2% of a year's gross revenue for doing so
gnatolf
2 days ago
Well, joke's on me: I use that extension too. And I never close my browser.
donaltroddyn
2 days ago
I think you're right that many (most?) CMPs are broken, though usually not deliberately. Most try to gate analytics and ad tracking on consent, just often misconfigured. The common exception is companies that deliberately hide Reject All, which is not complaint
My company scanned 209 European regulated sites in June, and roughly 7 in 10 had tracking that wasn't correctly gated by consent. It's rarely indifference, though. DPOs in the EU hold too much weight for that. It's usually a tag added that was never wired into the CMP or something added by a dev or LLM without going through proper review
Full disclosure: I run https://consentmark.com, which measures what tags actually fire under each consent state to create evidence packs companies can show regulators
TeMPOraL
a day ago
I don't buy it. 70% of the CMPs being "misconfigured" tells us that even if these panels were broken by design, the companies using them must all conveniently not notice this. Strange, given that even a small risk of large fines or prolonged legal process with public entities would warrant someone paying at least a moment of attention to this. I suspect they are, and the choice of leaving things misconfigured is deliberate.
> something added by a dev or LLM without going through proper review
FWIW, this was a problem long before LLMs were a thing, and it didn't get worse with LLMs. If anything, I'd expect LLMs to get it right by default, because ones ~everyone is using are all trained straight, they won't just silently read between the lines and write code/configs to facilitate one's illegal business model.
donaltroddyn
a day ago
> I suspect they are, and the choice of leaving things misconfigured is deliberate.
That honestly doesn't fit our data or my experience. In our scanning, about 60% of the misconfigured sites had a CMP with blocking active but one or two tags bypassing consent controls
Generally those misconfigurations aren't valuable to the business. We don't see for example lots of ad targeting and conversion tracking firing without consent on an otherwise compliant site.
What we do see is things like sites with CMPs generally working, but one or two analytics events tags firing because consent wasn't properly added to a trigger, or embedded Youtube cookies set without consent, or unexpected data from a URL or query param being accidentally ingested by tracking, or devs adding performance monitoring or observability tools to applications without realising the compliance implications
There's not much business logic in paying for a CMP, blocking your own ad stack, but then letting three analytics events pass through
> FWIW, this was a problem long before LLMs were a thing, and it didn't get worse with LLMs.
This isn't supported by our experience. In the last 18 months, we've seen a big increase in ungated tracking that we catch in CI (albeit with overall much higher velocity in general). LLMs will happily add non-compliant tracking to sites, often following defaults that might be acceptable in the US but not EU. If you push back, they'll also happily implement compliant tracking, but it's definitely not the natural default you can rely on
But your comment left me curious, so I just ran an experiment via Codex -p (gpt-5.6-sol) and Opus 5 via Bedrock
Codex returned the vendor quickstart on 5 of 5 neutral prompts. It gated properly when told the company is Irish, with full Consent Mode v2 defaults denied, GA4 only mounting after consent, with a reject button
So models can produce compliant/non-compliant code based on the context you give them, which reflects what we've seen in industry
Our business is giving devs and increasingly LLMs efficient tests to check the tracking they add is as expected for the EU and then providing signed evidence packs that prove that behaviour at a given time
xp84
a day ago
Another tiny data point example: A previous company used Stripe for a very niche feature (most companies who used our product didn't ever enable it) but having the SDK in the bundle drops their "anti-fraud" cookies, whatever they are). That is exactly the kind of thing that a CMP won't be able to fix without deeper engineering work, and which doesn't actually matter anyway because no one is profiting from that -- but that's the kind of thing that a company could be sued or fined for. A complete distraction from what actually matters.
ablob
2 days ago
It's a nag-box that appears every time someone visits a new website. Of course people are going to click it away as fast as possible. In the few cases you repeatedly visit a website one might want to reconsider, but by then it's out of mind due to not being shown after giving consent.
It is known that warnings and pop-ups that show up almost all the time yield diminishing returns. I think it was named "normalization of deviation" by some folks in a blog a while ago, and I believe that name fits. If you get warned about missing https all the time, or that something might be dangerous (even though it does precisely what you want it to do), it will loose its effect by the time you actually need it.
You can argue this is malicious compliance, but if you want it to go away it would probably be easier to go for banning tracking and personalized ads altogether. Eliminate the reason for this behavior, so to speak.
fnord123
2 days ago
> To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning.
There is one. It's a DNT header. Knucklehead websites ignore it.
sumeno
2 days ago
Including the one we're posting on
yjftsjthsd-h
2 days ago
What tracking does HN do?
sumeno
2 days ago
A fair bit: https://www.ycombinator.com/legal/
yjftsjthsd-h
2 days ago
That is for Y Combinator. I would characterize HN as less than a fair bit;
> Hacker News Information: If you create a Hacker News account (ID and profile), we do not collect any Personal Information unless you choose to provide your email address and/or information in the "about" field (“HN Information”). Your submissions to, and comments you make on, the Hacker News site are not Personal Information and are not "HN Information" as defined in this Privacy Policy.
xp84
2 days ago
Because it doesn't mean anything specific and breaks entire business models (merely logging that you landed from an ad click and seeing if you check out counts as 'tracking,' doesn't it?) if interpreted purely literally. So, the only way to treat it is to either ignore it or to just send back an error code and message that says "Sorry, having some tracking is the condition to get this free content. Accept or don't."
Like it or not, the Web is a two-way street, meaning that the server end of the transaction doesn't owe the client end anything in particular unless there's some relationship in place (like a payment). It appears the "just ignore it" matches the intent of most web users, though, since an overwhelming majority of web visitors accept a bunch of spammy ads + free 'content,' and a slim minority pay for ad-free alternatives.
windward
2 days ago
>breaks entire business models
So do car alarms.
I'm not convinced this is a business model I want to exist. We had an internet before it, and Google, and Facebook. I'm increasingly sad we can't return to it.
xp84
2 days ago
Let me be clear, I can't stand the social-media industrial complex and the advertising universe. I've seen the bottom that we've raced to, with absolute bullshit popping up everywhere and entire sites full of slop with clickbait "headlines" just rigged to get ad impressions.
And I'd gladly trade today's BS for any version of "The Internet" pre-2007.
But the "Before" Internet wasn't some natural sustainable state.
Before 1997 or so, "the Internet" was being paid for by academic institutions and big companies, and wasn't really all that commercial at all. It was also pretty tiny and blessedly simple. Honestly this version is the most achievable (re-creatable?) today since we can set up indie websites much easier today than we could then. Instead of using your free webspace from your university or employer, 20 of us could share a $5 a month instance, and link to each other's webpages, and add an IRC server to that instance just for fun.
In the 1998-2007 era, the Internet got a lot bigger, but was also still pretty fun and not that enshittified, but that's just because it was being paid for by VC money being burned.
Today we are where we are in terms of business model[1] because Google and Facebook achieved great success with ad-based business models because of the ability to target ads better, and because consumers of The Internet have spoken, loudly, with their closed wallets. They've said "We will only pay for content if it's All The Music and ~$10 a month flat rate, or if it's a big/interesting enough video on-demand service and under $20 a month. We'll never pay for news or text content of any kind." So, the businesses with other types of content do what the public wants them to do: have cost-free content whose access is conditional on being advertised to very annoyingly, or they marginalize themselves with paywalls, subscribed to by only a small minority of users.
[1] i'm setting aside the non-business aspects of our mess, namely the poison that social media, 'engagement' optimization, and ragebait-as-news has wrought on society.
ben_w
a day ago
> achieved great success with ad-based business models because of the ability to target ads better
There's an old saying in advertising, "Half the money I spend on advertising is wasted, and the trouble is I don’t know which half." - https://quoteinvestigator.com/2022/04/11/advertising/
The supposed benefit of the current model is to find and eliminate that wasted half.
Facebook has shown me ads for dick pills and boob surgery, ads I can't read because I don't know the Cyrillic alphabet, and ads for services that only apply to citizens of nations I've never been a citizen of who moved to a country I had in fact moved out of.
The reports I hear from people who buy ad slots are mostly unimpressed with the results; the word on the grapevine is that the "success" cases are not even average customers, but those who are vulnerable to getting scammed.
xp84
a day ago
There are lots of ads that don't work, but I can tell you from experience that there are a lot that do. A company I worked for a couple jobs ago basically just added a new pretty color of a clothing item, then ran ads with models wearing it on Instagram (targeted to female, right age range and income level) and the resulting cost per conversion was way below our margin. It was incredibly easy. What made it work though was how the Meta algorithm understood which of the users in that broad filter was into stuff like we were selling, based on all their on-platform activity.
I suspect hackers are far tougher to target - it's kind of a special case.
inigyou
a day ago
Megagiantcorp Proctor & Gamble cancelled all internet advertising, with no loss in sales.
xp84
a day ago
That proves little though. Their ads would be brand advertising anyway, notoriously hard to measure. Just "Don't forget Coca-Cola exists!" and you can accomplish the same with billboards or in-store advertising.
The ads that perform online are the direct response type.
dullcrisp
2 days ago
I don’t know, back in the day you could just buy a newspaper and read it.
Now, if you want to read an article you have to pay $20/month to that news organization in perpetuity. I don’t see how that can be expected to work.
fnord123
10 hours ago
>We'll never pay for news or text content of any kind... or they marginalize themselves with paywalls, subscribed to by only a small minority of users.
You should definitely consider supporting your favourite news sources directly. ft.com, economist.com, lwn.net, etc. Maybe your outlook might change regarding whether they are marginalising themselves or making sure their financial motivations are more correctly aligned with high quality output.
LtWorf
2 days ago
Their targeted ads suck. I've been a professional developer for quite a while and fb keeps peddling me programming courses for beginners to become a developer.
Or, I liked one single page of an amputee woman (I am myself) and now all I see are amputee women.
They just buy all the competitors, but they aren't good at all.
fnord123
2 days ago
> "Sorry, having some tracking is the condition to get this free content. Accept or don't."
The law that caused the cookie banners also says companies cannot block access to the site if the cookies are not required for the functioning of the site.
Some German news sites have broken this and have "accept or pay" and I think this leaked to news sites in other countries. Facebook even tried it.
So, sure, if DNT is true, try to make people pay. Fine by me.
zelphirkalt
19 hours ago
> Some German news sites have broken this and have "accept or pay" and I think this leaked to news sites in other countries. Facebook even tried it.
One annoying example: Golem. Some people in my circles sometimes share a Golem link every now and then. I don't even click them any longer.
rob74
2 days ago
The most annoying thing about that is not even the "accept or pay" banners. There are more:
- even if you accept the tracking, you might still not be able to read the article, because while the site may be free in principle if you accept ads, that specific article is not.
- and the most annoying thing is that such paywalled articles show up on Google News. Not sure if they're tricking Google into showing them (by showing the full article to search crawlers, but the paywall to actual users), or if this is some understanding between Google and EU news providers, but it's annoying...
xp84
a day ago
Speaking of the news-type sites you bring up:
I hate all these patterns too, but interestingly it feels like I hate it more because the whole Internet has been designed around the "free to read with ads" paradigm -- we've been taught that if you can see something, get the URL and share it, so that others can reference the thing you're trying to either comment on or raise awareness about.
With paper newspapers or magazines it wasn't ever a problem, because if I subscribed to the Dallas Morning News, I automatically got all their articles, and even stories that weren't local to Dallas were covered by them too. I didn't need a subscription to the San Francisco Chronicle and didn't miss it.
Today, if someone is reading an article in the Chronicle, or even the Verge, it's a huge problem for them to share it with someone else even if the other person actually pays for subscriptions to say, NY Times and Bloomberg. Even if all four of those publications each have articles just summarizing the same 5 bullet points.
I'd blame the "news" industry as a whole for not implementing some kinds of reciprocal agreements. Even giant news conglomerates like Media News Group[1] who publish dozens of major US papers don't give you a simple subscription that at least covers all their own properties. I'd argue that they should try harder to stand up some shared subscription services with heavy reciprocal benefits and revenue sharing, so that most people would be able to read most paywalled articles with one monthly subscription. That industry has no one to blame but themselves for not figuring this one out.
zelphirkalt
19 hours ago
I don't think the web (I think you mean web, not Internet, but that's hair splitting maybe) has been "designed around around the 'free to read with ads' paradigm". It has been designed around hypertext and putting information online. Ads is just one cancer that has befallen the web a long time ago.
zelphirkalt
19 hours ago
> "Sorry, having some tracking is the condition to get this free content. Accept or don't."
OK great! Lets have that! Honesty on websites! And then people will turn elsewhere, because they don't actually consent. They would go to places where this tracking is not precondition to see/read content. Then we will have revealed what people actually want and what they don't want.
Oh, but of course most businesses are too much of cowards to actually do this, fearing exactly, that their content isn't really worth that much to the viewer, and that they would lose whatever they gained through non-consensual tracking and ads.
TeMPOraL
a day ago
> breaks entire business models
Good. No one is entitled to a business model working in perpetuity. Doubly so when it's ethically dubious.
The very thing entrepreneurs are glorified for - their ability to invent and execute on new business models. They'll manage, don't worry about them. Hopefully they'll settle on more honest models this time.
user
2 days ago
ryukafalz
2 days ago
> But in many cases, you could just click "reject" and the banner would also disappear...
Oftentimes the reject flow is substantially more annoying than the accept flow. I click reject myself when it's an option, but I can absolutely understand how people might get conditioned to click accept when clicking reject might result in more popups.
thom
2 days ago
A lot of UK sites (Reach local news stuff) now explicitly say take cookies or pay, which tbh I always thought was illegal.
xp84
2 days ago
It's wild to me that anyone thinks that would be a reasonable law (whether or not it is law, I have no clue, I don't live in UK or EU).
If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway."
Note that I used "sign any name" as the metaphor, not "show ID," since it is trivial to not allow any important information exchange if you simply delete the cookies yourself, which is easy to configure a browser to do. The end-user has the choice, if it's so important to them, to configure their browser. Even Chrome can be configured for which sites to allow cookies, which to disallow, and which to clear when the browser closes (the smart choice, since accepting them and throwing them away soon after is the undetectable option that accomplishes your main aim).
thom
2 days ago
Allowing bad actors to act badly against all but the most sophisticated users is exactly where lawmakers should be stepping in. Sorry you find that controversial.
ApolloFortyNine
2 days ago
YouTube is a site that pretty much everyone has an account already for (and therefore have already consented), but say you make YouTube 2, you can only make money if people allow personalized ads (they pay 10-20x untargeted ads). 90% less revenue means your business model doesn't work. The government in the area has decided you can't refuse service to customers that cost you money (people who don't consent).
You simply will have to go out of business.
This is also why you see many large companies fighting for more regulation. It's harder for a competitor to emerge if they have to navigate mountains of red tape.
kalleboo
2 days ago
What if I want to start a restaurant that can only make money if I use expired ingredients, run the fridge at a higher temperature to save on electricity, and don't waste my employee's time by washing their hands? These food safety laws mean my business model doesn't work.
I simply will have to go out of business.
ApolloFortyNine
2 days ago
This is just a strawman, these aren't equivalent and I'm not going to waste time pretending they are. Might as well just compare ads to nuclear weapons at this point.
kalleboo
2 days ago
There are enough libertarians out there that believe that the government should not be involved in food safety inspections to establish that regulations like this ARE on a related spectrum. Do you have a right to trust that food you buy is safe or should you get to choose to buy raw milk? Do you have a right to consume online services while retaining privacy? It's a debate society constantly has, and the EU electorate has chosen the side of privacy over a specific business model, just like most developed societies have chosen food safety.
xp84
a day ago
> Do you have a right to consume online services while retaining privacy?
This is the part I don't understand. I'm actually all for regulations like being able to demand they delete the saved data they have on you, restrictions on transferring data to the control of third parties without disclosure/permission, etc.
But if your definition of "privacy" extends to not wanting cookies to work like they were designed to, why can't it be your responsibility to use a browser (a User-Agent) that carries out your intentions?
With services that are mandatory for all of us to use (e.g. government), I can see how being stringent makes sense because the users have no choice. But I can't understand applying the same burdensome requirements to things that people can simply choose to use or not use, such as a restaurant or some random guy's blog. I could be convinced that large platforms (tough to define properly, but things like Amazon, Uber or Meta) may be subjected to additional rules, but the tough rules being applied to even tiny one-person startups does nothing but advantage the giant platforms who have hundreds of lawyers and can devote entire dev teams to building complicated compliance features.
xp84
2 days ago
We ask more sophistication of drivers to understand the rules of right of way than we would be asking of users to hit Settings -> Privacy and Cookies and read the plain language there.
Sorry that you need the government to "help" people in this way, by forcing other people to give them free things.
kalleboo
2 days ago
Are you proposing a licensing scheme to use the internet?
xp84
a day ago
No, I'm just saying that it's okay to burden humans with the responsibility to learn a few basic ideas about how to operate their own computers if they want to control their data privacy.
Simple, easy tools are already there, such as the Clear Browsing Data menu item in Chrome, Edge, and Safari. For more complicated intents, the browser settings are no more complicated to navigate than the actual customization UI in the CMPs, anyway.
kalleboo
a day ago
Then I don't understand the driver analogy. Drivers are forced to take lessons and get licensed for the precise reason that we know people can't take the responsibility on their own.
Clearing browser data is anything but easy for people who aren't certain what is "browser data". Is this going to delete all my google sheets? Those are in the browser. And it's not a bad question, some apps actually use IndexedDB or whatever to store user data.
xp84
a day ago
One more thing re: my potentially distracting analogy.
> Drivers are forced to take lessons and get licensed for the precise reason that we know people can't take the responsibility on their own.
Ok, I see what you mean here, but I'd argue that the licensing requirement is only acceptable because the risk is both grave and impossible to limit to just yourself.
We don't require a license or training to use a table saw at home even though table saws are also dangerous unless used very wisely. That's because the risk is mainly limited to the user and at worst, someone who chooses to be nearby that table saw.
To bring it back to my point, I'm not discussing the licensing part, I'm saying rather that we don't make excuses for people who refuse to learn the rules of the road, or how to safely use a table saw, and we don't say that it's the job of wood manufacturers to somehow secure the table saws of ignorant DIYers. The responsibility is on the user of the car, the table saw, or the browser. If the user chooses to never learn the basic operation of their tool, they might get hurt. And if we do have to regulate something, we should regulate the saw, and give it clearly-labeled safety features. Not regulate all pieces of wood.
And in my opinion, the 'danger' from cookies is so trivial compared to any real dangers (mainly the danger of seeing ads that are "too good"), that I am not convinced anyone needs to be protected from it by a third party.
xp84
a day ago
> some apps actually use IndexedDB or whatever to store user data.
Not any notable apps used by noobs though. Unsophisticated users don't include Local Storage in their mental model - they simply believe that "When I log into Gmail, Google Docs, or Slack on a fresh computer, my stuff will be as I left it on my other computer." Webapps which subvert this by not persisting things outside of Local Storage would be taking wild and unnecessary data-loss risks with user data.
> people who aren't certain what is "browser data".
This I agree with you on. Everyone including EU legislators are trying to regulate something that none of them actually know or agree on what it even is.
The common person has basically only one single concern that relates to cookies: They don't like retargeting ads. That's it, that's the whole beef. They feel offended that by some mysterious (to them) means, they see ads 'around the Web' for things they've browsed before. Of course, those ads exist because they're incredibly effective. But they are annoyed that it, in their opinion, manipulates them into spending money. These ads are "too good."
This is a technical problem with a technical solution, and if the EU (and US) regulators weren't technically illiterate they would recognize this and issue clear requirements aimed at browsers[1] instead of the stupid ones we have today which are basically just rely on the honor system, meaning compliance will be patchy at best, and it relies on costly enforcement actions and complaints, is subject to litigation, and has so many gray areas - "If the CMP didn't work right and cookies were stored, is MY company liable? We tried!").
There is a second concern, but it has little to do with cookies, it's just that we ideally want to stop companies from keeping and exchanging dossiers on our behavior and preferences (and a dispute on whether anonymized data is ok, or whether it's unethical because if detailed enough it can be deanonymized). That is bigger than cookies, and applies just as much to offline companies.
[1] Here's an imaginary scheme, just for example:
1. Segment cookies storage by the domain in the address bar - the same way the memory/disk cache works today. This is really functionally the same as turning off third-party cookies, but if anything "needs" them, this sandboxing would nerf it so that a Facebook Like Button on a webpage can't be aware of a facebook session you created on a different domain.
2. Big switch in the browser's UI that defaults to "Temporary" - if you leave it alone, all cookies and storage are evicted 2 hours after last tab is closed, or you switch it to "Permanent" (preference stored per top domain) to have the current behavior where expiry can be longer.
Regardless of the specifics, a browser-side solution would solve the problems of "compliance" as it pertains to cookies and other client-side tracking (they can't abuse data the browser simply won't persist for them), and level the playing field between the tech giants and upstart competitors.
kalleboo
2 days ago
You're fooling yourself if you think clearing cookies does anything. Everyone is doing browser fingerprinting instead these days.
ben_w
a day ago
> If you made a website and you said "To view the private content on my website, you have to either pay me, or sign a name, any name you wish, in my guestbook" what business is it of the government to say "No, this random person refuses to pay or sign the book, but Thom, you have to let them see all your articles anyway."
More: "To view the private content on my website, you have to either pay me, or let more businesses connect the dots between this content and the rest of your internet browsing habits, than there were students and teachers combined in your high school."
Yes, it is technically possible to fake this content, or to auto-delete it.
But https://xkcd.com/2501/ applies. "It's easy to forget that the average person probably only knows the privacy settings for Safari and one or two Chromium derivatives."
(Real world user familiarity with software is much, much worse; this is an old survey now, but look at the chart near the bottom: https://www.nngroup.com/articles/computer-skill-levels/)
xp84
a day ago
I'm in agreement with you that most computer users haven't bothered to learn anything about how to use their browser or computer.
But still, let's say I agree that there's even an important problem to be solved.
We can (A) regulate the browser to dumb this down for these ignorant people, and have the problem guaranteed solved, or (B) we can burden every single company that operates a website, and rely on enforcement since otherwise it's all honor-system.
The EU and so far multiple US states, have chosen the stupid option B.
ben_w
a day ago
Option A is insufficient, as cookies are a mere implementation detail about how tracking is done, and the tracking is the concern.
tripzilch
a day ago
This is a false analogy. The cookie banner stuff is explicitly about sharing data with third parties. If that were the case in your example, it'd be a different thing, right.
roelschroeven
2 days ago
It is illegal, but compliance is not enforced to the degree that it should. Companies get away with a lot of GDPR infractions, unfortunately.
inigyou
a day ago
They're in UK, not EU, and it has a different law.
account42
a day ago
UK GDPR is simmilar to the EU one and German news websites do the same thing in the EU.
dredmorbius
2 days ago
The UK is somewhat famously no longer part of the EU (you may have heard of a thing called "Brexit" a few years back).
However the UK does have its own GDPR regulation (see: <https://www.gov.uk/data-protection>), though my understanding is that it may be less strict in requiring equivalence between "accept" and "reject" actions. (I may be wrong on this.)
UK sites accessed from the EU would have to be under EU GDPR compliance.
unclebucknasty
2 days ago
>This is a jaw-drop moment for me every single time I observe someone else using the web and quickly clicking "accept"
There's a mismatch between the velocity at which people visit sites and the time it takes to navigate the cookie particulars of each site.
And, we can dismiss this as people being uninformed or lazy but the reality it is that's actually not so unreasonable. Cookies are in some ways near the bottom of the list where privacy is concerned, given everything else from breaches to search dossiers to device finger-printing to mobile device location-tracking to the ubiquity of cameras in the real world, and on and on.
The idea that we're clawing back privacy in any meaningful sense by blocking a few cookies here and there is kind of quaint.
nickff
2 days ago
I believe myself to be fairly well-informed, and usually accept the cookies, because I don’t foresee any potential harms, and it helps the people running the website. I am worried about many things like phishing and hacking/data leaks, but the valuable data isn’t cookie-related.
What harm are you worried about?
fsflover
2 days ago
These popups aren't about cookies but really about spying. It seems you have nothing to hide. I understand: I also don't. However, the problem with spying is not about individual secrets but about the society and democracy.
Lack of privacy harms journalism and activism, making the government too powerful and not accountable. If only activists and journalists will try to have the privacy, it will be much easier to target them. Everyone should have privacy to protect them. It’s sort of like freedom of speech is necessary not just for journalists, but for everyone, even if you have nothing to say.
tqi
2 days ago
A right to privacy also includes the freedom to forgo privacy in return for other benefits.
layer8
2 days ago
Tracking usually happens across websites, meaning the information is shared with third parties outside the people running the website where you accepted the cookies. Knowing your interests, behavior and preferences makes you prone to manipulation. The selection of information shown to you will be crafted such as it maximizes engagement. For example, showing you information that upsets you, in order to get you to react. Or just information with a slant or spin to influence your opinion. Nobody is immune to being affected by the distribution of what they are being shown.
inigyou
a day ago
For instance, ICE buys this data.
whstl
2 days ago
The banner is not just about cookies, but also about data sharing, so by accepting you increase the amount of your data that can be leaked.
These banners handle both ePrivacy consent for cookies etc, but also GDPR Art. 6(1)(a) for processing purposes (personalised ads, measurement, audience insights, precise geolocation, even device fingerprinting).
montroser
2 days ago
Well, the whole thing is theater anyway. It does not matter what you choose.
They will fingerprint you with or without cookies. They may or not try to honor your preferences, but their "partners" will not try, and by the time you see that banner, it's all out there.
"Accept" is the close button.
stefan_
2 days ago
Because 90% don't even do anything? It turns out it's actually one of those really annoying problems to delay cookies which were supposed to be sent already in the HTTP request response until a user interaction has happened. And on a lot of pages, non technical people embed random 3rd party resources. And these 3rd party resources might claim to use only "technically necessary" cookies, but of course that's nonsense; I'm not visiting the 3rd party.
inigyou
a day ago
The law is actually about tracking, not about cookies.
WheatMillington
2 days ago
Most people reasonably assume that if they click Reject they won't get the page they're looking for.
user
4 hours ago
hobo123
2 days ago
"To me, having a browser setting for cookies is the only sane way to handle this, it's surprising that this was not considered from the beginning."
This is exactly what browsers did back the 90s, they asked about every single cookie.
Then browsers got configurable options to simply accept either all cookies, no cookies, or only first party cookies (excluding third party sites unrelated to the domain you visited).
For now well over 20 years I have disabled 3rd party cookies in all browsers I use, and only in a few cases overall did I need to make exemptions.
Gigachad
2 days ago
Usually when you hit reject it opens some insane modal with 5 million checkboxes. While accept always makes it go away fastest.
chillfox
2 days ago
The amount of sites that don’t persist rejecting feels very high, or it’s extremely painful when encountering. The cost of clicking reject is extreme if you have to do it on every page load as you navigate a site.
speleding
a day ago
Well, you would be surprised how many people think that blocking cookies means "no or fewer ads", even people in IT. No tracking, of course, just means it will show less relevant ads, not fewer of them.
So I'm not onboard with the "just block everything by default" crowd. If you frame the question as "Would you like ads to be more relevant to you" instead of "Do you want to allow tracking" you probably get a very different answer from users.
I would like the cookie banner to be changed to a browser setting, but I also would like the option to allow some sites to show relevant ads to me.
aetch
2 days ago
People expect visiting a website to be read only or contained within a sandbox to not read other files on their computer which is correct. Most people just don’t care about tracking and want to get to the content.
SlightlyLeftPad
2 days ago
There is also the fact that by rejecting, the cookie that remembers that preference expires after like a day, so you have to click that dumb banner almost every time you visit the site.
gbalduzzi
2 days ago
And that is malicious, it is not supposed to happen
bwb
a day ago
I run two plugins to just invisibly make them go away, I don't care, they are a waste of my time :)
dv_dt
2 days ago
if ever there were a need for a small local ai plugin...
agos
2 days ago
I suggest looking at "consent-O-matic" which might not be AI but takes care of the issue for you
dv_dt
2 days ago
I have it, it only seems to operate on maybe 60% of sites
XzetaU8
14 hours ago
Long time (former) user of consent-o-matic here and i concur, it doesn't seem to work on many sites these days.
"I still don't care about cookies" works seamlessly so far.
https://addons.mozilla.org/en-US/firefox/addon/istilldontcar...
cuu508
2 days ago
uBlock Origin's "annoyances" filter lists also do the job.
zelphirkalt
2 days ago
This happens when countless websites continue to do the illegal thing of making rejection take more effort than accepting, without being sued into oblivion for repeat offenders. Roughly 9 out of 10 websites today will be doing this illegal shit, and we are too timid to tear them down.
Robotbeat
2 days ago
If only there was a short little text file that websites could use to keep track of the setting...
tancop
a day ago
[dead]
goodrubyist
2 days ago
Agreeing to terms and contracts without reading or at least skimming them is not responsible adult behavior and should not be used as a model for legislation, no matter how many people do it. I agree that we do have a culture where private law is not taken very seriously, and that's very unfortunate.
People do not have a right (morally speaking, not legally) to access or use a service (or a website) etc without having to read/agree to the terms (applies to analog and digital).
Maxion
2 days ago
Try to get anything done then, there's so many places these days where you have to approve 300 page legal documents to e.g. record day care times, pick up packages and so forth. There is literally not enough time in the day. The option for me would be to not put my kid in daycare (I lose the spot if I don't put in the daycare times, and the only way to do that is a 3rd party service) and not pick up packages (have to agree to the EULA to get the app that I need to unlock the pickup locker) and dozens of other places.
We really need to stop companies from putting up these insanely complicated legal texts to use basic services when they could all be behind standard contracts.
goodrubyist
2 days ago
They're usually not that complicated. And most of them say usually almost the same things with some edits thrown here and there. E.g. compare the disclaimer of warranty/liability sections of two different EULAs. E.g. this kind of text in Apple macOS Tahoe EULA is found almost everywhere:
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE APPLE SOFTWARE AND SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE”
https://www.apple.com/legal/sla/docs/macOSTahoe.pdf
The same point applies to most of the text. But yes, some text is specific to the service. E.g. the same doc above says in bold:
"By using the Content Caching Features of the Apple Software, you agree that Apple may download and cache such Apple Eligible Content on your Caching Enabled Mac."
I'd say that's something worth knowing if you use that OS.
swat535
2 days ago
Terms of services and contracts are written for lawyers and not the average people.
If your terms require people to get a law degree and take a week to parse the 400 page document, then I would argue that it's a tactic to get people to sign up for the service without fully understanding it.
We need legislation that forces companies to communicate the terms in a way that an average person can comprehend.
goodrubyist
2 days ago
I'm an average person and I read them all the time. It's not usually 400 pages long. More like 3-4 pages. If a person genuinely can't understand, they should not use the service. That's not sarcasm, I, myself, do not like to sign contracts I cannot understand -- but that's rare when you can look up stuff.
inigyou
a day ago
Terms of service aren't even legally binding!
goodrubyist
21 hours ago
Wikipedia and a few other sites I saw say otherwise for the US. https://en.wikipedia.org/wiki/Terms_of_service Wouldn't make much sense otherwise.
sumeno
2 days ago
How much of https://www.ycombinator.com/legal/ have you actually read?
goodrubyist
21 hours ago
All of it, if it was presented for me to accept when signing up for this account. Don't remember explicitly. As I said to others, most of it is boilerplate, so you just learn to skim and see the stuff that's really different.
basch
2 days ago
Cookie control always should have been a browser control. The legal route always should have been to force it to be built into browsers that provide sane defaults, and make it illegal to circumvent what the browser declares as far as fingerprinting etc.
any sort of elevation prompt, IF I allow them to be popups or an icon in a toolbar, should always be in the same place and not cover the page.
MassiveQuasar
2 days ago
Just enforce the GPC header... https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/...
quantumwannabe
2 days ago
Or the "Do Not Track" header: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/...
IanCal
2 days ago
In a way it is - or rather it wouldn’t t change anything if we added more features.
The default is “no”. Without explicit consent you can’t do a lot of things.
You can’t have a default yes, because how can you agree with consent but automatically to everything?
And if it’s a no, are you saying you can’t ask a user for permission to use their data for a specific purpose?
And if you can ask, that’s what we have right now.
Voultapher
a day ago
They are asked _once_ during browser setup, same way on iOS users are asked once during setup if they want to allow Apps to track unique IDs (memory is hazy, they did that a couple years ago). And surprise surprise IIRC 96% of users said no.
lukeschlather
2 days ago
Yeah I think it probably does mean you should be banned from asking in most cases. If you have a legitimate interest you don't need to ask. If you need to ask your interest is not actually legitimate and you know it.
buzer
2 days ago
Legitimate interest is not currently enough to read or write cookies. You need either consent or it must be "strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service." (or "sole purpose of carrying out the transmission of a communication over an electronic communications network", but that's harder to apply to cookies)
inigyou
a day ago
Which part says legitimate interest doesn't apply to cookies?
buzer
a day ago
"legitimate interest" is legal basis in GDPR. ePD (which governs access to cookies) does not have such legal basis, only consent and the two exceptions.
Other processing (like after value is read) can happen under GDPR if the data is personal data.
inigyou
a day ago
My understanding is that ePD was obsoleted by GDPR.
Note that you don't comply with EU directives anyway - you comply with actual laws of actual countries, and the EU process helps them to mostly agree with each other. Did countries replace their ePD-based laws with GDPR-based laws? My understanding is they did.
buzer
a day ago
No, it's not. ePD is lex specialis in relation to original Data Protection Directive (and later GDPR). DPD was replaced by GDPR, ePD was not. There has been talks about ePrivacy Regulation over the years, but it was shelved again in 2025.
ePD is still active and national laws implement it. GDPR itself is not implemented by national laws as it's EU regulation rather than EU directive. Member States primarily repealed their DPD-based laws after GDPR and implemented various things that GDPR allows (like Article 23 restrictions). Some countries may have explicitly imported GDPR into their own law due to how their own legalization works. Like that's why UK DPA was originally pretty much just copy of GDPR.
nickff
2 days ago
If people really cared, they’d choose browsers that have better control, but that’s obviously not a priority for them. Why do you think this sort of thing should be regulated to suit your preferences when most people don’t seem to agree with you?
preg_match
2 days ago
Because everyone agrees - cookies banners are annoying and need to go away. Everyone is on the same page about this. The easiest way to make that happen is "move them into the browser".
How often do you get prompted for, say, secure DNS or HTTP? Almost never, because your browser has sane defaults and controls that. So, there you go.
tsukikage
a day ago
What is the sane default response to "we and our 242 partners value your privacy"?
I mean, it's even the literal truth: they value your privacy in the sense of having their software do a little internal auction to put a price on it.
ablob
2 days ago
I think that's a stretch. People can care, but be unwilling to spend the time researching it or accept the trade offs that come with small browsers (which are often unsupported for applications you might want to use). There are many things someone might care about and at some point you have to prioritize. This topic in particular is practically a cold war where you always have to catch up on how things are, lest you loose it all. The required effort is disproportionate to the result.
P.S.: No true Scotsman spotted
ClumsyPilot
2 days ago
> If people really cared, they’d choose browsers that have better control
If people really cared, they’d chose reputable suppliers that sell non toxic food. If they are eating food with lead, they don’t care.
Don’t force your wordview on people through regulation
whstl
2 days ago
> Don’t force your wordview on people through regulation
As opposed to enforcing your worldview with a lack of regulation?
Because that's precisely what's happening, with the advertisement industry enforcing their worldview through lack of compliance.
ClumsyPilot
a day ago
That was suppose to be a reductio ad absurdum, not a genuine argument
whstl
a day ago
Poe's law strikes again! My fault here, sorry for the misunderstanding!
yjftsjthsd-h
2 days ago
> If people really cared, they’d choose browsers that have better control
What browsers would those be?
ethin
2 days ago
IMO any contract, waver, etc., shouldn't be legally enforceable unless the signatory has actually read it. It's always seemed to me to be one hell of a pathway of abuse (in a way) to just be able to bind someone to be legally required to do anything you want, for example, by just relying on them not reading the thing they signed.
dotancohen
2 days ago
How to know if they actually read it? The signature implies that the contract has been read, understood, and accepted. I see no need for any alternative mechanism.
buzer
2 days ago
Well, if you presented them with list of 100 partners each with 20 page of privacy policies and they accept it within 10 seconds it should be tricky to argue that user actually read it all.
You could, for example, require that user answers very specific questions regarding 10 randomly selected partners and how exactly they can use the data ("is partner x allowed to build very detailed profile of you and target you with political adverts that are designed to manipulate you?").
ApolloFortyNine
2 days ago
If you did this people would only use the same half dozen sites and competitors would emerge.
We're borderline already there today when the cost of switching is typing a different url at the top of the screen. You add some mandatory 20 minute wait and you'll never see a new site again.
Google and Facebook would love it though.
inigyou
a day ago
Plus sites that don't track you
inigyou
2 days ago
Well for instance if the other party is pressuring you to sign it then it can't be assumed that you had adequate time to read it and understand it
dotancohen
2 days ago
Contract law of every civilised land already has a process for considering and accounting for duress.
inigyou
2 days ago
It only accounts for "sign this or I'll kill you" not for "you have ten seconds to make a decision or the dream vacation goes to the next person"
crote
2 days ago
Some countries already have provisions for this.
For example, in The Netherlands there is a legally mandated three-day period after signing the contract for purchasing a home during which the buyer can still call off the deal.
The reasoning for this is that it is a seller's market, with demand far outnumbering supply. In practice it is very common these days to end up in a bidding war, and even forego any kind of "sale is void if home inspection turns up issues" clause. Want to think about it for a day or two before signing the biggest contract of your life? Too bad, another buyer is willing to sign today.
With the mandatory three-day waiting period you avoid buyers being locked into a contract they basically immediately regret. It gives them some time to do due diligence, reducing the risk of buying a complete lemon. The seller can ask for a similar clause to be inserted, but it is less common. After all, the only risk to the seller is getting slightly less money for it, and that's already mostly dealt with during the bidding process.
tremon
2 days ago
Your specific example is not intended to address buyer's remorse, but mortgage financing. After agreeing to a house sale, the buyer has three days to have their bank sign off on it. Yes, it's nice that it slightly alleviates pressure but the primary goal is to streamline house sales by making the financing details part of the finalization instead of the decision-making process.
chrismorgan
2 days ago
I don't believe you’re correct. Certainly in Australia the cooling-off period is all about buyer’s remorse; “subject to finance” is a completely unrelated condition commonly added to the contract, and even with pre-approval it’s probably seldom resolved within three days.
ethin
2 days ago
Is that not what the courts are for? I imagine that if a court had to enforce a requirement like this, knowledge would generally be the best kind of proof. If you know what the contract said (or even it's terms in general) that would be enough.
The reason this isn't done is because corporations legal departments love writing 10-100 page contracts that absolutely nobody is going to read.
user
2 days ago
Ferret7446
2 days ago
The solution for the problem caused by regulation is more regulation. Sure, we didn't anticipate the negative consequences the first dozen times, but this time there will absolutely not be any unanticipated consequences.
LadyCailin
2 days ago
So, what, have no regulations whatsoever then? What an absurd suggestion. It’s a cat and mouse game, sure, but that’s like saying “there was a security hole in the software, might as well give up on trying to secure it.”
otterley
2 days ago
> From a factual perspective, I honestly think that shouldn’t be controversial: it’s well-understood that very few people actually read those things, they just want to get them out of the way
There’s no way this would fly. “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement. Every party to an agreement that flaunted its terms, even though they took advantage of the benefits granted by it, would invoke it as a defense, and it’s irrefutable. The system would completely fall apart if this happened.
There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
znnajdla
2 days ago
> “I didn’t read it” can’t possibly be an excuse to avoid being bound by an agreement
Only engineers have trouble understanding this. It can be a reasonable defense, and it has successfully been used in courts of law many times. The law is not a machine that compiles text like code literally. Imagine someone who coerces a dying or sick person to sign an agreement they couldn’t possibly be in a reasonable state of mind to understand what they were doing -- the law can and does invalidate such “contracts”. That is the same principle behind age of consent laws. The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
otterley
2 days ago
I am an attorney, and am aware of certain exceptions. But these are exceptions and not the general rule, which is what I am speaking of.
> The law could theorerically (and does) invalidate “agreements” which no one is reasonably expected to read and understand.
I haven’t heard of a single case where an agreement was voided because “no one could reasonably be expected to understand it.” Unless the language was so impenetrable or vague that the agreement itself could not be discerned. Lawyers tend not to write such agreements.
IsTom
2 days ago
EULAs are restricted in power in EU and at least to me these cookie banners are similar in spirit.
tempestn
2 days ago
"I didn't read it," sure. But, "A reasonable person would not read it?"
ChadNauseam
2 days ago
Why would a reasonable person not read it?
I just visited theguardian.com to see their cookie banner. The banner says this:
> Your Privacy (`x` button to close the tab)
> US residents have certain rights with regard to the sale or sharing of personal information to third parties.
> Guardian News and Media and our partners use information collected through cookies or in other forms to improve experience on our site and pages, analyze how it is used and show personalized advertising.
> You can opt out of the sale of all of your personal information by pressing
> <button>Do not sell or share my personal information</button>
It's 3 sentences, plus a button that says "Do not sell or share my personal information". I actually don't even think this is GDPR compliant, because my layman's understanding says that GDPR consent must be presented as opt-in, rather than opt-out. (I guess they are going for CCPA/CPRA compliance?) But anyway, I would think that a reasonable person could be expected to notice a button that says "Do not sell or share my personal information" and then click it, especially when it's portrayed prominently at the bottom of the page.
preg_match
2 days ago
> Why would a reasonable person not read it?
Because this is there 1 millionth cookie banner, because every site and their momma has one.
Also, 90% of cookie banners are not this good. They tell you nothing, hide the "reject" button behind multiple screens, etc. At that point the consumer is trained to click accept.
zenalt
a day ago
From Europe it's this text:
> Personalised advertising - it's your choice
> Independent, quality original journalism needs your support.
> Please choose an option.
> * Accept personalised advertising and all cookies
> We use cookies and similar technologies to support the Guardian and personalise your experience in other ways. To do this we work with a cross section of [139 partners].
> - or -
> * Reject all and subscribe to Guardian Ad-Lite for €5 per month
> Read the Guardian website without personalised advertising. This does not include ad-free. You will still see non-personalised advertising and we may still use cookies and similar technologies to improve our site.
Followed by:
> Some cookies are necessary to help our website work properly and can’t be switched off. Find out more in our privacy policy and cookie policy, and manage the choices available to you at any time by going to ‘Privacy settings’ at the bottom of any page.
> Cookies and similar technologies collect information from your device and may be used to access personal data about you including page visits and IP addresses. We use this information about you, your devices and your online interactions with us to provide, analyse and improve our services. We use cookies and similar technologies for the following purposes:
> * Store and/or access information on a device
> * Personalised advertising, advertising measurement, audience research and services development
> * Personalised content and content measurement
And finally the buttons:
> ( Accept all ) ( Reject all and subscribe )
> If you already have Guardian Ad-Lite or read the Guardian ad-free, [sign in]
inigyou
a day ago
Notice how they show you those three sentences and don't just put a bunch of small print at the bottom of the page. Because if they did, it would be invalid.
troupo
2 days ago
This is indeed a rather good implementation of ehat GDPR requires: clear unambiguous language, an opt-out available immediately.
This is the definition of informed consent
jkaplowitz
2 days ago
The GDPR doesn’t allow opt-out consent to count as consent. The only consent it recognizes as valid consent is opt-in.
However, since we are discussing the banner that The Guardian website shows to US viewers, I assume they’re trying to comply with California privacy law, which does allow opt-out regarding the sale of personal information.
troupo
2 days ago
> The GDPR doesn’t allow opt-out consent to count as consent.
wat
GDPR says that opt-out is the default, and if you are asking for consent, it had to be clear, unambiguous, and with both chouces clearly present.
inigyou
a day ago
You're both using different meanings of "opt-out"
Not legal: you have to click a button to be opted out, otherwise you're opted in. (Opt-out as a verb)
Legal: you are opted out by default (opt-out as an adjective describing the default situation)
ButlerianJihad
a day ago
https://en.wiktionary.org/wiki/opt-out
https://en.wiktionary.org/wiki/opt-in
You've muddled the definitions again. "opt" signifies an action by the user.
If I am "in a group" by default, then I can take an action to "opt out", requesting to be removed from the list.
If I am not initially joined to the group, then I can take an action to "opt in" and be added to the list.
There is no such thing as "opt by default". That is not a user action. It also makes no sense for the same list or group to be both "opt in" and "opt out" because, as adjectives, they imply the default states and they describe the user action taken to change that default.
opt-in: default state is out
opt-out: default state is in
inigyou
a day ago
>> The GDPR doesn’t allow opt-out consent to count as consent.
> GDPR says that opt-out is the default
do you see how these relate? The second one quite explicitly talks about being opted out by default, i.e. what most of us call opt-in.
tacitusarc
2 days ago
But it is complicated, no? Even if you click you agree, if the you thought you were agreeing to one thing but actually agreed to another because they buried the lede, “I didn’t read it” is a reasonable defense.
SiempreViernes
2 days ago
Why would you claim the false "I didn't read it" ahead of the true "I read it but understood it differently"? The latter allows for adding the fault shifting claim "because the other party wrote it deceptively", while "intentionally didn't read" makes it much harder to blame the other guy.
otterley
2 days ago
It just won’t fly in court. Full stop. There are perhaps other defenses to be raised, like unconscionable terms, but not that one.
tacitusarc
2 days ago
I think that means one of three things: the court system is broken, you are wrong, or I failed to be clear and you misunderstood me. So, to be clear, if a company buries or obscures terms while making it seem like they have presented them, so you agree without reading the actual terms, you cannot defend yourself by explaining that situation?
otterley
2 days ago
One possibility you failed to enumerate was that you are wrong.
But anyway. What exactly do you mean by “buried or obscured”?
As I said above, if the parties cannot be said to have an agreement because the terms of the agreement itself are inscrutable, then that would probably result in no contract being formed, or the terms at issue interpreted in the light most favorable to the non-drafting party. Like if the terms were presented in so small a font that only someone with a microscope could have read them, or it was written cryptographically or is gibberish.
Basically you have to successfully argue that no reasonable person could have read and understood the agreement. You’re unlikely to prevail if you argue only that you, the individual, did not. (Unless the court also finds you are incapable of entering into any contract because you’re a minor, are non compos mentis, etc.)
tacitusarc
2 days ago
A more concrete example may be useful to explain what I’m thinking. A company has you click to agree to their TOS. They link a doc, which is of course quite long. That doc has a footnote which links to another doc. You do not read the secondary doc, and it is the contents of that doc that allows the company to sell you data/prevent you from suing them/harvest your organs/abduct your family/whatever. My point is that “I did not read the document” should be a valid defense, such that if it is not I believe the law around this is wrong.
I suppose you can claim I am wrong to believe that, but it is accurate for me to state that I _do_ believe it, which is why I didn’t list me being wrong as one of the possibilities. Practically speaking, that is the first possibility I enumerated.
I should note that in my example, imagine neither doc is any more inscrutable than all the TOS we encounter in the wild, instead it is the construction (the fact it is a footnote link) that makes it easy to miss the additional doc.
otterley
2 days ago
Incorporations by reference are not unusual in contracts. A contract is unlikely to be voided merely because the contract has references and the counterparty didn't read them.
ferngodfather
2 days ago
It really depends on the term they're trying to rely on. We have the "red hand rule" in England and Wales that means that unusual and onerous terms will not be incorporated unless it can be expressly shown they were fairly brought to the parties attention.
victorbjorklund
2 days ago
It can and has been in many cases in many legal systems. For example, let’s say you walk into my store to buy a dish washer. I say ”here is an extended warranty that I will give you. Just sign” you sign it instead of reading 15 pages of boilerplate. In the end of the document it says you now owe me 10 billion dollars. Doubt I will be able to enforce it in most legal systems.
otterley
2 days ago
That’s not an “I didn’t read it” defense. That’s a “term is this contract is unconscionable” defense. They’re not the same thing. I was speaking strictly of the former.
Also, striking an unconscionable term typically does not void the whole contract. Just the term in question.
bryanrasmussen
2 days ago
As a general rule I believe many online terms of use, eulas and similar online contracts are examples of procedural unconscionability, in that length is often too long that one can be expected to read it in the day to day action of "surfing the web", I believe this is also the opinion of the EU and many of its member states, hence the limitations found on enforcement of such contracts.
Aside from that many of these contract have terms that might be considered substantive unconscionability - for example if terms state that what you post can be used by the company that owns the service for marketing of the company or the service I feel this would not make it through most legal systems that I feel before the attempt are not inherently corrupt.
otterley
2 days ago
I would personally be shocked if the EU voids click-wrap agreements for unconscionableness based on the process alone. I’m not super familiar with EU law; is that what it truly says? I rather doubt it because I do business in the EU and have been asked to agree to terms as a condition of making purchases online there.
simonra
2 days ago
Online retailers in the nordics occasionally try to post terms and conditions that contradict consumer protection laws, for instance retailers being on the hook for warrantying product(ion) defects for 5 years after purchases of products that ought to be durable, like electronics. The retailers win out on a substantial amount of the population not contesting it, but if you as a consumer go through the process the findings is basically always in your favor, despite there being agreements to something else. Telecommunications providers also have a long history of having their consumer invoices being voided for being unconscionable despite service agreements, especially in cases with children playing with devices (but otherwise also), going all the way back to the landline age.
otterley
2 days ago
Right. But those are substantively unconscionable terms, not about the agreement process itself.
bryanrasmussen
2 days ago
sorry I did not phrase that very well, when I said as a general rule I believe I meant that if put to the test it could be often won on length alone in conjunction with the activity being done, but almost always these contracts are substantively unconsionable and of course people contest that, because most people don't get angry and want to fight for no reason, they do it because it is violating their rights.
As an example I have an email account with site A. I go to site A and log in, they suddenly spring a large new contract for me to read, I cannot get through to do what I came to do, it will take me 5 minutes to read so I click OK because I am on my way to check my email with site A. Procedurally this is not reasonable behavior.
What would be reasonable?
"Hi, we are changing our terms of service, you can see it at this link and agree. If you don't have the time right now you can do it later, but in three days you will lose access to the service unless you agree to terms."
There are however lots of other laws in the EU which may in fact make this behavior substantively unconscionable anyway. I certainly believe there would also be substantive arguments to be made in this case.
SiempreViernes
2 days ago
The council directive on unfair terms in consumer contracts puts every pre-canned contract in scope, and unfair provisions on a contract are rule non-binding (if the contract can keep existing after the unfair bits are taken out).
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
otterley
2 days ago
Right. But those are substantively unconscionable terms (“unfair provisions”), not about the agreement process itself.
victorbjorklund
a day ago
No, it is literally ”I didn’t read the contract”. Let me guess you don’t have a law degree in Swedish law and you are just making statements on every legal system in the whole world?
Just read avtalslagen paragraf 30. It says just that. And it is different from paragraf 36.
otterley
a day ago
I read it. The law expressed therein appears to be consistent with typical contract law in the West, including the UK (from which US law is derived) and other European countries. I don't see any major differences. (Also, I'm not sure why you brought up paragraph 30 as that is about fraudulent inducement.)
See also https://svjt.se/svjt/1959/497 "En person borde sålunda bli bunden av ordalagen i det dokument han undertecknat utan att äga att ursäkta sig med att han icke läst igenom dokumentet."
victorbjorklund
a day ago
No, I have a Swedish law degree and you have totally misunderstood article 30 if you claim it is about unjust contracts. You are mixing it up with art 36.
You are referring to a 60 year article and the sentence you highlighted is NOT his opinion on the old contract law (the contract law currently in effect is from 2020) but rather he is explaining the opinion on German law from another person.
Of course you as an American sees no difference between contract law in continental European law and common law.
victorbjorklund
a day ago
This is what the Swedish Supreme Court said recently on the paragraph.
Enligt 30 § avtalslagen kan en rättshandling inte göras gällande om den, gentemot vilken en rättshandling företagits, framkallat rättshandlingen genom svikligt förledande eller bort inse att den som företog rättshandlingen blivit svikligen förledd av någon annan. Det finns en presumtion för att det svikliga förfarandet har framkallat rättshandlingen, om omständigheter som svikligen uppgetts eller förtigits kan antas vara av betydelse för rättshandlingen.
bad Google Translate:
According to Section 30 of the Contracts Act, a legal act cannot be enforced if the party against whom the legal act was performed caused the legal act by fraudulent misrepresentation or Should have realized that the party performing the legal act had been fraudulently misled by someone else. There is a presumption that the fraudulent misrepresentation has caused the legal act if circumstances that were fraudulently stated or omitted can be assumed to be of significance for the legal act.
otterley
a day ago
> you have totally misunderstood article 30 if you claim it is about unjust contracts
Fraudulent inducement is not about unjust terms in contracts. The elements of fraudulent inducement in the US are:
1. The other party falsely represented something to you regarding a material fact;
2. They knew that it was false;
3. They made the representation in order to induce you to rely on it;
4. You did actually rely on it;
5. You did not know that it was false; and
6. You sustained damages as a result.
I imagine it's not significantly different in Sweden.> According to Section 30 of the Contracts Act, a legal act cannot be enforced if the party against whom the legal act was performed caused the legal act by fraudulent misrepresentation.
OK. We have the same law. But I don't understand what this has to do with an "I didn't read the contract" defense. Since you possess a Swedish law degree, can you cite a single case wherein a party to a contract escaped their duty to perform merely because they didn't read the contract? Assume no fraud, clear language, no misrepresentation, no unconscionable/unlawful terms, both parties are competent to enter a contract, etc.
lukeschlather
2 days ago
All of these cookie forms have the same set of toggles. At a high level all anyone is saying is that we should just declare any kind of tracking cookies unconscionable terms for this kind of dialog box. Caching, shopping carts, explicit log in, these are totally fine and you don't need a dialog. The tracking stuff is not that hard to define and it should just be declared unconscionable.
Y_Y
2 days ago
That's why billionaires don't buy their own dishwashers
nekusar
2 days ago
This is bullshit.
https://www.nbcnews.com/news/us-news/disney-says-man-cant-su...
"Disney is trying to have a widower's wrongful death lawsuit dismissed and sent to arbitration because the man had signed up for a Disney+ account several years ago."
Now what happened was that Disney quit fighting over really bad PR. But the court challenge would have liteky succeeded.
victorbjorklund
a day ago
You get that US is a tiny part of the worlds entire legal systems right? Just because US is messed up doesn’t mean the rest of the world is. Most people don’t live in US.
Paracompact
2 days ago
What's bullshit? You mean to say the dishwasher buyer would legally be on the hook for billions?
nekusar
2 days ago
Its bullshit that a terms of use can "agree" to what amounts to unconscionable terms.
Mozilla with their Thundermail just tried saying in their ToS that if you're mentioned at all in anything legal, you agree to pay their legal fees.
c0_0p_
2 days ago
That argument has actually worked in some cases, especially when you need to click away to actually access the document. I assume it's why we see more and more examples where you need to scroll the full body of text in order to "agree".
bluGill
2 days ago
Of you need a nonstandard contract then you need to provide proof that it was understood. These are not provided in a context where I would expect anyone reading it to have a lawyer to advise so they obviously don't understand it
otterley
2 days ago
By that same logic, do you believe ignorance of the law is a valid defense to a criminal charge? Laws are also written by lawyers.
bluGill
2 days ago
No, but I do believe that if the jury doesn't find it was obviously a crime without any being told the law then it wasn't a crime. That is the text of the law isn't important until guilty is decided. (So the jury can decide degree if that is a question for the jury, otherwise the judge needs to know for sentencing but the jury doesn't care)
Avicebron
2 days ago
> There’s a balance that needs to be carefully managed here. Yes, fairness to consumers is important. But you can’t destroy the incentive to produce value in so doing.
The value is derived from the people consuming the product. Placing the "incentive to produce value" above the people who presumably are the source of this value seems...misaligned.
otterley
2 days ago
If there’s no product or service to be consumed, there’s no value produced either. That’s the point: it’s harmful to eliminate the incentive to produce.
Avicebron
2 days ago
People will _always_ need things. There are very few things that will eliminate people's need for things and producers will of course adapt to the environment.
What we need is an environment that does not give the producers asymmetric power over consumers and the products will naturally align with that.
inigyou
2 days ago
What if only the incentive to produce bad things is eliminated
monkpit
2 days ago
* definition of bad is subjective and may vary depending upon which lobby group has the most cash to throw around
inigyou
2 days ago
no, I referred to actual bad things
otterley
2 days ago
The point is still correct. People often disagree on what is good and what is bad. It’s a judgement, not an indisputable fact.
readread
2 days ago
Oh good, nothing's possible then, we should give up on regulating bad things because hitmen think murder isn't bad when they do it.
otterley
2 days ago
How did you arrive at that conclusion? Laws are the result of debate between sides and the prevailing opinion. The fact that laws aren’t identical in every jurisdiction worldwide reflects that there isn’t universal agreement on every question.
Also, sarcasm isn’t welcome here. Please read the HN guidelines.
readread
2 days ago
> Also, sarcasm isn’t welcome here. Please read the HN guidelines.
Ah yes, I didn't couch my post in any of the various, rampant HN-friendly versions of shitposting. I'll try to follow your example from here on out. Excellent touch citing the guidelines at me after your role in this thread, A+.
Re-reads this thread, taking notes
Y_Y
2 days ago
You can hardly expect a greenname to have mastered such a subtle art.
readread
2 days ago
I abandon accounts when they get way into the hundreds of karma, generally, or a couple times I’ve let it get a ways into the thousands before destroying the password. I prefer not to become attached to it, and find the minor clout of recognition (upvoted comments that probably ought not have been…) kinda gross.
inigyou
a day ago
You shouldn't admit to multi-accounting. It's grounds to be shadowbanned.
readread
a day ago
Meh. I never have more than one at once, and destroy my access to old ones before creating a new one (often taking weeks or months off from posting in between). I'd be a lot more "dangerous" or "risky" if I were sitting on an old tens-of-thousands-of-karma account, which is what I'd have otherwise.
People routinely create alts just to post sensitive stuff and seem to do fine, and presumably they are keeping multiple accounts active at once.
[EDIT] I mean plus if I gave that many shits about being able to post on HN, I'd probably care a lot more about holding on to my precious karma in the first place, no?
Fraterkes
2 days ago
Your condescension is also obviously unhelpful here. Do better.
otterley
2 days ago
What precisely did I say that is condescending?
HN is supposed to have higher than typical standards for participation than most internet fora and is largely self policing. It’s not condescending to tell people when they are misbehaving. Nor is it condescending to explain to people the law and how things work, provided you’re not insulting them in the process. Which I’m not doing.
I find much more concerning people’s certainty of their mistaken understandings and beliefs, combined with the most ludicrous possible interpretation of other’s positions.
inigyou
2 days ago
so why do anything if it's impossible to tell what's good and what's bad?
user
2 days ago
bee_rider
2 days ago
I don’t see how we could possibly prove that the person who clicked “I agree” is still the person using the computer.
Or that any actual human is aware that an agreement was made (since an AI can find a checkbox nowadays or software can be configured to bypass it). One way to add balance could be to require people asking for contracts to actually treat them like real serious legal documents, show up for the signing, and figure out who they are making an agreement with.
otterley
2 days ago
That doesn’t matter. If you authorize an agent—human or mechanical—to enter into agreements on your behalf (even by mistake), and the agent presents itself as operating on your behalf, the agent’s decisions will be treated as though they were your own.
Prinicipal-agent law predates computers by a very long time.
bee_rider
2 days ago
What if an IT guy installs one of those “cookie banner be gone” extensions without the user’s permission?
deaton
2 days ago
But "its specifically engineered to ensure that nobody reads it" is a real argument
otterley
2 days ago
Where has this ever been adjudicated?
user
2 days ago
arjie
2 days ago
Good grief no. Using websites in the UK and the EU is an exercise in pain. Every single one of them has the doorway effect where you follow a link to them and you’re faced with some Subway sandwich grade range of choices to be made and you’ve forgotten why you were there in the first place.
As it stands I just hit Accept on literally everything and that’s fine for me.
j1elo
2 days ago
You could use Consent-O-Matic https://addons.mozilla.org/en-US/firefox/addon/consent-o-mat...
It already pushes the correct "Reject" button for you on a lot of sites (not all; it works based on rule lists)
arjie
2 days ago
I used this for a bit and then some sites would just not work. I get it. It’s a hard thing to do and I admire it but getting blank result is far more frustrating than clicking accept each time.
bbg2401
2 days ago
How cookie consent has been deployed by the data sponges is my go-to demonstration of malicious compliance.
ymolodtsov
2 days ago
Websites need cookies. I don't get why I have to suffer through this for a few puritans who literally lose nothing in the process of this transaction but act as if Stasi is watching them.
estebarb
2 days ago
Session cookies do not require a banner.
tempestn
2 days ago
Aggregated analytics do, and you can't run a serious website without some kind of analytics. Preference-storing does as well, despite any reasonable user expecting that, if they set a preference, it will be saved.
preg_match
2 days ago
You don't need cookies for basic aggregated analytics. Now if you want to track and record mouse movement, you do, and that's a privacy concern.
The law really has nothing to do with cookies, it has to do with privacy, tracking, and PII. You can absolutely save preferences and perform analytics. What you can't do is hoard data that is personally identifiable for purposes that are not obvious to the consumer.
evcaldera
a day ago
You need cookies if you simply want to run conversion analytics or any kind of performance marketing for media/ecommerce.
TurdF3rguson
2 days ago
Actually you can't send any cookie that is not essential to the operation of the website without consent and that would include analytics regardless of PII. same for pixel tracking / fingerprinting, it's all a no-no.
inigyou
a day ago
There's "legitimate business interest" which I think is a catch-all for things you want to do as long as they don't invade privacy?
TurdF3rguson
a day ago
Most of those things involve tracking users I imagine but if there's any that don't, go for it.
tappio
2 days ago
There are many analytics solutions that dont require cookies. You can do aggregated analytics just fine without. Saving preferences does not require consent either.
tempestn
2 days ago
My understanding is that any front-end analytics solution will require consent. You're right about explicitly set preferences. I was mixing that up with inferred preferences.
jason_oster
2 days ago
It depends on what is to be analyzed.
How many requests per second are being served? How many error codes were delivered to clients? How quickly the service responded? Service logs without PII? All perfectly fine to aggregate and analyze without consent.
ApolloFortyNine
2 days ago
How long did it take x user to navigate from x screen to y screen is one of the most valuable metrics for any site, and most people consider this to require consent. Or at least it not being worth the risk to not ask.
Acting dense like this isn't productive... And literally this information would be stores as anonymous user 12345, but that still would require consent (probably, or at least arguably).
tappio
2 days ago
That can be implemented. Within a session you don't need to know it's the same person tomorrow, so a per-day key derived server-side is enough to measure that someone took 40 seconds from x to y. No cookie, no localStorage, nothing stored on the device, nothing to consent to. Hash ip + user agent + your domain with a secret salt that rotates and is destroyed every 24 hours, and you are on the safe side. Of course, recognizing users across days requires consent. But is that really necessary?
inigyou
a day ago
Or use some JS to put the time-on-page in the next request, right?
Is it a violation to send data that could theoretically be used for more invasive tracking than you actually do? I don't think so, or else you'd need consent just to receive an IP packet.
anonreplier
a day ago
In the world of zscaler, CGNAT & corporate proxies, IP address is nowhere near enough.
literallywho
2 days ago
>How long did it take x user to navigate from x screen to y screen is one of the most valuable metrics for any site
Stats like that are only used to implement dark patterns better and justify user hostile decisions since pretty much the time the idea of telemetry was introduced. Otherwise, we'd live in the world of perfect web ui and we're not.
micromacrofoot
2 days ago
that's not true at all, plausible can be configured to require 0 consent
yjftsjthsd-h
2 days ago
> Aggregated analytics do,
Good.
> and you can't run a serious website without some kind of analytics.
I don't believe you.
> Preference-storing does as well, despite any reasonable user expecting that, if they set a preference, it will be saved.
IANAL, but I'm given to understand that this is untrue.
tempestn
2 days ago
You're right about explicitly set preferences.
What do you see as the harm in website owners using aggregated analytics data to improve their sites?
yjftsjthsd-h
2 days ago
Abstract: It's still spying on users.
Practical: Supposedly-aggregated stats have a history of actually being perfectly possible to analyze back into individually identifiable information. Also, it's conveniently the same tech stack in a way that makes it easier to make an actual slippery slope.
tempestn
2 days ago
The practical argument I can understand. From the abstract argument though, it sounds like you'd be opposed even if the anonymization could be guaranteed, which I don't understand. Why is it "spying" to try to understand in aggregate how users are using your website? How are you supposed to eg. identify usability problems without this information? And what is the harm to users? (Again, in the abstract case where we leave aside any possibility of individual users being identified.)
micromacrofoot
a day ago
because no one has shown an anonymization guarantee yet
micromacrofoot
2 days ago
if you're talking about cross site cookies, which are the big ones that require consent: no they don't!
inigyou
a day ago
Consent has nothing to do with crosssiteness except insofar as that proves it isn't needed for the operation of your own site.
micromacrofoot
a day ago
lol sounds like it does then
goodrubyist
2 days ago
[flagged]
TheScaryOne
2 days ago
>If someone does not read a contract or a legal agreement, before accepting or signing, it's on them
When was the last time you read an entire EULA before installing software?
I'm going to guess the time frame is somewhere around "never."
These are nuisance contracts designed to jade people with legalese while stealing their rights to things like class action and enforcing binding arbitration.
Standard contracts sounds like the way to go.
goodrubyist
2 days ago
I skim or read all the time, and so should people -- but ultimately they're adults and if they want to agree to them without reading, it's their choice (they shouldn't expect to later say they didn't read - this doesn't work, and that's how the current American legal cases were decided as well, thankfully, see e.g. regarding arbitration). Btw, regarding class action and arbitration, many of us already know that these are present in bold in the terms of many services we use or are going to use without even actually reading them.