Hacker News new | ask | show | jobs
by drnick1 10 days ago
It's not "quasi-malware," it is malware.
3 comments

15 years ago people would've called it spyware.
20 years ago people would've called it a trojan horse.

But then, by standards of two decades ago, every website that cannot legally avoid showing a GDPR popup would be classified as malware. As it should be today. Alas, standards have changed.

> But then, by standards of two decades ago, every website that cannot legally avoid showing a GDPR popup would be classified as malware. As it should be today. Alas, standards have changed.

I don't think you've read GDPR. In Europe (at least my part), *every* organization has a GDPR policy you need to agree to. Your child's school. Summer camps. Etc. Most are also conservative and reasonable.

What's broken is the GDPR popup with a dozen "legitimate interest" toggles for spying on you.

That was exactly the point OP was making.
That pop up is not required by GDPR

You only need explicit consent from the user for tracking you do not require for valid business purposes

It's like complaining that OSHA sucks because every time you visit the grocery store you have to sign a waver that if they throw you in a wood chipper, you cant sue them.

That problem is not with liability wavers!

What feels really crummy to me is how many people don't seem to know that websites cannot really prevent you from using them if you reject optional cookies, so average people are afraid that if they say no, they can't use websites.

Funny some you can't say no, so I'm like alright guess I'm not going in
There were no cookie popups 20 years ago.
Err, there were, prepare to feel old "Cookie consent pop-ups first started appearing following the adoption of the ePrivacy Directive in 2002" 25 years!
I beg to differ, there absolutely was cookie popups. We also had popup windows, popup ads, java applets that melted your cpu, and browsers with no grid. Oh, and we had Shockwave and Flash…
I think they meant that the use of cookies for analytics/tracking, which is what triggers the popup requirement, would have been considered malicious.
Indeed.
Some browsers would individually request you approve each cookie s website set. This is a feature of the browser itself that the website is unable to control. Lynx still has this option, I believe.
Yes, let's put the Overton window back where it used to be.
... If it was spying—,it isn't
My understanding is that these apps' TOS explains that by using the app you consent to having third party traffic routed through your device. For example [1] the Hola VPN's free users agree to let third party traffic get routed through their networks. Now, how closely users actually read the TOS is a different story, but it's arguably not malware on the grounds that users are, at least on paper, informed and agree to this behavior.

1. https://en.wikipedia.org/wiki/Hola_(VPN)

Nope, still malware. Arguing that people can technically read the TOS is (maliciously?) ignoring the social contract that most of us live by (i.e. don't trick people and screw them).
My understanding of malware is that it must cause some problem for the user.
Slowing down your internet connection due to using your bandwidth without your knowledge, getting blocked by websites due to malicious traffic from your IP address, extra annoying captchas due to the same. Those were just the first 3 things off the top of my head.
Got plenty of bandwidth, sites block you regardless, you get captchas regardless. Plus, IP addresses rotate once a day so you're just as likely to get someone else's bad reputation anyway.

To sue them you'd have to show some actual, concrete harm. For example you contact a site that is blocking you and they tell you it's due to a certain request and you trace that request to the proxy.

  > Plus, IP addresses rotate once a day 
This is entirely specific to the user’s ISP, my “dynamic” IP goes months without changing.

And I would be miserable if I were subjected to the volume of captchas and blocks on my regular internet connection that I see on the occasion I use Tor.