Hacker News new | ask | show | jobs
by jackson1442 2 days ago
"necessary only" also tends to have a malicious compliance aspect where they don't store a cookie recording your preference and show the banner on every single page until you click accept.
3 comments

Perhaps I am overly optimistic in thinking this is just incompetence.
Yes, you are. The legislative process around EPD/EPR fully anticipated the malicious compliance and it became a back-and-forth political football long before anything was passed. The legislators were never dumb and the corporations were always greedy+powerful.
I had one of the providers recommending us that we leave the "Decline All" button out of Europe, since it's not widely prosecuted, buy recommended that we add it to California, since chances are slimmer.

Naturally in a camera meeting with a "don't tell anyone we said that" appended right before.

The marketing people in the meeting were very angry that California was "doing it to them".

If they fully anticipated this then surely they could've fully anticipated how annoying and useless cookie banners are?

There is nothing stopping a website from using cookies regardless of the banner. If they are outside EU jurisdiction then there won't be any consequences either.

The legislators were and are dumb. They have wasted an enormous amount of collective time for no benefit. Big corporations continued doing what they were doing and nefarious third parties could still track you.

> surely they could've fully anticipated how annoying and useless cookie banners are

They did. The laws were airtight in this regard. They simply lost -- whether through a last minute "tweak" or undermined enforcement mechanism I do not know, but I do know that the current state of affairs was fully anticipated and headed off at the point where I reviewed the proposal. Your vitriol is bass ackwards -- the lesson is to strengthen the walls between corporations and the legislative process and support enforcement mechanisms, because those were the places where the process failed. Not the intelligence of legislators. Otherwise you will keep losing to the corporations, and you will deserve to.

The law is airtight. Acceptance must be informed and freely given (this includes forcing through dark patterns and annoying banners that force you not to read), and withdrawal should be as simple as acceptance.

GDPR article 7 and its various recital already include that. GDPR wisely doesn't get into technical details like "cookie banners" anywhere, but various national agencies did set guidance and it's usually quite explicit: Rejection must be as simple as acceptance and reject buttons or link must be as prominent as the accept buttons and links.

For example, CNIL, the French data privacy authority, clearly says[1]:

"The CNIL has received complaints about dark patterns on cookie consent banners encouraging data subjects to accept cookies.

As a reminder, with certain exceptions, cookies can only be used with the consent of data subjects. Moreover, rejecting cookies should be just as easy as accepting them."

And gives examples of dark patterns such as different button sizes, multiple accept buttons, hidden reject buttons, etc.

The law and specific guidance is pretty unambiguous. This purely an enforcement problem. The regulatory bodies do not have the resources to go and chase most individual companies, and the non-profit NGOs that go after the violators apparently don't have the budget to make enough impact and scare companies into compliance.

[1] https://www.cnil.fr/en/dark-patterns-cookie-banners-cnil-iss...

>Otherwise you will keep losing to the corporations, and you will deserve to.

I get a cookie pop up on https://europa.eu

This is a website that effectively has infinite funding and has to make zero money. And I still get a cookie pop up.

Is this also the fault of corporations?

The EU isn't some kind of hero saving us from evil corporations. Just look at the recent customs duty that makes things much more expensive for regular people.

Sometimes the folks commenting here are exactly those corporations, so there.
We are on news dot rich corporate billionaires dot com, after all.
Well, maybe it is... but then the PM never prioritizes testing or fixing the problem. They're not intentionally trying to get more people to accept cookies, it's just that there are always more important features to build and fires to fight, and fixing the cookie banner won't move any of the metrics executives are breathing down their necks about, and it won't look good in the perf packet...

But of course, designing the system that pushes people to make this sort of decision was absolutely intentional.

So even when it's incompetence, it's still malicious, just in a way that obscures the explicit decision-making that led to the result.

I don't see that as malicious. Is my consent record "strictly necessary"? No. Don’t get me wrong. I’m sure they love that, but if sites saved that preference when only necessary was selected, I’m sure a bunch of people would be screaming that they weren’t following the law.
The entire banner is malicious. They don't need consent for necessary or functional cookies. They only need consent to track you - at no benefit to you ever.
I don't think anything is actually "necessary" if you want to be strict on definitions.

I think it's absolutely fair and unlikely to be illegal to use a cookie to remember cookie preferences. Unless the cookie value was not yes/no, but something like a precise timestamp that could be used for uniquely identifying.

Yes, it is strictly necessary to properly honour the user's choice. Not storing a rejection of consent but storing acceptance violates the GDPR because it creates an asymmetry between the effort required to accept vs the effort required to reject user data processing.
The malicious compliance aspect is that they're not offering a choice between "tracking" and "no tracking", but bundling "no tracking" + "painfully degraded functionality" (like repeating the question on every page) = "strictly necessary cookies only"
There is no legal requirement to ask for consent for first party functional cookies. The cookie banner is only for invasive 3rd party trackers.
which they can be sued for as that's not compliant way to handle it. Just that nobody bothers