Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Most people find these popups annoying. We don’t want to negotiate every time we encounter a new website. We’re used to social structures where consent is provided implicitly. A look of the eye and unspoken social contracts are the norm. But data is too brittle to capture this kind of nuance.

Hmm no, I disagree hugely.

You don't need approval to do basic things. You need it because when I open a news article that triggers a demand to share something about me to over 1500 different companies. Not an exaggeration. That requires consent and rightly so, because it's wildly outside of normal social contracts.



I disagree. These things are so annoying most people just use a browser plugin that removes them entirely. I don't need a warning label on every website and I don't trust pushing a button on a site does anything except send more data.


I don't think we are disagreeing here. They need that consent, and rightly so, in order to do those things with your data. Removing the popups is just not consenting.

You implicitly consent for some basic things - if you order a widget then you don't need to sign a disclaimer saying they can use your address for posting it to you.

You need explicit consent to go outside of that, just like regular social interactions. I don't ask permission to remember your name and address if you've asked me to pick you up, I should ask permission before signing you up for a mailing list using that info.

The popups are because they're trying to step hugely outside of normal interactions.


> I don't trust pushing a button on a site does anything except send more data

Most implementations either load the tracking scripts after you click the button or hold back certain actions like cookies and network requests until you consent. Enforcement isn't as strict as it could be, but good enough that it mostly works


Do you stick your foot into bear traps with mostly working safties?


If they use the consent modal to gather data about you when you try to "opt out", they're already deliberately violating the law more than they would by simply not having that banner.

We're not talking about something that will take your foot off or something dangerous with safeties. But if you want gruesome analogies this is more like hiding razorblades underneath a safety seal warning about the package having sharp edges.


Right, I use a browser extension that automatically declines consent.

On my personal homepage I also use anonymous, privacy-preserving, GDPR-compliant analytics that doesn't require prompts. Other websites made a choice.


Or could be a browser preference that then send an HTTP header ? Wait https://developer.mozilla.org/fr/docs/Web/HTTP/Headers/DNT


The problem with DNT was that there was no established legal basis governing its meaning and some browsers just sent it by default so corporations started arguing it's meaningless because there's no way to tell if it indicates a genuine request or is merely an artefact of the user's browser choice (which may be meaningless as well if they didn't get to choose their browser).

As the English version of that page says, it's been superceded by GPC which has more widespread industry support and is trying to get legal adoption though I'm seeing conflicting statements about whether it has any legal meaning at the moment, especially outside the US - the described effects in the EU seem redundant given what the GDPR and ePrivacy directive establish as the default behavior: https://privacycg.github.io/gpc-spec/explainer


It's not a warning label, it's a request for consent which means they are legally required to ask you for permission and allow you to refuse them. Most implementations are actually violating the law by making it more difficult to refuse than accept or at least not giving the refuse option equal visual weight when they're not outright hiding it behind a bunch of extra steps.

This is different from the old "cookie banners" that were just informing you and leaving you no option but to dismiss the "warning". The GDPR and ePrivacy directive require companies to justify their use of your data and the only justification mechanism applicable for most of the data they want to collect is consent which must by definition be voluntary - the limitations of which are defined fairly explicitly in those laws.

Some sites try to work around this because they need ads for monetization by offering a paid subscription or requiring you to accept (behavioral) ads - but they've also been dinged for trying to bundle all the stuff not related to showing you ads with the "accept ads" option (or not letting you buy a subscription without first having to agree to share all your data like before).

I'm always surprised how many people in technical spaces like HN seem to misunderstand the legal situation and why these "warnings" look the way they do and blame the laws rather than the companies desperately trying to trick users into giving up on their data in ways that barely pass at an attempt to comply with the laws they're spending so much energy on deliberately violating. But it shouldn't be surprising - these companies put a lot of energy into making the process unpleasant for users (often in ways that are blatantly violating the laws) while framing themselves as the victims.


Yes social norm is if I have phone number of my friend and I am going to share it with someone, I ask that friend first if he wants his phone number shared with person asking.

Crooked companies overstepped social norms because they could get away with it - which is clear definition of an asshole, someone doing something shitty just because he knows he can get away with it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: