Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This passed in Sweden about a year ago, as required by the EU-directive. What's happened since? Essentially, nothing.

While a few government-related sites show information on cookies and a checkbox for opting in, noting that the site may not work properly otherwise, the average site has made absolutely no changes.

I think this proposal sprung from good intentions, but has been executed poorly. It's likely aimed at reducing tracking-cookies, something which most of us would consider a good thing, but this is clearly not the right way. I know of no person or site that has gotten in legal trouble for not showing this "Cookie-warning" or an opt-in button. It's simply unenforceable.



>I know of no person or site that has gotten in legal trouble for not showing this "Cookie-warning" or an opt-in button. It's simply unenforceable.

Nor should it be. The day this becomes massively enforced (god forbid) is the day that an adblock-esque plugin will be created to bypass all of this idiotic government mandated nonsense. Those options exist in web browsers already.

And it is nonsense. It does nothing to protect users, for one. The average user has no idea what a cookie is, and will either blindly click accept or move on.

For two, its the government getting their hooks into mandating specific content on the web. Yes yes, slippery slope is a logical fallacy and all that, but when it comes to government expansion of power, it tends to ring true.

For three, it's a pain in the ass. I really do not care what kind of cookies random sites are sending me. If I did care, I'd be running a plugin to deal with it or changing my browser settings accordingly.

Fourth, it's more work for web developers for questionable benefit.

Maybe this is just me being a typical ignorant American, but this kind of nannyism is downright offensive to me.


They may have severely screwed up the implementation but there's very real and very murky tracking going on through ad networks using cookies and any other way they can think of. This is what the legislation was aimed at, but it went totally OTT.

99% of the time, there is no good reason for anyone to know what different sites I visit. Nor does anyone have any reasonable expectation that it is happening to them.

Also why an adblock-esque plugin? That really makes no sense to me. This is about a server not being able to set a cookie without explicit consent, I can't see how a plugin would help.


If you really want to track your users without a cookie you can do that just fine:

https://panopticlick.eff.org/

And if you do use cookies these can be restored after a wipe from lost of sources:

http://samy.pl/evercookie/


>I can't see how a plugin would help.

Either a "yes I accept the damn cookies everywhere" (you know, the hassle free system we have now) or a "no I don't accept the damn cookies anywhere" option.

People have an interesting way of engineering around annoyances.


It would obviously be the latter right? Because who wants some random advertising agency putting together you like concentrated acid and bathtubs?

Just me?


You already have that option in your browser. It's called "disable cookies".


Just to add, additionally, you can still track users just fine without cookies.

You can uniquely identify pretty much everyone on the internet by their browser version/plugins/etc etc, then do a callback with the info, store that serverside.

So if a user clicks to disable cookies, you can just fall back to tracking them via other methods if you really want to.

Having any policy around 'cookies' is idiotic and shows just how non-technical the government/politicians are.


It's not just cookies though. I believe they say it applies to all tracking technology, now or in the future.


There is a clear distinction between active and passive tracking. The law applies to active tracking, whereby something is stored on a user's computer and this something is subsequently retrieved/read. Cookie tracking is a form of active tracking. Passive tracking, whereby nothing is first stored on a user's computer, is not covered by the law. Indeed, it is difficult to see how it could ever be covered.


If tracking is done on the server, how would anyone know/be able to prove that it is taking place?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: