Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The EU didn’t tell those sites to show cookie banners, they just told them to stop collecting people’s data without their consent. It’s the sites that interpreted that as “annoy people until they consent so we can keep collecting their data”. That’s not really the EU’s fault, although they should have seen it coming.


The EU is showning these banners on their own websites. So not even the EU is capable of creating a website without banners (because - even the EU - wants analytics and other bullshit).


The EU parliament website says "We use analytics cookies to offer you a better browsing experience. You have the choice to refuse or accept them." I'd personally rather have the choice than not.


> I'd personally rather have the choice than not.

There are browser settings since the invention of cookies to control which sites are allowed to set cookies.


Yes, but not what the cookies can be used for, an important distinction.


They could have also started by making the ~4 web browser suppliers implement this consent dialog (remember Netscape cookie dialogs everybody hated 20 years ago?). Then the two W3C/IETF to create a protocol for transmitting consent to the server. Instead of making thousands of companies having to individually spend the money to implement it.

Great for job creation numbers. Crazy mismanaged in all other aspects.


Thank you! Actually, they could also take this strategy to protect kids from adult/violent/sensitive content. I suspect their strategy is to replicate, with Internet, what they have done with the Financial industry. So it should not be considered as incompetence... on the contrary. (See my other comment for further details https://news.ycombinator.com/item?id=37457745#37461669 )


I think the “Do Not Track” HTTP header was inspired by a similar idea…but then people used it for tracking (using a non-default setting is a good way to be unique.) https://en.m.wikipedia.org/wiki/Do_Not_Track


Policy makers are responsible for the unintended consequences of the policies they implement.


It's like we need to have a recurring demonstration of the old saying 'the path to hell is paved with good intentions' because we keep forgetting.


And I basically never give my consent. I'm happy that I have that choice (assuming a site honours it, of course).

This also allows me to decide which sites value my privacy (no cookie banners) and which do not (annoying banner every time I visit), so that's another plus in my opinion.


You always had that choice. All browsers Support deleting cookies.


Now that we live in age of javascript. Why not have user manually ask the server to set a cookie if they wish to be tracked?


GDPR isn't about "cookies", it's about how the website operator is allowed to abuse your personal data. Cookies are just a minor implementation detail that's only applicable to a subset of websites that don't require an account (otherwise it's stored in database).


This stuff is why I've moved over to the idea that governments doing nudges[1] is worse than just outright passing laws and polices to tell people what they have to do. In the case of cookies, pass laws forbidding collecting personal data. Done. Bonus getting to hear tech bro's whine they broke the law and can't go to Europe anymore.

[1] Thaler and Sunstein: any aspect of the choice architecture that alters people’s behavior in a predictable way without forbidding any options or significantly changing their economic incentives.


If a policy will predictably backfire, but the EU passes it anyway because the policy has good intentions, I would actually describe that as the EU's fault.


The purpose of these laws is exactly to change people’s behavior through incentives. So if the incentives produced by the law resulted in behaviors with negative social outcomes, that really is the fault of the people who came up with the law.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: