Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

it's an example of malicious compliance by some, and herd mentality by others.

I had a discussion with my CFO about removing the cookie banner from our website (because we don't set any tracking cookies, and cookies for things like login are exempted) and he said "yeah, but it makes the site seem less legitimate.



That reasoning isn't wrong, though it seems ridiculous when looked at with techie-brain. But if there is a standard expectation of what serious company websites are like, it makes business sense to look like that too. It's like dressing up appropriately to cultural expectations. You can deviate somewhat but you have to strategically spend your weirdness points.


How nice of the EU to have determined for the rest of the world that the “cultural expectation” should be that every business do the design equivalent of wearing clown makeup.


The EU doesn't require banners.

Companies could stop selling and storing your data. They could only use cookies when absolutely essential. They could use lots of kinds of UX.

This is the equivalent of businesses who put a big visible "20% the state says we have to give our employees healthcare" fee on their bill to throw a hissy fit and hope customers get angry at the government for protecting them instead of the business for exploiting them.


Banners exist to eliminate EU regulatory risk. You can try to convince people they aren’t required but its not going to remove any banners.


This is misinformed.

As many have said before:

  it's basically malicious compliance. They're supposed to be super annoying ... Instead of complying, they choose this obnoxious practice so they could continue ... monitoring every action a visitor does.

  You don't need a cookie banner to be allowed to create Cookies. You only need them if you're using them for something like tracking. [1]

  Regulators didn't enforce cookie banners. Cookie banners are a form of malicious compliance. When you complain about them, you are doing the lobbying work of ad companies for free. The correct solution is to just not spy on people, and the problem is that the EU didn't go far enough and just ban the behavior altogether. [2]

  Cookie pops are malicious compliance to regulations that legitimately protect consumers. You’ve cherry picked one bad side effect to throw out all the ways the EU is way ahead of anyone else in protecting consumers [3]
[1] https://news.ycombinator.com/item?id=29529148

[2] https://news.ycombinator.com/item?id=38299135

[3] https://news.ycombinator.com/item?id=46552795


Why does static site of Europe's parliament need big cookie banner? Or is that the parliament which created this law doesn't know what you know or they are doing "malicious compliance".

[1]: https://www.europarl.europa.eu/portal/en


Because they want to track people and they need consent for that.


I know the technical reason. I was contesting the GP's comment that most site display banner "Instead of complying". Most website needs basic tracking and there is nothing wrong in it.

We are just conditioned to see it without difference in basic tracking and tracking all your clicks across site and selling it to advertisers.


Because they use a commercial service (AT Internet) for analytics and visitor tracking as stated in their cookies policy and cookie inventory. This information is readily available through the cookie banner.


Clearly they are just trying to rile up users against the EU.


If properly following a law is malicious, then it's a bad law.

There's a reason you don't hear about people "maliciously complying" with HIPAA or PCI laws. Because that's just called compliance.

No excuses for poorly done EU regulations.


You can comply with the law without banners and dark pattern defaults. These businesses are maliciously complying by making things more obnoxious and painful than they need to be.

A comparison would be a store who was angry the law says you have to be 21 to buy alcohol and starts requesting everyone, even people not buying alcohol, to show ID or be kicked out. That's not a bad law, that's a bad business maliciously complying.


They certainly don't eliminate regulatory risk, since most of them don't actually comply with the law at all.


The EU didn't have to do anything. The User Agent can already handle everything from denying cookies to blocking requests for certain resources.


Let me know when you find a User Agent that can smack a CEO over the head with a virtual cluebat whenever he sells a list of email addresses that signed up to his site, because that's what the regulation is about and I certainly don't see how a UA could enforce it.


The user agent can refuse to store cookies, but it can't do much against supercookies (cookie-like features not knowingly implemented by the user agent programmers) or fingerprinting: you need something like legislation to curb practices like that.


I don't care about this. I explained why for an individual business trying to project seriousness, it makes sense to adopt a banner in the current environment. I didn't say it's nice of the EU or anything of the sort. It's an incentive pressure that exists on an individual company in the current situation. That's all I said.


It's more like a cultural expectation that business do shady things and the "clown makeup" is a compromise that government found between making those shady things illegal (utopia) and don't intervene at all and let the corporations set their rules (dystopia).

It's like those warnings in cigarettes packages saying they will kill you. I know cigarettes are bad, but the warnings also make me believe there's at least "some" control in how bad they are. Now if I buy one without the warnings, I will worry those in particular are extra-shady and likely to kill me even faster.


>warnings in cigarettes packages

Oh how I miss those warnings. Nowadays the packages are covered in graphic body horror pictures. And there's no branding on them any more, just white text on a black background, so I have to carefully check that the illiterate teenagers at the store gives me the correct ones.

Do anyone else hear circus music?


I think the point is to make you stop smoking, without actually making it illegal to smoke. Have you considered stopping smoking?


You could have a 'no cookies' badge that links to your cookie policy - 'we use no tracking cookies and so are compliant with EU law ... then list any cookies/local-storage used and explain what they're for.


That would make you sound a lot more professional too. And trustworthy. (As long as that's actually what happens).

When I see these dialogs listing they have 1289723 gazillion vendors they share data with, I know that whoever is in charge of analytics, privacy or both at the company is incompetent.


Best we can do is a full screen model or annoying toast telling users we dont use cookies and click 4 to 7 check boxes to agree.


But then you can't have tracking cookies.


No one is tanking UX to stick it to the EU. It would be better for them to simply not piss off their users. They are covering their ass.

The obvious conclusion is that when you try to regulate something like this you arent going to get the behavior you want.


They're not covering their ass, they're making a deliberate tradeoff.

It's trivial to make a site that doesn't need a cookie banner: don't set any cookies. Modern web devs have probably forgotten, but this is actually the default behavior. Cookies don't get set unless you do something to make it happen.

And cookies that you actually need for functionality don't need a banner either. If you're setting a session cookie for logged in users so they stay logged in when navigating between pages, you don't need one.

Why, then, does practically every site in existence now have one? Because they set unnecessary cookies. Because they choose to set unnecessary cookies in order to track you for purposes that are not necessary to the actual functionality of the site.

Every single cookie banner you see is a big sign that says, "We value our ability to track you for marketing purposes more than we value your time."

Apparently they're willing to say that. I still see it as a win. No tracking and no banners would be ideal, but at least the regulation forces them to be honest and up front about what they're doing. I'd rather have tracking and cookie banners announcing it than tracking with zero indication of tracking.


Every site needs analytics no, unless you're going to walk in the dark, and they need payment processors. If it was just about ads, they could have limited it to ads, like 'tracking for the purpose of advertising,' though even then is a press release advertising, and every serious company is going to have press releases.

They could have instead targeted it, and applied it, to third party ad providers only, like Google. And, btw, Google is big enough they could have just outright named it. They're worth as much as the GDP of Germany. Why not just make a Google law?

So yeah, maybe good intentions but it clearly shows the EU parliament is still too young and inexperienced.


Nope, you don't need analytics. You might want analytics, and you might want them enough to bother every single visitor with a popup so you can have them, but you don't need them.

And if you decide you need them, you can do them server side. That's not as good? Oh well. See above about want vs need.

Why not just make a Google law? Because Google is far from the only abuser. Using a VPN that routes through Europe is a real eye-opener. At least whatever country I got routed through apparently required that cookie banners include a list of every single partner who got your data. Pretty much every site had hundreds of them. One was literally over a thousand. No, the entire industry is rotten. And the epidemic of cookie banners just shows how rotten it is. They can't even be shamed into behaving.


I think at this point everyone has forgotten what problem they were trying to address exactly, because they clearly haven't addressed it.

I think it was something like Google knows what you eat, or will eat, for breakfast. Ok, Facebook too and some other trillion dollar companies. That is cross websites infrastructure, data mining, etc, etc - platforms in one word. Why not apply all this to the ones doing it though, instead of making all websites responsible?

In regards to analytics, the library needs to know what book you borrowed. Sure, a website doesn't 'need' in some platonic sense to know what article was most read today, but the EU parliament clearly does.

It is a hard problem though, what they were trying to address, but arguing that they were effective beyond showing that there is an EU jurisdiction is not at this point a persuasive argument.

It's fine though. This is still a very new parliament. It can and hopefully will learn from the experience and maybe even make an effective use of that very new EU jurisdiction, like maybe break up these tech monopolies, or try.


Consult a lawyer - anonymous analytics for a good reason are legal, with no banner.


Why don't they just not comply with the law then? HN doesn't, and gets away with it just fine.


HN does comply with the law, theres no tracking cookies set.

The only cookie is a functional one.


GDPR isn't about cookies. HN egregiously violates other parts of it, like the rights to export and deletion.


Many years ago, I used to make informational websites for small, local businesses and they all wanted the cookie banner "just to be safe", even after explaining they didn't need it.


But are you a software developer or a lawyer? Do they 'not need it' because the government provided a way to ensure it's not needed or because your interpretation of the law indicates it's unnecessary? Are you willing to indemnify them for legal costs if your guidance was wrong?

Most small business owner's I've spoken to are keenly aware they are only one bad lawsuit away of closing down. Almost no one care's about the cookie banner. Most just mindlessly click to allow cookies and go on with their life. There's almost no cost to having it.


The 'better safe than sorry' calculation of small businesses skews almost 100% toward 'safe' because almost all govt regulations contain no reasonable size scaling cap on penalties. Any penalties on a website that are per-occurance could be almost infinite.


GDPR actually has one. It's 3% of global revenue.


This website contains chemicals known to the State of California to cause cookies.


The Irish Republican Army, even at the height of their conflict, would never have stooped to such a website.


I'd say just remove it. Don't ask people who don't actually understand the cost of having it there because you will get the wrong answers. Sometimes people just have to do the right thing, take some heat and then everyone can move on. If it has severe consequences then that's probably a good reason to leave anyway.

Back in the day, this is how we introduced AWS at a large company. We just did it. And once done, they couldn't deny that it cost a fraction of what we were paying our supplier and that things took minutes to set up rather than weeks. And that they worked a lot better.

Yes, there was shouting in meeting rooms. And yes, people said "you can't do this". Turns out they were wrong. A few years later I mentioned this to Werner Vogels. During a meeting. Where my CEO and CTO were present. And where everyone was feeling very good about us being one of AWS' biggest customers in our region.

So when someone says "you can't do that", sometimes you should make them prove it.

(At the time AWS was a good idea. Today dependence on a US service provider is a harder sell in Europe. The _first_ question you get today is if we can host it ourselves if we need to or if we can use a local service provider.)


I have the same mindset and often did the same thing, but then I thought about my doctor sneaking into my house while I’m sleeping and injecting me with the “good medicine” I had refused in their office.


I did not anticipate where that sentence ended up :-).


Do you ask your manager whether to indent your code? Of course not, you just do it. Because it's your job and not theirs.


holy shit - if AWS cost you a fraction of your other supplier, you were getting really ripped off.


> but it makes the site seem less legitimate

I have yet to head that cookie prompts are a sign of legitimacy. What business has customers that would think that way?


Not customers. Owners.

Although if you've ever worked retail, you'll know that plenty of customers are idiots.

Whatever "Surely no one is that stupid!" assumptions you make will be proven wrong no matter what you do.


I have had the same discussion multiple times at multiple companies. Luckily most of them were fine with dismissing the popup with a timer.


Reminds me of the early days of the CANSPAM act.

One of the best indicators that something was not spam was the unsubscribe button.


I built an ecommerce site long ago, and even though the UI was fairly modern for the time, they insisted we use antiquated styling on the billing forms of the checkout page to help exude trust. As a developer it bugged me because I knew it was just styling, but they probably weren't wrong.


In my experience, most people come in two camps: 1) they just click to make it go away because they click everything and would agree to sell their own mother to organ scrappers just to get past the annoyance, and 2) they understand what it's asking and are immediately suspicious.


You may float an idea to describe what you've just said in the banner, and have just a "close" button.

E.g. "we don't set any tracking cookies, so we're already compliant with the law even without banner, so there's nothing to decline or agree to".


I would hate that more than an actual cookie banner. You didn't have to popup but you chose to anyway just so I could give you a pat on the back?


> and he said "yeah, but it makes the site seem less legitimate.

He may be right, sadly. I’ve seen the lack of a cookie banner used to suggest that a site was doing something shady or not complying with the law.

Most people don’t have knowledge about the finer details of cookie laws. They’ve been trained to believe that legitimate sites who comply with the laws will implement the cookie banner, and not seeing it feels suspiciously unprofessional.


Who suggests that? I've never seen it. I've never seen anyone who would even notice if there wasn't a cookie banner. They'd just think they'd been there before, and already accepted it.


It's not malicious compliance when the very governing authorities for this in the EU do the same thing.


Good point. The page should have 200MB of assets so that it loads slowly, making it look like there's serious engineering going on.


>it's an example of malicious compliance

So how would you do ePrivacy Directive compliance/risk avoidance in a non-obnoxious way?


Don’t use a bunch of unnecessary tracking cookies?

Completely eliminates the need for a cookie permission bar.


I am obviously referring to a scenario where tracking cookies would be highly beneficial to expanding the business, e.g. e-commerce.


Something being beneficial to a business does not make it broadly necessary, desirable, or - in many cases - legal.

It would be extremely beneficial to businesses to put a clause in their terms and conditions that limit damages to 1 cent in the event of any dispute. For obvious reasons we don't allow anything like that to be enforced.

I'm not saying whether tracking should or shouldn't exist, but "the business can make more money" is not a valid argument in my book.


Don't set a tracking cookie, use of IP addresses is allowed for legitimate purposes (Art 6(1)(f)) as long as they're not stored.

At least for GDPR...

The only ways to actually track without a consent pop-up are:

(1) stay off the device entirely and process server-transmitted data under legitimate interests with a privacy notice, or

(2) confine any device storage to what's strictly necessary for the service the user requested


This goes to show that the assertion that cookie banners are just "malicious compliance" isn't quite correct. These are significant trade-offs here.


you don’t need to track users by giving them an ID they send with every request.

in fact. you probably don’t need to track users.


tracking cookies are so obviously beneficial to e-commerce that they passed an entire law to disclose them because people... liked them so much?


I don't exactly see how these two statements are contradictory. Policy is about conflicting interests.


The law does not say 'tracking'. It says 'strictly necessary'. If you remember the user's light/dark theme preference in a cookie, that requires notification. (Or rather, what it requires in practice is that you hire a Highly Paid Consultant.)


No, it doesn't. If it's reasonably expected as part of the service, you don't need to gather consent. It's not even personal data.


The law does not say 'reasonably expected', it says 'strictly necessary'.


Sorry, getting my GDPR and e-privacy terms mixed up. The cookie is strictly necessary for the setting to be saved. The user has specifically requested that the setting be saved by changing it. The opinion suggests this should be a session cookie unless you indicate somewhere prominently next to the setting that it uses cookies to store it for longer. This still doesn't require a cookie banner.

What's more, if the 'cookie' is entirely local (i.e. it's never sent back to your own server, e.g. you're using the local storage API and the javascript on your page never puts that information into a request), like how this would normally be implemented nowadays, then these requirements don't apply at all (because a cookie according to the law is just something your server gives to the user's device and then the device gives back later).


Okay, but it doesn’t require notification for every user that hits your landing page.

If you want to remember dark mode with a cookie, then you can just gate that setting behind a “allow functional cookies” toggle.

Getting consent for functional cookies doesn’t have to be done with an intrusive cookie bar on landing. You can request consent as it becomes needed. There’s other ways of complying that aren’t dark patterns.


Can you please tell me what part of this law requires any sort of notification or toggle whatsoever for remembering your dark mode setting: https://gdpr-info.eu/art-6-gdpr/


You're replying to me, but I'm not the one asserting it. The GDPR law doesn't require it specifically, but the earlier ePrivacy regulation does and it is considered to be the guide for GDPR on this specific issue. Lex Specialis is the term for one regulation being applied within a different one.

In any case here is a plain text interpretation from the EU (https://gdpr.eu/cookies/):

"Strictly necessary cookies — These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookies. While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user.

Preferences cookies — Also known as “functionality cookies,” these cookies allow a website to remember choices you have made in the past, like what language you prefer, what region you would like weather reports for, or what your user name and password are so you can automatically log in."

Farther down:

"To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must:

Receive users’ consent before you use any cookies except strictly necessary cookies. ..."

So a preference cookie is categorized differently than "strictly necessary" by the ePrivacy rules predating, but now part of, GDPR. But elsewhere in this thread someone asserted that a cookie that is placed and the data never sent back to the server is exempt, so if you handle dark mode entirely client side you might be ok?

I'm beginning to understand why the lawyers in the EU just say "fuck it, put a banner up"


I thought GDPR replaced ePD. Are you saying it did but specific things like how you should ask for consent carried over?


I’m not your personal lawyer, and your tone is abrasive elsewhere.

Google “lex especialis eprivacy GDPR”.


OK, so don't do that. Web sites work fine without remembering anonymous users' preferences across sessions.


Can you point to the law in question?


Nonsense.

You are correct that people keep stating such things. But it is incorrect.

That example would be an essential cookie, also known as a strictly necessary cookie.

A shame this FUD is still being spread.


That's not what various references (and AIs) say. Strictly necessary means strictly necessary. They didn't bother defining it in the law. However, user preferences were called out specifically in the WP29 opinion as something that wouldn't count as strictly necessary if scoped any wider than the browser session. So if the plain English meaning and the drafters' opinion contradicts your opinion, why should I risk significant fines to trust it?


Yeah well most references on this are wrong, and AIs are doubly wrong since they ingest those references and also since they are AIs.

I suggest actually reading the GDPR if you think it applies to you. The EU put it up on a website for everyone to see. Here's the most relevant section: https://gdpr-info.eu/art-6-gdpr/

Notice how cookies are not mentioned, popups are not mentioned, and strictly necessary is not mentioned. Those are requirements the data harvesting industry invented out of whole cloth. They are not the actual requirements.

I'll just repeat that one more time: the GDPR does not mention cookies or popups. Let that sink in. It's all cargo-cult.

The GDPR also doesn't give a shit about dark mode preference. Literally nothing in it has any relevance to a dark mode preference, even (and especially) if you store it in a cookie.


See my other response with citations.

In short: the GDPR doesn't mention it but it is covered by the ePrivacy directive/regulations which does cover cookies very specifically, and which is enforced through GDPR.


What does "enforced through GDPR" mean here? That if you don't ask permission for saving a dark mode preference, they'll fine you for misuse of personal data even though it isn't personal data and you're not misusing it?


You read and replied to my other response. It answers this question and gives you the laws you demanded and the terms to research the answer to this question.

Have a good day.


Why are you even bringing up GDPR? The law requiring cookie banners is a completely different law. Have you not seen a cookie banner? You think all these huge companies with legal departments are just misreading a law? What are you even ok about here?


a) The law does not require a notification for this use of cookies.

b) Please don't re-implement OS/browser functionality in your website.


Don't, since ePD got replaced by GDPR.


To whom??? Literally nobody thinks that way. You should convince him to let you do an A/B test.


CFO should be fired immediately.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: