Hacker Newsnew | past | comments | ask | show | jobs | submit | jackson1442's commentslogin

"necessary only" also tends to have a malicious compliance aspect where they don't store a cookie recording your preference and show the banner on every single page until you click accept.

Perhaps I am overly optimistic in thinking this is just incompetence.

Yes, you are. The legislative process around EPD/EPR fully anticipated the malicious compliance and it became a back-and-forth political football long before anything was passed. The legislators were never dumb and the corporations were always greedy+powerful.

I had one of the providers recommending us that we leave the "Decline All" button out of Europe, since it's not widely prosecuted, buy recommended that we add it to California, since chances are slimmer.

Naturally in a camera meeting with a "don't tell anyone we said that" appended right before.

The marketing people in the meeting were very angry that California was "doing it to them".


If they fully anticipated this then surely they could've fully anticipated how annoying and useless cookie banners are?

There is nothing stopping a website from using cookies regardless of the banner. If they are outside EU jurisdiction then there won't be any consequences either.

The legislators were and are dumb. They have wasted an enormous amount of collective time for no benefit. Big corporations continued doing what they were doing and nefarious third parties could still track you.


> surely they could've fully anticipated how annoying and useless cookie banners are

They did. The laws were airtight in this regard. They simply lost -- whether through a last minute "tweak" or undermined enforcement mechanism I do not know, but I do know that the current state of affairs was fully anticipated and headed off at the point where I reviewed the proposal. Your vitriol is bass ackwards -- the lesson is to strengthen the walls between corporations and the legislative process and support enforcement mechanisms, because those were the places where the process failed. Not the intelligence of legislators. Otherwise you will keep losing to the corporations, and you will deserve to.


>Otherwise you will keep losing to the corporations, and you will deserve to.

I get a cookie pop up on https://europa.eu

This is a website that effectively has infinite funding and has to make zero money. And I still get a cookie pop up.

Is this also the fault of corporations?

The EU isn't some kind of hero saving us from evil corporations. Just look at the recent customs duty that makes things much more expensive for regular people.


The law is airtight. Acceptance must be informed and freely given (this includes forcing through dark patterns and annoying banners that force you not to read), and withdrawal should be as simple as acceptance.

GDPR article 7 and its various recital already include that. GDPR wisely doesn't get into technical details like "cookie banners" anywhere, but various national agencies did set guidance and it's usually quite explicit: Rejection must be as simple as acceptance and reject buttons or link must be as prominent as the accept buttons and links.

For example, CNIL, the French data privacy authority, clearly says[1]:

"The CNIL has received complaints about dark patterns on cookie consent banners encouraging data subjects to accept cookies.

As a reminder, with certain exceptions, cookies can only be used with the consent of data subjects. Moreover, rejecting cookies should be just as easy as accepting them."

And gives examples of dark patterns such as different button sizes, multiple accept buttons, hidden reject buttons, etc.

The law and specific guidance is pretty unambiguous. This purely an enforcement problem. The regulatory bodies do not have the resources to go and chase most individual companies, and the non-profit NGOs that go after the violators apparently don't have the budget to make enough impact and scare companies into compliance.

[1] https://www.cnil.fr/en/dark-patterns-cookie-banners-cnil-iss...


Sometimes the folks commenting here are exactly those corporations, so there.

We are on news dot rich corporate billionaires dot com, after all.

Well, maybe it is... but then the PM never prioritizes testing or fixing the problem. They're not intentionally trying to get more people to accept cookies, it's just that there are always more important features to build and fires to fight, and fixing the cookie banner won't move any of the metrics executives are breathing down their necks about, and it won't look good in the perf packet...

But of course, designing the system that pushes people to make this sort of decision was absolutely intentional.

So even when it's incompetence, it's still malicious, just in a way that obscures the explicit decision-making that led to the result.


I don't see that as malicious. Is my consent record "strictly necessary"? No. Don’t get me wrong. I’m sure they love that, but if sites saved that preference when only necessary was selected, I’m sure a bunch of people would be screaming that they weren’t following the law.

The entire banner is malicious. They don't need consent for necessary or functional cookies. They only need consent to track you - at no benefit to you ever.

I don't think anything is actually "necessary" if you want to be strict on definitions.

I think it's absolutely fair and unlikely to be illegal to use a cookie to remember cookie preferences. Unless the cookie value was not yes/no, but something like a precise timestamp that could be used for uniquely identifying.


Yes, it is strictly necessary to properly honour the user's choice. Not storing a rejection of consent but storing acceptance violates the GDPR because it creates an asymmetry between the effort required to accept vs the effort required to reject user data processing.

The malicious compliance aspect is that they're not offering a choice between "tracking" and "no tracking", but bundling "no tracking" + "painfully degraded functionality" (like repeating the question on every page) = "strictly necessary cookies only"

There is no legal requirement to ask for consent for first party functional cookies. The cookie banner is only for invasive 3rd party trackers.

which they can be sued for as that's not compliant way to handle it. Just that nobody bothers

My main issue with these systems is that they tend to not be able to do anything beyond what I can do myself in whatever self-service portal is available. If I'm calling, it's because I need support beyond what the bot can probably provide, and it just becomes a matter of arguing with the robot to get to a human who can actually solve my problem.


Yeah but unfortunately the majority of people calling are calling about things they can do themselves in the self-service portal.


They have not, at least in my region, it's a fun little party trick when I see a locked cart out on the sidewalk.


what if someone else takes your stuff and puts it on the internet unrestricted?

https://arstechnica.com/tech-policy/2025/02/meta-torrented-o...


yep, it can be detected in JS and even CSS with a media query: https://developer.mozilla.org/en-US/docs/Web/CSS/@media/pref...

Depends on how the dev wants to implement it, usually when I'm throwing a small animation on a site I'll silently respect the preference and skip the animation without an override option, but for a site like this I'd expect an override switch.


[ citation needed ]


I don't think I need a citation to say that it's feasible for China to inject malware via the TikTok app on people's phones. Would it be difficult? I imagine so. But, I think the risk is such that the onus is to prove that it's not possible, not the other way around. China is a hostile power and an authoritarian regime. It's a different risk calculus than Facebook, which is not controlled by a dangerous foreign adversary.


A more convenient manual that frequently spouts falsehoods, sure.

My favorite part is when it includes parameters in its output that are not and have never been a part of the API I'm trying to get it to build against.


My favorite part is when it includes parameters in its output that are not and have never been a part of the API I'm trying to get it to build against.

The thing is, when it hallucinates API functions and parameters, they aren't random garbage. Usually, those functions and parameters should have been there.

Things that should make you go "Hmm."


More than that, one of the standard practices in development is writing code with imaginary APIs that are convenient at the point of use, and then reconciling the ideal with the real - which often does involve adding the imaginary missing functions or parameters to the real API.


> Usually, those functions and parameters should have been there.

There is a huge leap here. What is your argument for it?


Professional judgement.


Could also make it a site rule that _all_ jobs postings should include a pay range. Shouldn't have to waste your time applying to a job that has a pay range you would never accept.


I've found that face/retina scans are usually bad UX, especially if you need to use a viewfinder or a statically positioned device. Apple's Face ID works well because it's on a mobile device and you don't have to align your face in a box.

I don't see how this is any more convenient than using a mobile wallet. In fact, it looks less convenient than using the actual card - even if you forget the card you can usually just key in the number at the terminal.


It will be just like all those little paper signs they stuck on EMV terminals. “Insert chip here”, “No chip”, “Tap card on screen”.

So how do you make people use a retinal camera? You cut a hole in a picture of a monkey or the store mascot’s head and put up a big sign that says “look at Mr. Groceries to pay your bill with MasterCard EyeScan” or whatever it is called.

Because explaining how to use it to every single person in line is definitely going to make it fast.


I doubt this will change anything in the space. iOS and macOS (through Safari) has offered password management for years at this point. This is just a more flexible version of that system.


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: