logoalt Hacker News

xp84yesterday at 5:55 AM1 replyview on HN

I think I’m kind of on your side in general, but I have more of the opposite feeling about legal versus technical solutions. If we had no idiotic EU cookie laws, no “consent” bs required, a technical solution would be easy: default segmentation of cookies by what site you are actually visiting, plus all non-first-party ones silently expired after 60 minutes or whatever. It seems like this would be very easy, except for the fact that the number one ad network is also the only browser vendor that matters.

But the attempted legal solutions suffer from being inside the sandbox, meaning all the “cookie management” software is a pile of hacks that barely work, and rely on browsers, as you’ve noticed, to allow their cookies in the service of…limiting cookies. And of course they also suffer from the politicians who wrote them having no clue how any of this works. I suspect if they did, they’d see how dumb it is to regulate that 10,000,000 websites each implement a ton of logic to self-limit their cookies they set (hard to police, buggy) instead of telling 2-3 companies they have to make their browsers have more conservative defaults with how they keep and send cookies back. (easy to prove it’s working with testing).


Replies

troupoyesterday at 6:49 AM

> If we had no idiotic EU cookie laws

The obnoxious cookie banners are not required by "idiotic EU cookie laws".

> a technical solution would be easy: default segmentation of cookies by what site you are actually visiting, plus all non-first-party ones silently expired after 60 minutes or whatever.

1. This was already implemented

2. Tracking isn't limited to cookies only

> except for the fact that the number one ad network is also the only browser vendor that matters.

Oh, so an "easy" solution isn't easy after all. Who would've thought.

> And of course they also suffer from the politicians who wrote them having no clue how any of this works.

But you do? Like how you only speak about cookies when tracking and user data isn't limited to cookies? Or how "stupid EU cookie law" doesn't even talk about cookies (if we're talking about GDPR)?

Usually the people who really have no clue are exactly the people who say that "there's an easy technical solution".

show 1 reply