Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Cookie consent is not required for technical cookies like auth.


It isn't needed, but third-party cookies were phased out by Chrome specifically to undermine their competitors, all under the veil of doing the right thing, and everyone that was using them for something ok got screwed.


I'm surprised at how often this needs to be restated.

By-and-large you only need to allow people to opt out of cookies if you're tracking _their_ activity and/or selling details of _their_ activity to your "partners".


Partly it’s because we’ve simplified the discussion to “cookie banners” when it’s about more than cookie tracking or cookie-like tracking (local storage). So it misses all the other ways tracking occurs.

The other thing is that it benefits those who wish the law would just go away to have it misunderstood this way.


Indeed. Nor is GDPR about cookies at all. GDPR is about identifiable user profiles and information. A piece of paper with someone's name falls under the GDPR; a cookie that hides a shown alert doesn't.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: