pwshub.com

Worn down by privacy options? Let users eat code

Opinion The people are defeated. Worn out, deflated, and apathetic about the barrage of banners and pop-ups about cookies and permissions.

Illustration of someone shrugging while looking uncertain and a question mark over their head

Brits hate how big tech handles their data, but can't be bothered to do much about it

READ MORE

Admittedly, the people here are the 40 percent of Brits who have never said no to a cookie in their lives. The rest of us can only feel smug if we've never clicked "Allow" to get into a site we don't care about and just need stuff from in a hurry. Those option boxes are there to protect us. They don't, and the laws that mandate them are an embarrassing failure.

Part of the problem is nothing seems to happen if you don't bother. Having your data privacy abused is like living in a house with faulty wiring. You know it's bad and you should do something about it, but it's always easier to put it off while nothing bad is happening. Then the bad thing happens.

You might not care that your car is snitching on you, until it catches fire and the maker refuses to take responsibility because you previously drove at 85 mph.

Taking your money without taking responsibility is a way of life for entire industries, and the more data they have on you the easier it is. They are far bigger than you and they've already got your cash, so good luck disagreeing.

Regulators and lawmakers recognized this power imbalance, which is one of the reasons behind things like the EU cookie law – more properly, the ePrivacy Directive and GDPR. This has the very best of intentions, mandating that cookies are personal data and we own them. We get to make mandatory decisions from an informed viewpoint about the specific use of such things. Only we don't. The constant call for choice wearies us and becomes our enemy. The cookie fighter has become the cookie monster.

The issue is one of psychology, not technology. In the same way that companies construct terms and conditions to be as appetizing to read as creek mud is to gargle, they design cookie options to take too much attention to properly operate. They know the default action to any online irritant is to do whatever it takes to make it go away with the least expenditure of thought. The cumulative effect of thousands of the things is capitulation.

Organizations whose business models rely on screwing every drop of personal data out of you can and do spend all day every day finding new ways to skirt privacy directives. It is very difficult to legislate against constant annoyances, although the regulators try. One of the latest enterprising innovations is to use the cookie law option box to ask for money to opt out of cookies and trackers. This "Consent Or Pay" approach is, at first blush, and second, against the GDPR. Regulators do like to be fair, though, which is why the UK's Information Commissioner's Office (ICO) is having a jolly good think about it.

Not that this matters if the cookie laws themselves are completely failing a large percentage of users and doing nothing much for the rest of us. The behavior of harassed humans isn't going to change, nor is the avarice of the bottom line. Regulators think in terms of behavior and practice, of stopping things that go wrong rather than innovating for improvement. Sometimes, however, you've got to go tech bro.

  • Extracting vendor promises won't fix cybersecurity. Extracting teeth might
  • AI to power the corporate Windows 11 refresh? Nobody's buying that
  • China's quantum* crypto tech may be unhackable, but it's hardly a secret
  • Upgrading Linux with Rust looks like a new challenge. It's one of our oldest

If people are easily worn down by repetition and misdirection, computers thrive on the first and are highly resistant to the second. If all cookie law option boxes were a standard format, so that it was easy for users to get the muscle memory to decline that stuff they didn't want, the story would change dramatically. They're not, of course, and given the variety of sites, as well as services and device display settings, it's not a practical option. Create a standard API, however, and those objections go away.

The user gets to configure their own default responses in the browser's privacy settings, and the cookie law option box disappears. Sites and services can ask to have their special cookies opted in, but the price to the users for not thinking about such options is zero.

Cookie-addicted businesses will hate this idea, but it's hard to construct a logical reason why it's a bad idea. It's entirely in the spirit of personal data protection, while being a small modification to an existing mechanism that's not working and needs to be fixed. The additional burden to site and service creators, and browser makers, is negligible. As APIs go, this is a bijou miniature compared to the complex monstrosities that enable all the online cleverness we know and love.

There are further advantages. As things stand, it's difficult to impossible to automate scanning for compliance of mandated data privacy options. With an API, we're off to the races. Even more intriguing, consider a landscape where publicly available compliance APIs are part of the armory of regulators and activists alive. That would focus a lot of minds in a healthy direction.

Computers are far better at following rules than humans. We might as well get them on our side. ®

Source: theregister.com

Related stories
6 days ago - Regulators know this is a nightmare and have done little to stop it. Privacy advocacy group wants that to change Smart TVs are watching their viewers and harvesting their data to benefit brokers using the same ad technology that denies...
1 week ago - Finding the perfect gift for a finicky teen is no small task. To help you out, we asked the teens in our own lives what they've got on their wish lists. Here's our teenager-approved list of the best gifts for teens.
1 month ago - The Plaud NotePin memory capsule is an AI-powered device you can wear around your neck like jewelry, and it helps you remember things.
2 weeks ago - Your easy guide for testing any type of smoke detector at home, from smart and wireless to traditional and wired.
1 month ago - In the grim darkness of the far future, there is no such thing as overkill — Strong first impressions of a game filled with enemy...
Other stories
10 minutes ago - Stay up to date on the latest AI technology advancements and learn about the challenges and opportunities AI presents now and for the future.
10 minutes ago - Preorders go live on Oct. 21, at 8 a.m. PT., and the $250 console is expected to ship in the first quarter of 2025.
10 minutes ago - If you’re looking for a nice pillow-top mattress, it’s hard to top the WinkBed -- especially for the price. Here’s what you need to know about this mattress before you buy, including who it’s best for.
10 minutes ago - CNET's shopping experts have a secret tool to help you get the best deals sent right to your phone so you don't miss any deals.
10 minutes ago - Can regular swimming sessions have a positive impact on sleep? I tried it, and here's what I found out.