Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You mean, like a checkbox that sends a `DNT` header set to `1`?

I think both the old cookie law and the GDPR kind of (directly or indirectly) include that case†, and sites know that they don't even need to display the dialog if they receive the header.

† the consent (or rather, intent not to consent) is explicit, and although non-interactive at the site level it was interactive at the browser level until MS defaulted it to `1`. Now I'm wishing it were like those notifications/location/webcam/mic access and the dialogs were required to go through the browser itself.



> I think both the old cookie law and the GDPR kind of (directly or indirectly) include that case†, and sites know that they don't even need to display the dialog if they receive the header.

Then I think that's the best kept secret of the industry.


Technically with GDPR defaulting to 1 is the only correct option. MS were only ahead of the time :)


GDPR affects the server default. A header that's supposed to show user intent still needs to default to blank.

A law enforcing DNT would be good, but honestly it would change the semantics of the header.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: