They tried

MDFL@programming.dev to Programmer Humor@programming.dev – 1091 points –

EDIT: I didn't realize the anger this would bring out of people. It was supposed to be a funny meme based on recent real-life situations I've encountered, not an attack on the EU.

I appreciate the effort of the EU cookie laws. The practice of them just doesn't live up to the theory of the law. Shady companies are always going to find a way to be shady.

164

You are viewing a single comment

Serious question: I know that there are tracking cookies and the user should be able to decline those,but most sites have an auth cookie that stores you're credentials. The devs can store it in a different place like local storage but thats really unsecured.what can the devs do in this situation when the user decline all cookies?

The eu rules are mostly about unnecessary cookies. Most web devs just copied whatever everyone else was doing and now there's this standard of having to accept cookies but the EU doesn't really enforce it like that

it's not up to the EU to enforce it.

not sure why you're downvoted. of course member states enforce it.

Usually the prompts are specifically for tracking cookies, not essential ones for login. Alternatives without cookies:

  • URL sessions
  • Tokens
  • OAuth/OIDC third party
  • Local/Session Storage (ditto - mind the risks)

The GDPR is not "cookie law", it only prohibits tracking users in a way not essential to the operation of the site using locally stored identifiers (cookies, local storage, indexed DB...)

Storing a cookie to track login sessions, or color scheme preference does not require asking the user or allowing them to decline.

4 more...