Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's convenient for them that their server-side opt-out code cannot be audited. It would have been easier for them to just set an anonymous, client-side opt-out cookie.


A client-side cookie is not sufficient, you'd have to set it in every browser you ever use. Practically speaking it needs to be server-side, but should be (but never would be) opt-in rather than opt-out.

The other option is respecting DNT, but that is never going to happen as a default behaviour for all companies.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: