I think this view is needlessly reductive and lacks compassion and understanding for their suffering. Not every problem should be approached with an engineering mindset.
You assume the problem was to determine the user’s preference in the most efficient way possible. The problem, instead, was to fool as many users into consenting as possible; and from that point of view, it is indeed rational to ignore any advisory signals and annoy the user so they want to just make the message go away.
The issue is with how browsers implemented it. Instead of implementing it with a per domain granularity it was implemented as a global option. People may enable the option to block tracking from malicous parties, but may unknowingly block tracking from good companies. So now good companies would need to ask the user if they actually want tracking since they may accidently be blocking it.
No, the real problem was that it worked too good from the perspective of ad-tech and data-gatherers.¹
It relied on the goodwill of those who run these services to i) invest some effort and money to detect the DNT headers and then ii) not collect/store the data of these requests.
Back, when only a tiny portion of web-users would send these headers along, the industry was fine to implement it. If only for marketing purpose.
But, as soon as they saw that it actually worked, the industry saw a threat to their revenues and stopped.
I believe a DNT2.0 that's more granular could've been a basis for GDPR, but the GDPR refrained -rightfully so, IMO- from any implementation details. For one, the GDPR never once requires some "popup", it merely states that if you are an a*hole and collect data that you shouldn't and/or send that to other parties, you should at least ask concent to do so - the idea being that web-owners would then massively ditch these services so that they don't have to nag their users.
And because the GDPR refrained from implementation details, the Ad- and surveilance industry adopted a "dark pattern" that annoys people to no end (the popups) so as to paint the GDPR in a bad light. This industry could've easily said "If we see a DNT header with level:x and domainmask:*, we'll assume NO to every tracking cookie and won't collect them". And the browser makers then could add some UI to allow users per-domain or global, or wildcard or whatever settings "set-and-forget". But alas, this industry is malicious at best and will annoy users to no end for their own agenda.
It's not a dark pattern, but actually is similar to terms of conditions and privacy policies that sites show. Requiring users to go through legal agreements sucks, but companies can't just ignore the law in order to make a better user experience.
My website has no tracker nor any third party cookies so it doesn't need cookie dialog. And even if I had some analytics that stays on prem, doesn't store or gather PII, I wouldn't need one.
The first dark pattern, is that websites want to send all your PII and other data to other companies, and act as if this is normal.
The second dark pattern is how they do this. They could just not track and share this data, but allow you to flip some setting if you really want them to gather and sell or share this data. No popup needed. Or one that has some big button "proceed" that denies all tracking and a tiny link "advanced settings" that allows opt in to tracking. Instead, their UX is the exact opposite. Sometimes with deliberate javascript to make the "nope" button not work, slow or clumsy.
the GDPR refrained -rightfully so, IMO- from any implementation details
I would disagree with this. If you're going to force bad actors to take actions that they don't want to, and you give them wide latitude to decide how to comply, then of course they're going to try to find ways to satisfy the letter of the law while avoiding the law's underlying goal.
surveilance industry adopted a "dark pattern" that annoys people to no end (the popups) so as to paint the GDPR in a bad light
We should in fact blame lawmakers when they fail to anticipate the obvious consequences of their laws.
This industry could've easily said "If we see a DNT header with level:x and domainmask:*, we'll assume NO to every tracking cookie and won't collect them".
If they were the type of people to do that, then they wouldn't have been doing the invasive tracking in the first place.
The GDPR would be far better if it simply banned individualized tracking. It would be somewhat better if it explicitly specified that sites must honor browser headers and specified the exact UI to use when requesting permissions.
I agree that much clearer constraints and less wiggle room would be better.
But imposing technical solutions in laws has hardly ever worked. Because these are almost always much easier to circumvent.
E.g. your suggestion to "honor browser headers" would be easy to circumvent by not having a browser - native apps, alt clients, etc. Google would easily track almost everything they do now through android, play services, email, docs, etc. And such implantation details inevitably get outdated.
E.g. in The Netherlands we have a law that forbids, with severe punishment, that you read people's paper post. If only lawmakers hundreds of years ago had abstracted this to "correspondence" rather than paper mail in envelopes, it would've applied to email and probably all network traffic.
There's proper and good tracking possible just fine.
Tracking to discover latency, errors, weird behaviour, malicious actors and so on.
Tracking to see what content does well and what not.
Tracking to see what rough demographics (mobile, desktop, country, region, time-of-day etc) visit your premises.
E.g. plausible-analytics or even Matomo do a good job at i) keeping the data rough and broad and without any PII, and ii) storing the data on-premise rather than at commercial aggregators who will either re-sell or use it for own services.
>I never understood why the HTTP Do Not Track header wasn’t used to signal cookie preferences.
You aren't really giving preferences related to cookies with these "cookie banners".
The laws in the EU require companies to get user permission for certain types of data processing.
Cookies may be involved in that, but they may not be.
Browser features like local storage or session storage would also be covered, and a lot of processing done server-side without the use of cookies requires permission too.
A single indicator like the DNT header or the newer GPC header can't cover all of this, so it isn't suitable for complying with the ePrivacy Directive or GDPR.
It’s broken in the same way as do-not-stab. We tried that in my town, but people started slashing each other. One person got a big knife and kept it sheathed, then clubbed people with the handle.
There’s clearly no way to indicate what sort of knife based assault is acceptable using a single indicator.
Why are people obsessed with “breaking into” Apple’s walled garden? There are already secure cross platform messaging services like Signal or WhatsApp that has feature parity with iMessage. This is a solved problem that doesn’t need another solution.
Some people are finding themselves excluded from their social group because of platform choice - basically not being able to use iMessage (sometimes) means people don't want you in the group chat (because mixing iMessage and SMS messages makes a bad experience.)
It is incredibly difficult to get a social group to change messaging platforms, especially if that social group's shared interest isn't "using a good messaging platform"
The easiest solution is to conform to the existing messaging platform in the group. In the case of a bunch of iOS users, that might mean leaving Android for iOS. People don't want to do this (For a variety of reasons.) So being able to participate as a first-world-citizen of the platform has its appeal.
Holdover of them being obsessed with SMS for some reason too.
I remember having to pay 20c per SMS and 50c per MMS before IMs on phones became a thing. Wasn't hard for literally everyone to want to change to the first available client which for most people was WhatsApp, 2 years before iMessage was even released. Guess messaging was so cheap in the US that they didn't have a good enough reason to hop on the IM train for years.
Because its the Hacker ethos. People need to be able to modify any software to suit their requirements and not have to blindly follow the prescription of a company whose interests may not align with yours.
Most people in the US use iPhones. They also like to use the default messaging app, which most of the time is iMessage.
Some people like to use Android phones (privacy, cost, freedom), but still want to message their peers who use the Apple-only iMessage.
This is the best and most concise summary on the thread.
The equivalent would be if Microsoft, when they had the largest market share of email clients in the US in the late 1990s with Outlook Express (OE), decided to make it so OE-sent group rich text emails with attachments could only be received by other OE users, whereas non-OE users only received plain text emails with image thumbnails and downscaled video attachments. People would have lots of good reasons to use a different email client, like forthcoming Thunderbird, Gmail, or Apple Mail clients. But they'd find they couldn't communicate well with Microsoft OE users.
If Microsoft had made this change early enough and also made it so non-OE responses were color coded with a green background to indicate they are "lesser emails," we'd be in a world of Microsoft Outlook Express users would wonder why everyone doesn't just switch to Windows (the majority OS, at that moment) to make everyone's lives easier. And friends/family would exclude non-Windows users from an email thread as not to "degrade" the thread.
Communication via text with friends and family should be an open standard. Barring the availability of such a standard (e.g. RCS), at a minimum, the chat clients to communicate with friends and family should be x-platform (like Signal, Telegram, WhatsApp, and LINE all manage to be).
Ergo iMessage should, at least, have an Android app, even if such an app requires an Apple ID.
https://www.ozbargain.com.au/product/apple-gift-card