Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

111–120 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#111

I am not convinced that GDPR will ever really be enforced. Severe breaches have mostly been ignored so far and the minor dark patterns that dominate GDPR compliance popups and wrong defaults are going to be the tail end of compliance enforcement. Just like cookie laws before it GDPR will probably just make websites annoying with obnoxious implementations and remain largely unenforced until the EU does something else…

One really incredibly annoying trick that I see more and more is when they pre-check only the "mandatory cookies" option, but then when you want to confirm this selection you end up allowing all tracking cookies. It's because they make the confirmation button less prominent, and something that looks more like the typical confirm button is actually "allow all cookies". I guess a lot of people just click on it automati…

There are a lot of dark patterns. The most common stuff I am seeing (and its basically everwhere) are:

1) Accept being brightly coloured and decline as white so its less prominent.

2) Having accept all be a simple thing but decline being a more information that requires turn lots of individual things off.

3) Requiring the decline to be individual across hundreds of individual cookies.

4) Clicking accept all is stored and used forever but decline is asked everytime you come back to the website.

5) Having the decline process take minutes to complete as if significant processing is required.

6) Having the default be acceptance.

I think breaches of GDPR are the normal, 95% of the websites I see these popups on is breaking the law in some way or another and at this point have been doing so for years.

Re: Only 9% of visitors give GDPR consent to be tracked

#112

Earlier quoted context omitted.

> For many services there is simply no (online, i.e. practically relevant) alternative, because none of the market players have an incentive to be privacy preserving (think major news outlets) or because the service is not interchangable due to network effects (facebook, twitter etc). But here's the big question: would these services have even existed in the first place if these laws had been in place? The internet h…

I would go the other way with it -- the problem is we don't have a low overhead system for anonymous micropayments, so ads are the only competitive way to offer a service with a very low cost (and thus price) per use. If there was an easy way to anonymously pay the site the five cents they get from the advertiser without incurring 500% payment processing overhead then would sites even be using advertising? But then w…

The payment processing overhead has nothing to do with rules and everything to do with Mastercard and Visa having decided to not compete on fees.

Re: Only 9% of visitors give GDPR consent to be tracked

#113

Earlier quoted context omitted.

> For many services there is simply no (online, i.e. practically relevant) alternative, because none of the market players have an incentive to be privacy preserving (think major news outlets) or because the service is not interchangable due to network effects (facebook, twitter etc). But here's the big question: would these services have even existed in the first place if these laws had been in place? The internet h…

I would go the other way with it -- the problem is we don't have a low overhead system for anonymous micropayments, so ads are the only competitive way to offer a service with a very low cost (and thus price) per use. If there was an easy way to anonymously pay the site the five cents they get from the advertiser without incurring 500% payment processing overhead then would sites even be using advertising? But then w…

I agree that it would massively help, but I don't think it would solve the entire problem. A lot of my interests online were cultivated as a kid where even a 10 cent charge would've made me click away. I'm sure it wouldn't have been an issue in highly developed countries, but it would've been a limiting factor for me.

Re: Only 9% of visitors give GDPR consent to be tracked

#114

Earlier quoted context omitted.

I would go the other way with it -- the problem is we don't have a low overhead system for anonymous micropayments, so ads are the only competitive way to offer a service with a very low cost (and thus price) per use. If there was an easy way to anonymously pay the site the five cents they get from the advertiser without incurring 500% payment processing overhead then would sites even be using advertising? But then w…

The payment processing overhead has nothing to do with rules and everything to do with Mastercard and Visa having decided to not compete on fees.

Then why don't you go into competition with them and undercut them on fees, if the rules make it so easy? Why doesn't anybody?

Re: Only 9% of visitors give GDPR consent to be tracked

#115

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

Verizon/Yahoo/Techcrunch is such a blatant offender, and especially noticable because they get posted here often. Their modal is a giant obfuscation dark-pattern, and far as I can tell, there is no way to opt out.

I'd like to remind you and everyone else about Firefox reader mode. Solves like 99% of this user-enslaving shit.

Re: Only 9% of visitors give GDPR consent to be tracked

#116

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

The latest trend in dark UI GDPR patterns is presenting an endless list of things that will track you.

It starts with "allow necessary cookies" enabled, and the rest disabled, and presents 3 buttons, a 2 small gray ones and a big green one, and unless you're REALLY careful, you'll end up accepting all cookies.

The text is something along the lines of "Cancel", "Save Changes", and finally the big green one is "Accept all cookies".

The trick here is that the small gray "save changes" button is actually the one you want, as the "accept all" effectively enables ALL cookies.

Re: Only 9% of visitors give GDPR consent to be tracked

#118
post #78
post #45

Earlier quoted context omitted.

In 2016, I think, there were 0 airplane crashes and 0 air travel fatalities. Across 200 countries, hundreds of airlines and several airplane manufacturers, probably thousands of airports, millions of flights. If you think that was an easy feat, then I don't know what to tell you. Do you know how it was achieved? With finely tuned and ruthlessly efficient bureaucracy. When people really care, bureaucracy works wonders…

> Do you know how it was achieved? With finely tuned and ruthlessly efficient bureaucracy. Not to dispute the effectiveness of a finely tuned and ruthlessly efficient bureaucracy, but pilots and airlines have a strong incentive to not have fatal accidents; websites however have a strong incentive to track their users. To use an analogy, enforcing this will be less like mandatory driving exams and more like net-zero c…

[deleted]

Re: Only 9% of visitors give GDPR consent to be tracked

#119

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

An interesting paper here on the influence of deliberate dark patterns in these consent boxes. https://arxiv.org/pdf/2001.02479.pdf

Thanks! This is the first proper breakdown I've seen.

Re: Only 9% of visitors give GDPR consent to be tracked

#120
post #93

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

Why would anyone consent to be tracked if given a real choice? What are the benefits? The 9% look like an error.

The 9% is probably people trying to opt out by selecting the minimum amount of cookies and hitting the big green "Accept all cookies" button instead of the small gray "save changes" button.
Post reply on HN