Live data from Hacker News

Only 9% of visitors give GDPR consent to be tracked

markosaric.com

331–340 of 457 posts

Re: Only 9% of visitors give GDPR consent to be tracked

#331

Earlier quoted context omitted.

DockerHub uses a company/product called "TrustArc: TRUSTe" and they have _exactly_ this method. The slowdown is intentional. People who come up with sort of tactics and those who implement them should go to jail. It's beyond infuriating. I've decided to not upload my images to dockerhub because of this. Edit: jail time is not for anger obviously, but for intentionally swindling people. It'll be handled on a case by c…

Causing you to get angry is all it takes to warrant justification for jail time in your eyes? I am thankful you aren't in charge of any lawmaking.

Jail time is probably the only suitable enough deterrent for adtech nightmares. Fines are just treated as a cost of doing business expense, and doesn't directly even hurt the terrible people making these decisions.

When someone commits a wrong, the punishment is in part based on the amount of harm. You might feel that adtech causes small harms, if you look at harm against an individual, but adtech folks harm billions of people, every single day.

If you're Mark Zuckerberg, Larry Page, or Sergey Brin, no fine is large enough to make you regret your life choices. The only way to punish billionaires who get rich off harming others is to take away their time/freedom, the one thing they can't just buy back. As long as corporate CEOs can't get jailed, crime absolutely pays in this country.

Re: Only 9% of visitors give GDPR consent to be tracked

#332

I hate ads as much as everybody else, and this reads to me like "given the choice only 9% of people would pay for their meal", should we forbid charging for food then? Probably not. As sad as the current ads-powered internet is becoming I haven't seen any promising viable alternative, and sure non-tracking-based ads is not the same thing as having no ads, but it significantly moves the needle in that same direction i…

It is possible to show content based ads rather than ads based on your tracking. It is perfectly reasonable for a website about motorcycles to show ads for motorcycle products, and this could be done without tracking the user. I don't want that one piece of furniture I (or my SO using my computer) looked at on Wayfair to follow me to the motorcycle website. I definitely don't need an ad empire following all of my act…

Sure but that doesn't work for everything, should Rockstar Games pay 100x what it currently pays for advertisement for advertising GTA DLCs or whatever to people who don't care about gaming? Should perhaps websites like YouTube not exist because people don't want to pay for stuff and the business is not sustainable via non-targeted advertisements (if that's the case)?

Re: Only 9% of visitors give GDPR consent to be tracked

#333
post #142

Earlier quoted context omitted.

The latest trend in dark UI GDPR patterns is presenting an endless list of things that will track you. It starts with "allow necessary cookies" enabled, and the rest disabled, and presents 3 buttons, a 2 small gray ones and a big green one, and unless you're REALLY careful, you'll end up accepting all cookies. The text is something along the lines of "Cancel", "Save Changes", and finally the big green one is "Accept…

The problem is that companies which do that kind of dark patterns are very likely to ignore your settings anyway in the future. Like, for example, Amazon. What then comes to my mind is the thought: "Well, would I try to do an ongoing delicate business with a well-known notorious asshole and trickster?". Obvious answer is "no". So, in most cases, I just leave that site.

Anything that refuses to let me view content without setting cookies is ignored here. Sorry, no matter how good your content is, it’s not that good.

Shady sites that use dark patterns are about to go the same route.

And I have privacy badger, uBlock origins, as well as Pi-hole/PFBlockerNG (not at the same location). Our phones have ad blockers as well, though I doubt they’re as effective.

Re: Only 9% of visitors give GDPR consent to be tracked

#334

Earlier quoted context omitted.

Causing you to get angry is all it takes to warrant justification for jail time in your eyes? I am thankful you aren't in charge of any lawmaking.

Jail time is probably the only suitable enough deterrent for adtech nightmares. Fines are just treated as a cost of doing business expense, and doesn't directly even hurt the terrible people making these decisions. When someone commits a wrong, the punishment is in part based on the amount of harm. You might feel that adtech causes small harms, if you look at harm against an individual, but adtech folks harm billions…

[deleted]

Re: Only 9% of visitors give GDPR consent to be tracked

#335

The author's consent form is very simple and isn't using any shady UX tricks to get the user to consent. One action will opt you in, one action will opt you out. I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookie…

How do you remember the user has opted out of cookies without storing a cookie?

Does anyone have an example of a site with a clear opt-in/out? I'm curious about what's actually stored on my machine in each case. And of course it's not really what's stored locally that's the issue: it's what is stored on their server.

Re: Only 9% of visitors give GDPR consent to be tracked

#336
post #279

What really drives me crazy are prompts that start by showing two options: "Consent to all cookies", or "customize". If you click "customize", it opens a new modal window with a loading indicator that just doesn't seem to finish. I literally waited 60 seconds and then tried again by refreshing the page, ending up with another infinite loading indicator. This means that users are de-factor forced to click "consent to…

Someone should write the next level of counter measures that just sends a bespoke cookie that contains the do not track info based on patterns similar to ad block - without ever having visited the site beforehand. Or if that's not working for some sites pretend you accept tracking but just forge the tracking ids with random data every visit

Or just use EFF's Privacy Badger.

Re: Only 9% of visitors give GDPR consent to be tracked

#337

What really drives me crazy are prompts that start by showing two options: "Consent to all cookies", or "customize". If you click "customize", it opens a new modal window with a loading indicator that just doesn't seem to finish. I literally waited 60 seconds and then tried again by refreshing the page, ending up with another infinite loading indicator. This means that users are de-factor forced to click "consent to…

I am not even sure, if it is legal to make the opt-in easier than the opt-out. But I guess that is some kind of grey area nobody really cares about, even if it is crucial from a UX perspective.

Re: Only 9% of visitors give GDPR consent to be tracked

#338

Earlier quoted context omitted.

> A viable alternative: show non tracking ads and see if it keeps the lights on, otherwise shut down? I'm not sure that'd be viable in general, like what would the economic impact globally if all websites that barely can manage to keep the lights on today because of effective ads just disappeared? Maybe the impact could be even positive, like by disallowing politically very-targeted ads, among all other kinds of targ…

I wouldn't miss it. If they can find a viable non-tracking business model, I'd imagine most would. People used to pay for newspapers so there's pretty good precedent.

I have friends who a few years ago switched away from WhatsApp because it was charging 1 buck per year, and for that amount of money they gave you instant global unlimited text messaging, and those same people would have happily paid 10x that for a one-time meal.

I think you are grossly overestimating how much the average person is willing to pay for a digital service.

And I don't think newspapers are a good precedent giving how nobody buys newspapers anymore, compared to pre-internet levels at least.

Re: Only 9% of visitors give GDPR consent to be tracked

#339

What really drives me crazy are prompts that start by showing two options: "Consent to all cookies", or "customize". If you click "customize", it opens a new modal window with a loading indicator that just doesn't seem to finish. I literally waited 60 seconds and then tried again by refreshing the page, ending up with another infinite loading indicator. This means that users are de-factor forced to click "consent to…

DockerHub uses a company/product called "TrustArc: TRUSTe" and they have _exactly_ this method. The slowdown is intentional. People who come up with sort of tactics and those who implement them should go to jail. It's beyond infuriating. I've decided to not upload my images to dockerhub because of this. Edit: jail time is not for anger obviously, but for intentionally swindling people. It'll be handled on a case by c…

Since your edit seems to be taking the jail suggestion seriously:

I think the data-money analogy isn't unreasonable, but you're overloading "swindle" pretty heavily here, in a way that defeats your point. Companies and people "swindle" others out of money all the time with dark patterns, and this predates computing by ten thousand years. Caveat emptor exists for a reason: the legal system is just too inflexible a tool to cram a person's view of "honesty in business" into.

Defining "making one side of an option an iota more of a hassle than the other" as criminal is broad enough that you're pretty much guaranteed to catch many honest transactors too. The law is a really blunt instrument.

Re: Only 9% of visitors give GDPR consent to be tracked

#340

What really drives me crazy are prompts that start by showing two options: "Consent to all cookies", or "customize". If you click "customize", it opens a new modal window with a loading indicator that just doesn't seem to finish. I literally waited 60 seconds and then tried again by refreshing the page, ending up with another infinite loading indicator. This means that users are de-factor forced to click "consent to…

Are there any good examples where the consent is done right?
Post reply on HN