Live data from Hacker News

Dark patterns after the GDPR: consent pop-ups and their influence

dl.acm.org

71–80 of 234 posts

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#71
post #45

Earlier quoted context omitted.

I was just thinking about that the other day. The billions of extra clicks and taps and wasted seconds. And for what gain? I think that this can be discussed outside of the basic "should we regulate" or not. Specifically looking at these modals that have spread all over, what actual protection does the average user get from this modal?

The modals don't exist to protect the user. Their goal is merely to annoy users to the point they just give up and blindly click "Accept". They only exist for the benefit of companies, and most of them violate GDPR.

Right. I'm not saying the intent of GDPR was to provoke them. But empirically, they are an effect of the GDPR. An undesirable one - that does not fulfill its intent. I'd say we are in agreement here.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#72
post #69

These regulations seem worse than nothing. We already have browsers, we can block and filter cookies based on our individual preference and adjust depending on our tolerance for privacy vs functionality. How has this changed the data collection practices of Facebook or Google in any meaningful way? Not enough people are asking what effect the many new regulatory burdens will have for the internet. It entrenchs the ex…

Why is this downvoted? This is exactly what happend. Speaking with non tech savvy users here in Germany, they feel safe and secure on Facebook and fear the „world wide west“ that the open Web has become, where you need to click 20 consent messages on every website without knowing what all that stuff means. This is just like EULAs - one more annoying thing they simply accept with a slightly bad gut feeling.

One thing I don’t understand is why in the good lords name do I have to consent to being tracked every day when I have already agreed to the goddamn cookie jar? Often several times per day as well!

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#73
post #54
post #41

Earlier quoted context omitted.

An Android version would be great. The mobile web is becoming harder and harder to use.

You can use it on Android with Kiwi Browser, a Chromium derivative. It used to work with Firefox, but it looks like Firefox still hasn't un-broken extensions on Android.

Looking at the source code suggests that Kiwi is based on Chromium 77. A shame; it's a great idea. We need a mobile browser with extensions.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#74
post #48
post #18

Earlier quoted context omitted.

EVERY WEBSITE I visit from my location in the USA seems to have these stupid cookie popups. We added one to OUR WEBSITE even though nothing is hosted in the EU - simple cargo-culting "everyone is doing it so we must do it also". I doubt it actually does a @#$@$ darn thing.

> We added one to OUR WEBSITE even though nothing is hosted in the EU Location of the host is irrelevant, it depends on the target audience. Serve pages to the EU? You get to follow it. > simple cargo-culting "everyone is doing it so we must do it also". If your site is cargo culting everything it probably also has a ton of third party trackers for the same reason.

> Location of the host is irrelevant, it depends on the target audience. Serve pages to the EU? You get to follow it.

This is completely false. Your laws do not follow you around on the internet.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#75
post #60
post #48

Earlier quoted context omitted.

> We added one to OUR WEBSITE even though nothing is hosted in the EU Location of the host is irrelevant, it depends on the target audience. Serve pages to the EU? You get to follow it. > simple cargo-culting "everyone is doing it so we must do it also". If your site is cargo culting everything it probably also has a ton of third party trackers for the same reason.

> Serve pages to the EU? You get to follow it. What can the EU do about it if the company has no physical or legal presence in the EU? Have there been any serious attempts at such enforcement?

I have decreed that anyone who serves pages into my machines owes me $billion.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#76

These regulations seem worse than nothing. We already have browsers, we can block and filter cookies based on our individual preference and adjust depending on our tolerance for privacy vs functionality. How has this changed the data collection practices of Facebook or Google in any meaningful way? Not enough people are asking what effect the many new regulatory burdens will have for the internet. It entrenchs the ex…

[deleted]

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#77
post #64

Earlier quoted context omitted.

Because there are shades of gray

There's a spectrum of gray in the effect and scale of the manipulation, but deciding to manipulate the user or not is a binary choice.

Is it? It's comforting to think so, but I'm not convinced there's a meaningful dichotomy that can be drawn. I add a "save this card" functionality to my store so users don't have to type it in every time they buy something: am I offering a neat convenience feature, or am I manipulating them by reducing the psychological barrier of a sale?

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#78
post #60
post #48

Earlier quoted context omitted.

> We added one to OUR WEBSITE even though nothing is hosted in the EU Location of the host is irrelevant, it depends on the target audience. Serve pages to the EU? You get to follow it. > simple cargo-culting "everyone is doing it so we must do it also". If your site is cargo culting everything it probably also has a ton of third party trackers for the same reason.

> Serve pages to the EU? You get to follow it. What can the EU do about it if the company has no physical or legal presence in the EU? Have there been any serious attempts at such enforcement?

It's weird how people keep claiming this.

No one says that all sites should honor China's laws for visitors from China. No one claims that all sites should honor Saudi Arabia's laws for visitors from Saudi Arabia.

But magically the GDPR must be followed by the entire world if a visitor shows up from France.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#80
Whether something is "legal" is a fuzzy computation that runs in the minds of average citizens on a jury, though it's more commonly simulated by judges and lawyers. The text is not absolute.

So what if an accept-only contract (like a ToS, EULA, or consent pop-up) did what average users think they agreed to, regardless of what the text says?

This would shift the burden of understanding from the user, where it currently lies, to the company. If it's essential to a company's business model that users agree to something complex that most users don't understand, the company will just have to help the users understand, deploying all those marketing and UX patterns they've perfected over the years to do so.

(Yes I know this isn't how contracts currently work; it's just a harmless little thought experiment.)

Post reply on HN