Live data from Hacker News

Dark patterns after the GDPR: consent pop-ups and their influence

dl.acm.org

131–140 of 234 posts

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#131
I am working as a developer for a medium sized publisher in germany. Im pro GDPR and dont like the way the industry treats the users. But they just seem to continue on their course. Reaction on GDPR was very slow. Cookie Banners (before GDPR) where ignored. When GDPR was there we started to implement regular cookie banners - despite the warning from us developers that this would be illegal.

The first real reaction on GDPR came at that moment Google forced them to. There was a deadline (somewhere in february 2021) where Google would limit ads if no consent-manager is implemented.

When we finaly implemented it they set everything they can to fight against the user: The big blue floating button for the consent manager was hidden - instead i had to implement a link into the footer. Nobody will find it there. Then they disabled the "disable everything"-button. Now you can just allow everything or manually tick a hundred boxes. They totally know that its not legal. But nobody cares. Ad revenue is the most important thing and if they would follow the rules they would loose quiet a lot of money.

As a developer its frustrating to see how user hostile the web has become ... Sure you can get another job, but its the same situation in every other place ...

If you are just a user browsing the internet and beeing annoyed by all this stuff and mistreatment: Im sorry.

Get an ad-blocker (uBlock Origin) and maybe additional uMatrix and learn how to protect yourself. The only way to "vote" is with the active denial of your data. They can see that statistics. They can see the rising number of people blocking all this tracking and advertisement stuff.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#132
Is this even relevant nowadays? I've been doing some tests with Edge and Firefox, and with their built-in tracking prevention + uBlock, it didn't matter whether I accepted all or only essential cookies, because at the end, only first party cookies are set.

One might argue that accepting all allows tracking by the site itself. But, does it really matter? I'm already on the site because I'm willing to. At this point, we're no longer talking about tracking but analytics.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#134

Interesting that this site itself may use one of the described dark patterns. The banner on the main page has options "Got it" and "Learn more". There is no indication as to whether the "Got it" button is taken as consent for tracking, nor is there a "Reject all non-essential tracking" option on the main banner. Whether or not this site is compliant depends on whether the "Got it" button is taken as affirmative conse…

I get some sick satisfaction whenever I mouse over these, right click, and hit "Block element"

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#135

Earlier quoted context omitted.

The site itself completely stops working if cookies are disabled, it just forwards me to a "cookie absent" error page. Their privacy policy says: > Other than in the restricted-access portions of the Web Site that require an ACM Web Account, ACM does not log the identity of visitors. However, we may keep access logs, for example containing a visitor's IP address and search queries. We may analyze log files periodical…

One of the areas on the cookie consent that confuses me is if a cookie is required for the website to function it doesn't need consent. Since the only cookie my website uses is a session cookie, I don't use a cookie banner. My site won't without it due to the security login area. If you're in a public area and your browser doesn't accept cookies you can still do public things such as reading things and sign up but no…

On this point GDPR is pretty simple. In general security do not require consent, nor does cookies that are used for functional aspects of the sites.

A simple guideline is to imagine if someone breaks into your server and steal data. If that data can come to harm real people somewhere then you likely have something which you needed to have gained consent in order to handle. On top of that there is an additional exception for data only used for security purposes.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#136

Earlier quoted context omitted.

"Interesting that this site itself may use one of the described patterns." Is it really interesting, though. For example, we have seen this as a very common retort in HN comments every time an author is critical of advertising, tracking/analytics, etc. Someone points out the author's site itself uses the thing being critiqued. Is that supposed to detract from the argument being made by the author. That does not make…

It seems like a valid complaint to me. If it's so hard to do the right thing that someone who apparently both cares and understands the problem space still messes it up, then the issue is more fundamental than education.

This isn’t official ACM policy, it’s a paper from a conference last year that they may or may not find convincing.

In general, demonstrating GDPR compliance is an expensive process, and I’m not sure that a US nonprofit corporation like the ACM ought be trying.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#137

These regulations seem worse than nothing. We already have browsers, we can block and filter cookies based on our individual preference and adjust depending on our tolerance for privacy vs functionality. How has this changed the data collection practices of Facebook or Google in any meaningful way? Not enough people are asking what effect the many new regulatory burdens will have for the internet. It entrenchs the ex…

I can think of two noticeable effects.

1: It makes leaks a liable issue and one that get additionally costly if the company tries to hide it.

2: All data collection by the big players are sitting behind a single legal argument that informed contained can be gain by a pop up window or by passively clicking a link, both which the GDPR writers said was not informed consent. That big players explicit ignore part of the regulation and get away with it is a problem that not enough people are questioning. The discussion has moved away from the law makers and into the enforcement.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#138
post #53

Earlier quoted context omitted.

That's like accusing the flashlight of making rats scurry under the floorboard

You keep using this when people complain about GDPR consent banners. We get it, cookies are bad and privacy needs to be protected. It's just a really disingenuous and dismissive comparison. Nobody is complaining about flashlights. GDPR may have been necessary, but the complete garbage heap of an experience the popups have turned the web into is worth lamenting.

>It's just a really disingenuous and dismissive comparison. Nobody is complaining about flashlights.

I don't make that comparison lightly. I'm not dismissing the issue: it is a serious problem that is widespread over the internet. It's not disingenuous: it describes a series of institutionalized behaviors that are directly parasitic on the user.

Now the reaction is to be angry at GDPR because of the pop-ups, which aren't even GDPR compliant in the majority of cases as directly evidenced by the OP link. This reaction is comically absurd, hence the comparison. This garbage heap is the result of shitty implementation by the websites, and ironically a lack of enforcement of the law.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#139
post #104

What absolutely infuriates me is this "legitimate interest" crap that is almost always hidden away, and often you have to scroll through literally hundreds of opt-outs with no way to disable them all in a single click. If I'm so damn "legimately interested", why is it on by default and basically impossible to turn off? Find me one person on this earth who is legitimately interested in being tracked by marketing compa…

"legitimate interest" is a legal term with specific definitions in the GDPR. (And indeed it refers to the interest of the site , not yours) IANAL, but as I understand, it refers to data collection that is inherently needed to perform a service. E.g., a pizza delivery service has a legitimate interest to know the address of the place where it should deliver the pizza to - because, well, otherwise they can't deliver th…

> because, well, otherwise they can't deliver the pizza.

This is covered by one of the five other GDPR principles for lawfully processing data ("to fulfil contractual obligations..."), so it wouldn't be considered a legitimate interest.

An example of legitimate interest would be the Pizza Place keeping your address on their phone system, so that when you call from the same number on a future date, they can confirm your address without having to ask for it again.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#140

Earlier quoted context omitted.

You mean developer or website manager who do not apply the law properly. All those deceptive patterns are not part of the GDPR, they should clearly label accept and refuse. I think it will take time for people to stop gathering so much information from users. Once a competitors start to figure it out, users might start using them (i.e. New York Times & GitHub.)

> . All those deceptive patterns are not part of the GDPR GP isn't talking about deceptive patterns. Point is that no one really understand what these popups are for and everyone just blindly clicks ok. I don't think i've ever declined a cookie popup. have you?

I ALWAYS go through them. Either reject, tediously try to find the hidden settings like legitimate interest. Lately I open some sites in incognito window, accept all, then close the window when I'm done. Some science mag I recently visited set 143!! cookies and that's before even showing the consent screen. I've also started to write scrapers for news sites I visit on a daily basis who go over the top with all the tracking and ads. So I "just" scrape their content and have written a frontend to read the content. Most of the time that content is just blown up but if there's something really interesting I have a link to the original article there and again open it in an incognito window.

It has become such a chore, when ever I visit a new site on my phone and see a cookie screen, I navigate back and/or open an incognito window.

What the EU should do is disallow those cookie full page modal consent windows.

Many use overflow: hidden when showing it so you can't just adblock it without having to modify the markup. It has all gone out of hand.

Post reply on HN