Live data from Hacker News

Dark patterns after the GDPR: consent pop-ups and their influence

dl.acm.org

141–150 of 234 posts

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#141
post #90

Earlier quoted context omitted.

The problem is that the GDPR is not being enforced properly. The GDPR explicitly bans annoying/misleading consent prompts, so this shouldn't be an issue if the law was enforced. It explicitly learned from the earlier "cookie law" which merely enforced disclosure and led to stupid & useless cookie banners with no easy way for the user to actually act on them.

Exactly. It’s amazing that this is not widely known. The deceptive GDPR pop-ups we all hate are not GDPR compliant!

But you can't do anything about it, legally.

You can complain to your country's data protection expert, and they will tell you this or that company blah blah but not act. Nothing ever happened. I filed 3 complaints in 2 countries. 2/3 took over a year to receive a response. 1 took about 6 months and nothing changed.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#142
post #47
post #19

I recently purchased something from the official UK Nintendo Store [1]. I did not opt-in, and was not asked to opt-in, to marketing emails. Several days after purchase I received a marketing email with an Unsubscribe link. I submitted a GDPR enquiry and after a few weeks I get: Having investigated this matter fully, we can see that you were opted in as a result of a small technical difficulty which we are now fixing.…

I complained about tv2.dk (I used to be a customer) sending me a e-mail after I deleted my user and told them not the send me e-mail. This was a really bad experience where their support attempted to make me login to the site which I refused to do since I removed my user previously. Then I sent them a GDPR request to remove all my info and complained to the Danish Data Protection Agency. I stopped receiving e-mail bu…

I agree, had similar experience. Idk why this is downvoted.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#143

These regulations seem worse than nothing. We already have browsers, we can block and filter cookies based on our individual preference and adjust depending on our tolerance for privacy vs functionality. How has this changed the data collection practices of Facebook or Google in any meaningful way? Not enough people are asking what effect the many new regulatory burdens will have for the internet. It entrenchs the ex…

I argue the problem is not the regulation itself, but the all but complete lack of enforcement, and red tape around reporting offending companies.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#144

These regulations seem worse than nothing. We already have browsers, we can block and filter cookies based on our individual preference and adjust depending on our tolerance for privacy vs functionality. How has this changed the data collection practices of Facebook or Google in any meaningful way? Not enough people are asking what effect the many new regulatory burdens will have for the internet. It entrenchs the ex…

If nothing else, it definitely raised the awareness. The thing with cookies and tracking is that it's invisible. Especially for the average Joe users. But even I was surprised when, thanks partly to these dark patterns and not letting me to opt out with a single click, I saw how many trackers some sites actually use.

Now as users got pissed off, solutions started to emerge. Yes, the EU does not seem to enforce it too much, though I'm curious how many reports they get. Anyway, Mozilla just announced that they started compartmentalizing most cookies, so tracking will stop working for a lot of sites/services.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#145

Interesting that this site itself may use one of the described dark patterns. The banner on the main page has options "Got it" and "Learn more". There is no indication as to whether the "Got it" button is taken as consent for tracking, nor is there a "Reject all non-essential tracking" option on the main banner. Whether or not this site is compliant depends on whether the "Got it" button is taken as affirmative conse…

The site itself completely stops working if cookies are disabled, it just forwards me to a "cookie absent" error page. Their privacy policy says: > Other than in the restricted-access portions of the Web Site that require an ACM Web Account, ACM does not log the identity of visitors. However, we may keep access logs, for example containing a visitor's IP address and search queries. We may analyze log files periodical…

Maybe they found a loophole. If you make your website stop working without what are otherwise unnecessary cookies, suddenly the cookies are essential.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#147
post #69

Earlier quoted context omitted.

Why is this downvoted? This is exactly what happend. Speaking with non tech savvy users here in Germany, they feel safe and secure on Facebook and fear the „world wide west“ that the open Web has become, where you need to click 20 consent messages on every website without knowing what all that stuff means. This is just like EULAs - one more annoying thing they simply accept with a slightly bad gut feeling.

I for one welcome it. If a website has this popup, and it doesn't default to disabled tracking, and there are "legitimate interest" bullshit that cannot be turned off, I close down the website. I even uninstall apps (chess.com, here's looking at you). Just because website purposefully give a terrible UX in an effort circumvent the law does not mean the law is wrong. It's the implementation.

I have a sneaking suspicion that if you leave the site without doing its maze of opt-outs, then they go "oh great, user didn't opt out!" and you didn't even get to read what you were looking for.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#148
post #38

My favorite deceptive pattern I encountered is "double click the checkbox to disable". Literally a checkbox but it wouldn't do anything. I got a little frustrated and started clicking furiously just to discover that a double click would reliably disable the items... (I don't remember if this was on desktop or mobile, on mobile s/click/tap/g) Also, I personally lean towards being in favor of GDPR and cookie law (wish…

Such dark patterns are not allowed under GDPR, which says it must be opt-in, not opt-out.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#149
post #134

Interesting that this site itself may use one of the described dark patterns. The banner on the main page has options "Got it" and "Learn more". There is no indication as to whether the "Got it" button is taken as consent for tracking, nor is there a "Reject all non-essential tracking" option on the main banner. Whether or not this site is compliant depends on whether the "Got it" button is taken as affirmative conse…

I get some sick satisfaction whenever I mouse over these, right click, and hit "Block element"

Another technique:

I've just been trying out the tridactyl Firefox plugin. (vi-inspired keybindings for browser usage).

In tridactyl, the element can be hidden by typing out ";k", followed by a couple of letters to select the element hierarchy to hide.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#150
post #138

Earlier quoted context omitted.

You keep using this when people complain about GDPR consent banners. We get it, cookies are bad and privacy needs to be protected. It's just a really disingenuous and dismissive comparison. Nobody is complaining about flashlights. GDPR may have been necessary, but the complete garbage heap of an experience the popups have turned the web into is worth lamenting.

>It's just a really disingenuous and dismissive comparison. Nobody is complaining about flashlights. I don't make that comparison lightly. I'm not dismissing the issue: it is a serious problem that is widespread over the internet. It's not disingenuous: it describes a series of institutionalized behaviors that are directly parasitic on the user. Now the reaction is to be angry at GDPR because of the pop-ups, which ar…

First, thank you for explaining your point.

But, nobody here is complaining about GDPR. They are complaining about the terrible UX, and wasted time, and attention, which the non-compliant implementations have caused. That is not an absurd reaction, it's perfectly reasonable. That's why your comment comes off as dismissive.

If anything, it's more akin to complaining about the shitty, half-rate pest control person your landlord calls to get rid of the rats. They do a bad job, poison your house, waste your time, and the rats never go away.

Post reply on HN