Live data from Hacker News

Dark patterns after the GDPR: consent pop-ups and their influence

dl.acm.org

161–170 of 234 posts

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#161
post #138

Earlier quoted context omitted.

>It's just a really disingenuous and dismissive comparison. Nobody is complaining about flashlights. I don't make that comparison lightly. I'm not dismissing the issue: it is a serious problem that is widespread over the internet. It's not disingenuous: it describes a series of institutionalized behaviors that are directly parasitic on the user. Now the reaction is to be angry at GDPR because of the pop-ups, which ar…

First, thank you for explaining your point. But, nobody here is complaining about GDPR. They are complaining about the terrible UX, and wasted time, and attention, which the non-compliant implementations have caused. That is not an absurd reaction, it's perfectly reasonable. That's why your comment comes off as dismissive. If anything, it's more akin to complaining about the shitty, half-rate pest control person your…

> But, nobody here is complaining about GDPR.

Yes they are, everyone here is blaming the GDPR.

You're right that the issue isn't the GDPR, it's the tracking industry trying to figure a way around it. The EU learned a lot from the original cookie law, but the industry have not, they still try to continue as normally, until someone is hit with a crippling fine.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#162
post #45

Earlier quoted context omitted.

The modals don't exist to protect the user. Their goal is merely to annoy users to the point they just give up and blindly click "Accept". They only exist for the benefit of companies, and most of them violate GDPR.

Right. I'm not saying the intent of GDPR was to provoke them. But empirically, they are an effect of the GDPR. An undesirable one - that does not fulfill its intent. I'd say we are in agreement here.

I'm not in agreement with that. The banners are an effect of shitty companies being shitty to their customers. They already put as many annoyances and dark patterns on their website as they can, with or without GDPR: newsletter subscriptions, opt-in as default, multiple trackers.

Those banners are merely the effect of shitty companies trying to cover their asses and being non-compliant to a law that's actually sane.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#163
We should standardize the GDPR “pop up” by putting it inside the browser settings, and send a HTTP header that reflects user choice.

I see no difference between websites adhering to a HTTP header versus what the visitor chooses in the website’s custom pop up.

To start with, we should add to the GDPR regulations that a “Do Not Track” HTTP header requires the website to not display the pop up and interpret it as the visitor allowing only “strictly necessary cookies for website to functionality”.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#164
Things could be so simple if politicians had made the law more concrete or if it would be enforced.

Because some websites do comply and have a reject all button on the first pop up. I know this us the law, but it should be... you know literally the law.

Why is the law not enforced for the online marketing industry? After all, you will scarcely find an industry so full of criminals as this one!

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#165
post #16
post #4

Who came up with the term dark patterns? It's psychological manipulation and fraud, pure and simple

Another alternative proposed to IETF inclusive terminology draft is 'deception pattern'. https://github.com/ietf/terminology

> Sanity check → Quick check, confidence check, coherence check

> Crazy → Unexpected, surprising, puzzling

> Dummy value → Placeholder value, sample value

They're getting more and more ridiculous with this Newspeak nonsense.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#166

Earlier quoted context omitted.

That point has been beaten to death here in case of GDPR, though. The problem isn't with regulation, but enforcement. The fines aren't applied nowhere near enough, so almost no site cares. The consumer experience being worse is, in a large way, purposeful UX degradation done by the sites themselves. The typical consent popup tries to simultaneously walk the line between "illegal under GDPR" and "just scummy" (often c…

Fully legal and compliant GDPR cookie warnings are also awful UX and a pain in the ass. This should have been done at the browser level.

Not necessarily.

If you're using cookies for things like shopping carts, you don't need a cookie popup at all.

If you're using cookies to track visitors across sites for advertising purposes, you're the problem, and the cookue popup only documents that.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#167
post #69

Earlier quoted context omitted.

Why is this downvoted? This is exactly what happend. Speaking with non tech savvy users here in Germany, they feel safe and secure on Facebook and fear the „world wide west“ that the open Web has become, where you need to click 20 consent messages on every website without knowing what all that stuff means. This is just like EULAs - one more annoying thing they simply accept with a slightly bad gut feeling.

I think the GDPR and other sites would have better results if they approached these in a similar manner as how the "nutrition warning labels" are done in Mexico ( https://mexiconewsdaily.com/news/new-warning-labels-now-requ... ): Make it so every page that contains a tracking element MUST permanently display a large-ish (say, 1% of the screen for each) seal/label indicating that it is tracking you (like ESRB labels).…

This is an interesting idea.

In the end this option still hampers genuine users of those websites. That is the point and instead of people taking issue with the website tracking them, they'll complain about the banners instead.

Just look at this entire comment section... No guys, the problem is not that the law is bad, it's that the state of the internet is absolutely fucking terrible. "Why do I have to click so many consent things?" - because everyone is tracking everything about you, this is the point!

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#168

Earlier quoted context omitted.

It seems like a valid complaint to me. If it's so hard to do the right thing that someone who apparently both cares and understands the problem space still messes it up, then the issue is more fundamental than education.

This isn’t official ACM policy, it’s a paper from a conference last year that they may or may not find convincing. In general, demonstrating GDPR compliance is an expensive process, and I’m not sure that a US nonprofit corporation like the ACM ought be trying.

> nonprofit

Is this somehow suggesting nonprofits are less liable? I was quite shocked to read an article that gave a weekend sports team as an example of an organization that was maintaining GDRP protected data, basic the list of their team members

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#169

Earlier quoted context omitted.

That point has been beaten to death here in case of GDPR, though. The problem isn't with regulation, but enforcement. The fines aren't applied nowhere near enough, so almost no site cares. The consumer experience being worse is, in a large way, purposeful UX degradation done by the sites themselves. The typical consent popup tries to simultaneously walk the line between "illegal under GDPR" and "just scummy" (often c…

Fully legal and compliant GDPR cookie warnings are also awful UX and a pain in the ass. This should have been done at the browser level.

No. If you act in the spirit of the GDPR you never need to prompt people at all.
Post reply on HN