Live data from Hacker News

Dark patterns after the GDPR: consent pop-ups and their influence

dl.acm.org

171–180 of 234 posts

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#171

These regulations seem worse than nothing. We already have browsers, we can block and filter cookies based on our individual preference and adjust depending on our tolerance for privacy vs functionality. How has this changed the data collection practices of Facebook or Google in any meaningful way? Not enough people are asking what effect the many new regulatory burdens will have for the internet. It entrenchs the ex…

> We already have browsers, we can block and filter cookies based on our individual preference and adjust depending on our tolerance for privacy vs functionality.

Blocking cookies on the browser side is a cat-and-mouse game where the cat is a multi-billion-dollar corporation and the mouse is a handful of volunteers.

You're also vastly oversimplifying the tracking issue to just “cookies”. The big advertising networks will use any method imaginable to track you. In the US (sans e.g. CA) they do not even have to tell you that they're tracking you, let alone tell you what they're doing with the information or let you opt out.

The GDPR gives you rights that work against all kinds of tracking.

> How has this changed the data collection practices of Facebook or Google in any meaningful way?

They have to tell us what they are and obtain our consent before doing them. They also have to tell regulators before doing novel and particularly intrusive things.

> Not enough people are asking what effect the many new regulatory burdens will have […]

The burden of putting the least effort to respect people's privacy is a good one. If you actually aren't trying to spy on people the burden imposed by GDPR is much less, perhaps giving good actors a competitive advantage. You don't even need consent most of the time.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#172
post #38

My favorite deceptive pattern I encountered is "double click the checkbox to disable". Literally a checkbox but it wouldn't do anything. I got a little frustrated and started clicking furiously just to discover that a double click would reliably disable the items... (I don't remember if this was on desktop or mobile, on mobile s/click/tap/g) Also, I personally lean towards being in favor of GDPR and cookie law (wish…

Facebook et al would really like you to believe GDPR is useless and purely a waste of your time.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#173

Earlier quoted context omitted.

You mean developer or website manager who do not apply the law properly. All those deceptive patterns are not part of the GDPR, they should clearly label accept and refuse. I think it will take time for people to stop gathering so much information from users. Once a competitors start to figure it out, users might start using them (i.e. New York Times & GitHub.)

> . All those deceptive patterns are not part of the GDPR GP isn't talking about deceptive patterns. Point is that no one really understand what these popups are for and everyone just blindly clicks ok. I don't think i've ever declined a cookie popup. have you?

I click accept all of them cause I use Firefox + Privacy Badger :D Badger icon shows in orange the number blocked resources and cookies and in some sites is an amazingly high number.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#174
post #134

Interesting that this site itself may use one of the described dark patterns. The banner on the main page has options "Got it" and "Learn more". There is no indication as to whether the "Got it" button is taken as consent for tracking, nor is there a "Reject all non-essential tracking" option on the main banner. Whether or not this site is compliant depends on whether the "Got it" button is taken as affirmative conse…

I get some sick satisfaction whenever I mouse over these, right click, and hit "Block element"

I have had some luck just using reader mode. It is not important when I am on my ipad, because I use Safari in private mode and it doesn’t share cookies with other tabs, but this is even easier.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#175

These regulations seem worse than nothing. We already have browsers, we can block and filter cookies based on our individual preference and adjust depending on our tolerance for privacy vs functionality. How has this changed the data collection practices of Facebook or Google in any meaningful way? Not enough people are asking what effect the many new regulatory burdens will have for the internet. It entrenchs the ex…

These big companies are not compliant. For example Instagram if you make a GDPR complaint they will reply with a couple of canned responses and when you keep pointing out they have no read your complaint they will simply stop responding. What could you do next without having your account deleted in retaliation?

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#176
post #135

Earlier quoted context omitted.

One of the areas on the cookie consent that confuses me is if a cookie is required for the website to function it doesn't need consent. Since the only cookie my website uses is a session cookie, I don't use a cookie banner. My site won't without it due to the security login area. If you're in a public area and your browser doesn't accept cookies you can still do public things such as reading things and sign up but no…

On this point GDPR is pretty simple. In general security do not require consent, nor does cookies that are used for functional aspects of the sites. A simple guideline is to imagine if someone breaks into your server and steal data. If that data can come to harm real people somewhere then you likely have something which you needed to have gained consent in order to handle. On top of that there is an additional except…

Second paragraph is false, first one is partially true.

There are many legitimate reasons for storing and processing data, and you should not ask for consent needlessly - among other reasons, because consent can be withdrawn, at any time, and you are obliged comply stop processing and remove data - unless you have other legitimate reasons, in which case the whole exercise seems pointless.

Whether the data can be used to harm real people has significant correlation with whether it is covered by GDPR, but does not relate to consent. It can also be of relevance on what security precautions are required and when weighing right to privacy vs. needs to process specific data.

As a typical example, you do not need (and shouldn't ask for) consent for data and purposes that are reasonably necessary for the services customers ask for. You are not allowed to share / use for unrelated purposes other than allowed by other stipulations. Also, information on data collection / processing should be reasonably, easily accessible.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#177
post #135

Earlier quoted context omitted.

One of the areas on the cookie consent that confuses me is if a cookie is required for the website to function it doesn't need consent. Since the only cookie my website uses is a session cookie, I don't use a cookie banner. My site won't without it due to the security login area. If you're in a public area and your browser doesn't accept cookies you can still do public things such as reading things and sign up but no…

On this point GDPR is pretty simple. In general security do not require consent, nor does cookies that are used for functional aspects of the sites. A simple guideline is to imagine if someone breaks into your server and steal data. If that data can come to harm real people somewhere then you likely have something which you needed to have gained consent in order to handle. On top of that there is an additional except…

This is completely wrong. I don't want to pick your comment apart, but I suggest actually reading the GDPR. It is available in every European language.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#178

Earlier quoted context omitted.

I think the GDPR and other sites would have better results if they approached these in a similar manner as how the "nutrition warning labels" are done in Mexico ( https://mexiconewsdaily.com/news/new-warning-labels-now-requ... ): Make it so every page that contains a tracking element MUST permanently display a large-ish (say, 1% of the screen for each) seal/label indicating that it is tracking you (like ESRB labels).…

This is an interesting idea. In the end this option still hampers genuine users of those websites. That is the point and instead of people taking issue with the website tracking them, they'll complain about the banners instead. Just look at this entire comment section... No guys, the problem is not that the law is bad, it's that the state of the internet is absolutely fucking terrible. "Why do I have to click so many…

They law was aimed at the big guys and they are in my opinion still not compliant, but have not heard of them being fined, some small guys on the other hand... This law feels more like it was a bribe fishing and checkbox exercise rather than genuine attempt at solving the issue.

Re: Dark patterns after the GDPR: consent pop-ups and their influence

#179
post #88

Earlier quoted context omitted.

It's usually a good hint that it really isn't a legitimate intrest case if they allow you to turn it off. A legitimate intrest does not require an opt in (or an opt out). Consent does. If the page mixes those two up they're either clueless or trying to walk in the gray area and don't really understand(or don't want to understand) what either of those terms mean.

Legitimate Interest has a legal definition as a Legal Basis. It's a list of Purposes and Special Features that a Vendor declares to the IAB that they claim to need [0]. A User absoultely has the right to Object to Consent and Legitimate Interest. Any CMP that does not allow you to opt-out is on shaky GDPR legal ground. [0] https://vendor-list.consensu.org/v2/vendor-list.json (see 'vendors' object)

What's an IAB or CMP?
Post reply on HN