Live data from Hacker News

Request for comments regarding topics to be discussed at Dark Patterns workshop

regulations.gov

381–390 of 542 posts

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#381

Earlier quoted context omitted.

App developers do this in their apps too when asking to rate the app in the App Store. They first show you a fake popup asking if you are enjoying the app OR want to send feedback. They will only show you the real iOS popup for reviewing the app if you tap "Yes" to the enjoying app.

Can’t believe this isn’t against App Store rules.

It sort of is against the rules (disallow custom review prompts) but it doesn't seem to get enforced as far as I can tell. Even top apps like YouTube do this.

https://developer.apple.com/app-store/review/guidelines/

> Use the provided API to prompt users to review your app; this functionality allows customers to provide an App Store rating and review without the inconvenience of leaving your app, and we will disallow custom review prompts.

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#382
post #306
post #152

A common one is fake consent popups for system notifications. Websites need to ask for consent before sending system notifications via the Notifications API. If a user declines, that website is blocked from asking again (for obvious reasons) But many websites cheat this by showing a fake consent popup designed to mimic what the browser would show. If a user clicks "Decline" on the fake popup, the website won't show t…

Thank you! This is something that has been annoying the hell out of me on instagram using desktop Firefox. Every time I login it prompts to show notifications; I always decline so it shows it again next time I log in. This time I accepted, but blocked it from within firefox. I get it's not a dark pattern because it's clear it's not the browser asking, but still it's very annoying.

> I get it's not a dark pattern because it's clear it's not the browser asking

I disagree... that does make it rather a dark pattern.

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#383
post #380

The "hold-your-offline-device-hostage-until-you-attempt-to-connect" pattern. It goes something like this: When setting up a new unlinked kindle device, Amazon tries to trick you into connecting to the internet by showing a wifi setup screen that cannot be skipped. The only way to skip it is to supply the device with bad credentials and let it attempt to connect and fail. Only when it fails will it allow its owner to…

Microsoft has really pushed this in the recent(?) versions of Windows 10. When it was first released it wasn't this bad, now it pretty much forces you during install to link an account then also forces you later (as you mentioned).

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#384

Earlier quoted context omitted.

Can you explain why this is a dark pattern? How does slack benefit from you using the native app vs. the web app?

As an engineering manager in an unrelated field... this could also be a way to not have to support a feature on X platform because I don't have the resources to make it work on every possible mobile browser. Or the mobile browsers don't support X feature and I don't want to (or can't) spend the resources to make it work there, QA it there etc. It's not something likely to be able to curb with regulations.

I do not think this is a dark pattern. I don't see any exploitation or misrepresentation.

I think we should be careful to distinguish between exploitation / malicious intent vs. airing of grievances of about UI/UX feature completeness.

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#385
post #310
post #71

Earlier quoted context omitted.

Reddit is just as guilty of this. If you want to see all the comments on a thread on their mobile site, you're pushed to install their official app and presumably create an account when doing so. As far as I can tell, the best workaround is to use the desktop site.

I'm so thankful for the Reddit redesign, I had a serious problem spending way too much time on that site. Now it's almost completely unusable.

Now reddit have gone from blocking 'adult' content on mobile browser to flagging stuff as 'unknown content' and trying to force you to install app.

I was trying to research a vinyl cutter purchase instore with spotty coverage and every bloody reddit page would be blocked within seconds of loading with this stupid unknown content crap.

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#386
post #280

Earlier quoted context omitted.

Can you explain why this is a dark pattern? How does slack benefit from you using the native app vs. the web app?

Slack app has 4 trackers, requests 21 permissions on Android. Harder to block trackers, while their more tech-oriented audience probably uses browser adblockers more often. https://reports.exodus-privacy.eu.org/en/reports/com.Slack/l...

Aha! This makes sense. So basically, on native, there's lessened ability to leverage browser extension ecosystems to block ads and tracker scripts?

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#387

One example for sure is the endless CAPTCHAs you receive on virtually any large website when you attempt to connect from TOR. Each time you solve one it takes forever just to complain about how you spending several minutes selecting every 'light' suddenly isn't good enough to prove your humanity. You're not "checking if I'm human" 60 times in a row, you're blocking me for not wanting to be tracked on your website.

Can happen with non-TOR, too. Cloudflare is a cancer on the web for this kind of awfulness.

For me, Cloudflare and hCaptcha walls are solved problems with things like Privacy Pass. It's Google's never-ending captcha system that prevents me from browsing the web. They continue refusing to support Privacy Pass like other big players for some reason that is certainly not related to free labor and going around US labor laws.

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#389

I think a more effective route forward here is for places like YC to set standards for their portfolio companies. Only the strongest investors can do this, but once they do, it will setup a new playing field and the YC brand could mean 'no dark patterns here' in the way that buying an Apple product signifies quality hardware and privacy. It could act as an 'integrity' label that companies purchasing software would us…

Yc encourages "growth hacking", which is pretty much just code for dark patterns. I don't think they would be interested

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#390
post #15

TrustArc is a company used by major brands that utilizes dark patterns to FAKE opt-out time for GDRP compliance. Major companies employ lies. It will hold your browser captive for 2 minutes in hopes that you cancel or accept all. If you don't, it shows "We are processing the requested change to your cookie preferences. This may take up to a few minutes to process.". Not even incompetence could make this an honest pro…

I don't understand why most companies even bother. If they aren't going to be compliant in how they handle getting permission, why even pretend?

I think one reason is that we have reached a tipping point where website owners now view these banners as a signal of a "legitimate" website, without bothering to look into actual compliance.

Without enforcement, these things shouldn't exist. They are just a nuisance to everyone

Post reply on HN