Live data from Hacker News

Request for comments regarding topics to be discussed at Dark Patterns workshop

regulations.gov

471–480 of 542 posts

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#472

Earlier quoted context omitted.

But what requests would it even make? If you opt out you're effectively telling it to _not_ make any requests.

If it's the TrustArc Ads Compliance Manager, it makes a call to all the ad networks requesting the network's opt out cookie. The opt out cookie prevents the user from being tracked by that ad network across all sites. Cookie banner opt outs usually only prevent tracking from the site you are one. Unlike GDPR, which uses a website as the gate for all cookies, the ad industry also has self-regulatory programs. Particip…

The problem is you're being presented a mandatory popup for what appears to be used as GDPR compliance but realize that it isn't because real ones are instant. This is fake GDPR in the sense that it isn't (compliant); it's other things, as you note. If the purpose is to facilitate GDPR, that opt-out time shouldn't be conflated (the ad stuff shouldn't be bundled), given that GDPR appears to have a requisite "It shall be as easy to withdraw as to give consent.". Is that a correct interpretation? You're suddenly notified you can't operate for minutes (unless you opt-in), which is definitely dark, and unnecessary (unless you want to achieve the action they're doing, but you didn't; you just need GDPR). Sitting captive for minutes is not a modern day web experience anyone finds acceptable, that's why Google is so focused on empowering loading speed inspection/resolution. The experience made me wonder if they use users who don't opt out (I almost gave up just to get out of being locked out) as a selling point. There wasn't, that I could find, an instant GDPR-compliant way around this obstruction. Why would any company care for this experience? If they wanted to be polite and do extra action (this ad network regulations thing), they have the tech to do it asynchronously/unobtrusively, right?

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#473

One example for sure is the endless CAPTCHAs you receive on virtually any large website when you attempt to connect from TOR. Each time you solve one it takes forever just to complain about how you spending several minutes selecting every 'light' suddenly isn't good enough to prove your humanity. You're not "checking if I'm human" 60 times in a row, you're blocking me for not wanting to be tracked on your website.

This is likely coming from reCAPTCHA itself. As another commenter noted reCAPTCHA is likely detecting a large amount of interaction originating from your particular exit node's IP. This flaw is Google's responsibility, not that of the site. It's less of a dark pattern than a common usage pattern being incorrectly interpreted as hostile.

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#474
post #152

A common one is fake consent popups for system notifications. Websites need to ask for consent before sending system notifications via the Notifications API. If a user declines, that website is blocked from asking again (for obvious reasons) But many websites cheat this by showing a fake consent popup designed to mimic what the browser would show. If a user clicks "Decline" on the fake popup, the website won't show t…

This is commonly referred to as a “soft ask.” The reasons for it are not always nefarious. On some platforms you cannot provide any commentary on why you want to send push notifications and so the soft ask provides a way to give more context on the next (real) permission dialog. I’m not saying this isn’t abused all over, but when used effectively it can provide the user with more information to decide if they want to…

> This is commonly referred to as a “soft ask.” The reasons for it are not always nefarious. On some platforms you cannot provide any commentary on why you want to send push notifications and so the soft ask provides a way to give more context on the next (real) permission dialog.

What I'm reading here is that you (not you specifically) want to ask for my browser permission, but know that the popup is non-descriptive and your one shot.

If you are nefarious, creating a fake popup makes perfect sense. You lower the risk and increase your chances.

If you are not nefarious, why even go for fake popups? Why not have a button in the corner? A choice in some menu? "Hey? Want updates from us? Click here!"

Wanting to do more commentary on why you want to send push notifications never non-nefariously leads to creating fake popups.

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#475

Earlier quoted context omitted.

Thank you! I almost universally use the mobile website but it just keeps getting worse, presumably on purpose. I installed the official app but it’s very bad. I’ll download this one now!

You will still have the annoyance of search results only opening the official client but Apollo is a great app made by a single developer who has put a lot of time and effort into the app. He (Christian) is also very active on the /r/apolloapp subreddit and communicates upcoming features/bug fixes. Apollo does have an option to scan your Copy/Paste buffer so when you open the app, and if there is a reddit link in you…

Just to add to this: I can highly recommend Apollo as well, it's the official app in my mind. Nothing else even comes close. Also, there is no need for a shortcut. If I open the sharing menu, "Open in Apollo" is already present and I never needed to add the shortcut.

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#476

Connecting to an Azure AD / Office 365 account from a desktop application will pop up a dialog box with a small hidden blue link on the bottom left corner to "log in to this application only". The big button in the usual OK position will let the organisation manage your device , including pushing software to it and remote wiping. Even if it's not their device. Even if you're just logging in to one app, one time. Micr…

One other interesting interaction I found was that the org can seemingly tie certain setting to your Windows activation key. I've been using an Education license to W10 on my school laptop and it has "Some of these settings are hidden or managed by your organization". https://i.judge.sh/heavy/Sunburst/ApplicationFrameHost_nhjT7... https://i.judge.sh/stupid/Derpy/ApplicationFrameHost_G2GR6fW... https://i.judge.sh/blin…

Are you sure this isn't related to any GPOs set by yourself? I remember the same thing happening on my Windows 10 Edu install when I setup GPO's to disable start menu internet search, telemetry, tracking, Cortana, etc.

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#477

Earlier quoted context omitted.

So is letting you know about old.reddit.com a bad thing?

if they removed old reddit i would stop using the site

So I’m in the same boat but I’ve noticed an interesting dark pattern they use now to discourage old Reddit.

I often land in a comment section of a specific post, and then want to see more of the subreddit by clicking the link of the subreddit in the top of the page. Since about a month now, every subreddit shows me it’s only available through the app. I used to then preface the url with old. however now they’ve somehow done it that I will see the specific (locked) subreddit page, but the url will just be Reddit.com with nothing else, effectively making it impossible to add the old. before the url.

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#478
post #268

Although not software, gym memberships are notorious for using all manner of slimy tactics to keep you paying. Online reps can't do anything, your local gym somehow never has a "manager" around who can do anything. You can "freeze" your account but then they can just arbitrarily unfreeze and start charging you again. Very close to having my CC company issue a charge-back to our local gym for fraud. Very shady and hop…

Yes! Cancelling my 24 Hour Fitness membership was a nightmare. I also found out that the name is not indicative of their 6 AM to 8 PM hours. Horrible experience all around.

One of the largest gym chains here is called Fit for Free.

It’s very much not free.

Re: Request for comments regarding topics to be discussed at Dark Patterns workshop

#480
post #71

Earlier quoted context omitted.

Reddit is just as guilty of this. If you want to see all the comments on a thread on their mobile site, you're pushed to install their official app and presumably create an account when doing so. As far as I can tell, the best workaround is to use the desktop site.

Has anyone else noticed reddit on mobile browsers being ridiculously slow? My experience is that the page loads fine, but then there's 10 seconds or so of loading animation before the page displays. Requesting desktop site makes it load immediately. I'm 95% sure they just have a timer they make you sit through in an effort to get you onto their app.

Just opened a Reddit page on Desktop and it has 7.77mb resources and 97 requests and 4 seconds till DOM loads. Its bloated, probably to boost app downloads. Imgur also features fighter plane levels of bloat to show an image and comments.
Post reply on HN