LinkedIn dark patterns, or why your friends keep spamming you to sign up for it
medium.com
medium.com
I'll start: 1) The ability to go no-opportunities. When you're not looking for work, you turn this on, and you will not turn up on any search result. 2) Simple export API, with a guarantee of you having complete say over your data. You may export as a json anytime, and import into another service. 3) Non-profit is possible. A resume directory can be run by a few people with a small revenue. Trying to make a unicorn is what leads to linked-in level shit.
Others?
Related discussion: https://news.ycombinator.com/item?id=9045677 and archived page: https://web.archive.org/web/20150812004139/http://www.stopus...
The only way I can think of to deter this is cost per action. So accounts start with some virtual (or real) currency which spends on actions like connecting or adding to the graph. This will at-least minimize if not stop the behavior.
Any other ways of implementing non-creepiness?
It's hard to imagine this idea getting traction, but one way to implement this would be to require new features to be approved by (say) a majority of active users. This could act as a brake on roll-out of creepy features (if people read before approving …), but it might also slow or retard genuine advancements (although "no to constant interface re-design" is a feature in my book).
You might find the guy who seemed awkward and nervous in the interview was always very helpful to the rest of his teammates. You might learn that the guy who seemed to know your entire tech stack is actually notoriously slow in delivering working code.
If you're employed and discreetly looking for new work and you 'activate' your profile, now everyone in the office knows you're looking to switch jobs.
The target group of LinkedIn is mid-level managers of any kind plus the people who want to join that group. Individual contributors such as programmers will not get any value of such a network - no job to be done.
GitHub is way better suited, but won't capture the purely professional programmer who never works on public stuff.
Leaves StackOverflow, maybe expand the user profiles into a full profile (maybe already done, not using SO myself as I am said mid-level mgr).
Basically - you need a hook. Something useful on top of the networking aspect to attract ICs.
Career-focused people are on LI and use it, no matter what. Very hard to beat them by now, similar issue with FB - to compete you'd need at least equivalent data. And yes, LI built their dataset with very slimey tactics.
Simply, a directory of connections where I can define my relationship with another individual. Something that people won't hesitate to connect on after even a brief meeting. Additionally, I want to control individually what contact information they have access to.
There might be some room to tailor it with options which control the visibility of that connection by your other connections. (e.g. I don't want to show that I'm closely connected with Bill Gates. But I will let people see I'm connected with Arnold Schwarzenegger and I feel comfortable offering introductions)
The ability to confidently wipe all data you've ever fracked from me as part of deleting the account if/when I chose to leave your service.
Please plan the delete operations as a core part of your architecture, rather than an addon you can't properly support because you didn't think about deleting data when you designed the system.
Instead how about no contact-data (email/phone) be made publically available at all. And all friends request, messages or recruiter contacts goto a public box for that contact? So we can recycle old PO boxes after set intervals, and you only listen to the latest one. Anyone trying to reach you has to be OKed by you.
There's also another negative PO, and you try to keep that empty. Bad player that spam you get a a megative PO message, and those that get too many such are lowered on some scale.
Or of course, charge per action, so it'll be cheaper for someone to contact a dozen people, but too expensive to mass spam.
It's got nothing to do with other people. When your company goes under, and historically speaking most do, someone will buy your DB. With all your debts, you won't be in a position to refuse. Who will the buyer be? What countries laws will they operate under? Will /they/ be willing to protect my contact data? Or will they sell it to telemarketers for a quick buck?
Sorry, but if you can't find a way to let me wipe my data, even if it takes 6 months while your backups cycle, I'm not interested and never will be.
Perhaps that could be added to your wish list, again as opt-in/-out functionality.
Further there is a huge problem with companies being shit when it comes to providing feedback to candidates (which to be fair this problem LinkedIn never offered to solve). An issue that Glassdoor initially because they positioned themselves as some kind of review platform. But unfortunately glassdoor did a u-turn and now copy/paste LinkedIn's subscription/recruitment model 1:1 and even spams me more often than LinkedIn asking me to buy their job-posting packages.
The problem is that there is no way of holding companies accountable to their recruitment practices. If you apply for a job you have no idea why you get no feedback or what happened with your data that you supplied. How many other applicants have also never heard again or been left waiting for 3 months without an answer from the company. One of my companies is in recruitment so I know a thing or 2 about how recruiters often are stuck in the middle if the client doesn't provide proper feedback of why a candidate gets rejected.
Pushing for transparency here would be a killer service. Though I'm totally disillusioned with another walled garden where I have to take some founders word for it. I want to see something anonymous that does not put the candidate at risk if they give bad feedback about an employer. Also it should be decentralized and without a possibility to be killed (e.g. no censorship or EU data protection law or "right to be forgotten" should allow an employer to remove a bad review/comment from the web). I think the blockchain would lend itself to such a concept.
Is it possible for the value of a node in a blockchain to grow with time, and cardinality. Because that would be killer. No one may create spam nodes, and a pgp like trust develops over time.
Linked-in actually has this but I still get messages from recruiters. I'm not sure if the Linked-in flag affects search results but I can think of ways to circumvent "search ghosting." For example, I could be found without search by looking at the company profile or the connections of people in my company.
I'm sure there are ways to fix this but the only one I can think of involves penalizing the recruiter and at the end of the day these people are just trying to do their job.
One page (member homepage perhaps) displays a list with the standard "add these people to your network" and in an absent-minded moment I clicked a few. Too late, I realised it was a mixed list of LinkedIn members and non-members extracted from my address book. Existing members, fine, they get an invite to connect. But non-members no doubt receive a message "from austinjp".
I texted one friend a pre-emptive apology and logged out. I very rarely bother with LinkedIn, and this is another reason they leave me cold.
This is why nothing like linked-in gets anywhere near my address book, and therefore nowhere near my portable devices because the only way to install the phone app is to agree to that permission and the site itself is terrible on mobile.
If you let an app install that asks for permission to read your address book assume it will one day it will spam everyone in it and if someone in your address book also uses the app assume that the linking information will be used for profiling purposes (which means more advertising by one of many means).
And any who gives a web app their email address & password to access their mail account to look for contacts (seriously, I know people who have done this and damn well should know better) they need a good smack up the back of the head with the security clue stick.
I'm a friend of Tom, Jerry, and Spike. We all have each others' email addresses in our address books.
We're all LinkedIn members apart from Spike. Tom and Jerry both upload their address books to LinkedIn, but I don't.
LinkedIn doesn't require a wizard to work out that austinjp may know non-member Spike. They simply have to display Spike in a mixed-list of members and non-members and wait for me to click him.
They even differentiate non-members from members, but too subtly, and all it takes is one mistaken click.
There, we have a winner!
iCIMS would like to access some of your LinkedIn info:
YOUR PROFILE OVERVIEW
YOUR FULL PROFILE
YOUR EMAIL ADDRESS
YOUR CONNECTIONS
YOUR CONTACT INFO
NETWORK UPDATES
GROUP DISCUSSIONS
INVITATIONS AND MESSAGES
So I looked up what this meant :
Network Updates - Retrieves and posts updates as you.
Group Discussions - Retrieves and posts group discussions as you.
Invitations and Messages - Sends messages and invitations to connect as you.
So it seems I gave them access to pretty much every feature except the ability to close my account and/or change the password (which I promptly did.) Woops.
This is a category of dark patterns: have the user click on something that has been benign the last 20 times they've seen something similar, but this time isn't.
This is the nature of OAuth, in which the scopes can be different for many different clients. Not that this makes it any better, you just need to be aware of it. Slideshare do the same thing when you click download - if you verify using linkedin they want access to everything on your linked in profile just so you can download the slides. Ridiculous (even if they're essentially the same company).
Changing your password here is no good, you need to go to linkedin and then your account settings, then third party apps and delete whatever it was you allowed to connect. Despite all the failings of OAuth that's one of the good features about it, you can actually control the access.
Tip: if you're logging in using OAuth (generally when you get redirected to another site to confirm) always check the requested scopes and always remove all the scopes but those essential to the functioning of the calling app/site, which is usually just access to your e-mail address.If you can't disallow certain scopes then try logging in using something else, github, facebook, whatever, and rinse and repeat. If you're still not happy then just signup with a throw away email.
Does anyone remember how FB ensured growth? "Import your yahoo/google contacts to see who is on FB". What they didn't mention is that they would hold on to the email addresses to notify anyone who signed up that they had friends already, and exporting your contacts was disabled soon. Despite being officially dismissed, the "shadow profiles" claim rang true to me too.
Before FB, MySpace was built on spamming the bejesus out of people [1].
[1] http://gawker.com/199924/myspace-the-business-of-spam-20-exh...
I can just picture hundreds of engineers deploying experiments, looking at data and concluding all things that move numbers up are a success... Regardless of how deceiving or confusing the UX might be.
Really?? This made me even more uneasy than before. Why would that add additional security to my profile? Has anyone else seen this on their home page yet?
Im all for jumping on the bash LinkedIn train, but let's be reasonable here.
So, positives are there for me so far.
[1] http://techcabal.com/2016/02/08/linkedin-has-quietly-killed-...
Also, who are the sociopaths designing and coding these deceptive user interfaces? Have they no empathy for their users?
Unfortunately, LinkedIn serves a niche in the market for keeping in touch with ex work colleagues who you don't necessarily know well enough to connect with on Facebook. And to be fair, it's also a good way of getting a job nowadays.
If someone built a better intentioned, less spammy alternative, I think it would stand a good chance of succeeding.