Dark patterns after the GDPR: consent pop-ups and their influence
dl.acm.org
dl.acm.org
Just because website purposefully give a terrible UX in an effort circumvent the law does not mean the law is wrong. It's the implementation.
Make it so every page that contains a tracking element MUST permanently display a large-ish (say, 1% of the screen for each) seal/label indicating that it is tracking you (like ESRB labels). That way, website will be pushed to remove the tracking elements so that they can remove the offending banners.
In the end this option still hampers genuine users of those websites. That is the point and instead of people taking issue with the website tracking them, they'll complain about the banners instead.
Just look at this entire comment section... No guys, the problem is not that the law is bad, it's that the state of the internet is absolutely fucking terrible. "Why do I have to click so many consent things?" - because everyone is tracking everything about you, this is the point!
For a company the size of Google, it's a slap on the wrist (especially when compared to the 5 billion euro fine from 2018 over antitrust violations) but they have been going after the big players. In fact most stories I've heard related to GDPR actions have exclusively been about big players getting fined.
Don't they currently have the same incentive? (And mostly don't act on it.)
The point of GDPR is that they shouldn't have any bad gut feeling about accepting these terms - because anything even slightly shady, in any way beyond the most basic necessities for performing the service, must be opt-in by default, set to "no consent".
Alas, national data protection agencies are way too reluctant to chase the offenders and issue fines, so a big chunk of the sites on the Internet are breaking the law with impunity.
The problem is that you could frame almost anything like that
Take an extreme example: Let’s imagine gold traders were allowed to go around taking people’s jewellery at gunpoint. Gold would be cheaper to buy. Traders make more profit. More jobs! Surely this is a win all round? Of course not, for obvious reasons.
Competition is not a an excuse for damaging your rights
And your example of clicking through 20 scary messages is because the websites, as is pointed out in the article, are not complying with GDPR
GDPR is about data collection, not about cookies.
Using cookies for core functionality instead of tracking does not require consent. Tracking without cookies does require consent.
The consumer experience being worse is, in a large way, purposeful UX degradation done by the sites themselves. The typical consent popup tries to simultaneously walk the line between "illegal under GDPR" and "just scummy" (often crossing to the illegal side; see the problem of low enforcement), and shift the blame for bad UX on those pesky, no good regulators.
If you're using cookies for things like shopping carts, you don't need a cookie popup at all.
If you're using cookies to track visitors across sites for advertising purposes, you're the problem, and the cookue popup only documents that.
If EU cancels GDPR would everything go back to normal? Probably.
As an unhappy consumer, that's all I need to know. The cause and effect is pretty obvious here.
Sure, some people may be happy (I hope?!) with whatever privacy benefits GDPR is supposed to bring about. But blaming websites for responding to EU regulation one way or another, doesn't make me, who doesn't care about these supposed benefits, feel any better. If GDPR people feel like this is a cost worth paying then so be it. I certainly don't believe more enforcement will somehow make companies come up with fewer legal derisking strategies.
GDPR forced bad actors on the Internet to document their bad behavior openly. If this made your overall Internet experience worse, it should reveal to you the magnitude of the problem of surveillance capitalism.
1: It makes leaks a liable issue and one that get additionally costly if the company tries to hide it.
2: All data collection by the big players are sitting behind a single legal argument that informed contained can be gain by a pop up window or by passively clicking a link, both which the GDPR writers said was not informed consent. That big players explicit ignore part of the regulation and get away with it is a problem that not enough people are questioning. The discussion has moved away from the law makers and into the enforcement.
Now as users got pissed off, solutions started to emerge. Yes, the EU does not seem to enforce it too much, though I'm curious how many reports they get. Anyway, Mozilla just announced that they started compartmentalizing most cookies, so tracking will stop working for a lot of sites/services.
Blocking cookies on the browser side is a cat-and-mouse game where the cat is a multi-billion-dollar corporation and the mouse is a handful of volunteers.
You're also vastly oversimplifying the tracking issue to just “cookies”. The big advertising networks will use any method imaginable to track you. In the US (sans e.g. CA) they do not even have to tell you that they're tracking you, let alone tell you what they're doing with the information or let you opt out.
The GDPR gives you rights that work against all kinds of tracking.
> How has this changed the data collection practices of Facebook or Google in any meaningful way?
They have to tell us what they are and obtain our consent before doing them. They also have to tell regulators before doing novel and particularly intrusive things.
> Not enough people are asking what effect the many new regulatory burdens will have […]
The burden of putting the least effort to respect people's privacy is a good one. If you actually aren't trying to spy on people the burden imposed by GDPR is much less, perhaps giving good actors a competitive advantage. You don't even need consent most of the time.
You do not need a consent popup if you are using cookies for core functionality instead of tracking and you do need a consent popup if you tracking without using cookies.
So, from a privacy point of view, it's improved the situation. If some DMP has their S3 bucket hacked, then there's less of your personal information being leaked.
Whether or not this site is compliant depends on whether the "Got it" button is taken as affirmative consent for non-essential tracking or not.
Their privacy policy says:
> Other than in the restricted-access portions of the Web Site that require an ACM Web Account, ACM does not log the identity of visitors. However, we may keep access logs, for example containing a visitor's IP address and search queries. We may analyze log files periodically to help maintain and improve our Web Site and enforce our online service polices. ACM only uses analytical cookies and does not use any user-specific targeting cookies.
> A cookie is a small file of letter and numbers that is placed on your device. Cookies are only set by ACM when you visit restricted portions of our Web Site and help us to provide you with an enhanced user experience. Raw log files are treated as confidential.
So... not sure why a public portion of their website straight-up won't load without them. They're clearly not only checking/setting cookies on certain pages, otherwise they wouldn't know that my cookies were disabled.
In general, it's unfortunate their page doesn't degrade gracefully if cookies are disabled (though that's not always possible; for example, you can't assume that traffic Cloudflare can't analyze for trust is trusted... but those BACKEND and sessionState cookies being mandatory feels lazy).
If you use it only to keep track of the logged in status and access management of the user then you are compliant.
If you use it to track the user server side, then depending on the use case consent is probably required.
GDPR is not the only regulation at play here. The PECR also applies. You need consent for the session cookie in the public areas of your site. It doesn't become essential until the user logs in, registers, adds an item to the cart, etc.
And considering the ICO, the UK org that enforces these laws and where you have to go to find out the UK laws on it, literally just tell you that they use cookies to make their website work and don't ask for consent makes me think this is so much more complicate than any of us truly understand.
If they're setting cookies without consent with a user tracking id, I am going to guess that my session cookie falls under the same thing theirs does.
https://ico.org.uk/for-organisations/guide-to-pecr/what-are-...'. - Check developer tools and cookies.
No, that's just one basis for processing data. Another basis for server-side tracking like this could be legitimate interest. The site will need to provide evidence that they've weighed up the user's interest in this and be able to demonstrate a convincing case in favour of the site.
For example, it could be a legitimate interest to track A/B testing in order to increase shopping cart checkout rates - the legitimate interest is arguably that the site wants to increase its revenues and if it can demonstrate a convincing case for this, it will be allowed by the regulator.
So you may rely on legitimate interest to process the data, but you need the consent to store the session cookie to collect the data in the first place.
If you have special offers based on the URl they came from then it is strictly necessary to be able to remember where they came from so they get the special offer and don't fall victim to false adverstising.
Strictly necessary means if the website will break in anyway without it.
You could a/b test based on even or odd numbered IP address and not require consent to store a cookie. You can pass the referrer around via query string and not require consent to store a cookie.
However, as you said, there is no enforcement of the regulation so the risk of non-compliance is basically zero :)
No if a user clicks a button to see the prices at 10 euros but see the prices at 20 euros then that is an issue. That is a rather serious issue, if I show you a price and then when it goes the payment processor on the second request that is illegal.
There are many ways of doing things but considering the ICO's list of strictly necessary this falls into it.
Also, I use the session id in my logs so I can debug issues such as the user saw x on page then did y so z happened. This is falls under it as well due to it being required for the operation of the website.
The fact there are other ways of doing things doesn't remove the fact for my way the cookie is strictly necessary. The system will fail. And yes, the tech stack and the way I built it does affect this. Look at the laws and you'll see a number of times where they say something along the lines of "if feasible". The recommendation from ICO is that you don't need to ask for permission for everything and they kinda make a point of saying that as it's annoying as hell for everyone.
I agree with you, that is a serious issue. But that issue is caused by your use of a/b testing, and if you solve that issue with a cookie then you need consent.
The ICO PECR guidance explicitly states that you can not rely on the strictly necessary exemption for analytics cookies.
A simple guideline is to imagine if someone breaks into your server and steal data. If that data can come to harm real people somewhere then you likely have something which you needed to have gained consent in order to handle. On top of that there is an additional exception for data only used for security purposes.
There are many legitimate reasons for storing and processing data, and you should not ask for consent needlessly - among other reasons, because consent can be withdrawn, at any time, and you are obliged comply stop processing and remove data - unless you have other legitimate reasons, in which case the whole exercise seems pointless.
Whether the data can be used to harm real people has significant correlation with whether it is covered by GDPR, but does not relate to consent. It can also be of relevance on what security precautions are required and when weighing right to privacy vs. needs to process specific data.
As a typical example, you do not need (and shouldn't ask for) consent for data and purposes that are reasonably necessary for the services customers ask for. You are not allowed to share / use for unrelated purposes other than allowed by other stipulations. Also, information on data collection / processing should be reasonably, easily accessible.
The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, by public authorities, by computer emergency response teams (CERTs), computer security incident response teams (CSIRTs), by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems.
GDPR is compatible with information security and do not interfere with it. The section is technology neutral in that you can use cookies, logs, firewalls, blacklists, oracles or any other methods that include data processing and as long the purpose is strictly necessary and proportionate to ensure network and information security than that is acceptable as according to Recital 49.
> A simple guideline is to imagine if someone breaks into
> your server and steal data. If that data can come to harm
> real people somewhere then you likely have something which
> you needed to have gained consent in order to handle.
The website admins and developers are not those who decide what data is covered, based on any idea we might have as to what may be likely to cause harm. Rather, the GDPR defines personal data and the rules for handling it differ between controllers and processors. I should have typed up a more thorough answer.In any case, there are always more and more nuances to be discovered about the GDPR depending on field. I'm not a lawyer and I'm glad to always be corrected and updated.
Never said that the information needed to be likely to cause harm, but simply can. The exact phrase that GDPR use is "Any information that relates to an identified or identifiable living individual".
An example where any information that related to an identified or identifiable living individual would be harmful would be in a court. Any information about juries, judges, accused or defendant is potentially harmful if abused. All legal systems depend on the presumption of privacy in this regard, and all legal system that I know have processes in places to replace individuals when that harm can be actualized.
A similar situation is possible when it comes to information being distributed to a very large audience. Unimportant "harmless" information can be perfectly safe in a small group, but if millions of people see it in a harmful context then such harmless information can turn harmful. Any person operating a forum, a voice chat group, or a place where any two people meet should treat any logs with the threat model of it being leaked and the information harming real people.
I should have clarified in the above comment that information that related to an identified or identifiable living individual should always be assumed as potentially harmful, and thus involving a risk to the identified person. This is the problem GDPR is mostly attempting to solve, and thus the situation for which the operator need to act on. Similar, if the information is of such nature that it can't be harmful, it is also very unlikely to be information that relate to an identified or identifiable living individual.
When GDPR came it a lot of people asked similar questions as the parent post. What about Apache logs? What about login credentials and sessions. What about CRM and customer registers? The collective answer from that conversation, as I remember (and much of those discussion can be found archived), was that the question depend on the context. If its purely for security then the operator can likely continue on as before per the above quoted section, with some caveats to proportionality. For most everything else, look to the purpose of the GDPR.
I feel like this is a horrible implementation of this browser feature. If the user disables cookies, the browser shouldn't tell the website "I don't support cookies", but rather let the website's JS think it happily set a cookie but not store anything when you navigate to any other page.
(Note that you could also check server side on the redirection page)
I believe (but I cannot formally prove it) that it's actually impossible to prevent detection.
It's a bit similar to private browsing mode (which in that case should in theory not be detectable) but has revealed to be a challenging problem.
That said, I think cookie auto deletion basically satisfies that use case? I personally have cookies set to wipe when I close my browser, and I close my browser fairly frequently. That's not quite as often as you're suggesting though.
Is it really interesting, though. For example, we have seen this as a very common retort in HN comments every time an author is critical of advertising, tracking/analytics, etc. Someone points out the author's site itself uses the thing being critiqued.
Is that supposed to detract from the argument being made by the author. That does not make much sense.
It is a bit like another common retort we see in discussing tech company behaviour: "But everyone else is doing it." Does that make it OK. Or one we see when discussing regulatory action: "They should be focusing on X not Y." Don't look here, look over there.
I am highly skeptical of comments that try to leverage these tactics. The message is what it is. Whether or not it is valid does not depend on who is voicing it, where it appears, or what's going on somewhere else. This is pure misdirection.
This paper might be a worthwhile read. It makes little sense to pre-judge it before reading, simply because it appears on ACM's website, and ACM's website developers try to get users to enable cookies. What if the paper is re-posted on a site with no Javascript and that does not try to set cookies. Does the content of the paper then become "legitimate". Why or why not.
It is easy to retrieve this paper without using cookies, from another site. For example,
https://web.archive.org/web/20210305175101/https://dl.acm.or...
PDF: https://web.archive.org/web/20200701025846if_/https://dl.acm...
Not trying to single out this one comment. It's fine. The paper is not really arguing for or against banners and other notice and consent mechanisms, just studying their use. I cannot even see the banner because I use a text-only browser.
The most interesting paragraph in the paper IMO is the last one. They ask why the client, e.g., through browser settings, cannot be in control of the legal consent mechanism. What if clients were to sed an additional HTTP header to indicate whether or not the user consent to cookies. For example, Allow-Cookies: no.
The online advertising companies have apparently fought against this, e.g., the DNT header. If you enable DNT in one popular browser deployed by an advertising company you get this ridiculous warning message. Why the heck is it a big deal if the user controls the headers sent and the server has to honour them. When you read RFCs about www development they always make it sound like clients and servers on are equal footing. The reality is quite different. These companies want to control how a user "consents".
If it's so hard to do the right thing that someone who apparently both cares and understands the problem space still messes it up, then the issue is more fundamental than education.
In general, demonstrating GDPR compliance is an expensive process, and I’m not sure that a US nonprofit corporation like the ACM ought be trying.
Is this somehow suggesting nonprofits are less liable? I was quite shocked to read an article that gave a weekend sports team as an example of an organization that was maintaining GDRP protected data, basic the list of their team members
I've just been trying out the tridactyl Firefox plugin. (vi-inspired keybindings for browser usage).
In tridactyl, the element can be hidden by typing out ";k", followed by a couple of letters to select the element hierarchy to hide.
"It shall be as easy to withdraw as to give consent."
All those dark patterns to hide the rejection, keep some things ticked etc. are a complete waste of time. They all violate GDPR and are just another case for: no one has read the GDPR and is just copying everyone else.
It is just a waste of developers time, hiding rejection of consent, making it less understandable, etc. is just violating the GDPR. Google is violating it, Facebook is violating it,... but they have money for lawsuits, if you have it too, no problem, just copy them, if not, reconsider your tactics.
Bottom line, you are wasting time and effort to implement it, you are trolling the users with popups and at the end even the consents that you got is invalid and void. So why doing it?
Imagine the scenario, your beautiful website, your beautiful android application is being checked for a GDPR compliance based on lawsuit.
And you bring in your dark-patterned consent dialog (whoever the provider is, it doesn't matter, YOU are the controller, YOU are the one who needs to care for your visitors/users privacy and you will be fined if google ads are violating privacy by their scripts run from your application/site).
What do you think will happen, you will get pat on your back and someone one will say "you poor thing, you didn't understand, let me pardon you" or you will get an "Tommy Lee Jones" implicit facepalm [1]?
Same goes for all the sites that stuff the user id into the "consent/no consent" cookie where just setting "consent=yes" or "consent=no" would be enough. Again, just same thing, for avoiding storing one PII you create another PII (by GDPR, anything that is unique to a person is PII) and violate it by doing that. Just why. Dont bother. Wait for a law suit and that is it. Dont just waste more money with same result as not wasting it, rather label a jar with "GDPR Lawsuit" label and stuff the money wasted for illegal consent methods into the jar.
[1] https://me.me/i/implied-facepalm-when-something-is-so-ridicu...
If I'm so damn "legimately interested", why is it on by default and basically impossible to turn off? Find me one person on this earth who is legitimately interested in being tracked by marketing companies who sell their information on to whatever giant collections. This should be illegal.
A legitimate intrest does not require an opt in (or an opt out). Consent does. If the page mixes those two up they're either clueless or trying to walk in the gray area and don't really understand(or don't want to understand) what either of those terms mean.
Any CMP that does not allow you to opt-out is on shaky GDPR legal ground.
[0] https://vendor-list.consensu.org/v2/vendor-list.json (see 'vendors' object)
> The processing must be necessary.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
IANAL, but as I understand, it refers to data collection that is inherently needed to perform a service.
E.g., a pizza delivery service has a legitimate interest to know the address of the place where it should deliver the pizza to - because, well, otherwise they can't deliver the pizza.
In such a case, the GDPR wouldn't require the pizza place to get consent. (the GDPR requires that a service is performed even if consent is denied, so without the legitimate interest exception, the pizza place could end up in a legal catch-22 if someone ordered a pizza but denied consent to collect the address.)
The basic idea seems perfectly reasonable to me, but of course sites always tried to stretch the "legitimate interest" definition as wide as they could get away with, and this seems to be the latest iteration of that.
I have no idea where the latest fad of claiming all kinds of ridiculous things as legitimate interest as long as there is an "object" button comes from, but I imagine there was some court case that decided this was borderline legal. If anyone else knows more about this, I'd really like to know as well.
But at least I think this is why many consent popups ask the exact same questions twice, once as "consent", off by default and once as "legitimate interest", on by default: They are simply trying their luck on two separate legal avenues. (Not that this would make any sense from a UX point of view or from the intent of the law. But I guess it does make sense from a "scummy lawyer" point of view)
This is covered by one of the five other GDPR principles for lawfully processing data ("to fulfil contractual obligations..."), so it wouldn't be considered a legitimate interest.
An example of legitimate interest would be the Pizza Place keeping your address on their phone system, so that when you call from the same number on a future date, they can confirm your address without having to ask for it again.
I expect the first point of divergence between UK GDPR and EU GDPR might be here (since they are now separate), in how 'legitimate interest' is interpreted in the law.
Sure. I'm legitimately interested in that.
I prefer being marketed to by people who have a good idea about what I would like, rather than getting phone calls at dinner time from people trying to refinance my non-existent mortgage.
And no, I'm not scared about Google knowing details about my life. If a dangerous entity such as a rogue government wants to do me harm, they will be able to find out whatever they want about me whether or not I use a 'secure' browser and search engine.
(I don't remember if this was on desktop or mobile, on mobile s/click/tap/g)
Also, I personally lean towards being in favor of GDPR and cookie law (wish there were some improvements though); I'd like to say it just because every opinion you find is "GDPR useless", "cookie law bad"
Several days after purchase I received a marketing email with an Unsubscribe link.
I submitted a GDPR enquiry and after a few weeks I get:
Having investigated this matter fully, we can see that you were opted in as a result of a small technical difficulty which we are now fixing. We have taken action to set your marketing permissions to "no" as requested.
I think we're so far past the GDPR "start date" that there's an apathy to it from companies and they're pushing the limits again. How Nintendo can have such a formalised GDPR enquiry process but such sloppy controls is beyond me. I will formally complain to ICO (UK data regulator) but I doubt it'll effect much.There are still some operational differences, around the fact that the UK regulators will not participate the cooperation mechanisms that the other regulators will. This ends up mattering for businesses: a significant aspect of GDPR was that a company only ever had to deal with one regulator, but now they need to interface with one for the EU and a second for the UK.
I've had multiple merchants get back to me after such a complaint claiming that under the PECR they're allowed to send further marketing solicitations following a purchase.
I haven't pushed it further so no idea if this is actually legal or if the GDPR supersedes it.
Section 22 is the relevant section they are hoping to rely on, specifically section 22(3) which allows them to:
----------
(3) A person may send or instigate the sending of electronic mail for the purposes of direct marketing where—
(a) that person has obtained the contact details of the recipient of that electronic mail in the course of the sale or negotiations for the sale of a product or service to that recipient;
(b) the direct marketing is in respect of that person’s similar products and services only; and
(c) the recipient has been given a simple means of refusing (free of charge except for the costs of the transmission of the refusal) the use of his contact details for the purposes of such direct marketing, at the time that the details were initially collected, and, where he did not initially refuse the use of the details, at the time of each subsequent communication.
----------
So in this case, they are obliged to let you withdraw your consent every time they email you. It is not a blank cheque for them to keep emailing you simply because you've purchased something; it is consent-based and therefore uses the same consent processes as the GDPR.
--
Probably because only 1% of 1% of their customers even bother to notice. I'd be willing to bet money that you were the first person to discover this implementation error.
To Nintendo, marketing is not a "core" business function, so when the company was sorting out GDPR, no one invited them to the room and they didn't ask to be invited. When companies think about "what data do I have" they tend to get tunnel vision to their main business operations. I bet Nintendo has robust processes for their online gaming services. No one ever seems to think about the twenty dozen Google Analytics accounts they're all running, and a good fraction of them don't even think about their CRM systems.
Then I sent them a GDPR request to remove all my info and complained to the Danish Data Protection Agency.
I stopped receiving e-mail but got nowhere with my complaint. The agency wrote me that they didn't want to pursue this. Based on this .. I don't think that anyone is taking GDPR seriously and no one is trying to defend the small people (me!).
On a positive note, I have noticed that deleting accounts have become much easier after the introduction of the GDPR, and more and more I see tracking opt-in/out forms where opt-out is just as easy as opt-in. So something is working.
The first real reaction on GDPR came at that moment Google forced them to. There was a deadline (somewhere in february 2021) where Google would limit ads if no consent-manager is implemented.
When we finaly implemented it they set everything they can to fight against the user: The big blue floating button for the consent manager was hidden - instead i had to implement a link into the footer. Nobody will find it there. Then they disabled the "disable everything"-button. Now you can just allow everything or manually tick a hundred boxes. They totally know that its not legal. But nobody cares. Ad revenue is the most important thing and if they would follow the rules they would loose quiet a lot of money.
As a developer its frustrating to see how user hostile the web has become ... Sure you can get another job, but its the same situation in every other place ...
If you are just a user browsing the internet and beeing annoyed by all this stuff and mistreatment: Im sorry.
Get an ad-blocker (uBlock Origin) and maybe additional uMatrix and learn how to protect yourself. The only way to "vote" is with the active denial of your data. They can see that statistics. They can see the rising number of people blocking all this tracking and advertisement stuff.
The irony is that the Cookie warning you get on all Googles sites are including all the dark patterns and seems to be there only to pretend they follow the law. All is op-out by default and you have to dig through many settings to turn off tracking
Because some websites do comply and have a reject all button on the first pop up. I know this us the law, but it should be... you know literally the law.
Why is the law not enforced for the online marketing industry? After all, you will scarcely find an industry so full of criminals as this one!
So what if an accept-only contract (like a ToS, EULA, or consent pop-up) did what average users think they agreed to, regardless of what the text says?
This would shift the burden of understanding from the user, where it currently lies, to the company. If it's essential to a company's business model that users agree to something complex that most users don't understand, the company will just have to help the users understand, deploying all those marketing and UX patterns they've perfected over the years to do so.
(Yes I know this isn't how contracts currently work; it's just a harmless little thought experiment.)
When we drew up the Ts & Cs for my first business that was selling online, we took advice from a lawyer who specialised in this kind of work, and one of the first points they made was that if there was anything at all surprising or unusual in what we wanted for our terms, it should be emphasized prominently and early, not buried in small print at the back, for exactly the kind of reasons above.
I once saw an anecdote (possibly apocryphal, I don't know) about a consumer rights lawyer who said they never bothered reading the small print in these situations. When someone expressed surprise that even a lawyer wouldn't check what they were signing up to, they replied that either the terms offered would be reasonable, in which case the lawyer would have no problem with them, or they wouldn't, in which case the unreasonable aspects would be unenforceable anyway.
Every time you open a site and it shows a popup for picking your cookies, just open uBlockOrigin from your browser toolbar, click the quick element picker (eye dropper icon), click the popup.
Done. Now you will never see the popup for that site (even if you do not save cookies, or clear your cookies), and you are technically guarantee to not accept any non-essential cookies ever (if they follow spec)
Also, off-topic: it's annoying that acm.org has now added a horizontal progress bar, similar to QuantaMagazine.org. I already know how far through the article I am, my browser shows me a scrollbar.
It is useful for mobile browser users.
Without legal backing, advertiser's will weasel out of any technical measure. You can even see this in the common practice of showing a app specific permission prompt ahead of browser/OS level prompts because they no that being rejected at the OS level removes their ability to prompt again later.
Legal systems are not so willing to prescribe specific technical solutions to avoid the "oh, you had very specific rules about advertising on radio, but this is TV so we get a few years of free roaming before you can update the law" issue
Also, when they do that, it is often critizised that the technical solution is out of date, inappropriate, prevents competition in the space and many more. (Often rightfully so.)
The problem isn’t the gdpr, it’s sites trying to use your personal data against your will.
The second best thing would be a law to prevent consent popups from making it harder to opt-out than it is to opt-in:
[Accept] / [Decline] / [Manage preferences]
We tried it at the protocol level with do-not-track and it just gave them an additional bit of info to track.
But I agree: It would be awesome to have this as a browser option. Just send a list of all the optional things to my browser which responds with the accepted results.
> The second best thing would be a law to prevent consent popups from making it harder to opt-out than it is to opt-in
Isn't this what's written in the GDPR?
Yes. A pity it's almost never enforced. From [0]:
> Consent requires a positive opt-in. Don’t use pre-ticked boxes or any other method of default consent.
> Explicit consent requires a very clear and specific statement of consent.
> Make it easy for people to withdraw consent and tell them how.
[0] https://ico.org.uk/for-organisations/guide-to-data-protectio...
See also: https://ico.org.uk/for-organisations/guide-to-data-protectio...
I wish it was this explicit, but it isn't. EU member states have all interpreted the regulation differently.
Making it harder to opt out than in is explicitly prohibited in the UK and Germany. It is perfectly legal in Italy. In Spain, it is legal to bury the opt out buttons at the end of a 50 page cookie policy.
Full compliance, across the whole of the EU, is exceptionally difficult.
The only company that sort of care is Apple. Without government intervention privacy would something reserved for wealthy.
One might argue that accepting all allows tracking by the site itself. But, does it really matter? I'm already on the site because I'm willing to. At this point, we're no longer talking about tracking but analytics.
* explicitly opt-in, so no action from the user means they shouldn't be tracked - pre-ticked checkboxes are not allowed
* it should be as easy to opt-in as to opt-out, so approaches like a big "accept tracking" button but a "learn more" or putting the deny option in the fine print isn't allowed
* needs to be "informed consent", so the user should be made fully aware of what data will be collected and how it will be used
* needs to be granular, so the user should be allowed to decide what data to provide and for what purpose
* optional - you are not allowed to deny/degrade the service if the user does not consent to tracking
The problem is that the GDPR is not being enforced properly. The annoyances you are facing would not be a thing if the law was enforced. It explicitly learned from the earlier "cookie law" which merely enforced disclosure and led to stupid & useless cookie banners with no easy way for the user to actually act on them.
No, that is literally impossible. If you only press the consent button because it's easier, you didn't consent.
I see no difference between websites adhering to a HTTP header versus what the visitor chooses in the website’s custom pop up.
To start with, we should add to the GDPR regulations that a “Do Not Track” HTTP header requires the website to not display the pop up and interpret it as the visitor allowing only “strictly necessary cookies for website to functionality”.
"making their lives easier" implies that the purchase is the default outcome that the user needs to improve their lives, when the purchase could simply not be made at all. As long as the intention is to make more money, and that the effort expended does not improve the nature of what is purchased in some way, I'd say it technically qualifies even if the consequences are the lightest of grays.
That said, your example is thoughtful, and you are probably right overall. We could look at the broader context of all these systems encouraging consumption, but that would be moving the goalposts on my part.
edit: just to clarify an edit took place while I was replying
Harry Brignull
Supermarkets have gotten customers to spend more than they intended with all their patterns as well -- just like social media sites get customers to spend more time online. It's just what they optimise for. The concept is much older than the coined word.
No, because the term seems superfluous or euphemistical to me. But yes in the sense that it is psychological manipulation.
Is an entity intentionally deceiving or manipulating the customer/user/etc. using their understanding of psychology? Psychological manipulation
>The concept is much older than the coined word
Indeed, we already have a name for it as I've been trying to say!
If you're wondering why, for instance, the milk is in the back, it's because it needs to stay cool and it's heavy.
That hasn't been generally true for a long time. The big chains spend a fortune deciding how their stores should be presented and optimising the layout of different products, and there is a lot of sophisticated analysis going on behind the scenes. There are certainly recurring themes in the results, but for example there are several major stores near me that have totally different layouts in many respects including all of the ones you mentioned, and it would be surprising if any of those differences was an accident. The stores don't run all those loyalty card schemes, nor rearrange their products from time to time, just for fun!
If in a "normal" grocery store trip you go through most of the store then of course you want to get refrigerated and frozen foods last, just before you go to the checkout. So they don't warm up too much.
By the way, frozen stuff is not all on the perimeter in my experience of US supermarkets. It's funny how something can be so mundane and everyday you never really look at it.
> Crazy → Unexpected, surprising, puzzling
> Dummy value → Placeholder value, sample value
They're getting more and more ridiculous with this Newspeak nonsense.
then take them to court and make a killing.
They are playing completely within the rules but taking advantage of human psychology to tilt the outcome in the direction the website owner wants (and, it is assumed, against what the average user wants).
Following intent isn't a good legal framework either, of course, better to make the people with legal training work hard to write them correctly once rather than making them complicated to interpret.
On one hand, you've technically got the right idea that I ought to put some skin in the game. On the other, it's a reasoning meant to shut down criticism on the same level as the infamous "yet you participate in society, curious!" comic
Then whats the point of GDPR if its not worth taking them to court. Is the idea that only govt can bring them to justice?
- GDPR shone a light on these practices that is visible to the casual user. This highlights some examples long term counter-productive thinking: people blaming GDPR for showing those practices instead of the practices themselves. A symptom of the messed up ways in which all this has been developed over the years
- Even single governments alone aren't enough in some cases (see France's measly series of fines against Google that probably evoked laughter in the boardroom)
- As a user, the prospect of being able to download my data from FAANGs seemed so miraculous and unrealistic at first that it made me realize I complacent I had gotten to unequal practices and to these websites and companies just doing whatever they wanted whenever they wanted. That specific point alone is worth the entirety of GDPR to me
- Baby steps. GDPR is already a step in the right direction, they are still figuring these things out (especially enforcement) whereas the private sector has decades of experience in anti-user practices, honed by some of the finest minds. The next step is to get a better share of the deal for Europeans as a whole.
Mostly, yes. The main enforcement authority is the government regulator in each member state (and the UK, which retains the system post-Brexit).
The term is in the best case superfluous, in the worst case a harmful euphemism.
The whole topic is a sensitive one. I'm sure a sizeable number here on HN derive some direct or indirect profit from such practices (running, being employed in or having stock in a company that does this sort of thing, especially FAANGs) while also having some dissonant misgivings about how the internet and technology is evolving. Terms like 'dark patterns' only serve to deepen this confusion and create additional moral distance between such tech workers and the consequences of their work, even if they are not necessarily intended to be nefarious: therefore, we ought to discourage it whenever possible.
Of course, in the grand scheme of things, none of what I say here will actually have an effect on any of this, but it's fun to discuss these topics all the same.
In any case, I don't see how any of this can be inferred from that single original sentence, but I'll take your word for it.
I can't decide yet if this is a good or a bad thing but thank you for the appreciation.
I’m not quite sure why this term proved to be so popular. I think it is helpful to have a term that is a little vague though, as it can be a lot of work to pin down whether something is truly deceptive with an outcome of harm - or just an annoying attempt to nudge.
>I’m not quite sure why this term proved to be so popular.
Well, it does sound cool and memorable on its own...
It can be seen as ambiguous, but a lot of language relies on assumptions about what a reasonable person would be thinking. Which causes trouble if you're trying to express a contrary or startling opinion.
I don't know if it's a "dark" pattern much as an "inaccurate" pattern....
https://chi2020.acm.org/chi-2020-free-proceedings/
Actual paper from 2nd author web page: https://people.csail.mit.edu/ilaria/papers/Midas-MITCHI2020....
(I was under the impression that all ACM conference papers with NSF grant numbers in the acknowledgments would automatically be added to CHORUS, but this one seems to be missing.)
GDPR should have been aimed at the browser and then force websites to comply with the settings defined in the browser. Non-compliant sites would be immediately flagged by the user's browser instead of hiding behind numerous dark UI patterns.
Perhaps it was easier to force thousands of EU sites rather than trying to coerce Google, Apple, Microsoft.
- tracking cookies are bad and yes it is an issue. - GDPR and consent pop-ups are pain, surfing is becoming similar effort like moving through the mud.
Solution? I hope we can embed response in the browser, so you say once I do not want to be tracked not even for "legitimate interests" :P and then in background browser does the rest? How difficult is that?
It is simply the case that large bureaucratic organizations are too slow and too incompetent to deal with rapidly changing technology. And the tech community sees this and has no respect for governments. How can you respect impotent Industrial Age structures today anyway?
My view is that by mid-century Western governments will be going bankrupt in droves since tech will optimize out their ability to collect taxes or inflate currency. Plus they will just be extremely behind the curve and become irrelevant to everyone’s tech-dominated lives.
It is tech companies that will lead the future. It doesn’t matter if this does not agree with pro-democratic sensibilities. Sensibilities will change and adapt to reality.
Sometimes I hit a USA based news website which simply denies access, because I'm in the UK, on GDPR grounds. Which seems an overreaction.
I doubt it actually does a @#$@$ darn thing.
Location of the host is irrelevant, it depends on the target audience. Serve pages to the EU? You get to follow it.
> simple cargo-culting "everyone is doing it so we must do it also".
If your site is cargo culting everything it probably also has a ton of third party trackers for the same reason.
What can the EU do about it if the company has no physical or legal presence in the EU? Have there been any serious attempts at such enforcement?
No one says that all sites should honor China's laws for visitors from China. No one claims that all sites should honor Saudi Arabia's laws for visitors from Saudi Arabia.
But magically the GDPR must be followed by the entire world if a visitor shows up from France.
Also a lot of people speaking out against China had to find out the hard way what some western companies will do when you speak out against a cash cow that will happily kick them out if its rules are enforced.
It would be like Wendys slagging off the Thai king on a billboard in Dakota, then an employee of Wendys went on holiday to Bangkok and was arrested.
In this case you are arguing that Russian law should follow a citizen, where as the US said it shouldn't. So the "precedent" that was set (if in fact there was one set) in a case from 20 years ago in which the case against the accused was dropped, was actually that your laws don't follow you around.
The Meng Wanzhou case had the EU being able to extradite a US citizen from the UK for breaking EU law.
This is completely false. Your laws do not follow you around on the internet.
No, merely serving pages to the world (that happens to include the EU) does not mean you have to follow the GDPR. That is only the case if you cater to EU residents specifically (e.g. by taking payments in Euros).
Those banners are merely the effect of shitty companies trying to cover their asses and being non-compliant to a law that's actually sane.
GP isn't talking about deceptive patterns. Point is that no one really understand what these popups are for and everyone just blindly clicks ok.
I don't think i've ever declined a cookie popup. have you?
It has become such a chore, when ever I visit a new site on my phone and see a cookie screen, I navigate back and/or open an incognito window.
What the EU should do is disallow those cookie full page modal consent windows.
Many use overflow: hidden when showing it so you can't just adblock it without having to modify the markup. It has all gone out of hand.
You can complain to your country's data protection expert, and they will tell you this or that company blah blah but not act. Nothing ever happened. I filed 3 complaints in 2 countries. 2/3 took over a year to receive a response. 1 took about 6 months and nothing changed.
It's just a really disingenuous and dismissive comparison. Nobody is complaining about flashlights.
GDPR may have been necessary, but the complete garbage heap of an experience the popups have turned the web into is worth lamenting.
I don't make that comparison lightly. I'm not dismissing the issue: it is a serious problem that is widespread over the internet. It's not disingenuous: it describes a series of institutionalized behaviors that are directly parasitic on the user.
Now the reaction is to be angry at GDPR because of the pop-ups, which aren't even GDPR compliant in the majority of cases as directly evidenced by the OP link. This reaction is comically absurd, hence the comparison. This garbage heap is the result of shitty implementation by the websites, and ironically a lack of enforcement of the law.
But, nobody here is complaining about GDPR. They are complaining about the terrible UX, and wasted time, and attention, which the non-compliant implementations have caused. That is not an absurd reaction, it's perfectly reasonable. That's why your comment comes off as dismissive.
If anything, it's more akin to complaining about the shitty, half-rate pest control person your landlord calls to get rid of the rats. They do a bad job, poison your house, waste your time, and the rats never go away.
Yes they are, everyone here is blaming the GDPR.
You're right that the issue isn't the GDPR, it's the tracking industry trying to figure a way around it. The EU learned a lot from the original cookie law, but the industry have not, they still try to continue as normally, until someone is hit with a crippling fine.
>If anything, it's more akin to complaining about the shitty, half-rate pest control person your landlord calls to get rid of the rats. They do a bad job, poison your house, waste your time, and the rats never go away.
I don't want to stretch the analogy further than it can work, but a more apt comparison in my view would be this: a person discovers that every inch of their floorboard and walls are filled with highly intelligent rats. The pest control comes, creates some measures that have a small effect but does not enforce everything at the outset. It's likely they will come back for another round since they are still learning the ropes for such an enormous job. The rats have been there for decades and it is the only pest control service even trying to fix the problem in the entire city. The rats scurry around in a panic, but keep infesting the apartment. In this scenario, would the person try to get the pest control to enforce the measures and get better at it over time, or would they simply carry on as usual and feel comfortable with the infestation?
All this talk about how the problem is lack enforcement is an absolute riot. Hey, I've got an idea! Let's write another law to address the lack of enforcement. Uh, even better, a third one to address the dark patterns!
(I'm very sorry for the low value comment but I've apparently got a condition where I am physically unable to resist the urge when the topic is rage inducing enough.)