I was let go for refusing to deploy a dark pattern
peachesnstink.com
peachesnstink.com
Before this feature was released you had to call Xbox support to cancel.
Once word spread that you could do it on the web, huge numbers of customers, that had been stuck paying for an Xbox Live Gold subscription they weren't using, began cancelling.
So our PM got a call from a VP. We were instructed to remove it from the site immediately. We fantasized about telling the VP to stick it and quitting en masse, but we knew it wouldn't change anything. We'd just be replaced by someone that would.
So we complied, but we all lost a little bit of our faith in Xbox that day.
Ye goode olde self-fulfilling prophecy.
This is the norm.
I think that was the point of the comment.
Vote in the next election for people/party that are more consumer friendly than industry friendly.
For all its flaws, CA had some of the most consumer and employee friendly (such as no non compete) laws.
While I agree it should be a default setting, it's a useful little trick.
Vote.
Personally I think that any time you grant permission to anyone to bill you automatically on a recurring basis, you need to be able to revoke that permission. This ought to be a fundamental mechanism of personal banking that you ought to be able to manage on your bank account online. It's astonishing to me that your bank can't even tell you all the ongoing recurring payments that are permitted on your account (or if they do, it's an ad hoc implementation that tries to detect recurring payment amounts, vendor names, etc.)
But hey, we get startups whose usp is cancelling services.
Seems pretty normal to everyone I complain, that I still pay for my O2 bill after sending the cancellation letter(Physical piece of paper) for the umpteenth time.
When you say “you can”, are you just saying “you can ask”, or that you’ve had success doing this?
If the latter, mind sharing which card provider that was with?
If there's hope for beating this dark pattern, it lies with banks/CC companies
My understanding is that this will be reflected in credit reporting as delinquency- seems like a lose-lose in that sense. Can someone who has done this weigh in?
Eventually most states passed similar laws and so we opened it up to all US accounts. I'm not sure what the experience is like today.
I.e., user can cancel subscription on website, system automatically writes cancellation letter, letter is sent to corresponding company address. If cancellation fails, then an official complaint is served to the company, and from there it follows the usual court process.
You mean shady subscription business models right? Because Microsoft is certainly not alone.
Just the other day I had to CALL (as the only option) Network Solutions to cancel a security product.
so what that Microsoft isn't alone, their (poster) experience allows them to know unequivocally that Microsoft and the employees that work there make decisions that don't align with their personal ethics -- so they take out their anger on Microsoft.
the statement '...but we all lost a little bit of faith in shady subscription business models ' makes no sense -- the shady ones don't self identify, and it's not the methodology that is generally despised, it's the entities that that employ such methodologies against the public.
I signed up for America's Test Kitchen one time, because they had a nice program for learning the basics. Probably used it for a couple months, and then I was done with that content and wanted to cancel. Of course, even though you can sign up online, you have to cancel on the phone. On hold for 20-30 minutes during work hours, then talk to the rep, then listen to their retention offer, then it's successfully cancelled.
I actually loved the content, and would probably have resubscribed for a month here and there. (Cook's Illustrated is part of the same group and their content is also great.) But I will never do it again because of this experience.
How many people decided to get the new Playstation next time because of a frustrating experience cancelling their xbox subscription? You won't see those numbers in a spreadsheet.
I haven't been in this situation, but I always imagined that there is a simple way out: send them a certified letter instructing them to cancel your subscription. If they continue charging after that, it's chargeback time.
Any opinions on whether or not this would work?
And digital "purchases" aren't really purchases.
I'm pretty sure a business that accepts credit cards cannot decide to 'opt-out' of chargebacks!
Says all purchases are final. You may only request a refund and they reserve the right to deny it. Forcing it via chargebacks basically locks your account.
https://www.playstation.com/en-us/legal/psn-terms-of-service...
Reserves the right to suspend and terminate accounts associated with chargebacks.
I will never use Xfinity/Comcast again in my life if I have a choice and will try to make sure everyone knows how shitty they are. Unfortunately they have monopolies in many areas and can be as shitty as they want, but if you have a choice I recommend never using them.
I can't believe that in 2021 these tactics are still legal. It's also stupidly shortsighted because in the long term I'm pretty sure they lose money by making everyone hate them. If it was easy to cancel, I would happily sign up again in the future without giving it much thought and would think positively of the company.
Edit: I also want to add that I was paying extra to not have a contract so I could easily cancel.
"Why are you cancelling?"
"I'm moving overseas."
"Where to?"
"I'd prefer not to say."
"North Korea"
Ask me a stupid question, get a stupid answer.
For a time, I resorted to having an attorney cancel my Comcast service to ensure it actually happened.
But once, months after the attorney forwarded my Comcast cancellation confirmation, I received a notice from a collections agency for the exact Comcast account I had cancelled. The attorney took care of that too.
My new (and best) method for dealing with Comcast is to use a fake name and social. I've been using the cats' names for the past few years, and it works great!
I recently wanted to quit Comcast service at one of my properties, so I went online to chat. No agents available, so I just removed my credit card from the account and stopped paying. They'll figure it out eventually. And good luck of they're going to try to collect from Westley the Cat. He's unemployed.
They let you use a fake social security #?
I will never willingly use Comcast (and they don't care, because monopoly).
Like shibboleet, but for cancellations.
If you are optimizing for money made in the next month - or even next two years - then by definition making it hard to cancel will bring in more money. But it does hurt the brand long term (which is harder to measure)
I'm mad that it works.
1. You have all the necessary data and
2. You are interpreting it correctly and completely
This is almost never true, so instead “data driven” is mostly “data covering-your-ass.” Maybe the future will yield leaders more capable of wielding data less like a cudgel, but I’m not optimistic.
I'm a fan of Serious Eats for cooking content. Again, ATK was great except for the subscription thing. Looking at their Support page, it looks like nothing has changed with their cancellation policy[1] (the fact that you can cancel your physical magazine subscription online, but not the website subscription is hilarious). I would LOVE to know if they have support for online cancellation for California customers, that they just disable for non-California customers. I've heard of companies doing things like that.
Not sure if Playstation did the same, but Xbox doesn't make this difficult this anymore anyways. In fact, recently I started a Game Pass Xbox subscription on my xbox account and used it for a couple days. Then I realized I should do it on my main microsoft account instead (so I don't have multiple accounts anymore), so I cancelled. They gave me a full refund automatically without me needing to ask or do anything. So companies do change, although I imagine it's just easier to implement it this way anyways. Phone-based customer service is really expensive.
[1] https://www.americastestkitchen.com/support#change-membershi...
Now I use a privacy card for all subscriptions to avoid the hassle
I was able to switch to a new company with transparent simple billing and I will never go back to Comcast even if they offer me a better deal on a better product.
Their customer service policies were horrible and anti consumer. They also routinely throttle certain types of traffic. BitTorrent and Xbox were both verifiably throttled for me during different periods of being a customer of theirs. They increase billing every few months until you complain.
I had to constantly fight to prove that my modem was owned by me. And they just kept adding it back as their equipment and charging me a monthly fee for it. They wanted me to prove I bought it. Wanted to know where I bought it. Etc. I had to call and prove that I indeed bought and paid for it myself numerous times.
Point being. I will never go back. I suspect many others will not go back either once given another option. And options are coming through community fiber projects, 5G and Starlink to some of the areas where Comcast has been the only option.
And the English version of the government website about it: https://business.gov.nl/regulation/automatic-renewal-subscri...
Which says: "Consumers must be able to cancel their agreement in exactly the same way as they signed up for them."
As well as disallowing an automatic fixed term renewal. After an initial contract the customer must be allowed to cancel at any point not just yearly. This one had a big impact on the telecom industry a couple of years ago.
The crazy thing is they replied, but refused to take me off the list unless I sent them an actual physical letter in the post. A few emails in they claimed it was due to a "technical" issue. That BS annoyed me so much, I am now into the 3rd decade of my own personal British Airways boycott
Edit: I realise that's insane but it makes me giggle everytime I deliberately don't book BA, and I wonder to myself how much money I would be willing to loose by going for the next most expensive ticket, just to keep my boycott going
Even if it’s PEANUTS to them. I feel better, because at least I’m not participating in perpetuating a shitty system.
I feel especially good about it when those companies are ubiquitous and hard to avoid, because I feel rather righteous against an all encompassing behemoth that likely would have got my money otherwise.
I'm surprised BA even had email in 1991 or earlier. Since britishairways.com doesn't even make an appearance in the Wayback Machine until late 1998, perhaps we can forgive them their anachronistic practices of the day.
If someone says they are "into the 3rd decade of" something (for example, programming experience), I would generally assume that means 30 years or more.
But what you're saying is that it could mean as little as 11 years, e.g., from 2010 to 2021 (yes, 2010 is still part of the '00 decade¹ and 2021 marks the beginning of the '20s, strange as that was to me).
¹ https://www.farmersalmanac.com/new-decade-2020-or-2021-10090...
It's much more fun for me to think of that as "in to the 3rd decade", rather than just over 20 years ago.
I end up engaging in the same type of behaviour with companies that also do not make unsubscribing obvious, or, worst of all, have slightly annoying GDPR-mandated tracking-denying UIs. Trying to get me to go through two sub-menus and not having a "Deny all" toggle ? Good, good, good. See how petty I can get, $COMPANY !
I just use Gmail's "Report as Spam" feature in these cases. If enough people do it when they can't unsubscribe easily, it's gonna start eating into their deliverability.
No it's not. The VP is maximizing their bonus and career growth within the company. That is likely tied to relatively short term metrics and especially to not having drops in metrics.
> How many people decided to get the new Playstation next time because of a frustrating experience cancelling their xbox subscription
If you make it hard to unsubscribe when people are short on time/money/interest, they will probably be less likely to resubscribe when they have the time/money/interest.
Long-term customers on something like Xbox Live have a larger incentive to resubscribe to recover access to their game library.
On the other hand, random web site X is probably just looking to churn through subscribers.
It's something of a tragedy of the commons; the incredible difficulty of unsubscribing from (everything that's a monthly bill) makes people wary of subscribing to anything.
Companies rely too much on analytics.
On the other hand, it's quite well-known how easy it is to stop/start a Netflix subscription.
IE, you're part of the problem. You're just rationalizing to make yourself feel better.
General Premises: 1. Agent A enforces Action X onto Agent B 2. Action X hurts C with some probability. Not Action X hurts B with high probability. 3. For all persons D under A, the probability of Not Action X is vanishingly small.
Reasonable Argument: 1. If B performs Action X bad things happen to C. This makes them partly responsible. However, under premise 3, B's counterfactual contribution is vanishingly small, whereas A's contribution is close to 100%.
Unreasonable argument: 1. As the final link in this particular chain of events, B is wholly responsible for the harm done to C, because had they suffered harm with high probability, they would have ensured the reduction of the probability of non-harm to C by a vanishingly small amount.
That's not true. Governments exist to deal with this kind of situation. If companies make it difficult for citizens to cancel subscription, it is time to regulate subscriptions.
Why is the responsibility of some developers to lose their jobs to stop a company doing something that is completely legal. If they have done that, they will have my gratitude and admiration. But, the developers are not "part of the problem". Microsoft is the problem, and the lack of regulation the other part.
The one I'm still hooked on, that this reminds me I've now given something like $3,000 dollars to over 3 years because I've been too lazy to make a phone call and wait on hold, is the YMCA.
Even religious nonprofits are engaging in dark patterns.
Unionize.
That's a very bad argument. If you guide yourself by that logic then you can't really blame anyone for doing anything, because everything is justified.
It’s possible for the argument to be true in this context and false in another context.
A few publications that I enjoy is on my "Never subscribe" list because of the difficulty of unsubscribing. On the other hand, unsubscribing from HBO Max (at least via Apple TV) was so easy that I don't hesitate to unsubscribe and resubscribe and have done so a couple of times.
Unfortunately that's the allure of dark and customer-hostile patterns - they extract a lot of money from people, at least in the short term.
If you're Microsoft/Xbox, though, you might want to think a bit about long term.
It went live, and almost immediately the number of ad clicks dropped significantly. It turned out that the older site was so hard to use that customers would inadvertently click on ads, bringing up the revenue. The new site was so much easier to use that customers clicked on less ads.
The changes were almost immediately rolled back.
I think eventually the new site was put back in, but only after they ensured that ad clicks wouldn't go down precipitiously, but I had after by then.
Maybe the immediate threat of developers quiting wouldn't have, but I think something might have eventually. Probably change from the top. My recent experience with the xbox gamepass app on Windows let me cancel my subscription fairly easily on both the console and the pc (two different accounts) without ever having to call someone. I like to think the culture at xbox has changed, maybe not microsoft, but maybe it will trickel up eventually.
I sympathize with you. If you have quit, you would have my admiration and gratitude. But, what you did is reasonable. Microsoft was not doing anything illegal.
This is the reason why regulations exists. If companies are abusing consumers by making it difficult to cancel a service, developers cannot be the responsible to bring justice. Governments have that responsibility.
> I ran the diff. Each file had the same change - they had added code that makes an ajax saveEmail() call onBlur. In other words, email addresses were being saved to the database when a user inputs an email and the input loses focus.
e.g. The article situation is solved by the GDPR. This would completely break the GDPR as it requires informed consent before saving personal information like an e-mail.
If your government is not solved this issues, it is time to get a better one. I wish people, including in this threat, stop blaming employees for the fault of the bad action corporations. Corporation morality is a good example when the total is less than the sum of its parts.
I would have resubscribed shortly thereafter if the cancellation flow had been good, or even just average. But because of how bad it was, I have never resubscribed, and most likely never will. Their cancellation UX cost them 5+ years of subscription revenue from me. Not only that but I go around telling people about how bad it was
That is human dignity from the sales point of view: that of a particle.
Somewhere, in the back of my mind I know that all data I enter online is inevitably being hovered up and used for god knows what, but when you're suddenly made aware of it, it's really unnerving.
Something about this makes me want to have a 'falling down' moment. Let me get this straight, not only is our tax system so complex and error prone i have to pay money to a third party to figure out how much I should be paying to our government, but the software company I pay then turns around and sells my data? The government does nothing to remedy this? It really goes to show who our government serves, and it sure as hell isn't 'the people'.
in a "To Serve Man" sort of way ;) https://en.wikipedia.org/wiki/To_Serve_Man_(The_Twilight_Zon...
installing ublock Origin should help block most of those nasty analytics hoovers
> Internal presentations lay out company tactics for fighting “encroachment,” Intuit’s catchall term for any government initiative to make filing taxes easier — such as creating a free government filing system or pre-filling people’s returns with payroll or other data the IRS already has. “For a decade proposals have sought to create IRS tax software or a ReturnFree Tax System; All were stopped,” reads a confidential 2007 PowerPoint presentation from an Intuit board of directors meeting. The company’s 2014-15 plan included manufacturing “3rd-party grass roots” support. “Buy ads for op-eds/editorials/stories in African American and Latino media,” one internal PowerPoint slide states.
> The centerpiece of Intuit’s anti-encroachment strategy has been the Free File program, hatched 17 years ago in a moment of crisis for the company. Under the terms of an agreement with the federal government, Intuit and other commercial tax prep companies promised to provide free online filing to tens of millions of lower-income taxpayers. In exchange, the IRS pledged not to create a government-run system.
> Since Free File’s launch, Intuit has done everything it could to limit the program’s reach while making sure the government stuck to its end of the deal. As ProPublica has reported, Intuit added code to the Free File landing page of TurboTax that hid it from search engines like Google, making it harder for would-be users to find.
> What is clear is that Intuit’s business relies on keeping the use of Free File low. The company has repeatedly declined to say how many of its paying customers are eligible for the program, which is currently open to anyone who makes under $66,000. But based on publicly available data and statements by Intuit executives, ProPublica estimates that roughly 15 million paying TurboTax customers could have filed for free if they found Free File. That represents more than $1.5 billion in estimated revenue, or more than half the total that TurboTax generates. Those affected include retirees, students, people on disability and minimum-wage workers.
Did something happen? Did they change ownership? Any good alternatives to taxact?
My tax preparer is something like $250 a year and reduced my liability in a very tumultuous year from about $20K to about $9K by understanding what I actually had going on and helping to work through it.
The first year I moved to the US, I had a whole bunch of things going on. Buying a house, working from home, buying a hybrid car etc., getting married. I had no real idea about the tax system, so saved all our receipts etc., and went to H&R Block.
"So what do you want to claim?"
"What can I claim?"
"What do you mean?"
"Here's a bunch of receipts and I can tell you all the details."
[vaguely confused look] "Let's go through the app."
And I watched as basically she transcribed our most basic information into their in house version of something akin to TurboTax.
I could have done that myself.
I complained. And did, eventually, get someone there who knew how to not be a glorified transcriptionist.
And then the next year found someone who had knowledge of their own.
It hit a weird case and she didn't know what to do. Eventually I looked up the actual tax code and told her what to do. As far as I remember it was about splitting the cost basis over multiple years. I owned some weird stock where that came up.
For more than twenty years, we had to click "upload" or alike to confirm the upload of a file to a server. I wonder how many millions or billions files Google steals (yes, that's theft) from gullible users who use their web interface.
If I take an analogy: think of it as if you were typing a message in an IM chat window. Anything you'd type would be sent immediately to the service owner, whether or not you click "send" at the end. I understand this feel normal to you but I personally find this abusive and a total treachery from Google.
To support my point: I used to have access to a corporate proxy that performs TLS inspection for a little less than 50k employees. I looked into this specific scenario to get an idea of how many employees were being abused by this. It is quite easy to find: just filter for queries sent to GMail's API when you cancel a file upload or you remove an attachment from a draft. We have several hundreds of those events each year in our logs.
These people quite candidly think they "cancelled" the upload, but it didn't. Google got the file, analysed it, extracted knowledge out of it and potentially adjusted your profile and your employer's. This falls under the definition of a dark pattern.
There is something worse than using GMail for your emails: it's using GMail's web interface.
How do you know this? It's against their stated privacy policy.
This is also a kind of strange position to be arguing when you just described snooping on people's secure communications. Why is that OK and what Gmail does isn't?
We do not prevent our users from using GMail for personal use, but we analyze the traffic for malicious or deviant patterns to detect potential data leaks. Analyzing the amount of users who inadvertently send a file in GMail then rapidly "change their mind" is still, in our shared opinion, a relevant analysis to perform. We report the number of quarterly cases in an awareness newsletter and remind users to be attentive when selecting a file to be uploaded in webmails.
Good thing: the occurrences have decreased since we raise this concern. We cannot prove it is linked to our newsletter but our "ego" enjoys believing so.
I would have agreed with you if I actually had both a username and a filename shown on my screen, but this does not happen. Our report shows the total count of cancelled uploads per country.
We have someone at HR who can actually see the detailed events (including file names) for a given user. It seems to that this would match what you see as "snooping". But this an investigation led by Human resources upon a suspicion of employee misbehavior. It has nothing to do with our infosec activities.
I hope I changed your mind, at least a little ;)
Think twice before pasting unknown clipboard contents, typing while angry, etc. Best, explicitly copy your finalized reply from another app and paste it into the chat.
(I confirmed that first hand when a support person replied to specifics of my message while I was editing the phrasing.)
Unsavory.
Related Related PSA: Tools like Logrocket record full-fidelity videos of your entire session on a website. They're great for debugging. It also means you should assume that every website you use has a video of everything you did that people can scrub and search through (it's more than a video actually, it's capturing and re-rendering the DOM, network traffic etc... like I said, amazing for debugging)
Also with a lot of these tools you can configure them to redact user input so you don’t capture too much.
||*.logrocket.network^
||*.logrocket.io^
||*.lr-ingest.io^
||*.logicanalytics.io^
in uBlock/ABP filtering rules would be a good start. Not sure what logicanalytics is exactly, but it's used on logrocket's main page.
Using NoScript like the other commenter said is safer though (this won't catch on-premises deployments of logrocket and it will stop blocking it when they change the domain).I'd like to believe the karma for not letting any of our customers be creepy (and/or violate their customers' privacy), pays for the lost business many times over.
The least you could do is post a blog post about the dark patterns you refuse to unleash on your customer's customers and why.
Not entirely bad, because recording what I type without my hitting send is shady asf on the company's part, but it makes me feel bad for the human on the other end of the chat.
Anyways, thanks for sharing, I'll have to keep this in mind in the future and maybe do less angry-typing-and-then-backspacing.
It’s immoral because you’re lying by hiding that this is happening and not making it go both ways, so why not show users and just make it part of the UI?
As long as you're told what the behaviour is, I don't see a problem. I think for short lived chats such as those support chats it would speed up things.
Am aware of several folks going to prison from confessions when they thought they weren’t being heard.
Eventually, he threatened to hire outside developers to do the work. Previous to my employment, he'd used foreign contractors who were quick to cash checks and slow to do the work, and rarely satisfied the order. I called him on it. "Go ahead, go back to your past contractors... but by the way, wasn't your dissatisfaction with them the whole reason you hired me?"
I think he managed to find an external marketing company to spam for him, but he never got popup ads under my watch. The funniest was the time he discovered popunder ads -- he thought I'd be cool with those, for some reason. Sorry, guy.
I was hired to build a rudimentary tool for detecting nudity in images, over large datasets, as fast as possible/reasonable, with a pretty generous margin of error. The agreed pay was extremely good for the performance the client wanted.
Not long after I started, after getting an advance payment, one of the clients called me and very tactfully broke the news to me that what they actually wanted was a tool that would detect women in bikinis, or showing lots of skin, and that they would be crawling social media and photo sharing sites, and their 'service' was a private premium forum that included a section where members could trade pictures of girls they knew, and they wanted to add a gallery of girls who post bikini pictures, with their real names and locations and links to their socials.
I re-payed the advance that day, and it very much shaped my approach to consulting.
I took a whack at articulating _why_ it's wrong while not quite fitting a clear definition of malfeasance here: https://news.ycombinator.com/item?id=27632365
I don't have my beliefs on the topic clearly articulated, but I'll give it a crack. There's the argument that public information is public, and that there's no issue in aggregating it or otherwise making it more accessible, as long as the access is through legitimate means. I'm sympathetic to this and understand why people believe it, but I think it contradicts other consensus moral intuitions about privacy rights. A salient example that other HNers may be familiar with is the doxxing of Scott Alexander; any intellectually honest person familiar with the internet can tell the difference between "you can find out who he is if you do some digging" and "real name published by the NYT", despite the pathetic attempts at dismissing the possibility that doxxing him was bad (amusingly, including by people who I am 100% sure would find the bikini example to be a horrible violation). Hell, I was a reader of Scott's for years before I first came across his real name. The entire social Internet is built on security through obscurity, because opsec is hard and many people aren't constantly vigilant.
There's even precedent for these intuitions outside of the social media context. It's uncontroversially okay for someone's face to show up in your photo taken in public; once you've taken it, nobody cares if you study the guy in the background. However, aggregate and operationalize this, and it changes not just in degree, but in character: It's practically a trope in thrillers for universal CC cameras + alphabet-agency elbow grease to stitch together comprehensive tracking of an individual, and the public is rightfully a little creeped out by the thought.
The main difference here is that technology, as always, is democratizing the ability to do this, pushing the threat model from the unrealistic "NSA spends huge resources to track you" to the prosaic "facial recognition can just track and store everyone's movements at low cost" (or "some under-the-radar shop is aggregating your bikini shots") and a million other mundane violations of our moral intuitions. To my mind, we're in the uncomfortable period before a new norm equilibrium is reached that matches the technological context. This has already happened locally: I'm sure this group knows people who have good opsec since the early 2010s, and "treat everything you post as if it's public" is at this point an age-worn piece of wisdom.
I mean, I guess that's the reason why it was downvoted, don't you think?
That said, I didn't actually downvote it, I just gave some argument for why I think the downvote was justified.
IMO, this distinction is usually illusory, and only taken seriously in the kinds of conversational spaces that aren't worth being part of. "Most reasonable people think it's immoral" can be applied to any number of horrific things over the course of human history. If you want to hide[1] a potentially sincere groupthink simply because it doesn't comport with groupthink, there a million and one fora full of dumb, narrow-minded people you can do that on. HN isn't all the way there yet, and I think it's worth pushing back against the tide.
This doesn't suggest that it's impossible to post something so alien that there's likely little of value to discuss, but this is demonstrably untrue of the parent comment, as evidenced by my response to it and the half dozen people who found it interesting enough to upvote it.
[1] Again, we're talking about flagging, not just downvoting, though it applies weakly to the latter too.
> IMO, this distinction is usually illusory, and only taken seriously in the kinds of conversational spaces that aren't worth being part of. "Most reasonable people think it's immoral" can be applied to any number of horrific things over the course of human history.
Your solution to the fallibility of human judgment, especially when it comes to ethics, is to assume that there can be no moral judgement anymore, because one might be wrong. I don't think this is productive. I'm quite sure there are a number of things you would consider deeply immoral that you would be shocked to read here. People are allowed to have a sense of ethics and to use that to guide downvotes. If you disagree, just upvote instead, or discuss why you disagree. But you yourself admitted that most people would find the behaviour in question immoral.
> HN isn't all the way there yet, and I think it's worth pushing back against the tide.
Your mistake is to assume that HN is somehow above basic human nature. But HN is also full of explicit and implicit biases and those can often hide behind a veneer of supposed rationality.
> This doesn't suggest that it's impossible to post something so alien that there's likely little of value to discuss
I found your contribution to the debate to be actually sort of interesting, but more as an answer to a question such as "how can we explain why we find that sort of behaviour to be immoral" and not to the OP's implicit "I fail to see what's immoral here".
Also, it was just in a sense a low-effort comment. I'm sure that poster can perfectly well understand why someone would find the behaviour in question immoral given that that person presumably has spent time around other people, including women who might object to this kind of objectification. So if they still disagree that it is immoral, they could at least try to argue why.
(Also, the sole reason why I'm engaging you, as opposed to OP, here is because I find these sorts of meta-ethics / meta-rationality discussions to be quite interesting and important in a world where "reasonable people" seem to be less and less able to agree on how to ascertain both what is true and what is moral. This is, I think, a discussion worth having, I just happen to disagree with your conclusions.)
Right, I mentioned that the case against downvoting is weaker, since at this point it's basically describing my opinion about what makes a forum a worse place to hang out. No real disagreement here.
> Your solution to the fallibility of human judgment, especially when it comes to ethics, is to assume that there can be no moral judgement anymore, because one might be wrong.
I don't think this is what I expressed; the intent of my second paragraph is to explicitly clarify that I'm not defining away the ability to signal (via downvote/flag) that certain content isn't welcome in a forum. My point was that moral judgment without care and thoughtfulness is extremely unproductive for a forum of this sort. (I actually hold the stronger opinion that it's evil, but this is so much stronger a claim that it would derail this conversation significantly to go into it).
> Your mistake is to assume that HN is somehow above basic human nature.
I don't follow how this applies to what I've said. Differen communities are suited to different types of discussion, and HN is better-suited to thoughtful consideration of non-consensus views than others. It's not perfect at this goal; I'm certainly pretty hard on HN in my meta-comments, but that's largely because I was lucky enough to have found a couple other fora that are even more highly-selected for intelligence, intellectual honesty, compassion, and open-mindedness. The default state of an Internet (or non-Internet) forum is to allow people to perform "thinking" while basking in the warm fuzzies of guaranteed social approval and never having to challenge their beliefs. If the behavior you're defending isn't pushed back against where possible, every forum in the world will become the same formless sludge (and inability to empathize with those outside of your bubble). As I mentioned, "suppress this without discussion because I think it's immoral" has a horrific track record; were this 50 years ago, I'd be saying "seriously, why _is_ being gay so worthy of persecution" and you'd be saying "it's immoral to even think that, no need to engage, just downvote".
I know I was pretty hard on the concept of mutual-approval societies, but I actually think there is value to this approach. The term "safe space" is often used derogatorily, but it has significant value. If there's a forum dedicated to discussing the minutiae of Christian theology, I think it's completely reasonable to keep it a "safe space" from those who want to argue the basics of, say, God's existence. There are many types of productive discussion that require holding constant certain assumptions (rendering questioning of those assumptions unproductive).
HN is fairly high-percentile when it comes to acceptance of non-consensus ideas, expressed in good faith. That is (historically) the culture of this forum, and its value. As I mention in my previous comment, there are non-consensus ideas which one can judge do not come anywhere near interesting topics, but as evidenced by my response to him/her, this comment was not one of them. Note also that this doesn't even preclude downvoting, though it's not ideal; my comment specifically mentions "downvoting without replying".
Particularly without a reply, it seems much more likely that the downvotes come from the knee-jerk reflex to pattern-match that afflicts the especially-stupid ("this guy must be a misogynist! I must come to the rescue! I'm such a good person"). People like this are _everywhere_, and by definition are extremely unlikely to learn or be learned from. I get that there are hordes of these people even on HN, but their comments and their anti-thought impulses are precisely what I would like to push back against to preserve the distinct value this place still retains.
> more as an answer to a question such as "how can we explain why we find that sort of behaviour to be immoral" and not to the OP's implicit "I fail to see what's immoral here".
What's the difference? If there is a difference, why does the comment fall in the latter bucket instead of the former, given that his comment is _literally_ a question?
> Also, it was just in a sense a low-effort comment
If there is a difference in intent, why should that matter? I'd happily lose a million reflexive downvoters from HN to retain a single poster of "low-effort" questions that probe a Sacred Tenet of Groupthink, even if I disagree with the assumed implicit conclusion of the prober. Downvoting-without-response is both lower-effort _and_ more harmful than asking these questions: If the comment is so obviously wrong, surely a low-effort response should suffice, right? If you've spent much time on HN, you'd know that easily-rebutted comments are rebutted thoroughly and repeatedly.
I think perhaps where our views here diverge is that I couldn't care less about "punishing" the commenter, and am certainly not willing to damage the quality of discussion here to do so. It's not even a good idea from the pragmatic perspective of stigmatizing these views: when I see a downvoted and unanswered question, I don't think "he's definitely wrong", I think "1) I can't think of a rebuttal and nobody else seems to have either, so they just suppress it and 2) boy, HNers have gotten even fucking stupider".
Sorry for the length, and I likewise appreciate the conversation!
This is not sarcasm, or me trying to be mean.
If you have to say "I'm not trying to be mean" before anyone accuses you of it, then you're clearly aware that what you're saying sounds mean, but you don't care to try and avoid it, but you want to pretend you are still nice. Which, ironically, is something that would cause some intensive pencil scritching during a psych eval.
So roll in on first day after signing up to fuck knows what and it was a ticket touting company. I listened to their pitch which lasted until lunch, went and got myself a sandwich, sat on a bench and thought “fuck it, this is wrong” and just went home.
When I told the agent he went crazy at me because I’d burned his commission. Gave them the finger too. In some places it’s bastards all the way down.
Next time someone pulled that on me, I cut the interview off and only worked for predefined work for a number of years. If something is off grid on your contract, no is the answer.
ticket touting = ticket scalping.
That said, scalpers in particular seem to cause a whole lot more harm than good in general. As the above podcast addresses, it's a very difficult problem to solve systemically if you are intentionally undervaluing your goods.
You could argue the “true price” is what the scalpers charge (who will stop drinking water when the prices skyrocket?).
But in reality they squeeze the supply to create artificial scarcity. Any economist knows this is market manipulation.
But how do you square that with scalpers causing the tickets to sell out so quickly? I mean, they're the ones creating their own market. They're not really providing a service if they're the ones creating the annoying need for the service in the first place.
Obviously, yes, if I am mad about scalpers' prices, I have the option to not pay them. I would like to go the event, though.
It artificially inflates ticket prices by inserting a completely unnecessary middle-man in the purchase process. This is done by people with no intent to actually use the tickets they bought, so it's very much not the same as "oh I can't go would you like to buy my ticket?"
This is similar to a dark pattern I've seen at shopping malls where they offer a valet service, but also rope off all the close parking spaces for valet. This creates an artificial scarcity of close parking spaces which helps to drive the valet business. If they never did this there would be little desire for the valet service.
> It artificially inflates ticket prices by inserting a completely unnecessary middle-man in the purchase process. This is done by people with no intent to actually use the tickets they bought, so it's very much not the same as "oh I can't go would you like to buy my ticket?"
I think this is called "retail."
That's sonewhat misleading about how chain-of-commerce strict liability works. The injured party can sue any/all parties in the chain of commerce directly, its not that the retailer is exclusively directly responsible, and then they have to work up the chain.
There is nothing inherently wrong with middlemen asserting themselves into a transaction. Our whole economy depends on it.
Some middle men serve a function to buyer and seller. Specifically they are motivated to put those two in touch with each other and in some cases act as a sort of mediator for a transaction. The ones who insert themselves between parties that are already in touch and ready to deal offer no value.
Example. When the Wright brothers wanted to sell an airplane to the US army, after much effort they got the army to solicit bids on a flying machine that basically matched the capabilities they had (even that was a big deal because nobody though it could be done and the army didn't want to fund "research"). Strangely they got 3 bids. The Wrights IIRC was $25,000. One of the other two dropped out because the reality was they had no product. The third intended to bid lower than the Wrights - enough that he could buy a plane from them and sell it at a markup to the army. The Wrights told him they would not sell an airplane to him (fuck off dude) and he dropped out. That other guy was what I'd call "trying to insert himself as a middleman" where one was not needed in any way, strictly to enrich himself while adding no value.
Back to scalpers - they do offer one particular thing that might be of value. Some can get their hands on premium seats, and by selling those at very high prices they allow rich people to pay extra for special privilege. What you think about that varies from person to person ;-) It's still something the venue could have done a better job of.
On the contrary, it naturally inflates the price.
Tickets that can be scalped were priced at below what you might naively consider "market" prices. The purchasers gain some value from this, and usually the sellers do too — often in the form of hype, perennially useful for promotional purposes. Someone who scored a hard-to-get ticket for a good price is likely quite excited about it.
But the difference means there is a strong incentive to turn the difference into cash, and even with inefficient processes in the middle, that incentive is substantial.
You can of course spend all day saying it's "wrong" and it's a position you are welcome to take; there are interesting questions we could ask about who should rightly "own" abstractions like the hype, and why, but it is not protected by normal property law, and if property rights don't exist or aren't enforced then you know that the necessary conditions for free-market efficiency do not exist.
But again, it's as natural as any other economic effect.
Often I hear people supporting scalping as an example of a free market working, and I get that argument.
The problem is the market that actually exists is anything but free, and largely based on deceptive practices and even outright collusion, which is I think what is what a lot of people really object to.
Supply is already fixed on things like tickets anyway, due to venue sizes, so this is just further restriction. It's not natural.
It is the supply-demand balanced value. If it wasn't, they wouldn't be able to sell them.
Namely, he'd announce tours slowly. And basically the strategy was that as scalpers bought out shows, he'd add another show in the same city. And keep doing that until there was no demand, no resale market, so scalpers were forced to sell at face or near face value. "I can keep throwing dates at you, and you're paying for the seats, so it doesn't hurt me, but no-one will buy them from you".
Eventually the scalpers learned to not, or minimally resell his tickets.
This doesn't just solve scalping, this fixes the lack of supply of tickets which allows scalping to exist
edit: I'm not sure I completely stand by this. There are various good reasons to sell tickets for cheaper than the maximum price you could and still sell out. Still, it's a harder problem to solve than it looks
Maybe. The scalpers are taking a risk buying tickets they may not sell, so it might serve as a mechanism to find the market price for the tickets. OTOH it also creates artificial scarcity which artificially raises the price.
In the end, the scalper is inserting themself into a transaction between two parties that didn't ask for them to do so and were mutually satisfied with the situation prior to that (nothing changed for the seller, and I think most buyers would appreciate the lower price).
Events should auction off a percentage of tickets, and reserve a percentage "for fans" -- and all fixed to a name & photo id.
One has to suspect that many events are in-cahoots with scalpers, and are just pricing their tickets below the market for PR reasons.
You're not the first to think of this I assure you.
Most modern scalper platforms collect your credit card and personal info in advance and use it to buy your ticket with their bot. So even if the venue is matching purchase info to your ID and credit card, it all lines up.
Scalpers aren't hawking tickets on show night 200 feet from the venue on the sidewalk anymore.
You pre-buy through them to guarantee that you'll get the ticket you want since everything sells out super fast (because of scalpers!) and you pay the markup for that service.
Remember those guys last year who would drive around buying up all the masks, selling them online for 10x? You don't know why everybody hated them? This is why:
The original seller has a reputation to protect and doesn't want to be seen as taking advantage. Maybe it's a musician who would rather sell to kids who are willing to wait in line than to whoever has the most money. Maybe a pharmacy selling masks in 2020. The arbitrage opportunity is for somebody with no reputation or scruples, who chooses to see themselves as just an Angel of the Free Market. To everyone else, he's a jerk.
People talk about it in these detached terms, call it laws of economics and say that it is something that happens naturally. But of course, when one remembers that these so-called laws of economics describes interactions between people, and that you always can choose what kind of influence you want to have on the world.
Also, I have some friends in insurance companies, and they say that the insurance companies right now are actively trying to learn how to scrape people's social media - secretly - so they can catch "dangerous" behavior or violations of their rules. My dad's client was telling how there was a guy who was running a happy hour secretly in his insured bar, and his company which scraped Facebook found posts from other people saying "great happy hour at this bar", he reported it to the insurance company, and they sent the bar the bill. That's freaky and should be illegal as a violation of privacy.
Remember, this wasn't the insurance company that was spying. This was a data broker whom you've never heard of, who scrapes social media pages, and gets paid by insurance companies for reports. A bounty hunter using computers and scraping. That's dystopian.
If all this speech was in a central repository by government mandate, I agree it's China
The anti-Chinese rhetoric on HN is starting to grate.
You don't live in the DPRC. How do you know what China does with surveillance if any?
The same way we know what happened with the SS or the Stazi - lots of detailed evidence, first hand accounts, reports from other intelligence agencies etc.
Can you explain what this means and why it is a problem? --Confused
https://en.m.wikipedia.org/wiki/Happy_hour
It's illegal in several States. It was only made legal here a couple of years ago.
>The reason for each ban varies, but include: to prevent drunk driving, avoid the nuisance to neighbors from loud crowds and public drunkenness, and to discourage unhealthy consumption of a large amount of alcohol in a short time.
Gotta say, I haven't really noticed any of the problems occuring that the wiki article mentions was the reasoning behind most bans myself. Haven't seen any news reports about those things since the laws changed either or anything.
Edit: Maybe I get it. It seems certain states have made it illegal to run "happy hours", presumably because people drink too much and behave badly. https://spoonuniversity.com/place/why-did-these-8-states-mak...
If the bar owner didn’t want to pay that higher premium but did want to run a happy hour at his bar, and told the insurance company that he didn’t have happy hours at his bar, then well, he lied to the insurance company. They could have found out another way, by sending a mook down the way, but this saved labor and expense claims, and maybe even on their own insurance bills if something happened to the mook in the bar during the happy hour.
By the way, just pointing out another hypothetical here; we don’t have sufficient information to be making judgement calls on that specific situation.
I don't think there's anything about scraping that makes this disgusting. It would be equally bad if individual people uploaded compromising photos of their exes.
The issue here is that people need control — not ownership — over their image and personal data/information. (The difference I intend to draw between control and ownership, is that the legal notion of control would be written in such a way that the fine print is irrelevant. Most online systems have some fine print somewhere giving the site owner certain rights over your content. Such fine print about a person's image needs to be rendered such a risk that if a business owner suggests including something like that to a lawyer, the lawyer starts quivering in their boots. "If I include such a clause, I will never get paid, because within half a nanosecond of it being visible you will be sued into kingdom come and your great grandchildren will still be paying off your debts."
Assuming that the guy was running a happy hour in a place where they are banned, your argument reinforces the view that privacy is only needed for those who break the law.
Explaining why privacy is important is hard enough as it is. Please don't make it harder.
Happy hour here is just when you can get a $2 cheeseburger, or $0.50 wings on special. I had never even considered something like a happy hour being reflected on your insurance premium.
So, Thank you, for truly leading by example.
Reminds me of this lawsuit against Facebook:
https://www.wired.com/story/facebook-six4three-bikini-app-la...
Also you can usually mail a check with a short letter explaining you are paying the estimated cost and caching the check is the same as honoring that estimate.
A month or so after an emergency visit to the hospital, I started getting random bills in the mail ranging in $50-$100 amounts. I went back to the hospital and asked them what the total was so I could just pay them the full amount right there, which was only about $1000. They simply wouldn't tell me. They told me to wait for all the bills. As I paid them off, there was no indication of whether I had completed all the payments.
Guess I missed one, as I also ended up in collections a year later for $50. My credit score was harmed instead of theirs.
I got the mortgage.
It will be much easier for a developer (or an outsider) to throw up a red flag that is taken seriously if it’s a legal concern.
In my experience, honest business folks don't mind honest regulations. It keeps the playing field level.
May I take issue with this statement?
Why do you say they are well-intended when you subsequently say that the intention is to make money? (compete to make money)
I respectfully disagree with Milton Friedman's oft-quoted line, that the purpose of a business is to maximize value for its shareholders, at least if we set value = money.
For example, here's an HHS page that exists to brag about the effectiveness of HIPAA enforcement[1], and even by their statistics, about 0.3% of complaints result in reviews. Now imagine what percentage of violations never result in complaints.
GDPR is arguably more successful, insofar as they levied around $150M in fines last year, but most of that was from a couple big cases (Google chief among them) involving companies who are so big that even getting a $50M fine isn't going to change their underlying practices. It's the cost of doing business if hoarding private data is your business model.
Pretty much every website I've ever looked at that had a GDPR compliance notice was implementing it in violation of the actual regulation: they set cookies first and then notify you about them. That's not how it works, dude. If you consider that GDPR applies to any business that transacts with EU citizens, the number of non-compliant websites is so huge that $150M is nothing. The only effect of GDPR in practice has been to fill the world with meaningless banners, not to protect anybody's data.
And in a nutshell, that's how data collection and privacy regulation has worked out in the real world: a lot of meaningless compliance theater, while business goes on as usual.
[1]https://www.hhs.gov/hipaa/for-professionals/compliance-enfor...
As someone who has worked with HIPAA data, I have personally seen the data treated with a great deal of thought around compliance. I think the numbers you cite are a result of that, not in spite of it. As your source points out, many of those complaints aren't eligible for enforcement. This isn't because HIPAA isn't enforced, it's because many of the people who are complaining don't know what HIPAA does.
But the US needs their own general privacy law too, GDPR is not enough, as it isn't applicable to a lot of software built in the US.
The big realization I had, which I'm surprised I didn't have earlier: if you don't want to do gross things, don't work for B2C startups.
The only way to get an edge when trying to grow a B2C startup is to start continually start squeezing whatever revenue you can from your users. This is inevitable even if you start with a solid product as your base.
We would track metrics on how many users were upset with how royally we screwed them with fine print and as a long as that number was small enough that it didn't impact monthly revenue "leadership" didn't care. We had no product vision at all, it was just iterate random ideas to get more money, and most of the ideas that stuck involved dark patterns that means the user didn't realize they were taking a bad deal.
I was honestly smiling when I got fired, it was as though I had passed some secret test that a company like that would not want me.
My experience with B2B has been much better, especially if you have enterprise customers. In the B2B space customers can easily be paying 100k-1M a year, and, if you treat them right, will be your customer for many, many years. It typically makes economic sense to treat the with respect, and make products that are beneficial to them. Dark patterns, and sleazy tricks have a serious penalty because losing a contract can be very, very painful.
Dark patterns are more borderline in many cases and I think the best approach is building a culture of respect for users that doesn't result in dark patterns, but in this case it looks to me like this was more than a dark pattern, it was an actual privacy violation.
I said that was a gross violation of our users' privacy and that we would only implement our own significantly restricted server-side tracking that didn't reveal any user info. Their response implied they really weren't challenged on their practices often at all.
We had to get special sign of from their senior leadership to implement the server-side tracking because it meant they could lose out on revenue if we didn't get it right.
Ironically the server-side version bypassed adblockers/tracking protections (all we did was ping back after checkout with the total order value, no user data), so it was likely that they would make more revenue given than ~50% of users have some sort of blocking in their browsers.
I think there is a fairly bright line in the sand for defining a dark pattern, and the line is between hiding and being open, between being misleading and straightforward, between trying to force someone to do something and seducing them with plain intentions. The later behavior can still really suck, without being dark.
Uber Eats used to have a "$0" option for tipping, but removed it, it's no longer clear if you're going to be giving a tip or not, but if you don't click anything you don't actually give a tip. Is that a dark pattern? I think so, because the UX makes it seem like you have to select something, and that no isn't an option. But it's not hard to argue in the negative, since doing nothing will not take money from you.
I feel pretty strongly that tracking cookies are evil, but the entire ad-tech industry did not think that was a dark-pattern.
I feel pretty strongly that GDPR "accept all or leave site" dialogs are a dark pattern, but the EU is happy with that implementation.
I would also love to point out that "dark-pattern" is still a blossoming terminology, there's no definitive body of law or ethics that describes what is and isn't a dark pattern.
Similar for Google that went the "you can disable cookies in your browser" way, I doubt that will survive a lawsuit in the coming years.
Popup that asks for email address that doesn't have an 'x' (or the 'x' doesn't appear for a while) and the email address field secretly records what the user types and even though they clicked cancel their information was secretly shared: dark pattern
At what point does it not? Pop-ups exist to steal attention. It's abuse. Why do these marketers believe they are entitled to anyone's attention? They are not.
> a business owner can have a very hard time grasping why
Of course. Businesses generally couldn't care less about how much they're abusing their workers or their consumers. The only thing they care about is their profit. Dark patterns are just value extraction mechanisms, it's their abusiveness that makes them dark.
> they can often act like they're simply herding sheep. Users are ephemeral zombies to some, and from that lens, it's totally fine to capture them with sneaky tactics
Yes. It's an inherently abusive and sociopathic view. They don't consider us human beings.
Any amount of coercion and trickery is unethical. This is absolutely clear to me.
I was acquainted with some black hats in junior high and high school. Guessing how they are as adults, I'm pretty sure you can always find someone who will do it for the lulz, if not for the money.
I'm still proud of my answer.
I typed of this excerpt and have used it countless times:
>To those men in their oddly similar dark suits, their cold eyes weighing and dismissing everything, the people of this valley were a foe to be defeated. As he thought of it, Dasein realized all customers were "The Enemy" to these men. Davidson and his kind were pitted against each other, yes, competitive, but among themselves they betrayed that they were pitted more against the masses who existed beyond that inner ring of knowledgeable financial operation.
>The alignment was apparent in everything they did, in their words as well as their actions. They spoke of "package grab level" and "container flash time" -- of "puff limit" and "acceptance threshold." It was an "in" language of militarylike maneuvering and combat. They knew which height on a shelf was most apt to make a customer grab an item. They knew the "flash time" -- the shelf width needed for certain containers. They knew how much empty air could be "puffed" into a package to make it appear a greater bargain. they knew how much price and package manipulation the customer would accept without jarring him into a "rejection pattern."
>*And we're their spies, Dasein thought. the psychiatrists and psychologists - all the "social scientists" we're the espionage arm.
The Santaroga Barrier,
Frank Herbert, 1968
But I'm not one of those parents who things screens are inherently bad anyway. I think you would be hard pressed to find any credible evidence to the contrary. I grew up on screens and now I have a good job as a programmer where I can provide a good life for my kids.
The tortoise lays on its back, its belly baking in the hot sun, beating its legs trying to turn itself over, but it can't. Not without your help. But you're not helping.
Why javajosh? Why aren't you helping?
Would it be too on-the-nose to point out that this hypothetical smartwatch would probably be running Android?
Had to read this two times and check the year of the article to make sure this wasn't from 2001
I work with clients every day that don't have version control. Some of them are even using PHP!
> I told my client - apologies, but I don't want to work on this task because it's a dark pattern. And they reply - no, no, we are just sending people 3 email reminders. And then I try to explain that it's basically saving email addresses secretly.
Perhaps because this is a short post, but it seems to be missing context. The email addresses are saved, which may or may not be questionable. It's unclear whether there are any mechanisms to auto-remove the email addresses once three reminders have been sent.
It doesn't seem immediately obvious what the dark pattern is here. What am I missing?
Edit: That got a lot of push back. I'm just saying, this is not the hill I'd die on. At best it would spare some small single digit percent of visitors 3 unwanted emails.
We'll provide an unsubscribe link, I promise.
... But let's just record they clicked unsubscribe because that means they're engaged. I mean maybe they clicked in error? Let's ask them to confirm.
... But maybe they confirmed because they were confused and didn't understand the great value we provide.
We can beat around the bush our way to full-blown scammers all day.
Saving emails from a form NOT submitted is bullshit, and you know it. The user never intended to submit.
Most people. Because we have form autofill.
Absolutely f*ing not. Not a small thing in any way. This is unethical and if I got an email from that company you can bet I'll push back.
I think it's still a dark pattern to email someone who hasn't expressed interest in receiving those emails. There should at least be text informing you of that and giving a way to opt out up front.
I think this is a pretty important thing to try and get right.
Many of the online mortgage rate tools are really just lead generation sites, including some of the big name brand ones.
One wanted me to create an account, and I got about half way through (I stupidly gave my phone number) and then exited without creating account. I believe they had a sort of "enter email, next. enter phone, next" kind of page by page pattern.
Anyway, within an hour of exiting I was getting 3 phone calls per hour from mortgage companies soliciting me for business.
If they added a text for user like "Your email address is saved by XXX Inc, we will just send you 3 reminders", then it would be ok.
For example of the same dark pattern: if you look at any hotel booking page (not aggregator like booking.com, but hotel-owned), I bet you will see at least 5 third-party tracking scripts, they all store every action you make on the page without user explicit knowledge.
I’d agree with that as long as the text is visible before entering the email address, and the text also mentions that email will be saved before completing the form.
> I bet you will see at least 5 third-party tracking scripts
Analytics and tracking scripts is a good point. Sometimes it’s implemented in a way where tracking scripts don’t have access to keystrokes, for example by iframing them, and you’d hope that the web site owner would care enough about their own security to do that. But you’re right that unfortunately it’s common. In this case I think we need some legal protection in the US and elsewhere similar to GDPR that clarifies that collecting such information can only be done with explicit consent.
if yes, it’s a dark pattern.
if no, it’s not.
i side with, yes.
Let's not kid ourselves. We know most users naively think the data is just on their screen and nowhere else until they hit submit. If we write code to circumvent that expectation we know it is a deception. After all, the default behavior is that the form data is not available early. The programmer has to explicitly do something to counter the default.
Oh. "too nuanced". The author is too soft. Most probable reason is that business owners are assholes.
EDIT: oh, and because most developers are spineless creatures not being able to stand up for their principles, unlike the author. If everybody really cared about privacy as they say they do we wouldn't have so many issues. I mean, somebody is implementing all those features.
sorry for the harsh tone but I don't know how to say it any other way. When developers - professionals who enjoy royal treatment on the job market at the moment - are too afraid to upset their employers over an ethical question, it makes me mad.
The free market only works to an extent, and harm to consumers is a valid reason for the government to step in.
One of my faves: in a Spanish-speaking country, an Ernest Hemingway book published (legal status unknown) in English, titled "Goodbye to the Weapons".
Another: from a customer service rep in Southeast Asia: "If I am in your shoe..."
I'm a big believer in being part of the solution, not the problem, but there are always plenty of developers who don't care at all and are fine with "sure, boss, whatever you say, boss".
Real example:
Client> We want the "I agree" button checked by default
Me> I'm not a lawyer, but I think this goes against the GDPR in that users must give their consent by action, not by inaction. I would advise to at least check with your lawyers first.
Client> Oh! I'm so tired of those laws, we'll get back to you after checking.
(a couple days later) Client> Yeah you were right, lawyers say we'd better leave it unchecked.
I know that client very well. I would have _never_ been able to convince them on a morality argument.
What's more, after a few interactions like the above now they don't bother going to the lawyers anymore. I just say "I'm not sure this is acceptable" and they immediately agree to whatever non-shady alternative I propose.
And what would the language you propose look like for this legislation that doesn't have loopholes, caveats, etc for people to get around once the lobbyists are done with it?
That consumes bandwidth, and means that these sort 'they should step in and decide how people write software!' ideas are going to get corrupted by pressure groups who want to use the power to achieve their own ends.
If I have to vote for someone who is going to enact policy I actually want, and the trade off is they are shady on web implementation policy - I don't care about web policy that much. No-one does. The government can't possibly put out reliably good regulation on the range of topics that people want good regulation while that dynamic is in play.
The other fault in your model is that Congress actually delegates the vast amount of lawmaking to administrative agencies, who are equipped to deal with the less important issues. The FTC, the CFPB, or the FCC could all credibly claim some authority over dark pattern regulation, though I don't know enough admin law to know who would be most appropriate. Agency rulemaking isn't a perfect process either, but it doesn't have the concentrated power problem you're describing and it deals with tons of lower-priority topics. Go read the Federal Register: https://www.federalregister.gov/
> The other fault in your model is that Congress actually delegates the vast amount of lawmaking to administrative agencies, who are equipped to deal with the less important issues.
Those bodies typically end up full of industry insiders who lock out new entrants and promote the status quo. They aren't going to stop dark patterns, it is more likely they'll want everyone to have a license before starting a website (which is the obvious enforcement method).
That is exactly the sort of corrupting force that will gather to any power that gets gathered to the regulators in the name of pushing back on 'dark patterns'. It isn't a case of 'of this is too hard', it is pointing out that you're implicitly advocating the creation of a point of failure for these people to attack in an arena where they have an advantage.
Talking is cheap. We've been talking. Most of the congress critters in office now do not understand most what's being legislated (if they've even read the full bill past the talking points). That's why most bills are actually written by lobbyist groups, and the congress critter just puts their name on it. Surely, there's nothing that could go wrong with that now is there?
Sure, individual developers should stop deploying dark patterns. Many many developers do, though, and saying they shouldn't isn't going to change things. Change requires collective action, rather than expecting a huge number of developers to magically reorder their priorities. And unless you think a nationwide ad campaign is more feasible, that means legislation.
On a tangent, I wonder what the response rate of Facebook's nationwide ad campaign looks like. Not really sure what the point of Facebook's campaign is, but it's a really lame ass commercial. I hope they are paying above market rate for it too. Any laws being passed to regulate Facebook would immediately be suspicious to me wondering how much FB spent to write said legislation. Just like when the rules regulating TV owners could only own a certain percentage didn't make anyone actually sell anything. So many pieces of legislation are like this. I don't see "Don't be evil on the interwebs" regulations being any different. Maybe I'm cynical, maybe I'm too pessimistic, but it's not like I'm grabbing my hesitancy from air.
The idea that software patterns can be made illegal is just absurd, and goes against the early vision of the free software movement which recognized the most important thing was the freedom to write software, rather than the freedom to get a job writing exactly the software you think you should be writing, and the right to throw employers in jail if they fire you for not doing what you're told on the job.
The things I advocate the government to ban are things I believe are bad for society.
I don't like ice-cream, but I don't advocate for an ice-cream ban because I don't believe ice-cream is tearing apart our society at the seams.
Dark patterns are bad for society, and prey on people's miscalculations and inefficiencies of our chemical-brains. In the same way that child labour came up because it was profitable short term, but it was decided against that it was still a bad thing for society.
The government's job is to steer society to a better place, god knows we'll take it down a bad path left unsupervised.
The free software movement has never been about a libertarian, free-for-all, wild-west. In particular, it has always been about taking power away from developers, and giving it to users (e.g. see gnu.org/philosophy ).
Whilst FSF, GNU, etc. don't advocate banning certain software (AFAIK), they're certainly not averse to government intervention for social good. GNU Taler is a good example: a cryptocurrency which offers anonymity to buyers, but sellers remain identifiable for tax collection.
Also note that 'freedom 0' (freedom to run the software for any purpose) only requires that a license itself doesn't impose restrictions on users. It's taken for granted that users are already restricted by other mechanisms. For example, a license with a clause like "the software must not be used to commit bank fraud" would be non-free, but that doesn't imply that the free software movement approves of bank fraud; simply that (a) in places where bank fraud is illegal, such a clause is redundant, and (b) in places where bank fraud is legal, such a clause would constitute a developer exercising unjust power over users.
For actual furthering of the discussion on wording, something vague like 'any dialog presented to user must be done in the most consumer friendly manner' isn't very good because it's too vague. Getting specific like 'automatically checking/highlight/enabling the options vendor prefers' is too specific because then the vendor would use something not a check/highlight/etc. These kind of things are ripe for "spirit of the law" interpretations, but we've long since given up that kind of good intentions.
For example, a response could have been:
> How would you tailor that law? I have a hard time describing exactly what's wrong with dark patterns in a way I think would be enforceable, even though I know it when I see it.
or
> I think a law would have to be carefully written. One starting point might be requiring cancellation to be available using the same process as subscription - for example, if there's a signup form online, there must be an equivalent cancellation form.
which are at least contributions rather than just an insistence that there's a problem that has to be addressed before these ideas can even be considered.
Even just "what language would you propose?" without all the baggage of the original comment at least moves the discussion forward.
Judges being able to "know it when they see it" would be the only way "spirit of the law" type of legislation would work. Then you have the problem of Judge A in District 1 being much more lenient than Judge B in District 2. Not sure if that's a bad thing or not, just mentioning things.
It already exists - it's called GDPR. It deals with the root cause of this design pattern which is collecting data about clients secretly. It's enacted in the EU and it's excellent. It's not perfect - there's still some oddities and extra work for implementers (and the 'accept cookies' on every page thing is a faff for users) but the overall effect is extremely positive.
Why holding only developers responsible for non-ethical features? What about the actual decision makers and legislation.
By the same logic, if only factory workers decided it's immoral to build weapons, there would be no wars. But those spineless creatures just want bread on the table and don't care about world peace.
The only way to avoid these dark patterns is a set of laws that punish them. The reason why we don't have such laws is that we as a society don't know and don't care. It's we all, not only "spineless developers".
I think the question is, are developers engineers or just programmers? The responsibility of an engineer is to give pushback when it is deserved.
As you say, the responsibility is on decision makers. But they care about the politics. They will try to make it look like you're on your own. But if you clearly demonstrate the mood of the company's employees, they will reconsider their position. The result will be compromise not capitulation but it's better for something to be better even if it isn't great yet.
There's plenty of blame to go around. But at current, we really do have to do better as a community and refuse these requests far more often than we currently do.
Some business owners are. Some of us do try to run our businesses in ethical ways, despite knowing very well that we could probably make a lot more money if we included a dark pattern or two. It would be nice if people could at least not insult us while we're doing it by lumping us in with the $$$ crowd and normalising the bad behaviours we want to resist.
Why assume they have principles?
I feel like a lot of people saying this lately haven't tried to get a job since the pandemic.
Invitations to apply from recruiters whose job it is to get people in the door are not job offers, nor royal treatment.
it's understandable why people feel that way.
Sure, that’s understandable.
But to be understand it, also remember that when highly paid experts that get royal treatment so long as they conform confront employers over ethical issues...you get the Google Ethical AI massacre.
“Royal treatment” isn’t unconditional, and means you have a lot to lose.
You shouldn't have to apologize. Nothing wrong with being harsh. We should be harsh, especially with people who perpetuate these unacceptable practices. Indignation is a perfectly valid response when faced with this.
At a meta level, this post seems a little strange to me. Is the linked site your blog? Or a discussion forum you're trying to bootstrap and drive traffic to? If telling the story of this ethical dilemma and the consequences were the driving motivation for this submission, it seems a little low effort and light on details of the consequences. But if it was to drive traffic to your forum, then I guess it did a good job.
You aren't just working for an ad company. You are working for the benefit of manind. You bring joy to everyone and restore justice in this world... with ads.
Then you have the coworkers that drink the koolaid and talk as if you were in a cult.
I filed his talk under "corporate bs for 500" but sadly our local leadership drank the cool aid.
I do not have a problem with making money. Or helping companies do so. I know that this is the center piece of capitalism. Great if you provide added value with your offering but making money is paying our mortgage in the end.
But for the sake of it. Don't try to brainwash me into believing that what I do makes the world a better place in any significant way.
Exactly! Why do we have to pretend we have a goal other than making money without compromising our principles? The best way to make money and keep on doing so is to give people something that is worth spending their money on. A good product at a fair price isn't healing the world, but it's not breaking anyone's leg either.
I wonder if a lot of this goes back to early 20th-century businessmen who tried to apply Transcendentalist thought to business, promoting unity and loyalty by creating a feeling of a noble cause in their employees (Charles Ives, an insurance executive and composer, is the example I'm most familiar with).
Not sure about your scenario but writing code does at least sometimes improve the world. I helped create a product that was later used to restore the rule of law in a country trying to recover from genocide. The homicide and assault rates for the entire country dropped by double digits following use. That seemed significant.
While most of my efforts since have had far less dramatic outcomes but the general circumstance is that even mundane things like keeping the lights on are instrumental for peace in our societies. Such things are far from the dark patterns side of the industry but there's something about babies and bathwater. We can contribute to supporting the more constructive and healthy efforts.
Is there a reasonable list of "dark patterns" that this tactic in the OP falls into? I don't doubt it is a dark pattern. I'd just like to know which one it is, and have it explained to me in a little bit more detail. Thanks!
In my experience it's because the marketing team has already sold the dark patterns.
You're going to flip when you find out what they know about your location from your mobile phone.
This is just illegal data storage.
How is this any different than when telephone conversations are recorded on phone support lines, or when a video game records all user input and streams it to the remote server?
It's all about disclosure up front. As long as the web site has done that properly, it's legal, right?
This is similar to when I see people posting in local contexts (like on FB groups) that so and so local company provided terrible service but the poster doesn't want to name names.
What good is done if names aren't named? If we have a name, then things get fixed. Otherwise there is no feedback loop so there's really no point.
Zoominfo sells a tool that will "auto fill" visible or hidden form fields based on the user's initial input.
https://www.zoominfo.com/solutions/formcomplete
The tool is marketed specifically as a way to reduce the number of "visible" form fields.
At least in this case, the user has to actually submit the form.
When my client made the initial request I responded with "I don't know if that's possible OR legal" and then a couple weeks later they sent me Zoominfo welcome emails and asked to integrate into their web forms.
FWIW, my clients' forms actually display the fields (none are hidden) so I at least can sleep a little better at night.
The right to buy food and pay your bills is what you get from your payment if, and only if, you are willing to compromise your own ethics.
If you start to make your work decisions based on ethics it will be really hard for you to stay at your current job or get a new one.
Unfortunately, this is the world we live now.
I have the impression that grocery retailer Costco is relatively good in terms of respecting their workers and customers, and I think that is one factor in their success. I'd be interested in learning about other companies that have priorities beyond maximizing this quarter's numbers, or learning why my impression of Costco is wrong.
About Costco, I really don't know, but I know some big companies can have ethics because I've worked for one. It was the best place I ever worked.
Unfortunately, it is rare these days.
If a user had already typed their email onto the field, then the user had at least some intent to sign up whatever the user wanted to sign up for.
This makes what ad trackers and ISPs do with how we browse seem like war crimes if you were to call this a 'dark pattern'
How is the reasonable? The real-world equivelant is going to a shop, looking around, and then leaving without buying anything and going home. If a store representative then knocked on my door and offered to help me find whatever I was looking for, that would be extremely creepy.
Sure, it might work out if someone did get stuck with a form, and actually does want someone to help them with it, but that's a tiny perentage of people. The real reason is not altruism, it's to make money.
The tech team at the time was entirely located in Utah at the time, and all of us were repulsed at the idea. We countered with suggestions for improvement and made it clear the project would not be worked on:
- You can make a "promoted" restaurant section above the fold - The UX concerns since users expect some reasonable ordering. Like distance from location or alphabetical.
We didn't get fired, and it was really scary. I appreciate standing up for ethics and principles. bravo.
I can imagine situations where this is to the user's benefit and the company could handle the data ethically.
Example: Situations where the user would be likely to have very unreliable connection and be on the page with the email field for some time with other data entered that they wouldn't want to lose.
It might seem a bit contrived but I've had similar scenarios in the past.
EDIT - as others mentioned localStorage is a better solution for this problem.
You're right there are places where this sort of thing can be useful, but they're rare, and could even be handled client-side in many cases.
I think there's a very reasonable general expectation on the web that your data isn't used until you've clicked submit/save/etc
I definitely have this expectation and would be angry if it was violated.I wonder: do non-engineers have this expectation? In 2021?
I've been involved with web development since the more or less earliest days. Back when websites were mostly static pages, and eventually spouted some forms here and there.
But, would a non-greybeard engineer have this expectation today now that UX is generally so different and "app-like" and anything you see in your web browser can basically be assumed to be in constant communication with the server(s)?
Please note that I don't think the current state of affairs is really an improvement. In fact, I more or less hate the "modern" web. I'm just curious about how user expectations have changed.
If you're dealing with user data you should never compromise a basic respect for that user's intent. Designing for implied consent where consent should be explicit (e.g. sharing personal data) is unambiguously a dark pattern.
Data entered in a form don't require an active connection. If submitting the form fails you can resubmit it.
Usually such issues start to appear when companies decide to implement their own custom UI from the ground up in a way that the result can only be described as undefined behaviour and things like input fields reset their state when you look at them the wrong way.
Such an important property of the web. Server sends a description of what it wants, client renders and handles interactions. Things like server side rendering are anti-web.
Server-side rendering, streaming video, and such aren’t incompatible with internet philosophies in the slightest, just not aligned with the intent of the www. Apps, even the ones that aren’t merely web views, are more www-like in this regard.
In this case, the boss simply assigned the task to someone else. Employee stayed employed.
My website doesn't contain any textbox, so there's no personal data except IP address. Nevertheless, I more or less know who's reading my page because every student has a static IP.
Nowadays, I don't collect mouse moves anymore, but I have navigator.sendBeacon() for video playback behavior.
I think some of these widgets similar to intercom do this.
In short, I assume that the sales team is just following industry practices for that vertical / type of the sites. If not, then it is your job to explain the best practices for your industry (i.e., how these kinda of things will generate a lot of spam, will make potential customers weary the service, etc.).
We get it, you personally think dark patterns are here to destroy humanity. Lesson learned, don't shit where you eat. There's a lot I don't like about my work too but I'm not about to risk my stability just to make a point to some people on a blog post.
I would say, no! If you voluntarily quit instead of being let go, there can be certain disadvantages, depending on the employment laws and such in your jurisdiction.
Unless you have something lined up, of course; then it is largely moot.
In my mind this gives me some relief that the company was a small outlier, which is not to say I don't think there's a problem here, which is that morally objecting to work assignments doesn't seem to be a thing in the corporate world.
The real issue is the legitimate companies that take it way past dark patterns. Credit rating bureaus that scrape 100% of your data and the data of anyone you've ever been near, Facebook stalking you across the internet, etc. As far as I'm concerned, if it's okay for Facebook to do this exact dark pattern on everyone in the world, I can make a stupid directory site have a little more juice.
How is this pretty benign?
some examples:
https://github.com/carlsednaoui/ouibounce
https://www.hubspot.com/products/marketing/exit-intent
i like how this page describes them more as 'needy' than 'dark', since dark seems to imply immoral
> it's very easy to create something spammy-looking.
...and then they list "good" uses that are... all spammy.
These actions can be used to infer possible intent to leave: scroll up (to reveal address bar on mobile), move mouse toward top of viewport (to move mouse toward address bar), swipe down (to reveal address bar on mobile), loss of UI focus, probably others.
I hate these patterns, and they are 100% appropriately described as dark. I and the other devs spent months at one place arguing with a PM about how janky and broken the third-party intent-to-leave detector they injected using Google Tag Manager without dev involvement made our app feel. (GTM was the product that convinced me Google gave up on not being evil)
I was once pitched the exact dark pattern as in the OP - covert email collection. I was gobsmacked. I wrote about it at the time thus:
> Towards the end of the slide deck, Dom excitedly explained how if a user enters an email address in any form field anywhere on the website, then regardless of whether the form is submitted, that email address will be captured by IntegriMart and paired up with a browser fingerprint for that user. This, presumably, allows us to “continue to build a dialogue” with that user.
Full story for those interested: https://www.michaelbromley.co.uk/blog/the-covert-opt-in/
The feature you describe is annoying (I think it's fair to say that everyone hates these pop-ups) but rather innocuous and certainly not unlawful so there isn't any reasonable ground to refuse to do it if you're employed as a web dev.
That's the nature of employed work.
Software engineering is largely think-work. Some of it is creatively coming up with ways to solve novel technical problems, but an often understated part is thinking about how your implementations will affect your users, and optimizing for solving your users problems.
Ultimately you may need to comply if the decision is made, but they literally hire us for our judgement and ability to work independently for the companies objectives.
Yes, you 'need' to comply because you're an employee. That's all there is to it and I'm very surprised by the emotional reactions to my simple statement of fact. It's odd.
A software dev is not hired for their judgement on company strategy or marketing. It's never a good idea to tell others how to do their jobs.
I would also say that pushing back and refusing are two very different things. If you think something is not good for the company you may say it constructively (though be careful). In the end, "disagree and commit" or quit are the two professional options.
There's a principal-agent problem here. The owners of the company don't care about a random manager's feelings. The manager certainly does, however, so much of what any particular manager will require is more about making the manager feel better than about making profits. Other employees are correct to disagree with such misuse of resources.
Granted, if you refuse to do something your boss tells you to do because it violates your concept of professional and personal ethics, they may decline to continue employing you. And you might not have a legal basis to challenge your termination if what they asked you to do is legal. But walking away from a job may be the best option in some situations.
My reply was also specifically to a comment about a pop-up window when a visitor leaves a web page. It's over the top to bring ethics into this and I feel the term is being completely diluted into meaninglessness these days and too often used as an excuse to choose to do only whatever one agrees with, which both unprofessional and, frankly, childish.
Again, I'm very surprised that my comments are being so badly received when they are simple statements of fact and reality of the employment relationship. Maybe many readers are still quite inexperienced...
I wouldn’t have accepted the position in the first place.
If I really would have needed the job, I would have left as soon as possible (6 months max).
They did him a favor by letting him go.
How many users:
1. type out a complete email address
2. and then decide at the last moment to not hit "submit?"
Who even does that? Like 0.00000001% of all users? I've been using the web since the mid 90s and I don't think I've ever done this. Ethics aside, it's hard for me to believe that this dark pattern even yielded a useful return.
To be perfectly clear, I'm not defending this dark pattern. It's bad. I'm just questioning its efficacy.
I’ll use auto fill to save time and quickly click through to the page that finally shows the full price, then I will back out.
More recently, instead of auto fill I take extra time to type a fake email address just to prevent the “lost cart” marketing emails that were mentioned in the article.
You say that you "click through to the page that finally shows the full price." So, you are explicitly submitting multiple times. There's a reasonable user explanation that your information would be received by the server.
In the author's example, they're describing something more insidious -- saving the user's information before they submit the form, thereby subverting user expectation.
While I understand the intent, words matter. If those were the real words that were used, yes it will lead to souring of relationship. Unless we notice a systemic pattern, accusations should wait and that sounds like an accusation.
Perhaps the client was indeed trying to do something customer friendly and they did not know better. It would have been better if the OP had offered a solution rather than excuse of them engaging in dark patterns and refusing to work on it.
And, if the client had not taken that solution, yes, I will agree there is something nefarious. But till then, I wouldn’t have jumped to that conclusion so quickly.
Yes, there are some settings panels that automatically save changes, but I have never seen it for forms.
If there's an submit button on that form then that would be an even stronger signification to the user that nothing will be sent to the servers until you click that button.
As I said, it is distasteful but not a trick.