Starbucks and TrustArc add fake cookie processing delay if you don't click agree
twitter.com
twitter.com
Not just because of these dark patterns, but usability is messed up. The web should be redesigned to force standards compliant requiring websites to allow a “no script” support where you just go for information.
Cookies are not even remotely the largest problem on the fucked UX web we have today. It’s less about data delivery and ubiquity of the original WWW concept and more about “how do we force users to stay on our platform” or “how do we extract data on our users and sell it to the highest bidder.”
They also need to pass laws forcing companies who sign up users for services to have a graceful way to sign down and delete their account instead of these stupid cookie banners.
Unfortunately some cannot be helped as they just want to feel like they are helping/connecting with someone.
Sometimes, I swear the people I'd be helping knew they just didn't care, they were that desperate for human interaction.
It's a tale as old as time. I remember spending far too many hours as a kid convincing my grandmother not to send various people/fake businesses money (you owe the IRS! You power is going to be shut off!) and trying to curb her purchasing on QVC (I ended up later having a roommate who worked for them - the horror stories I could tell!).
So, increase the complexity. A certain number of savvy people will click off immediately, but they were likely too clever to bother with your game, so no love lost there. The ones who stick with it are your ideal targets. They'll wrestle through anything you throw at them to get what they want as long as you keep teasing that there's a light at the end of the tunnel.
However, you also can't make totally random, nonsensical design choices. They need to have a pattern that guides them in the darkness to the actions and outcomes you want most. It's your site after all, and no one can or will tell you how to run it as long as you show those retention and engagement numbers going up, so remember that.
Now that they're spinning in circles clicking on anything and everything trying to understand the labyrinth you've set out for them, you've got nothing to worry about. They've sunk their time and attention into solving this, and you're going to have them come back soon with a new strategy they're excited to try to beat the game. Once they feel like they've beaten you, you've won. They'll keep coming back just to prove to themselves that they've figured it out. They'll search on behalf of their friends and family, rising in their estimation.
Now they smirk and with just a hint of pride say whenever someone complains about how hard your site is to navigate, "Oh, it's not that hard. You've just got to know how it works."
> Subsets of IMDb data are available for access to customers for personal and non-commercial use. You can hold local copies of this data, and it is subject to our terms and conditions. Please refer to the Non-Commercial Licensing and copyright/license and verify compliance.
> The dataset files can be accessed and downloaded from https://datasets.imdbws.com/. The data is refreshed daily.
> Each dataset is contained in a gzipped, tab-separated-values (TSV) formatted file in the UTF-8 character set. The first line in each file contains headers that describe what is in each column. A ‘\N’ is used to denote that a particular field is missing or null for that title/name. The available datasets are as follows: [...]
I’d wager the license does not permit republishing the data on the web using better UX paradigms either—though I am too lazy to read through the fine print.
javascript:(function(){ window.location = window.location+'reviews?sort=userRating&dir=asc&ratingFilter=0' })()starbucks.co.uk works fine for me without trustarc, newrelic, googletagmanager or cloudflareinsights. No point executing all of that extra JS as its not for your benefit.
It does in the context of usability:
> What I remember learning was that any latency of more than 1/10th of a second (100ms) for the appearance of letters after typing them begins to negatively impact productivity (you instinctively slow down, less sure you have typed correctly, for example), but that below that level of latency productivity is essentially flat ...
> That's for visual feedback that a specific input has been received. Then there'd be a standard of responsiveness in a requested operation. If you click on a form button, getting visual feedback of that click (eg. the button displays a "depressed" look) within 100ms is still ideal, but after that you expect something else to happen. If nothing happens within a second or two, as others have said, you really wonder if it took the click or ignored it, thus the standard of displaying some sort of "working..." indicator when an operation might take more than a second before showing a clear effect (eg. waiting for a new window to pop up).
> but this delay is tens of seconds.
Oh, I wasn't aware of that - in that case it's ofcourse unjustified and definitely a "dark pattern".
Thankfully, I haven't had to deal with any of these stupid pop-ups since installing the 'I don't care about cookies' add-on. [1]
Related question: Does anyone have experience using 'Stardust Cookie Cutter'? [2] Is it better than 'I don't care about cookies' or does it do the same thing?
I don't want to live in a world where the criminalization of everything that ever happened that you didn't like means that I'm always breaking the law.
How many people not liking gaslighting personal-data-theft dark patterns will it take to make it into a law?
We're transitioning from purely physical beings to having a more virtual presence. Virtual crimes are much less visible and have much greater impact at scale than their physical counterparts, identity theft by Equifax breach or a hack, VS physical force or pickpocketing, for example.
The impact of violating privacy is neither increased nor decreased by the impact of theft and/or murder. If we compare theft and murder, theft «in general» is less impactful than murder, as I'm deprived of property and potentially physically injured with theft, with murder I am deprived of life itself.
That murder is generally more impactful doesn't make theft more acceptable/less bad; we should have laws for both.
On the flip side, this particular dark pattern was caused by regulation. As usual, shades of gray
Regulation is a possible cure.
Call me crazy, but if some place would be weary of going straight up for the “let’s ban things with lawyers ” approach, I would think is HN.
You'll be fine as long as you're not in the habit of doing things like this that are clearly outwardly hostile to everyone you come into contact with.
You could argue that the artificial delay is implemented as a way to dissuade people from declining which would fail the idea that data processing consent should be freely given (you can’t force people to opt-in).
You could also argue that even if there was a legitimate technical reason for the delay then it wouldn't be compliant because it would prove that data processing is enabled by default before the user opts-in (otherwise the delay should be on opt-in and opt-out should be instant as it's essentially a no-op).
Here are the ICO’s guidelines on the subject - you’ll see that this TrustArc trash fails on multiple points: https://ico.org.uk/for-organisations/guide-to-data-protectio...
TrustArc essentially provides "breaching the GDPR as a service" and their continued existence proves the incompetence of the data/privacy regulators in all EU countries.
Or maybe it shows that they are underfunded relative to the task set them. Which is actually true of many government departments.
I suppose the counter-argument would be that passing legislation is cheap, but enforcing it costs money, and governments have other priorities, but, for example, in the UK there can be fines of up to £500,000 for breaches of the e-Privacy Directive[0], which should be more than enough to cover the cost of the investigation.
[0] https://www.pinsentmasons.com/out-law/news/gdpr-e-privacy-br...
Surely there is a way to get this "machine" started and use the money from previous fines to fund future enforcement?
Of course, still a good strategy to name/shame a well known party that may care more about their public image than "TrustArc" does.
Then, also enable uBlock origin's "annoyances" filter.
Blocking the notice (or ignoring it) is technically equivalent to opting in. Of course, if you're using a competent ad blocker it's likely that the trackers themselves were also blocked, making this a non-issue.
* it's hard/impossible to prove - given how many factors go into ad targeting there isn't a conclusive way to prove whether an ad was targeted because of illicitly-collected data.
* as you see here even blatant GDPR breaches and acting in bad faith doesn't actually land you in trouble, so although it's "illegal", the law isn't enforced. Experian (or Equifax) got caught by the ICO knowingly misusing people's credit data for marketing purposes and all they got was a warning, so clearly the message is that "breaching the GDPR does pay".
It does appear (from their website) like the aforementioned Stardust can auto-decline everything, but I haven't tried it myself.
One problem you run into when declining cookies is that on many sites you won't be able to view embedded YouTube videos, tweets, etc. unless you go back in and allow social media cookies.
A 1 second delay in page response can result in a 7% reduction in conversions. [1]
47% of consumers expect a web page to load in 2 seconds or less. [2]
40% of people abandon a website that takes more than 3 seconds to load. [3]
...etc
Either those cookies make up for the lost business, these statements only hold for the initial page load or these statements are factually incorrect. I suspect the statements only hold for the initial page load, that spinner and the slowly but surely updating fake counter holds visitors enthralled for the final outcome.
Anyway, the path is clear: close that Starbucks tab after ~2 seconds of faked cookie setting time and get your caffeine kick elsewhere.
[1,2,3] just search for it - most results are commercial entities trying to sell some "marketing" or "website enhancement" service which I do not feel like boosting by linking to them. Much of the original research seems to come from Google and can be found in a report titled “The Need for Mobile Speed".
It’s likely TrustArc trying to make their widget look muscular to an idiot executive at Starbucks.
Considering everything else about it also screams bad faith, I think it's a deliberate tactic to train people to click "accept" on these so they can then boast about how their "consent" management platform provides better conversion, which in turn somewhat justifies the salaries of the oxygen wasters in the marketing/advertising departments.
Being privacy minded and traveling during covid has been a nightmare.
Almost certainly these tests do not take into account longterm affects on user's opinions on the brand, etc.
"In January 2006, Harvard economics researcher Benjamin Edelman published a study showing that sites with TRUSTe certification were 50 percent more likely to violate privacy policies than uncertified sites:
https://www.benedelman.org/news-092506/
And perhaps ironically (if honestly true - maybe it never was the intention), TrustArc was nominally/purportedly started to promote privacy at TrustE. A lie perhaps.
"TrustArc, was founded as a non-profit industry association called TRUSTe in 1997 by Lori Fena, then executive director of the Electronic Frontier Foundation, and Charles Jennings, a software entrepreneur, with the mission of fostering online commerce by helping businesses and other online organizations self-regulate privacy concerns."
There’s a few hills worth dying on and I feel this is one of them. It is just unambiguously evil.
Interestingly there are laws and whistleblower protections against murder and slavery.
But regardless, even if it were true, you still need to protect your own soul. Better to let someone else corrupt themselves.
Anyway, they wouldn’t fire you since just finding someone else to do it is easier than starting any HR process.
That’s pretty sad by itself.
Ethics should follow the same standard normal distribution model as everything else. Which means that 50% of the population has less than average ethics.
Since morality is socially mediated, I think it's reasonable to hypothesize it would tend to be N-modal.
You obey or get yourself and your family kicked out of the country.
What if you have kids who were born here? You're now going to take them back to a place they don't know? Or are you going to let them go to foster care here?
How about if you've bought a house here? You're going to have just a few months to settle everything before you can go.
Perhaps I’m finding this hard to understand since I have no desire to live in the US whatsoever and have turned down several offers from companies that wanted me to move there. Nice place to visit, but I can think of dozens of places I would rather live.
I was once that kid who had to go back to Iran without knowing Persian. It was fucking terrible.
They did the right thing because I was able to still have a childhood that wasn't bogged down with learning Persian.
I swear the US must be the worst possible country in the world to emigrate to.
I’m sure there are some people in the unfortunate position you describe, and in their case it’s understandable. But it’s not the general case.
Actually, I got interested in this and checked trustarc's careers page and it seems most technical positions are in Philippines/Canada with a mention of "global team" so I'm convinced now all this thread is arguing about strawmen and in reality the product is being written by some remote contractors from third world country who will be easily replaced by a million others if they refuse.
Isn't this true of every full-time job? But people quit and get new full-time jobs all the time.
If you are asked to commit a crime by your employer, do you go ahead and do it for the sake of keeping your job? What about something legal yet highly questionable on moral grounds? Going ahead with an annoying UI feature you don't agree with is probably justified if the alternative is getting deported, but there's a threshold somewhere and it's different for everyone.
Not going to argue about how each person defines literally.
Really the issue is being fired over it isn't it? The visa just makes being fired worse for employees requiring one.
I would hate to work at a company where a bit of debate on 'is this really a good idea' were a firable offence; sounds like the 'believe it or not - jail' scene from Parks & Recreation! That's satirising a visiting delegation from a developing country under military rule.
Right, and you don't have to because your continued existence in a country isn't dependent on it. Companies with attitudes like that don't reveal it until it's too late.
But then I've never lived or worked in the land of the free, so what do I know.
What a depressing thread this has been.
Also, there is no inherent racial component to an H1B or other status.
The example of an H1B person seems to have been provided only as a sample to further illustrate the point that "Just quit on principle, rather than implement this thing!" is often not an acceptable action due to other effects.
You seem to be one of those “assume good faith” people, who knows exactly what the others actually mean.
And everyone in this thread is discussing how that company could be using American laws to pressure workers. This thread is an indictment of an American system, no one is blaming the H1B workers.
Same for if you’re disabled, your partner has a medical condition… moving between jobs can be cost less for some, but changing jobs is not cost less universally.
Which means in a given developer pool, there’s usually at least one person who “won’t put up a fuss about implementing industry standard code”.
The same is not true for a ‘cookie selection dialog’, where the stated goal would be to allow people to easily select what cookies they want to allow.
This is not why I got into software.
If you adopt this kind of metric/moral stance any web programmer workng in the last 20 years is guilty ...
This is only possible for people whose job stability or financial situation is above average.
Just look at all the engineers at Facebook, or even worse: the defense industry
* About 8 seconds on Docker Hub
* About 32 seconds on Starbucks
Umm what is going on with that one?
Or why doesn't Facebook support opting out here?
some newspaper sites start autoplaying a little video window, and it you click the "close" X, the player will keep playing for several more seconds with a phony subtitle saying "shutting down" or "closing"
btw why do some many sites do whatever they can to force a video to play when you click on them?
So there is a big change that this is a lot of outrage while there is no dark pattern here.
Granted, it could still be some sort of a polling situation vs. just a deliberate fake "make this take a really long time", but it still doesn't matter - it's still a dark pattern because the site owner is deliberately OK with the "opt out" solution being so onerous that hardly anyone would wait that long.
I still think this is a dark pattern (see my grandparent comment).
E.g. consent should be opt in and not opt out.
Here's a list of emails/sites for contacting your local authority and take action.
https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
I thought it was clever and unusually honest.
As if some tracking bullshit could ever be essential to anything.
> Almost nobody wants tracking cookies.
It's complicated because a lot of people do want to stay logged into certain websites. Even if that's not "tracking," what about recommendations? Youtube does recommendations for logged-out users, and I suspect a lot of people find some value in that.
Also, their site is currently VERY slow loading.
First we all know that increased loading time also increases the bounce rate - so we are all working really hard to minimize it.
If you add a fake loading time you actually say that you don't want particular users. Why then they don't just block the site if cookie policy is not accepted? Does anyone actually accepts cookies and expects website to work faster? That sounds very counter intuitive to me.
Actually wondering what you can achieve with introducing a fake loading time and how can company benefit from that.
The "beauty" of it is that so many websites in the internet are doing it, that even if it's your first time going to a website, when you see the cookie popup you already know the drill and are primed to just accept everything.
Why? They’re literally adding friction to their purchasing process. Nothing they sell is critical. Nobody’s privacy is being violated. They aren’t lying. They’re just being annoying.
This is the most trivial non-issue one could possibly get hysterical over.
Does that mean the law doesn't apply to them? You do business in Europe, you follow European laws + the laws of the specific country you're doing business with, doesn't matter what the type of business is.
The ePD is notoriously ignored and unenforced [1]. It is also not clear what part of the law a simple delay would violate. (Most of the sparing enforcement has been around dropping cookies after someone opts out.)
[1] https://petsymposium.org/2019/files/papers/issue2/popets-201... Figure 5
How, precisely? It's a one and a half second delay. Functionality is not changed one iota. No cookies are loaded.
Would it be better if there were an energy-burning inefficient server-side algorithm spinning away?
It's a decent attempt at an argument, but far from convincing. One could argue it's to dissuade opting out. One could also argue it's being presented to show the opt out has teeth. (Non-technical people ascribe meaning to fantasy progress meters. A number of UI studies have shown that.)
As for opt out needing to be instant in comparison to opt in, the argument holds no water. If a legacy system were patched for GDPR, it's reasonable for the opt-out to involve more code, not less, as an extra routine undoes the defaults. That or making a record of the opt out is done tediously. (In this case, the argument is moot since the delay is fake.)
The toughest argument one could make from the ICO checklist [1] is that a one and a half second spinner delay constitutes a material "detriment" or penalization of withdrawal of consent. Those are technically true to a trivial degree, but immaterial. Far from meriting a 1% fine per the original comment.
These kinds of arguments hurt everyone working for privacy by trivializing it to a sympathetically mockable degree.
[1] https://ico.org.uk/for-organisations/guide-to-data-protectio...
In this case, why isn't the same applied to the opt-in?
> If a legacy system were patched for GDPR, it's reasonable for the opt-out to involve more code, not less, as an extra routine undoes the defaults.
The GDPR mandates that no non-essential data processing should happen unless the user opts-in. Even if there was more code involved in making a legacy system GDPR-compliant, said code would need to be ran first (essentially applying the delay to the initial page load). Otherwise, since this consent form is overlaid on top of the existing webpage (as opposed to being on its own page with none of the trackers being loaded) this essentially means that data is being processed until the slow opt-out process completed, thus being in breach of the GDPR. In short, GDPR-compliant systems should work on the basis of "opt-in", not "opt-out". Having the delay on the opt-out proves that the system assumes the user has opted in (and thus immediately processes data that the user may not be willing to share) until told otherwise.
Also, regardless of the delay, the simple fact that the flow has a big prominent "agree and proceed" button which takes one click and then a less prominent "manage settings" which takes multiple clicks is enough for this to be in breach, at least according to the ICO's guidelines.
Seems your argument is that the change is trivial, thus safe to ignore; that there is some threshold below which changes to functionality don't matter. Do I read you right? i.e. "Important functionality is not changed one iota"
It doesn't get much clearer than that.
Of course it doesn't matter if the friction is 1.5 seconds artificial delay or if the friction is because you are forced to send an opt out in two copies via fax.
The only argument to why it wouldn't be in violation would be "it's too trivial" - but I don't think that's a very good argument.
People must not be punished for choosing to have their privacy respected. This is coercion.
The problem with having three sigma or more excess knowledge about a problem domain is that solutions designed for the center of the bell curve likely won't work well for the many-sigma outlier population, and the fraction of the population out in that many-sigma part of the curve is too small for providers to justify expending significant resources there. It's not uncommon for businesses to optimize for the center of the bell curve and leave many sigma outliers poorly served, as is happening here.
If they really needed this delay, surely it only needs to be a few seconds tops.