1. Client asks for something that is a dark pattern.
2. I outline that it is morally questionable to do that and give a suggestion on how it can be done otherwise.
3. Client insists that they don’t care or don’t agree because they feel as it will bring in more money.
4. I end up building it.
I do have the choice to outright say no, but I’ve found that it normally comes down to a compromise. Some clients are not willing to budge but we can always steer them in the right direction.
I understand it’s hard to say no but it would perhaps be easier to say “we’ll build that but it’ll cost you 5x more because we would be taking a legal risk”.
Making the option to follow the regulation cheaper has to be the goal.
There will be room in prisons when they let people out who used <blink> tags 20 years ago…
The developer knew what s/he was doing. We're not talking jaywalking here--this person (!!) made it slightly more difficult to make a choice that most users don't understand or care about anyway! And the result is more targeted advertising! How can you stand idly by?
Imagine your own mother being subjected to this kind of thing. Wouldn't you want jail time for the perpetrator? Would you stop there?
You're not being subjected to some kind of torture; in fact, you are responsible for sending the HTTP request and executing it on your computer.
You sound like a Stalin (I came from an authoritarian country).
Imprisonment usually does an amusingly bad job at "teaching a lesson". If you want to "teach a lesson", then why not torture?
https://en.wikipedia.org/wiki/Slippery_slope
There's nothing "authoritarian" about imposing criminal penalties on those responsible for not just violations -- but as in this case, egregious, massive and intentional violations of consumer protection regulations. It's just how a civil society works.
The vast majority of users like free websites and do not feel like targeted advertising is a serious problem. This was true before GDPR and these silly cookie warnings, and it continues to be true. Likewise, implementing a cookie dialog that requires more clicks to opt out completely is not so morally questionable as to justify the discussion I had responded to.
I'm not sure that's the right thing here. You'd end up with some poor junior dev getting punished for what is essentially a decision by their boss.
"The client didn't want to pay for a GFI so it's not my fault he got electrocuted ¯\_(ツ)_/¯"
However a large amount of dark patterns aren't legally forbidden anyway.
No, the solution is jail time for the founders and board members of these companies. Along with extremely harsh and vindictive confiscation of their assets.
And generous incentives for developers (such as the GP commenter) to snitch on these people for asking them to be knowingly complicit in their immoral activities.
Just that about 99 percent of our resources should be focused on those with the most leverage over the situation.
It's about focusing on people with (1) the most leverage over the decision-making process and (2) perfect visibility into the consequences (legal and otherwise) of their actions.
That is -- when you're dealing with the mob, you doing go after the delivery boy. You go after the foot soldiers and kingpins.
That's not how the world works. When she says no, they just find someone else.
That they don't have leverage over the decision-making process seems like a cop out.
No one said they have "no" leverage. Just that those at the executive level have infinitely more.
I never liked the "will find another" trope.
The Chinese , after the opium wars, simply executed dealers and users.
Very radical, but you bet dealers wouldn't just find the next user and vice versa
There's potentially a lot of inherited DNA out there that could cause damage to society in the future.
That quickly turns in to, the rich guy who will profit from the lawbreaking needs a scapegoat. Always more dignified to tell important people they're out of line by punishing their serfs, don't you know.
I don’t mean developer as in an individual contributor, I mean an implementor, often contractor, which will normally be a company too.
Right now it’s too easy to cut out a niche of selling snake oil services like “automatic cookie banners” with dark patterns and batteries included. Meanwhile companies are fooled by these companies into thinking that if they just pay the $ for their “compliance solution” they are done. Here is where I’d like to see the sellers of the snake oil take part of the responsibility and not just the buyers.
Unless, of course, they have some weasel note in the terms, which is far easier to do in the B2B space.
Are they aware that this is when they stop complying, to the point that they could just as well have ignored buying the banner service and just shoved cookies on people quietly like they did before? Perhaps. It's possble that lawsuits could work here too. I'm (like you) guessing there is some fine print saying that you absolutely cannot use the switch that makes the "reject" button disappear under the mouse and have a delay of 60 seconds. And if you do then you are responsible yourself.
Modern weapons require cutting edge engineering. Going after web devs but leaving alone engineers who created litteral death machines would be an interesting position.
Now, engineers could decide to make software engineering a real discipline by getting a regulatory body with and start enforcing the tittle properly (but this is widely unpopular and as far as I know, not done anywhere).
Also, weapons manufacturing isn’t illegal I can’t see how there could be a case for going after anyone for it? We don’t have a morality and ethics police (at least not in most western countries)
They might complain to their manager, even log a formal notice that they believe this feature to be breaking the law (if they are smart), but quitting a company for this specific dark pattern seems a bit unusual.
There’s a lot of a-moralistic attitude towards FAANG on Hacker News, which honestly I find strange; Google and Facebook in particular are just giant douchebags with lots of cash.
FAANG (and any VC funded company that touches ad revenue) is already selecting for developers who are willing to overlook these kinds of things. It's one of the reasons why they need to pay people so much more.
If I tell my boss that doing xyz is illegal and he doesn't dispute it, I'm absolutely certain he would not ask me to implement it.
Certainly there will be shittier bosses that will ask anyway, demand it, and perhaps even go so far as to fire someone for not violating the law, but I should hope those in the last category are few and far between and there would be internal and/or external outcry over it. Even if you have a boss that wants to fire you over it and nobody cares internally or externally (I'd find this situation very unlikely), you'd still get unemployment benefits / severance / whatever is typical in your jurisdiction, since you were fired rather than choosing to leave yourself.
what happens when xyz isn’t illegal?
I was specifically talking about the scenario where you're asked to do something illegal and immoral, and its illegality is not disputed by the boss or legal team or something.
I don't quite understand what you're trying to say. If you were asked to kill someone, clearly you wouldn't say "what are you supposed to do anyway" and go off to find a murder weapon since the answer there is rather obvious. What makes being asked to violate a different law different? (Assuming you find the request morally objectionable, I've probably violated laws that I thought were counterproductive for everyone.)
Now, how severe is this? You're not a lawyer, you can bring it up, and the company lawyers (that are paid maybe more than you are) say they reviewed the spec and it's legal. What standing do you have, as a developer, to say "no it's not legal, I won't do it!". Do you really know better than the lawyers?
[edit]
> If you were asked to kill someone, clearly you wouldn't say "what are you supposed to do anyway" and go off to find a murder weapon since the answer there is rather obvious.
What if you were a soldier? Or a drone pilot? Is the answer still obvious?
I'd be very surprised if anyone thought this was clearly legal after reading the law. But yeah, that would be a valid answer to the question: legal team says it's legal. If something is legal, you cannot be prosecuted for it, and you can have some reasonable confidence in lawyers reading the law and providing legal council correctly.
However, you were saying "I have implemented things that are illegal. I objected against it in meetings", so I was more thinking from the scenario where everyone knows it's illegal but the dev is asked to do it anyway. Presumably not even explicitly, just implicit "we need this feature" without ever bringing up "and we know it's illegal, but if you want to keep your healthcare..."
I think a lot of this dark patterns would be even darker but for the push-back by some developers. Though I've been at companies where some workers are like robots and will carry out management's desires down to a T, even when the idea is total insanity. Some workers are immigrants who cannot afford to lose their employment or they will be thrown out of the country and potentially lose their partner and children.
When I have to work on my own projects, I generally avoid all dark patterns - I try to go as far in the opposite direction as possible, while still generating revenue. Though, with the torrent site I built once, it was "Anything Goes". You're already running an illegal site, might as well write something that bleeds the users dry if you can.
EDIT: I want to add that most of it was down to lack of technical knowledge by management. They were business guys who didn't know the Web. Most of the time they weren't trying to be assholes, it just appeared that way.
- Only a tiny fraction of all web devs read HN
- If business wants something done, the devs are rarely in a position to oppose the decision
I think so. There are many devs who are against government regulating the web and will happily code around them. HN is pro regulations so it's either keep quiet or get down voted to hell.
The customer in this case was rather non-technical and just wanted his tracking, so he wanted to have it like everyone else does. I/We actually told him very clearly that this is most likely illegal and talked it down a notch (from having "reject" hidden in the text), but he said he checked that with legal and we should do it. Loosing the customer over this was really not worth it (especially since this is basically the way cookie dialogs are done everywhere), so we did what he asked, with our asses covered in case it backfires. I might send him this case, though.
On a side note, it was really hard to implement the cookie dialog correctly so that it only loads Google Analytics and our tracking when ok is clicked. We thought this was a solved problem, but nope. Especially when you want to delete cookies when consent is revoked. I would not be surprised at all if most dialogs actually don't work at all.
Often what happens is that someone (hopefully you) will raise the issue internally, but if the company decided to ignore regulations and take the risk of legal punishment, well it's not an engineer that will be able to stop it from being implemented. Hopefully such fines will make product owners and upper management consider the problem more seriously, but I wouldn't bet on it.
I made a client side firewall-esque library for Transcend Consent Manager so that site owners can load trackers immediately and locally quarantine tracking events for replay once consented.
This makes it possible to track like before but move the annoying cookie banner into an integrated UI so that site owners can ask for consent when the user is more invested in the site (e.g. during signup/checkout).
each these people may have a different viewpoint on what they want to happen and why
And they're thinking: "Yup, that's me. That's my handiwork, my impact on the world." And then they think: "But what can you do? R&V, R&V, R&V ..."
As in: rest & vest
These types of engineers will also build stupid stuff that doesn't work, because that's what the specification written by a group of business people who have never even looked at code before said.
It's also why frameworks like React are popular.
It's a bit sad, but each time you try to be nice and friendly, you get "raped" I feel, so well, might as well make some money off of some people to pay for when we get scammed ourselves.
The original saying (that I don’t necessarily agree with) is not about competence but about ethics: if every ethical person refuses to work in weapon manufacturing/ advertising / whatever is deemed morally unacceptable, then the only people that will do it are people with no morals and we will be worse off as a society.
So really, in this case the person just shutting up and doing it is already the worse fallback.
When they get fined in France the basis is a French law. Probably a law to implement an EU directive. The cookies directive (don't remember the official name) is older than and different from GDPR.
Sub-processors are not allowed to sign data processing agreements.
So not that clear it would seem ...
Sub-processors are not allowed to sign data processing agreements.
So not that clear it would seem ...
If GDPR allows controllers to slip out of their obligations by using sub-contractors to firewall their legal responsibilities, then it would be useless as a data protection law. If you want to run a data processor that relies of byzantine structures in an attempt to create plausible deniability, then you’re gonna have a bad time.
Ultimately this is just a problem of dependency resolution, and conflicting dependency requirements, but it’s an unavoidable problem if you want to have truly accountable data controllers. Accountability is far more important than operational convenience. Remember GDPR exists to protect EU citizens, not businesses. It explicitly makes life hard for business, to ensure protection for citizens. Don’t like it, then leave, go exploit some other population.
And that's why it is.
Because it didn't take into account how companies work in practice.
A SaaS company has both individuals as well as organisation as customers and thus operates as a data controller and data processor.
Reality is that you can't ask each individual company to sign a document for each new subprocessor or data processing agreement modifications.
What on earth are you talking about? I’m making fundamental statement about accountability, you can’t allow companies to outsource their data protections responsibilities, because history has shown time and time again, if let companies outsource responsibilities, they’ll outsource it to someone who just ignores the law and provides a fig to protect execs.
> Because it didn't take into account how companies work in practice.
The whole point of GDPR is to prevent shitty business practices, not enable them. How companies work in practice is most irrelevant, GDPR protects people, not companies.
> A SaaS company has both individuals as well as organisation as customers and thus operates as a data controller and data processor.
Yes, so what?
> Reality is that you can't ask each individual company to sign a document for each new subprocessor or data processing agreement modifications.
Yes you can. If your customer has given you explicit instructions on how they want their data processed, in the form of a data processing agreement, then you’re contractually bound to that agreement. You want to change it, the you need to ask all your customers. You can’t unilaterally just start doing something new with data you’ve been given because you feel like it. Otherwise what prevents you from just deciding that selling all the data your customers gave you is how you now handle their data?
I don’t know you find this so difficult to understand. Your not even taking issue with something unique to GDPR. Modern day slavery laws work in a similar manner, so does financial regulation, so does any contract where you customer gives you instructions, and you want to modify those instructions. Companies update their T&Cs and force customers to explicitly accept the new one all the time, this is not a new concept.
This was while working at a bank, where the level of scrutiny from financial regulators, privacy regulators, and customers with a bone-to-pick with us was sky high. It’s was a total pain in arse dealing with data protection agreements, and vetting them (both the agreement, and company) to make sure they met the standards. But you can bet your bottom dollar we did it.
I skimmed this [paper](https://epub.wu.ac.at/7523/1/HCIS2020_A%20Human-centric%20Pe...) which, among its main topic, argues the issue being intentional and ubiquitous, but I am unconvinced.
GDPR (which is basically all such acts from across EU in one legislation) has been around since 2016.
If in 2021 your company pretends not to understand the law, your company deserves to be sued into oblivion
some/ most implement directives in cut and paste manner some don't.
No. The fact that the last letter in "GDPR" is not "D" is a pretty good hint that it's not a Directive ;)
It's a Regulation. Regulations apply directly, and are not translated into local law.
But omgitsabird is correct that GDPR is not the relevant basis here, but a clause in French Data Protection Law. And this clause exists because of the ePrivacy Directive.
I hadn't realised that regulations existed in this manner
https://en.wikipedia.org/wiki/Regulation_(European_Union)
so the EU regulations come into Law of all EU countries via "Article 288 of the Treaty on the Functioning of the European Union"
IMHO, as long as devs weren't trained on cookie law, they are not morally responsible.
If you want to block third party cookies you have always had a switch there in your browser options.
If 5 years after GDPR went into effect you still don't know what it is and why it exists, your company deserves to be sued into oblivion.