Outlook just asked me if I want to upgrade to bigger ads
twitter.com
twitter.com
Here's the CJEU case in question: https://www.insideprivacy.com/european-union-2/court-of-just...
Like the ones in my Gmail.
I came across an EU site that now make you click accept before they show you the LINK to a youtube video.
This is a video they made themselves. It's really interesting
Politics dont understand the web but noticed its dengerous if left unregulated.
And EU tax avoidance is mainly done through Ireland and the Netherlands which are still member states.
You are also confusing legislation with rulings. GDPR says your business interests cannot outweigh my rights. That's it. Now courts find that leaking my IP address to third countries is something that harms me more than it does your business good. I can live with that.
Anyone with half a brain and a real intent to reduce tracking would have mandated websites abide by the existing Do not Track toggle. Unfortunately the law was instead introduced by politicians with strong lobbying from media industry. So no brain, and no intent to reduce tracking.
If the law was instead “no non-essential cookies may be stored when the do not track flag is set”, consumers would be far better off. But that’d cause significant financial impact to the media companies that lobbied for the current wording, so now the whole world is screwed.
Yes, and the result of that nuance is less privacy and more annoyance. It's an open invitation for sites to use dark patterns to get you to "agree" to tracking. (In fact they "have" to use dark patterns because they specifically aren't allowed to offer you anything in exchange). Either banning tracking outright or requiring sites to obey the DNT header would make much more sense.
Your browser opens the connection to the original website and downloads the base page. That base page references images and js and fonts hosted elsewhere, so your browser opens a connection to download those images. At this point the browser could pop open a dialogue box that says "Hey you said you wanted to communicate with foo.com but I need to grab a pic from bar.com is that cool?"
At no point in this use case does foo.com send anything to bar.com
IE 6 in the default configuration did something like that with its yellow bar, IIRC, and all it amounted to was the fastest known method (minutes, for me) to provoke warning fatigue and make people vulnerable, seeing as the same UI was used for installing ActiveX controls.
(Could be it did that all additional resources, though, not just those from a different origin? I don’t remember since I disabled the whole thing near-immediately even when I did actually use IE 6.)
This is unworkable from a usability perspective for as long as hotlinking to external resources is so commonplace. And a user permission might not be an effective way to do this, anyway, given the imbalance in bargaining power, as already seen with adblocker-blockers and such. (See also the 2006 paper, “A pact with the devil”[1].)
https://developers.google.com/fonts/faq#what_does_using_the_...
They don't say how long the raw data is kept either, on a page trying to minimize the tracking, so we can probably assume it's longer than necessary for technical purposes.
They keep it separate from their other tracking, but that's still collecting user data.
No.
The fact that you linked that page makes it seem like you agree that a CDN could collect user data.
So what would it look like to meet that bar, by your reckoning?
This is an extremely disingenuous way to phrase it. It's deliberately not hosted on a domain which would have any session information sent. There's no tacking information set by that service. I invite you to actually look at a call to this service (you'll want to Google "browser developer tools", that should get you started) and realize that there is no user data in the request. Because of course there isn't.
>...makes it seem like you agree...
Ah, the classic tactic of standing up a weak strawman and then arguing against that. Good to see you again, nemesis.
It's not disingenuous because I was going by what those terms allow. They say nothing about detail level, so when I talk about whether they could be tracking you I will talk about the worst thing those rules allow.
> It's deliberately not hosted on a domain which would have any session information sent.
Being a separate service from the rest of google is an entirely different question from whether it tracks you. And tracking doesn't need session cookies.
> There's no tacking information set by that service. I invite you to actually look at a call to this service (you'll want to Google "browser developer tools", that should get you started) and realize that there is no user data in the request.
That doesn't stop them from fingerprinting me to a moderate extent and storing that with my IP and exact time forever.
> Ah, the classic tactic of standing up a weak strawman and then arguing against that. Good to see you again, nemesis.
It's not a strawman. Strawmen don't say "makes it seem". That's my doing my best to figure out your opinion, so that I can effectively respond to it, and making it very clear that I'm guessing.
So are you saying that guess was wrong, or are you being vague on purpose here?
In terms of strawman and related, my guess would actually fall under "steelman". Assuming the opposite would have been a strawman. Because if my guess was wrong, and you don't think it's possible for a CDN to collect user data, then why did you make this conversation be about a specific CDN in the first place?
> if my guess was wrong...
As I have previously said, you're totally wrong and your misunderstanding is so far from what I said that it's hard to understand how you got there. You asked if CDNs that don't track user data needed to worry, I gave an example of one which doesn't track user data and still got into trouble.
That's not disingenuous. You disagree with me about what counts as "details to log". Nobody is acting in bad faith.
> As I have previously said, you're totally wrong and your misunderstanding is so far from what I said that it's hard to understand how you got there.
I made a post talking about the difference between a "CDN that tracks people" and a "CDN that doesn't track people".
You responded by linking a specific CDN as an example of a "CDN that doesn't track people".
So I guessed that you agreed that "CDN that tracks people" and "CDN that doesn't track people" are both things that exist.
Why is that guess "so far from what you said that it's hard to understand"?
You're saying you don't think that, so why didn't you just say "No CDNs can track people"?
If every CDN is a "CDN that doesn't track people", then what use is it to link the terms of a specific CDN? If no CDNs can track people, then it doesn't matter what their terms say!
-
But as to your argument, I think your definition of tracking is too narrow, but I don't see any way to convince you otherwise so I'm not going to attempt that.
Now people say "oh but if every website hosts their own fonts the browser can't cache them" while sending me 35 megs of shitty tracking Javascript code.
There is a very clear aggressor here and it's not the EU or the regulators.
[1] https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
[2] https://github.com/w3c/webappsec-subresource-integrity/issue...
[3] https://hillbrad.github.io/sri-addressable-caching/sri-addre...
But it's not "everyone" - it's you. Your computer sends out all the information that is requested from it. That's how the internet is built. Even when a website tries to use an external font it is still your browser that asks the font host for the font.
It seems you either missed the point of what the post was getting at, or you are being purposefully obtuse about it.
I agree that it would be nicer if websites slurped up less data. But to portray a lot of this stuff as the user being the victim is ridiculous. The users are the ones that voluntarily started using browsers made by an adtech companies. There are alternatives but they don't use them! And yet they complain that their data then ends up with the adtech company because their browser, that is under their control, sends it to the company.
Of course, the web browser should do something about it... but the adtech company built that too. "That's how the internet is built" is an aggressively dismissive attitude, because there are specific companies building the Internet. Note that every new trash web standard is written by... oh, yeah, Google too.
Sidebar: I block Google Fonts. You should too.
If this was a clickable link to Google, and the EU was saying that telling people to go to Google makes you a GDPR data exporter, then I'd be up in arms about this.
But it's not.
What we're talking about are subresource references, not anchor links. Those get loaded automatically without user control, and users do not get the ability to audit them by default. So it's reasonable to argue that subresource requests are "caused" by the developer of the website, not the user.
Furthermore, this is how actual ad trackers work. It's very common for ad trackers to include a reference to either a script file or a 1x1 pixel GIF (the latter called a "tracking pixel"). This isn't a misinterpretation of GDPR, it's the heart of the issue. If we treat subresources the same as clicking a link, then GDPR is a hollow, toothless meme of a law.
Then make one that does. Or demand for one. But everybody wants to use Chrome and then they're surprised that their browser doesn't give them the control they want.
The whole point is that Google gets your data because you send it to them. Your browser and computer are under your control.
It's no wonder Apple thrives while taking away control from the user. Because when we do have control we just don't use it.
>Those get loaded automatically without user control, and users do not get the ability to audit them by default. So it's reasonable to argue that subresource requests are "caused" by the developer of the website, not the user.
It would only be reasonable to argue this if you think your computer/browser/os is not under your control. NoScript has been a thing for a long time. How many people actually use it?
The same concerns apply to NoScript and that browser extension the FSF has that bans non-Free JavaScript. If you point them at GDocs, you don't magically get a tracker-free, Free Software word processor. You just get a broken web page. The reason why users don't exercise this control is because they don't have it to begin with. It's not their webpage to modify.
On a more meta-level, you're arguing for technical controls & DRM where legal ones are needed. We don't want browsers where users can pick and choose where their data goes, but if they choose wrong and don't enable enough trackers they don't get the website they wanted. We want websites that don't have trackers on them to begin with.
The problem was the legal framework to enforce it didn't exist so the industry was just using it as a suggestion. The EFF's voluntary declaration didn't help either.
I think if it had been enforced in the style of GDPR it would have been a great thing to have.
https://andydavies.me/blog/2018/09/06/safari-caching-and-3rd...
https://www.zdnet.com/article/chromes-new-cache-partitioning...
https://arstechnica.com/gadgets/2020/12/firefox-v85-will-imp...
Then the consent question would actually be presented in a balanced way. And the preference could be stored even if you wipe cookies. At moment if you distrust cookies, your preferences expressing your distrust of cookies is constantly being reset forcing you be re-prompted again and again.
(It might be harder for regulation to require changes in browser though, and then there's legacy browsers, so I can see how we ended up here)
And legal precedence wise, laws have been requiring things of websites for a long time, but I can't think of any legislation that has required certain behavior by browser applications themselves. Since browsers, in theory, just implement open web standards, requiring something of them is effectively legislating a forced change into web standards. That's a spooky thought.
But let's be real... having individual websites ask for cookie and 3rd party request consent makes opt-out massively less popular than if this was built into the browser. If the "disable ad-targeting cookies" button wasn't hidden behind obtuse UI bespoke to each site, far far more people would opt out of them. I suspect that's a big reason why we got to this arrangement.
The browser has no way of knowing what kind of tracking is going to happen on the server it's connecting to or what jurisdiction that data would fall under.
If trackers would provide metadata indicating what kind of tracking each resource is going to do, then browsers could handle it, but trackers would never do that without being forced because they want to make opting out of tracking as painful as possible.
(Then there is a separate issue with a human rights dispute between EU and US that makes things a bit more complicated)
> You either have to host everything yourself, or ask the user for consent first.
As a user, I am very very glad that this is the case.So it is approached from the consuming end for better or worse.
Acting like the EU isn't reacting to american spying is frankly just ignorance of the situation.
This was somewhat common in Germany for years. I also remember Facebook buttons behind such an opt-in mechanism.
Such a disgustingly unethical design. What kind of sick people come up with this stuff?
Edit: Perhaps showing ads in line with real emails is less visually intrusive then traditional "banner" ads. I take issue specifically with the false choice presented to users in order to manipulate them.
Well, Microsoft in this case, and companies like it. They're out to maximize the profit they can extract from their users, so they will do so. People aren't leaving their products in large enough quantities for them to stop doing it.
Which makes this a good opportunity to re-evaluate whether you really need any of their products, or at least see if you can reduce your dependency on anti-user companies.
For people in the software biz I think being allowed to make quality products is one of the most important aspects of our working conditions, particularly for our social standing in the long term.
Edit: AND unionize AND vote for proper labor rights that make unions unnecessary. I just mean to say that it's better to remove the problem rather than trying to "battle" it with more force.
It's not asking for money nor does it save your personal information, it's just a Github CoPilot for resumes.
The linked thread talks about a "home" version, and I have (I assume) a business version, though I dont remember seeing an option, that may be why
Probably a lot of the fine guys and gals on this forum, or people we would all work with. Lets be real here...
We simply need to change the incentives. Calling people names just has zero effect on the situation.
How do you propose to change the incentives? The incentives are money. Surely you have something more helpful than whatever you wanted to accomplish with your retort.
HR are sick and vile
Is it? I think this an overstatement.
then should n't that UI layout be specific only to EU users?
Similar to clicking buttons during checkout flow that literally say things like "No, I don't want extra protection for my purchase".
When did various mail providers start deciding to go from having a spam filter as a selling point to having spam built in?
plus email inboxes have a huge amount of valuable data it could be one of the most relevant ad experiences if they truly leveraged that data. I buy ads and don't have a problem with a lot of the industry, i'm minority on that here. To me highly relevant ads are way better than mortgage loan quicken shit ads and virus crap I see otherwise.
But I would especially hate ads showing up in my mailbox. I pay for O365 business so they don't, but if they did I would drop the service immediately. Spam is a big problem and artificially adding ads on top of all that makes it even bigger.
Those are niches, though, not "any sort of pc gaming."
I remember free flash games. I wonder if flash dying, and then nothing quite replaced it, in terms of being 1) easy for the user to 'install' and 2) easy for the creator to make something.
There was also stuff like Urban Dead and Nexus War, almost like MUDs for 2007 or so. Urban Dead is shambling along appropriately enough...
From what I gather all the growth, audience, and money moved into "social gaming" (fb farmville / Mafia wars) and mobile.
Some players from Urban Dead (the spark more or less came from the ridleyband resistance front, I think) eventually made Nexus War, which had a similar feel to it, but better design (skill trees, etc) and a more interesting theme (angels vs humans vs demons). Eventually that shut down, and somebody from the community made a similar game called Nexus Clash. That's still running, although I guess the population is probably ever-dwindling.
This sort of asynchronous mostly HTML based game seemed to be really good at fostering a community. Play the game a bit, find a faction of some sort, and then join their phpbb forum...
I also got single GPU kvm passthrough working the other day so I don't even need to dual boot.
You could even take a principled stand and just not play those games.
Yes, this requires having two PCs, but I don't need a GPU for Ubuntu anyway (the integrated one suffices).
I also like my hardware isolation between Microsoft/NSA spyware/adware my actual computer.
What makes a good PC for daily work is also very different from what makes a good having PC. My daily driver is a quiet and energy efficient NUC. My gaming PC is quite noisy with its 3080Ti..
I'm sure I can bring noise levels down with expensive fans but consumption will remain higher. This way I don't have to as I always game with a headset on anyway.
(In fairness, it was then and is now otherwise free of charge, isn’t it?)
buy airpods? start getting more ads for music
How else would you present the tradeoff to the user? How is the presence of the tradeoff any more of a "dark pattern" than if they had simply turned on inline ads with no option to avoid it?
Instead of just moving to a different ad delivery mechanism (right option) they are still trying to push the inline option (which is objectively "worse" for most users, but good for bottom line) as the best choice, using language that make the "good choice" seem like a stupid option (slower and less space). Hence the language and design here certainly reads like an anti pattern to me.
I don't see how the inline option is objectively worse for most users. If I had to have ads in my email client I'd definitely prefer inline. My normal email already includes things I don't normally read so I'm already skimming the inbox to select what to read and discarding the rest. Ignoring ads would be no different than ignoring the other things I ignore. Unless they went totally overboard on the number of ads all it would do would mean maybe a little bit more scrolling on average to get through the inbox.
Having a separate ad section would be a lot more distracting and would likely reduce the space available for displaying the messages that I do read.
Inline is certainly the worst option for most users. If the ad is always displayed in the same location (a location separated from what you're there to read: your emails) it can be ignored. As big and distracting as they'll try to make it, most people will eventually tune it out entirely, because they already know nothing they care about will be there. The term for this is "Banner Blindness" (https://en.wikipedia.org/wiki/Banner_blindness) and it means that most people will spend very little time paying attention to the ad.
Inline ads are mixed in with the content you care about (your emails). You say yourself that you'd be forced to skim over them along with everything else that you're forced to evaluate to determine if you actually care about that message or not. That means every time one shows up you'll be forced to determine if what you're seeing is an advertisement or an email that you may or may not care about. You won't be able to become blind to the ads because that would cause you to miss important messages you want to read. Ads, legitimate messages you care about, and legitimate messages you don't care about, they will all need to be evaluated and that will require you to read the ad the same way you are forced to read the sender/subject lines of the email in your inbox you don't care about.
Microsoft knows that inline ads are more effective. It's why they are pushing them so hard. Microsoft wouldn't try to manipulate people into selecting an option that wasn't advantageous for Microsoft. They aren't looking out for your best interests. They are looking out for themselves at your expense. Any time they seem to be steering you toward something, that's a warning sign that you should be extra careful.
Do inline ads really make that much more money? I would have thought advertisers would pay more for bold in-your-face banners over subtle grey text somewhere.
How? I laid out precisely what the choice is in my comment, but I'll lay it out here again: smaller, inline ads vs larger, out-of-mailbox ads.
There are positives and negatives to both. The only sense in which this is "not a choice" is that you will be served ads regardless, but "free service has ads" is not "a new dark pattern", in any way.
If you think we’ll all kiss the corporate boot and accept the limited range of options offered, think again. The better choice is the one not presented. Hint: it’s obscenely visceral.
But believe it or not, not everyone is simple-minded enough to think that it's impossible to be incorrect as long as you're rooting for the right "side".
There's a group of people (let's call them "adults") who are capable of discussing reality in more detail than "hurr durr ads bad". The claim I responded to was that the choice of ad format was a new dark pattern, which is a specific claim that's independent of your feelings about ads overall.
For someone this supercilious, you sure make a lot of bad assumptions en route. The only person to have used the phrase “new dark pattern”, by the way, is you. So if you want to argue whether it’s new or not, go right ahead: you’re just arguing with yourself. If you want to argue it’s not a dark pattern, then good luck on the next zebra crossing.
I’m not your “buddy”, either.
From the comment I responded to: "Add this to the list of dark patterns". (You don't _add_ existing instances of a category to a list enumerating that category)
As it seems the only thing worse than your emotional continence is your reading comprehension, I should probably take my leave of this "conversation". I hope your day goes better than it has been.
There are multiple interpretations of "Add this to the list of dark patterns". The asinine paraphrase of this to "a new dark pattern", especially coupled to the absurdly rigid thinking of the explanation offered, is not merely one of many interpretations; it is the least likely, because the general case of Hobson's choice and its related dilemmas have been recognised for centuries. Ergo, we can trivially reject that interpretation. The author might instead merely be suggesting this is their first personal recognition of such a pattern, or they could be imagining a list of specific instances of major tech companies deploying such a pattern, or offering simply a figure of speech to say "this is a dark pattern", and several other variations besides.
Tip: the world is not a fucking Lisp machine.
In light of which, the cheap crack about "reading comprehension" looks even more sophomoric.
What's more, none of that invalidates the actual point, viz. it is one.
Presumably the reason they're pushing people toward inline ads is they're harder for adblockers to block?
You know, bugs are inevitable.
Very glad I'm not using web-outlook (hotmail?) for my e-mail.
Then again I would not see the ads anyway. In the case of the tweet we're discussing, I would probably have opted for the "bigger ads" which seems more easily removed by uBlock origin.
Except every fifth grain in the bread is rocks.
Like, it is surprising they decided to make that an option. Nobody adds options these days. But it should not be surprising that some people would prefer different options. If I had to guess, I'd assume the big ads version is the old behavior and the small one is what they are migrating to for consistency between mobile and web (or higher revenue).
Seriously, though, I do wish there was a non-profit (similar to signal) that focused on providing free first class email.
I'm assuming most people have no idea about the "advanced" options when it comes to email. Most non-tech people use a browser based gmail/yahoo/etc. account or (ugh) their ISP email
I'll also point out that it takes two to tango and most every internet content company is actively offering free stuff. I suspect one reason that ad-based revenue models are so hard to remove are because eliminating it would require coordinated effort on two separate axes:
1) Consumers would have to coordinate on, "From now on, let's pay for all our services"
AND
2) Companies would have to all agree, "Let's stop providing free product subsidized by ads"
Without some sort of drastic fundamental shift in technology or radical technological invention, I just don't see it happening. Maybe someone makes a killer OS or product that has ad-blocking built-in from the ground up and is also so amazing that everyone switches to it, and so suddenly ad revenue drops to near zero? I guess we can dream.
I'm not even sure that's the dream I want. There has to be a middle ground with free services paid for by privacy-respecting ads, right?
If your site makes its money by showing ads from some third party ad network, that is just going to be ordinary corporate income which you will deal with when dealing with the corporate income tax in your country and/or state.
If your site makes its money by selling products or services to end users it will still be ordinary corporate income in your country and/or state but it will also be sales income and so may also be subject to sales taxes or VAT where your customers reside. That can easily result in you having to deal with taxes in several dozen or more jurisdictions.
If you can make enough money from ads it will almost always be a lot less hassle than making your money by charging customers.
Ads in your email that skip the spam filters or big ads on the side that may slow down your browsing!
Nonetheless, I appreciate that they give you three options (inline, sidebar, paid no ads).
Imagine having that option on Google Search?
They're playing on the idea that users will think "Bigger ads? Why the hell would I want bigger ads? This is obviously a trick to try to get me to click that.", when in actual fact, Microsoft don't want that.
The choice is actually between having ads show up as faux-emails (making them difficult to avoid) and having them show up on the side (making them easier to ignore, despite the "Bigger ads" copy). They want you to pick the option where you don't have banner blindness.
We now have push-polling notifications.
https://twitter.com/edgalligan/status/1494746064318091267?s=...
Despite webmail's many flaws, I haven't found an MUA that's as good for me as the Gmail web UI.
- Most MUAs choke on my archive. Simple searches take seconds.
- Every modern email service has a tag-like construct. Representing tags in IMAP duplicates messages.
- Decades later, IMAP sync is still slow, unreliable, and annoying to debug.
- A surprising number of MUAs ignore account boundaries when integrating with my contacts.
- Depending on my job, I go through years-long periods with lots of calendar-related mail. Tight integration between Google Calendar and my mail client is very convenient.
- I use snoozes and (especially) delayed sends often.
- I use all these features on my phone, too.
I haven't found an email client that solves all these problems, on both my laptop and my phone, that's better than Gmail web UI + Gmail iOS app. With two exceptions, all the clients I've tried are slower and less reliable, and they often have fewer features important to me. These days, they're often a less-polished, poorly-tested website in an Electron container. I'm happy to pay for GSuite (or whatever they're calling it these days), because I get ad-free clients that work for me and excellent uptime/deliverability.
* The only genuinely good clients I've found are Mailbox (never shipped a stable desktop client, but had useful innovations) and Superhuman. Mailbox was discontinued post-acquisition, and Gmail has implemented their best features. Superhuman is fine, but not worth paying for (though I'd perhaps feel differently if I spent hours each day in email).
I use webmail + Firefox containers to access multiple inboxes at the same time. I have like half a dozen email accounts that I access regularly, so it works well.
Pay with your wallet or pay with your eyeballs & personal information.
Use a better email client.
Thunderbird
Browsers can't, and absolutely shouldn't, do everything.
If you are asking if you can login to a webpage you want webmail: horde, squirrelmail, roundcube.. rainloop looks like gmail, Zimbra, mailspring (has undo send), Cypht, mailpile...
Mailspring
What is very unusual here is that they are asking you if you want bigger ads, a slower experience, and recommend that you don't chose that option. There is also an ad free, paid alternative in the small print.
It is the opposite of what the usual suggestions are. Generally, the most predominant is the paid option, then the one with big ads, then the one with small ads.
The most probable reason here is that they want to show you that if you don't like integrated ads that look like emails, you can, but it will be terrible. Maybe it is a legal requirement or something.
This is yet another option, Outlook the email service. Neither Outlook the Office application nor Outlook the bundled free Windows mail client have ads (currently).
This is only the free Outlook mail service web interface.
In the thread on Twitter Adam Waltham stated (imho quite correctly):
'This is the point, they want to make “show the ads separately from your mail” sound like a bad option, because they make more money when the ads are disguised as emails in your inbox.'
So this very dark pattern is designed to make you not click to see bigger ads. They want you to have ads disguised as emails in your inbox. And because you choose the are legally in the clear in the EU because there new regulation (as stated other places in this thread already) requires them to.
"Either the user controls the software, or the software controls the users":