Manipulative Consent Requests
wideangle.co
wideangle.co
This is one of the more annoying ones for me.
I'm probably navigating in a very goal-directed way, with various efficiency tricks, juggling tabs and windows and thoughts.
As soon as I see the "Accept Cookies" and "Manage Preferences" button pair, I assume one will let me see the page, and the other make me go through a pile of disingenuous, punitive nonsense.
* "The [French] CNIL's guidance reflects the position of the European Data Protection Board (EDPB) and the Court of Justice of the European Union (CJEU)." [1]
* "although the CNIL’s decisions are only binding in France, these decisions should worry any website operators who have adopted similar cookie banner mechanisms to Facebook and Google in other European countries." [2]
[1] https://www.termsfeed.com/blog/french-cookie-compliance-2021... [2] https://www.technologylawdispatch.com/2022/02/privacy-data-p...
I noticed it months ago, but always thought they unlike most others had a lawyer that could read.
Edit: I'm bookmarking this for future reference and recommend others do to. It is proof that it is doable.
Is this in jest ("_ironic_")? If so, I at least am so used to such dark patterns that it did not register as a joke.
If it's meant as a joke, then OK, I can chuckle. But while I'm curious to see what happens, I'm not pressing no buttons, no sir, joke or no joke. I'm jaded like that.
I recognized that using a smaller X close cross button was not fair and could lead, especially on mobile, to undesirable action. Now, the button is equally sized, and this should prevent accident presses for those not interested.
(The orange button has a brighter background with the same white text, making it look like the lesser option.)
Of course I understand that it can decrease CTR :(
Dark patterns get clicked (I don't know how well they convert)
"This site uses cookies if you are logged on. But even if you aren't logged on, we share your browsing details with 6 other companies from around the world. And they sell your details onto other companies and possibly governments. We don't know. But we get $0.0003 for it, so we really want you to say yes to the following question.
Do you consent?"
Before this got reigned in a bit, I've once encountered a pop-up that required me to manually opt-out out of more than a hundred trackers, one by one.
When I'm king, you will have to assume lack of consent without asking. If users want to be tracked they can opt-in by emailing trackme@<your domain>.
That's one of the things the GDPR was created for. If your data is being shared, you must be informed of with whom it is being shared, and for what purpose.
And if the only reason the data is being shared is so that you can earn $0.00003 for it, rather than being necessary in order for you to provide the service, than you probably need consent anyway. And at the minimum, you must offers users the option to object to that processing.
vs
"I do not want my grandma saved from a house fire preventable by products from our sponsors' catalogue."
Almost all cookie prompts use at least one of these dark patterns on the websites I visit. Interestingly, Hacker News doesn't prompt for cookies at all.
I, personally, dislike TrustArc https://www.deceptive.design/brands/trustarc
Unconscionability: https://en.wikipedia.org/wiki/Unconscionability :
> Unconscionability (sometimes known as unconscionable dealing/conduct in Australia) is a doctrine in contract law that describes terms that are so extremely unjust, or overwhelmingly one-sided in favor of the party who has the superior bargaining power, that they are contrary to good conscience. Typically, an unconscionable contract is held to be unenforceable because no reasonable or informed person would otherwise agree to it. The perpetrator of the conduct is not allowed to benefit, because the consideration offered is lacking, or is so obviously inadequate, that to enforce the contract would be unfair to the party seeking to escape the contract.
Statute of frauds: https://en.wikipedia.org/wiki/Statute_of_frauds :
> A statute of frauds is a form of statute requiring that certain kinds of contracts be memorialized in writing, signed by the party against whom they are to be enforced, with sufficient content to evidence the contract. [1][2] […]
> Raising the defense: A defendant in a contract case who wants to use the statute of frauds as a defense must raise it as an affirmative defense in a timely manner. [7] The burden of proving that a written contract exists comes into play only when a statute of frauds defense is raised by the defendant.
> Uniform Commercial Code: In addition to general statutes of frauds, under Article 2 of the Uniform Commercial Code (UCC), every state except Louisiana has adopted an additional statute of frauds that relates to the sale of goods. Pursuant to the UCC, contracts for the sale of goods where the price equals $500 or more fall under the statute of frauds, with the exceptions for professional merchants performing their normal business transactions, and for any custom-made items designed for one specific buyer. [42]
IIUC, that means that if the USD amount of a contract for future performance is over $500 the court would regard a statute of frauds argument as just cause for dismissal? Or just goods?
I interpret this page as "calling out" the designers, rather than educating them.
If there is no disagree to tracking or “only required cookies” option then you can notify the company and/or police.
> Note: This suggestion comes from EDPB guidance, but there wasn’t a unanimous agreement among the regulators. Some data protection authorities believe that the “Reject” button can appear on the second layer of the banner, behind the “Manage Preferences” button.
It would be nice to know who employs those 'authorities'
"Why is it so hard to find where to cancel my subscription?" is more ambiguous than "Sigh, another 'accept, or go to the preferences department' dialog; what a dumb/jerky site."
Having a unchecked random button, then randomly skipping about in a playlist anyway, unless you are a youtube premium user, is super dark pattern. Google pulling more and more user hostile shit like this is a gift to their competitors.
The new pastime, some moron decided either that they should store the choice for "Auto-play on hover" locally, or purposefully write crappy server-side code so the choice just so happens to randomly go back to the default "On" setting. I mean, my god, YouTube can keep track of over 500 channels I subscribe to, all of my stupid large playlists, but can't remember to keep a single boolean value about me? Oh gee whiz we turned auto play back on shucks where did I put your preferences? Can't find em here's a totally unrelated video haha!
Just curious, what advantage does YoutubeMusic have over just playing songs & full albums in YouTube, other than the warm glow of being on the right side of copywrite laws?
I've been seeing it more and more lately.
Fundamentally, it's just easier to check patterns against an allowed list than against a banned list, because if the pattern is in the acceptable set, you're done, but just because it's not found in the unacceptable set, doesn't mean it's not deceptive.
https://i.postimg.cc/C1mZ6VLP/Screenshot-20230427-192121.png
Is it just my Linux, or the site is THAT bad?
Until all web browsers present identical fingerprints and reveal no identifying data about the user, tracking will take place, whether laws mandate consent or not.
Opt-in, opt-out, none of it matters as long as we're browsing the internet with our unique identities on full display to every site we visit. Thinking that the solution is to ask companies nicely to please not use that information is delusional.
And why wasn't it? Because "No one would ever opt-in!" Yeah. Exactly. Leave us the fuck alone.
Many of the folks doing this are news services with great local political power. Coincidence?
I can definitely see why people want to have the choice, but I simply don’t care and don’t want to be interrupted.
If it was opt-in, who the hell would opt in? What good would it do them?
If there was an annoying person then followed you around the mall, taking note of everything you bought so they could sell that list to the other stores in the mall for a profit, would you let them? What if every time you went into a new store, another, differently dressed person wouldn't let you into the store until you answered some goddamn riddle about whether you want to consent to them following you around? Who would shop at that mall?
I think the GDPR was a step in the right direction, but it should have more heavily regulated respecting the DNT cookie. Let me opt-out, permanently, everywhere unless I decide not to.
> If there was an annoying person then followed you around the mall, taking note of everything you bought so they could sell that list to the other stores in the mall for a profit, would you let them?
I use a credit card instead of cash, so I guess I have to answer yes to this one.
I think cookiebot lets it's customers do this.
If I don't want to be tracked I will use an anonymous tab or configure my browser to not allow any cookies. The solution already existed. The people that care about it already knew it. The companies would come up with something better if there was a real problem, with people being worried about to the point of changing browser.
Ayn Rand was right and still is. We live in the age of envy. Hatred of the good for being the good. Useless waste of time for all human beings to hurt a few big successful companies because of tiny, envious people with the excuse to protect some helpless citizens.
No, the idea is solid.
> bad regulation,
In parts, you are right.
>bad execution.
Agreed.
> The people that care about it already knew it.
Sadly, it is not so simple. There was and still is a group of people, “The people who did not know it, but would care if they did”.
> The companies would come up with something better if there was a real problem
Company, for the better or the worse, is usually oriented towards benefits of shareholders, not users, customers nor societies. Don't get me wrong, there are companies that are not evil. But how do we know which are? Luckily, we have laws that prevent escalation beyond certain norms and protect those, who are not shareholders.
It's embarrassing how out of control the industry is, how toothless regulators are, and how outraged companies are when something finally forces them to simply ask users permission to do things.
For me, consent is enforced at the browser level, not the website level. So I don't really care whether I hit "accept" or "decline". Their cookies aren't going to be stored either way. In fact it's even more ridiculous and annoying that they need to store a goddamn cookie or fingerprint me to remember that I declined, which of course doesn't get stored on my end, and results in the stupid dialog box appearing every time I visit the site.
You know where I really hate tech companies and consent? Asking for phone numbers for SMS confirmations. No thanks. You don't need my phone number to do business with me. Just the other day a goddamn restaurant needed a phone number to order food in person at the restaurant via their abomination of a QR code at the table and a mobile webpage ordering system.
Instead, your browser will accept any cookie, including unnecessary ones, because it can't tell the difference.
Therefore, you cannot enforce consent at the browser level.
I'm not trying to be cheeky here. Who can say what the "necessary" and "proper" functioning of a given website is? You can always imagine a similar-but-different website. I think usually people are talking about ad-related stuff, but then why not regulate that in particular?
GDPR is way larger than just cookies...
The cookie banners that came about after GDPR didn't help the culture around privacy and security. All they did was piss off the great masses of end users to the point where some browsers (ex: Brave) now have specialized pop-up blockers just to stop annoying users with something that was [ironically] put in place to safeguard the privacy and rights of the masses who didn't actually ask for that.
When I talk about privacy and security, most people tell me to my face that they prefer convenience and don't care at all, one tiny little bit, about their data or privacy.
And so now we're starting to regulate and consider "digital rights", using the strong arm of the law to force companies to care. I'm not saying that we shouldn't. I have very low trust when it comes to tech companies and online services, particularly in the field of data security and PII. I wish that companies would be held liable for data breaches. But my point is that a huge part of the problem is that there seems to be a major disconnect between what the government is trying to force companies to do (a government that is supposed represent the will of the people) and what the actual people (customers) are telling the companies that they want.
Changing culture is a near impossible feat, but I think this is more of a cultural problem than a lack of legislation problem.
The options are: have your privacy violated, or use some tiny boutique service that isn’t hitting any economies of scale.
I will share with you one specific anecdote. One of the people I admire most in this world, who taught me everything that I know about software engineering, who - we both suspect - might be on the high-functioning autism spectrum and has the exact personality and knowledge profile typical of someone who cares.
This person straight up told me that "convenience trumps privacy" for them. This is a concrete example of someone telling me that they don't care if companies prioritize privacy or not, they just love the convenience that modern tech offers them.
So those types of experiences make me wonder. If someone who is in the industry and has the personality type typical of someone who usually cares more than most, if THEY don't care ... what does that say about the average every day person?
Again, it's purely anecdotal. I would love for this type of stuff get researched properly at the academic level so that we can get answers.
EDIT: Another anecdotal example is my mother. She has told me that she doesn't value or care about data / online privacy at all. That convenience matters most. Anecdotally, the only times I hear people complain are either tech nerds or on Joe Rogan's podcast. The people I talk to about this in every day situations tend to tell me that it's just not top of mind for them and if they had to sacrifice convenience to get more privacy they would prefer the convenience.
It's [usually] a matter of:
- The users affected are in the minority
- Regulations are forcing us to do something to be compliant
- The ROI of doing it "right" is extremely low
- So what can we do to be compliant while getting that tiny minority of users to voluntarily GTFO because genuinely don't want to have to worry about such a small niche market?
In most cases it is much simpler to add a one-click reject-all option than to pretend there are users interested in granular choices that present long lists of toggle controls and put that behind a "Manage cookie settings" button. So the "I" of "ROI of doing it right" is lower than the "I" for doing it in a shady way.
I completely understand the companies' motives. But to the OP, I disagree that these UIs are because users don't care. It's probably because companies care a great deal more about their profit.
Which they should! That's what companies do and that's even why they exist. But let's not pretend users not caring is the problem.
Obviously people making the decision are going to try to come up with a justification to make themselves feel okay about doing it, though.
It is embarrassing indeed. The systemic nature of the problem is a good argument for increased regulation.
1. Acquire resource.
2. Transform or make it into something more usable.
3. Sell it to customers.
All businesses are directly incentivized to have as wide and efficient of a pipe for sucking up the raw materials they build products out of. Fishing boats want to use the biggest nets regardless of bycatch. Mines want to level the whole mountain regardless of what lives on it. Farmers want crop growing on every square inch of the field regardless of biodiversity. You get the idea.
This is not out of any deliberate malice, it's just an emergent property of how the system works. If you have a bunch of companies making widgets out of blobstuff, the company that can get the most blobstuff the cheapest wins.
And, as purchasers of widgets, we benefit from the system and tacitly support it by participating.
For ad-driven tech companies, the natural resource they acquire is human attention. They are structurally incentivized to acquire as much as they can, as cheaply as they can, for as long as they can.
One of the "obstacles" to harvesting human attention which can be then sold to advertisers is that those pesky humans would prefer to place their attention elsewhere. Given that, tech companies are always going to be pushing the boundaries of consent. It's not a strictly zero-sum game, because sometimes humans actually do want to consume ads. But as the amount of attention being sucked up by companies increases and as people get reasonably more and more covetous of their own attention, that game gets less non-zero over time.
Having seen quite a few instances of deliberate malice I beg to differ. It is out of deliberate malice, though there may be a couple of cases where it is an emergent thing. The vast majority of these companies are aware of it, won't change their ways and have a hundred different ways to rationalize their illegal behavior.
I define malice as deliberately harming someone without attaining an equal or greater benefit in return.
Malice is setting someone's car on fire. Stealing someone's car is selfish and immoral, but not malicious in my definition.
"Malice definition, desire to inflict injury, harm, or suffering on another, either because of a hostile impulse or out of deep-seated meanness"
The examples I've seen check all the boxes. They don't even see end users of these services as people, just as a potential source of revenues.
Note that the definition says that the "desire"—the intent—is the injury or harm itself.
It's not malice if you steal someone's car because the point isn't to make them feel bad, the point is to acquire a car.
I don't consider depersonalization to imply malice either. Depersonalization can make it easier to maliciously harm someone, but seeing a user as a potential source of revenue isn't malice. The intent isn't to harm them at all, the intent is to generate revenue. The harm is incidental.