Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
Advertising

Companies are Subtly Tricking Users Online with 'Dark Patterns' (cnn.com) 46

CNN reports: An "unsubscribe" option that's a little too hard to find. A tiny box you click, thinking it simply takes you to the next page, but it also grants access to your data. And any number of unexpected charges that appear during checkout that weren't made clearer earlier in the process. Countless popular websites and apps, from retailers and travel services to social media companies, make use of so-called "dark patterns," or gently coercive design tactics that critics say are used to manipulate peoples' digital behaviors.

The term "dark patterns" was coined by Harry Brignull, a U.K.-based user experience specialist and researcher of human-computer interactions. Brignull began noticing that when he reported to one of his clients that most test subjects felt deceived by an aspect of their website or app design, the client seemed to welcome the feedback. "That was always intriguing for me as a researcher, because normally the name of the game is to find the flaws and fix them," Brignull told CNN Business. "Now we're finding 'flaws' that the client seems to like, and want to keep."

To put it in the parlance of Silicon Valley, he realized it was a feature, not a bug....

Brignull, for his part, said he has spent time testifying as an expert witness in some class action lawsuits related to dark patterns in the UK. "The scams don't work when the victim knows what the scammer is trying to do," Brignull said. "If they know what the scam is, then they're not going to get taken in — and that's why I've enjoyed so much exposing these things, and showing it to other consumers."

The article notes that America's Federal Trade Commission "is ramping up its enforcement in response to 'a rising number of complaints about the financial harms caused by deceptive sign-up tactics, including unauthorized charges or ongoing billing that is impossible cancel.'"
This discussion has been archived. No new comments can be posted.

Companies are Subtly Tricking Users Online with 'Dark Patterns'

Comments Filter:
  • by Dutch Gun ( 899105 ) on Saturday July 16, 2022 @04:45PM (#62708650)

    My favorite recent example was the Windows 10 upgrade dialog Microsoft deliberately designed to trick users into upgrading when they didn't necessarily want to. And of course, Amazon's been under fire by the EU for it's slightly-too-obtuse method of cancelling Prime.

    Fortunately, things aren't quite as bad as they used to be, but only thanks to stricter laws. For example, it use to be possible to sign up for services electronically, but you'd have to actually call someone to cancel. That's kind of the ultimate in dark patterns IMO, and is thankfully illegal in many places now.

    • Dialogue? Trick? No, it was an outright direct pushed update and the only way to stop it was a change to an obscure registry item. It wasn't a deceptive request, it was an attempted mugging.
    • by AmiMoJo ( 196126 )

      The most common one is cookie banners that induce the user to agree, when in reality most people don't want to be tracked.

      I'm currently pushing a dispute with Techcrunch over that through the regulatory process. They have 26 days to justify whey their obviously deceptive and non-compliant website meets the clearly defined requirements of Recital 32 of the GDPR.

  • by cirby ( 2599 ) on Saturday July 16, 2022 @04:51PM (#62708656)

    I've noticed that a lot of unsubscribe options are not only hard to see, but not even linked from the main page or the user page.

    I had a trial subscription to one site that didn't have a visible unsubscribe option - and the only way I found it was to do a web search and use the Google link to the correct page. I assume they had to have an existing unsubscribe page that they could point to when someone sues them or complains to the credit card companies...

    • by Anonymous Coward

      Some don't even let you cancel without calling a number, like NBC parent company Comcast. NYT is a pain to cancel. There are so many cases of this, it's amazing nothing is done. Maybe not amazing, but rather, we may need to start having a parallel congress of Digital Representatives the people elect for them. We spend more time in virtual scenarios (apps, games, websites) than in the real world and nobody is really representing us.

      • by Anonymous Coward

        Some companies, you have to fight the "loss prevention/retention officer", and hope they don't hang up on you. Other companies pretty much don't allow cancelling, and if one just blocks the credit card, about six months later, they ding your credit. I've had to cancel some places with a legal C&D order from a lawyer, served via a constable. This works, but guarantees you will forevermore be on the company's shit list.

        Hell, this is why I like Apple Pay so much. If I want to cancel the NYT, I just log

      • Some don't even let you cancel without calling a number, like NBC parent company Comcast. NYT is a pain to cancel. There are so many cases of this, it's amazing nothing is done. Maybe not amazing, but rather, we may need to start having a parallel congress of Digital Representatives the people elect for them. We spend more time in virtual scenarios (apps, games, websites) than in the real world and nobody is really representing us.

        Actually, something IS already being done. Some states like CA are passing legislation to prohibit predatory and harassing practices like this, and I think it will eventually spread... probably as more and more legislators get annoyed by this like the rest of us.

        https://www.connectsafely.org/... [connectsafely.org]

      • NYT (Score:3, Interesting)

        by votsalo ( 5723036 )
        Since you mentioned NYT, when the NYT sent me notice to update my expiring card info, I replied to them, "no thanks, I will unsubscribe instead." But NYT got my new card info from my bank, anyway, without my consent, and happily started charging my new card. Apparently it is standard practice for banks to give updated card info to vendors. It gives new meaning to the process of asking for the new card, since they go ahead and get it, even if you refuse to give it to them. It also gives new meaning to the
    • by quantaman ( 517394 ) on Saturday July 16, 2022 @11:45PM (#62709136)

      I've noticed that a lot of unsubscribe options are not only hard to see, but not even linked from the main page or the user page.

      I had a trial subscription to one site that didn't have a visible unsubscribe option - and the only way I found it was to do a web search and use the Google link to the correct page. I assume they had to have an existing unsubscribe page that they could point to when someone sues them or complains to the credit card companies...

      I had a trial subscription with Scribd, unsubscribed, then a month later was charged a subscription payment.

      Turns out clicking unsubscribe led to a pay with a big "Sorry to see you go!" followed by a long scroll down where it turns out you haven't actually unsubscribed and in the words of Scribd [scribd.com] (emphasis added):

      Once you click on the link to start the cancellation process, you'll see a few pages of confirmations. Read and review before moving forward.

      I disputed the payment with both Scribd and Paypal, never heard back from either.

      • This kind of thing is why I never get trial subscriptions to any online service.

      • by AmiMoJo ( 196126 )

        It's best to avoid using PayPal because they are middle-men, meaning you can't easily do a chargeback (or Section 75 in the UK) because technically PayPal didn't breech their rules, and your transaction was with them and not the actual vendor.

    • You should be able to login to your bank web page, see a list of vendors that you have subscribed to, unsubscribe from any one of them without contacting the vendor at all, and set limits for how often and how much the vendor can charge you. Set the limit to 0 for trial subscriptions.
  • by Petersko ( 564140 ) on Saturday July 16, 2022 @04:53PM (#62708660)

    Even relatively trusted download sources play the fuckheaded game of "guess which download icon isn't an ad?"pu

  • CNN shows us... (Score:5, Interesting)

    by nicolaiplum ( 169077 ) on Saturday July 16, 2022 @05:20PM (#62708698)

    ... that now everyone, even CNN, knows about web design dark patterns.

    They provide you with a good example on your first visit to their website:

    The "Accept All" cookies button is highlighted with contrasting colour, but the option to reject them is a low-contrast text with a vague "Manage Cookies".

    The "Manage cookies" pop-over gives you another, invitingly green, "Accept All" button at the top. Only by scrolling the box do you find "Save Preferences" to avoid accepting all cookies.

    Even then, hidden behind headings you must expand, are "legitimate interests" about advertising content, market research, and other things not necessary to serve the web page. To avoid these, you must find them and click on them. The "legitimate" excuse here appears to be that they are entitled to use any means possible to turn a buck. That's pretty dark morals, isn't it?

    CNN doesn't need to write about dark patterns in web design in any other website. They just need to show their own website is as rotten as any other they may report on.

    • by splutty ( 43475 )

      And they do this.. Every.. Fucking.. Time.. Because storing a cookie with the information that "No I don't want cookies!" is not considered a "functional" cookie, necessary to the functioning of the site (which of course, is technically true).

    • They often outsource cookie agreement & other user compliance processes to 3rd party services that do all the skullduggery & they're probably the ones that sell users' data on too. I'd be surprised if CNN knows about anything other than the Google analytics dashboard that they think comes with their website or that they're literally giving away their users' personal data without any oversight.
    • by AmiMoJo ( 196126 )

      If you are in a GDPR country you should complain about this. It's not much effort, and now that Google has been fined again for non-compliance and is changing how their cookie banner looks, we are in a good position to force other companies to do the same.

      1. Find the GDPR/privacy email contact for a company. Usually the easiest way is to go to their privacy policy and ctrl+f search for the @ symbol.

      2. Email the company in question, pointing out that their website is non-compliant with GDPR Recital 32 (https

    • Even then, hidden behind headings you must expand, are "legitimate interests" about advertising content, market research, and other things not necessary to serve the web page. To avoid these, you must find them and click on them. The "legitimate" excuse here appears to be that they are entitled to use any means possible to turn a buck. That's pretty dark morals, isn't it?

      Not only do many of these websites make you click on the individual "types" of cookies to turn them off, they don't actually tell you tha

    • It's not just CNN. This is a standard UI that I see on lots of sites. Clearly it's being provided by some company that's made a business of it. A nice list of choices to say what kinds of cookies to allow, and then you click the big green button at the end to ignore all the choices you just made and allow all cookies regardless. Oh yeah, and there's also a less prominent, confusingly labeled button to use your choices, but who would click that?

  • by oogoliegoogolie ( 635356 ) on Saturday July 16, 2022 @05:45PM (#62708728)

    Would you like to install Microsoft Edge? Yes/Maybe later.
    Would you like to send us your usage data? Yes/Maybe Later
    Would you like us to send information on upcoming promotions we think you may be interested in? Yes/Maybe Later
    (and so on and on and on)

    I am not sure if those are dark patterns or just scumbag trickery, but changing responses from Yes/No to Yes/Maybe Later (apparently so they can ask you again, and again,and again because you can't say NO) have become ubiquitous across the www and apps, and they are ubiquitously annoying for being so obviously deceptive.

    • Re: (Score:2, Informative)

      by splutty ( 43475 )

      O&O Shutup is what I use to tell Microsoft to:
      - Fuck off
      - Get fucked
      - Disable Cortana, completely.
      - etc, etc.

      It's utterly ridiculous that a Windows 10 Pro install has so much garbage.

      And if people say "Well, use Enterprise", the Windows 11 Enterprise still has things in it that are actually illegal for many businesses I've worked for.

  • This is news? (Score:5, Insightful)

    by marcle ( 1575627 ) on Saturday July 16, 2022 @06:03PM (#62708750)

    Dark patterns have been a thing since forever, spawning endless articles, commentary, and even legislation. Why pretend, especially on a technical site, that this is some kind of revelation?

  • by devslash0 ( 4203435 ) on Saturday July 16, 2022 @06:08PM (#62708770)

    Just have a look here: https://hallofshame.design/rya... [hallofshame.design]

    They even won a Dark Patterns award of some sorts a few years ago, if I remember correctly.

    • by splutty ( 43475 )

      Dell is another great example. With their "Free support (automa ticallyex ten ded.afterthefirst month.fo ronly10bucks.withthe creditcardinformat ionyo ugaveus.soitstot allylegal)" being on by default and hidden somewhere obscure.

      Random spaces because fuck you Slashdot lameness filter.. *sigh*

  • by Orgasmatron ( 8103 ) on Saturday July 16, 2022 @06:26PM (#62708804)

    Why do they bother with misdirection and dark patterns? Clearly, they can get away with just blatantly ignoring your choices and preferences.

    Every web shop I've used in the last 10 years has had a checkbox to sign up for spam. I always uncheck it, sometimes many times because it always gets re-checked, and every single one of them ignores it and starts sending me spam anyway.

    These services could replace their entire cancellation process with a popup that says "Fuck you, take it up with your bank" and no one will do anything about it.

    • Of you got Gmail, try the 'unique email bright pattern':

      Gmailname +random_unique_alias @gmail.com

      Sign up each site with a unique alias, as above. The alias should be meaningful to you and remind you of the organization . No need to tell Google - they push all aliased emails to your inbox anyway.

      If you start getting spammed, block the spammers. Then check the 'to' address to see if you recognize an alias. If so, sinbin that address alias, and block the original 'leaker' too, as consequence.

      • Eg

        Realname+examplesite2022@gmail.com

      • Lots of sites will reject those email addresses. Some of them will even silently strip it when they send email.

      • I do this. I use my own private email server and domain, so I don't have to use my "real" email address plus something. I typically use the name of the company or website, then the date in ISO8601 order (to reduce spoofing). And they typically get either zero or one unsubscribe click before I add that address as an alias of /dev/null

        But none of that should be necessary.

  • by MindPrison ( 864299 ) on Saturday July 16, 2022 @06:35PM (#62708828) Journal

    Even reputable companies does this.

    Ever noticed how hard it is to remove items from your shopping bag in some online stores? I just recently perused a lot of items I wasn't entirely sure I'd purchase, but I kept them in my shopping cart for a little while, then next day I decided to remove them, but there was no "clear cart" function.

    After 20 minutes or so fiddling around with the website, going down that dark path of endless support pages, and even more dead ends, the cart remained.
    It turns out I had to clear EACH item by going to EACH items pages in order to do that, it was cumbersome and took a very long time, but I eventually did it.

    As a bonus I was greeted with a sad smiley, your shopping cart is empty, with a huge sad smiley on the screen after I cleared the last item.
    There is NO way this is a bug or not on purpose, it's all tailored to doctor you into buying and paying as fast as you can, that's easy and so convenient that you can even purchase by "mistake", but try to get rid of it and change, that's hard.

    It doesn't even stop there. Many of the businesses have a so called 30-days money back policy, and that you can cancel your order straight away.

    Not so - I remember I ordered something that I later regret, I managed to cancel the order as it said it was still not shipped, but 3 days later I would see the item shipped and an additional 2 days later I got a private message that we can't cancel your order because it has already been shipped.

    This happened for me on 2 occasions in 2 entirely different stores, coincidence? Sure you can ship the item right back, but there's psychology behind it - they KNOW you're more likely to just accept your mistake if you already know it's shipping (even if the postal office haven't even received the package yet, not even the shipping terminal using the tracking number).

    • by splutty ( 43475 )

      Even reputable companies does this.

      Then they are by definition not 'reputable'. Known, sure. Reputable, no.

  • by Otis B. Dilroy III ( 2110816 ) on Saturday July 16, 2022 @07:18PM (#62708880)
    Gallows do.
  • by devslash0 ( 4203435 ) on Saturday July 16, 2022 @08:02PM (#62708942)

    Perhaps not a dark pattern but something highly controversial is requiring payment/card details to subscribe for all sorts of free trials. This kind of practice is in fact in breach of the rules currently binding in the EU under GDPR, where information collected from the customer must be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);". Since trials are free, collecting any payment information upfront is technically illegal. Sadly, no one enforces that.

    • Nobody enforcing laws on corporations is the story behind most of the things on this page. A lot of the credit card charges being discussed need to be examined as fraud by false representation, selling goods which don't give the purchaser quiet possession of them, etc.
  • I pay for everything I buy on-line with one of my credit cards...ONLY one of my credit cards. When there's a problem, and yes, there have been problems, I don't bother dealing with the seller. I just contact my credit card people and cancel the sale. This has never, ever failed. I get my money back, and a multi-billion dollar, bank-supported corporation guts these thieves like fish. On two occasions, the unwanted item was actually delivered to my home. After having had my credit card cancel the sale,

  • ...how about never?

    Hate it when software does not offer a 3rd option here. I'll go out of my way to complete disable it then, either by denying internet access, renaming crucial files it uses for updates or disabling some background service -- as this kind of software usually also "forgot" to add a feature to turn off updates.

  • It might once have been "gently coercive", but it's now obvious and blatant as companies were able to get away with it and continued to push the boundaries.

    Many of the offenders - like "low-cost" airlines - have previous form with hidden charges or conditions in their print advertising which regulators have gradually got to grips with to varying extents.

    There's been a general problem of regulation on the Internet being too little and too late and unfortunately this is just one example of a regulatory backlo

  • The moment one of these companies falsely charges you, deny payment through your bank and have the bank send a manual approval every time that company tries to charge you in the future. Gives you back manual approval on charges that sites try to force you into making automatic by offering no other option. Fortunately these sites don't control banks, and can't override your bank account settings.
  • ... given their track-record with Prime unsubscribing, I do not trust Amazon.com anymore. I simply am not confident that the box I click on is doing what it is stated to do.
  • Tech has grown up. It ain't run by the creative nerds anymore. Hasn't been since about the early to mid 00s.

    It is run by the same people that run every other industry now: the corporate sociopaths and hipster narcissists.

    The tech industry has become the 21st century version of big tobacco. They know what they are doing and just don't care 'cause, ya know, greed.
  • "Dark Patterns" makes this shit sounds cool & techy. It's not. It's "Asshole Design", plain and simple. We should call it what it is.

A complex system that works is invariably found to have evolved from a simple system that works.

Working...