5 ms·
On some websites I get a tracking / cookie consent popup which, if I choose not to consent to everything, leaves me hanging for a _very_ long time while "saving
by dthul 6y ago
On some websites I get a tracking / cookie consent popup which, if I choose not to consent to everything, leaves me hanging for a _very_ long time while "saving my settings". I am talking about 30-60 seconds here. That must be deliberate to keep you from denying consent. I forgot which company it was but I immediately recognize those popups.
- alkonaut 6y agoClearly a violation too, since the experience is now worse when not giving consent. That its clearly deliberate doesn't help either.
- spoiler 6y agoOracle does this. I've had this happen the other day while trying to access some documentation.
- sseneca 6y agoIs it TrustArc? I remember having a similar experience with their pop-up, for example on Oracle's website when I'm looking for Java docs: https://docs.oracle.com/en/java/ https://docs.oracle.com/en/java/ That example doesn't have the long loading times for me any more, but I'm almost certain it was the TrustArc pop-up.
- dthul 6y agoYes, I believe it was TrustArc.
- privacylawthrow 6y agoSome tools call APIs from a whole bunch of ad networks. That 60 seconds is likely spent getting opt out cookies from dozens of different ad network domains.
- alkonaut 6y agoStill not acceptable to make a worse experience when the consent is rejected. They'd need to queue those things and process them async later, or find a solution that doesn't need those requests at all.
- ratww 6y agoTrustArc's doesn't, or at least didn't the last two times I inspected it deeply. It is possible to reproduce this claim by checking the browser inspector Network tab and by debugging trough the source code: it's just a bunch of setTimeouts. Not to mention that if there were any hypothetical API calls those could be made asynchronously after closing the modal. It's purely a dark pattern.
- privacylawthrow 6y ago>Not to mention that if there were any hypothetical API calls those could be made asynchronously after closing the modal. If you did that, users wouldn't be able to see whether their opt out was successful.
- rkachowski 6y agousers can't see if their opt-out is successful in any case, only that their preference was submitted
- cuu508 6y agoYou should be opted out by default. The "Allow All" is the one that could in theory need to make N separate opt-in requests.
- ratww 6y agoIt should not matter if they're following the law. Failure to access some API doesn't mean the user consented. Like the sibling poster said, the default should be opt-out. It's not as if this TrustArc modal is some old product that was repurposed for GDPR. This is all planned and done in bad faith, period. It's a dark pattern.
- Nextgrid 6y agoI thought so as well but if I recall correctly someone explicitly disproved that. Should be fairly easy to confirm by checking the traffic in the network tab - unless the ad networks themselves take 60 seconds to respond there should be no reason for that much delay.
- elliekelly 6y agoWhy is the “opt out cookie” necessary? Why can’t they just assume that anyone who doesn’t have an opt in cookie hasn’t opted in and can’t be tracked? Isn’t the opt out cookie itself a form of tracking? If you have the cookie I know you’ve been to a site I advertise on/track/am affiliated with.
- privacylawthrow 6y agoThe opt out cookie was created by ad networks prior to GDPR when many EU countries allowed for opt in by default. The opt out cookie was the tool to allow users to opt out. It still has value today as it allows an ad network to remember a user's choice not to be tracked. The opt out cookie is set by the advertiser, not the publisher, and the contents of the cookie have generic text like "OPT OUT".
- notimetorelax 6y agoI agree with your point here, it's in spirit of GDPR, unless expressly permitted the sites must assume that the user has opted out. The ad agencies with their cookies have it backwards.
- hlasdjlfhalwjk 6y agoDoesn't GDPR require opt-in for tracking? So as long as you didn't interact with the banner, _every_ page load should take ~60s?
- zaroth 6y agoOf course they have to track that they aren’t tracking you, or else you would get the consent banner repeatedly on every page load.
- TeMPOraL 6y agoThe actual way this should be implemented, if they wanted to be morally irreproachable, would be this: a consent popup always available, tucked down somewhere in the corner of the site. It defaults to opt-out from everything, you can click on it to expand it if you want to opt into something. An acceptable option is to pop up a consent form as needed, and set a cookie recording whether user made a consent decision. That can be classified as essential cookie to fulfill a legal obligation.
- throwaway2245 6y agoSo (in this hypothetical), it's sharing your data with ad networks, in order to not share your data with ad networks? That seems really wrong.
- Anther 6y agoZiff Davis sites do this. Very aggravating.
- LeonM 6y agoYep, that's TrustArc These fake progress spinners are only there to deter you from opting out (hint: if you just accept all, the modal closes instantly). I wish the EU would throw massive fines at these companies, and ban the persons in charge from over working in the business again.
- TeMPOraL 6y agoAt least in some cases I've seen, the progress seems to be tied to a staggering number of network requests happening in the background. I've heard this explained as being necessary to communicate your opt-out to all the relevant parties, but honestly, that smells like bullshit. More likely it's designed like this on purpose, to have plausible deniability for the dark pattern.
- patrickmcnamara 6y agoIf the default is to be opted-out, why would they even need to communicate at all with third parties? I'd say that it is bullshit.