7 ms·
> Each file had the same change - they had added code that makes an ajax saveEmail() call onBlur. In other words, email addresses were being saved to the databa
by etripe 5y ago
> Each file had the same change - they had added code that makes an ajax saveEmail() call onBlur. In other words, email addresses were being saved to the database when a user inputs an email and the input loses focus.
> I told my client - apologies, but I don't want to work on this task because it's a dark pattern. And they reply - no, no, we are just sending people 3 email reminders. And then I try to explain that it's basically saving email addresses secretly.
Perhaps because this is a short post, but it seems to be missing context. The email addresses are saved, which may or may not be questionable. It's unclear whether there are any mechanisms to auto-remove the email addresses once three reminders have been sent.
It doesn't seem immediately obvious what the dark pattern is here. What am I missing?
- 3pt14159 5y agoUsers expect forms to submit when the click the button. If they change their mind about signing up or purchasing something, they don't expect to get emailed if they didn't click the button. That's the dark pattern. Not the worst I've seen, but not great either.
- eloff 5y agoBut how many people enter their full email and then back out of the form? This seems like a small thing at the end of the day, especially for 3 emails that doubtless contain an unsubscribe link. Edit: That got a lot of push back. I'm just saying, this is not the hill I'd die on. At best it would spare some small single digit percent of visitors 3 unwanted emails.
- JustResign 5y agoSmall things can still be unethical.
- Phenix88be 5y agoIt's not out of the form. It's out of the email fields. So if you press tab to go to the next field, the email is send somewhere without notice.
- deleted 5y ago[deleted]
- HumblyTossed 5y agoProbably an awful lot for them to want to pay a developer to do this.
- slver 5y agoBy that logic let's monitor their clipboard for email and phone numbers. Let's tell them that they should enable notifications so we verify they're not a robot. Let's ask them to download a little executable to see if we can find helpful ways to reach them. We'll provide an unsubscribe link, I promise. ... But let's just record they clicked unsubscribe because that means they're engaged. I mean maybe they clicked in error? Let's ask them to confirm. ... But maybe they confirmed because they were confused and didn't understand the great value we provide. We can beat around the bush our way to full-blown scammers all day. Saving emails from a form NOT submitted is bullshit, and you know it. The user never intended to submit.
- slver 5y ago> But how many people enter their full email and then back out of the form? Most people. Because we have form autofill.
- zentiggr 5y agoAnd if I fill out most of the form, but some custom BS UI chunk can't play nice and borks the page... I'm done with "company", leaving the page since it never finished loading, but my email address is already saved? Absolutely f*ing not. Not a small thing in any way. This is unethical and if I got an email from that company you can bet I'll push back.
- raxxorrax 5y agoReally?
- dboreham 5y agoWe found a new kind of psychopathy test here.
- dahart 5y agoI’m sure you meant your question sincerely. FWIW, I have backed out of many signup forms, and often wondered/worried whether they were doing exactly what the OP talked about. The reason for back-outs is because there is another very common dark pattern this gets combined with: a multi-page signup where email is asked for early, and then something more onerous is requested on a later page, which is where the cancellation is much more likely to occur. The single biggest reason in my experience for late cancellation is when the signup asked for a credit card, even though the signup was advertised as free. It’s a bait and switch, and the deal ends up being a subscription that you can cancel after your first free day/week/month. I’ve had other things besides credit cards, though, like required personal information.
- eloff 5y agoYes, I can see your point. If you click through to the next step though, you should assume that submitted the form. Regardless of whether it was done through an old school POST or Ajax in a single page app. I think it's still a dark pattern to email someone who hasn't expressed interest in receiving those emails. There should at least be text informing you of that and giving a way to opt out up front.
- dahart 5y agoYeah, exactly, it’s about expressing interest, communicating intent, and offering a way to opt out. The broader point is that form submission is not the criteria for saving an email address at all, explicit consent from the user is. When the site itself provides an expectation that a signup process can be “cancelled” they are signaling an expectation that the information will be discarded and not used to market to you or sell your email address to other companies. When they do that despite having communicated to you that the process was cancelled, they’re playing dirty. And I do think selling the email address to third parties is the bigger danger here, not getting a couple of direct marketing emails from site you visited.
- rpdillon 5y agoThis is about control: does the user understand when the data leaves their hands and is given to another? If the user doesn't understand this, then they find themselves unwittingly giving out their personal information, not just to legitimate actors, but also malicious ones. I think this is a pretty important thing to try and get right.
- ipython 5y agoIn that case, why implement the feature at all?? Why die on the hill to capture email addresses from the “small single digit percent of visitors” who never consented to receive your spam in the first place?
- steveBK123 5y agoExactly. I've been a victim of a dark pattern like this years ago when I was trying to find mortgage rates. Many of the online mortgage rate tools are really just lead generation sites, including some of the big name brand ones. One wanted me to create an account, and I got about half way through (I stupidly gave my phone number) and then exited without creating account. I believe they had a sort of "enter email, next. enter phone, next" kind of page by page pattern. Anyway, within an hour of exiting I was getting 3 phone calls per hour from mortgage companies soliciting me for business.
- josefresco 5y ago"abandoned cart" technology is why many ecommerce websites ask for your email first when checking out. My kid recently added some items to an online shopping cart to determine shipping rates, which required their email, and now they get spammed incessantly.
- MandieD 5y agoSwitching to FastMail and the easy availability of arbitrary-business-name@mydomain.com was worth it just for that.
- whalesalad 5y agoThe dark pattern is capturing an email address even if someone doesn’t submit the form. Imagine you start a guest checkout, type your email address and nothing more, then close the window. That email would still get captured for marketing purposes. Because this isn’t what a user would expect, it’s considered a dark pattern.
- leephillips 5y agoAnd the browser’s autofill may fill in the email address without the user intending to, conceivably.
- InitialLastName 5y agoOr, conceivably, the wrong email address. I'm sure I'm not the only person who has multiple, context-dependent email addresses that (in some cases) are email aliases I share with others, all saved with appropriate supplemental information in my browser.
- deepsun 5y agoWell, if email was saved secretly, as author wrote, it means users were not aware of that their personal info is saved. Also, since it's Javascript, it means that they weren't first-party, who had the email address anyway. If they added a text for user like "Your email address is saved by XXX Inc, we will just send you 3 reminders", then it would be ok. For example of the same dark pattern: if you look at any hotel booking page (not aggregator like booking.com, but hotel-owned), I bet you will see at least 5 third-party tracking scripts, they all store every action you make on the page without user explicit knowledge.
- kube-system 5y ago5 is pretty low. There are many popular websites that share data with >100 third-parties.
- deleted 5y ago[deleted]
- dahart 5y ago> If they added a text [...] then it would be ok. I’d agree with that as long as the text is visible before entering the email address, and the text also mentions that email will be saved before completing the form. > I bet you will see at least 5 third-party tracking scripts Analytics and tracking scripts is a good point. Sometimes it’s implemented in a way where tracking scripts don’t have access to keystrokes, for example by iframing them, and you’d hope that the web site owner would care enough about their own security to do that. But you’re right that unfortunately it’s common. In this case I think we need some legal protection in the US and elsewhere similar to GDPR that clarifies that collecting such information can only be done with explicit consent.
- iovrthoughtthis 5y agowould it be surprising to a user if they received an email from a company they hadn’t given their email to? if yes, it’s a dark pattern. if no, it’s not. i side with, yes.
- slver 5y agoIt's not surprising because we're used to spam. /s
- dev_tty01 5y agoFor me, this is only ok if at the top of the form there is big easy to read text that says any data typed in the form is saved immediately prior to the user hitting submit. Anything else is a dark pattern. Let's not kid ourselves. We know most users naively think the data is just on their screen and nowhere else until they hit submit. If we write code to circumvent that expectation we know it is a deception. After all, the default behavior is that the form data is not available early. The programmer has to explicitly do something to counter the default.