Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, if email was saved secretly, as author wrote, it means users were not aware of that their personal info is saved. Also, since it's Javascript, it means that they weren't first-party, who had the email address anyway.

If they added a text for user like "Your email address is saved by XXX Inc, we will just send you 3 reminders", then it would be ok.

For example of the same dark pattern: if you look at any hotel booking page (not aggregator like booking.com, but hotel-owned), I bet you will see at least 5 third-party tracking scripts, they all store every action you make on the page without user explicit knowledge.



5 is pretty low. There are many popular websites that share data with >100 third-parties.


> If they added a text [...] then it would be ok.

I’d agree with that as long as the text is visible before entering the email address, and the text also mentions that email will be saved before completing the form.

> I bet you will see at least 5 third-party tracking scripts

Analytics and tracking scripts is a good point. Sometimes it’s implemented in a way where tracking scripts don’t have access to keystrokes, for example by iframing them, and you’d hope that the web site owner would care enough about their own security to do that. But you’re right that unfortunately it’s common. In this case I think we need some legal protection in the US and elsewhere similar to GDPR that clarifies that collecting such information can only be done with explicit consent.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: