varx is a user on infosec.exchange. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

Tumblr tried to sneak in data collection under the radar. After a few taps, you can get a list of who they're sharing data with.

The list takes 19 screenshots to see all the names on my phone.

NINETEEN.

List of names of the "partners" Tumblr shares your data with

1/5

List of names of the "partners" Tumblr shares your data with

2/5

List of names of the "partners" Tumblr shares your data with

3/5

List of names of the "partners" Tumblr shares your data with

4/5

List of names of the "partners" Tumblr shares your data with

5/5

Also worth mentioning a very nice (no) dark pattern. The last name in the list is always behind the gradient block, which means you can never untick it.

That's Oath, the new owners.

Go read they shitty website in which they try to justify their invasion of your privacy, and also minimize the rights you have to control that data: oath.com/en-gb/my-data/

The deletion right is barely mentioned, at the very end, and they don't even give you a link to do so.

You gotta figure that one out yourself, I guess?

Let's also analyze for a bit the UI of their mandatory privacy disclaimer. Keep in mind the spirit of the GDPR is all about the need to have "informed consent" to collect data about a user.

First of all, you get a massive wall of text. Please excuse the french, but notice how faded (light grey one white) the button to modify the settings is.

That's the first dark pattern of this flow. Clearly the goal is to put everyone to sleep and hope everyone will blindly click on the bright blue button to simply accept everything.

varx @varx

@skiant Trying to find this screen from Tumblr, I had to go through an Oath login screen, which said "Please wait while we collect your data"

how about no

· Web · 0 · 1

@skiant Actually, how the hell do you even get to these screens?

@varx
Only in the EU because of GDPR. I assume non EU citizen have the same tracking but no control over it.

@skiant Except... they don't know if I'm an EU citizen or not. :-/