Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So they add email addresses to a newsletter mailing address even when the user specifically opted out of the newsletter?

If that's true, then they're almost certainly violating federal law. Instead of ranting about ethics, you should calmly explain to the CTO that what they are doing might be in violation of federal laws and regulations. Possibly laws related to spam. But if this practice contradicts the company's privacy policy (or if the privacy policy is vague enough and the user's intention and expectation of an opt-out is clear enough), then the company you worked for is almost certainly in violation of its contractual obligations to its users. The FTC is starting to take this sort of thing more seriously -- see https://www.ftc.gov/news-events/media-resources/protecting-c... for examples of enforcement actions.

If I ever find myself in a situation where I'm tasked with making the commit on a "feature" like this, I would explain that I can provide technical assistance (up to and including writing/testing the code), but due to my professional ethical responsibilities, management will have to find another engineer to actually make the commit, deploy the code, and close the ticket. And I would also print out an email that proves I expressed my dissent and management dismissed my concerns.

IANAL.



Companies violate federal or state (or country, in my case) laws all the time.

I've read about Y Combinator actually encouraging some of its startups to violate laws (in the "hack the system" sense, not in criminal violations sense).

If you think about it, many of the top startups do: Uber, AirBnB (and others that are losing like Zenefits, FanDuel or DraftKings).

See: https://blog.placeit.net/startups-ignored-law-won/

It's, sadly, one of the only effective ways to get them to be discussed or modified, laws have a lot of inertia going for them.

I'm definitely not happy about the ethics in the above case, though.

Another thing I was going to add is that some CEOs knowingly violate the laws and incorporate that into their risk models (cost of fine + lawyers weighted by chance of it happening), it's usually a lot more cost effective to violate them (The CTO in the above example might have done such cost/benefit calculation).


I presume it said "check the box to opt-out of the newsletter", instead of being "check the box to opt-in to the newsletter".


Note that this would be... Well, stupid. People sometimes opt in for newsletters they care about and with this scheme they would opt out. Not only that, you would get tons of "subscribers" who explicitly don't care for your mails.

I am not arguing that dark patterns don't work in general, I just don't think this is a good example.


My interpretation was that the box just doesn't do anything; i.e., you can click it or not click it, but either way, welcome to the news letter mailing list.

Maybe I was wrong.


IANAL also, so my reading of it may be incorrect, but I'm pretty sure it violates the CAN SPAM act.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: