O'Sullivan's screenshot-by-screenshot inventory documents nine distinct dark patterns still live in June 2026, three and a half years after the DSA was meant to outlaw most of them. His framing treats Ryanair as the openly-running control group for how much coercive UX a regulator will actually tolerate before fines exceed conversion gains.
Former airline product managers in the thread confirm every pattern ships because A/B tests show it lifts revenue and legal has already priced the fines. They cite Ryanair's ancillary revenue per passenger climbing from €17.90 in 2022 to €24.30 in 2025 as direct evidence that the dark patterns ARE the delta.
By framing the post as a 'refresher' that catalogs the same patterns Harry Brignull documented in 2010, O'Sullivan implicitly argues the regulatory regime hasn't moved the needle. His evidence is the unchanged checkout flow itself — confirmshaming, pre-checked insurance, buried cookie rejection, and countdown timers all surviving the DSA's enforcement window.
The post's annotated screenshot format treats each pattern as a deliberate design choice with a name and a history, implicitly indicting the practitioners who ship them. By tying the 2026 flow back to Brignull's 2010 taxonomy, O'Sullivan positions this as a profession that knows exactly what it's doing and chooses to do it anyway.
A fresh teardown of Ryanair's June 2026 booking flow landed on Hacker News today (155 points and climbing), authored by Donncha O'Sullivan as an annotated 'refresher' of the airline's dark-pattern playbook. It's not a rant — it's a screenshot-by-screenshot inventory of the same coercive UI techniques researchers like Harry Brignull have cataloged since 2010, now updated for the post-DSA era.
The list is long enough to be educational. Insurance is pre-checked and worded as 'Recommended for your trip,' with the decline option phrased as 'No, I am willing to risk my €' — a textbook confirmshaming pattern. Seat selection presents 'random seat' as free but warns you may be separated from your travel companions; selecting adjacent seats for a family of four costs more than the base fare on some routes. The cookie banner has a prominent 'Accept All' and a buried two-click path to reject. A countdown timer pressures you through upsells. The 'fast track security' add-on is pre-selected on certain country defaults. Priority boarding is offered three separate times in the flow, each time with different copy. Nine distinct dark patterns in a single checkout, all documented with screenshots, all still live in June 2026 — three and a half years after the DSA was supposed to outlaw most of them.
The HN thread is unusually substantive. Several commenters are ex-airline PMs who confirm the obvious: every one of these patterns ships because A/B tests show it lifts revenue, and the legal team has priced the fines. One comment with 200+ upvotes notes that Ryanair's 2025 ancillary revenue per passenger hit €24.30, up from €17.90 in 2022 — and that the dark patterns are the delta.
This is not a story about one airline being annoying. It's a story about a measurable arbitrage between conversion-rate optimization and consumer protection law, and Ryanair is openly the control group for how much you can get away with. The Digital Services Act, in force since February 2024, prohibits 'dark patterns' in Article 25, defined as interface designs that 'materially distort or impair' user decision-making. The Consumer Rights Directive bans pre-ticked boxes for paid add-ons. The Unfair Commercial Practices Directive covers confirmshaming. All of these apply. None have produced a meaningful fine against Ryanair specifically.
The asymmetry is deliberate. A single DSA fine is capped at 6% of global turnover, which sounds severe until you model it. Ryanair's FY2025 revenue was €13.9B, so the theoretical maximum is ~€834M — but the actual fines issued under DSA to date average closer to €10-50M per case, and Ryanair's ancillary revenue from these patterns alone is estimated at €1.2B/year. The math is uncomplicated.
What's interesting for practitioners is that the same playbook is now standard across SaaS checkout, subscription cancellation flows, and any consumer signup that has a paid tier. Every pattern in the Ryanair audit has a direct analog in B2C software you've shipped or used this week: pre-checked annual billing, sneaky trial-to-paid conversions, hide-the-cancel-link UX, confirmshaming on downgrade. The FTC's 'Click-to-Cancel' rule, which was supposed to kill the worst US version of this, was vacated by the Fifth Circuit in July 2024 on procedural grounds and has not been re-proposed. Europe has the laws but not the enforcement bandwidth. The US is rolling back what little it had.
The community reaction on HN splits along a predictable line. One camp argues this is fine — Ryanair tickets are cheap precisely because they monetize the friction, and informed consumers can simply uncheck the boxes. The other camp points out that 'informed consumers' is a fiction when the patterns are designed by behavioral economists specifically to defeat informed consent. The second camp is correct on the evidence: Brignull's 2010 taxonomy was built from eye-tracking studies showing that pre-ticked boxes are missed by 60-70% of users even when they're looking directly at them.
If you ship checkout, signup, or cancellation flows, this audit is a free adversarial test set. Pull up the screenshots and ask, for each pattern: do we do this? If yes, what was the lift, and what's the trust cost? The honest answer for most teams is that nobody measured the trust cost because it doesn't show up in the funnel — it shows up in churn six months later, in support tickets, and in chargeback rates that get blamed on the payment processor.
The defensible position in 2026 is to treat dark-pattern compliance as a security review, not a UX review. Add it to your PR checklist alongside SQL injection and XSS. Specific things to grep for: pre-checked checkboxes in checkout forms, asymmetric button styling between 'accept' and 'reject' on consent screens, multi-step cancellation flows where account creation took one click, countdown timers that reset when you reload, copy that frames declining an upsell as personal failure. None of these require legal review to identify. All of them have been litigated somewhere.
The second-order implication is for anyone building checkout-as-a-service. Stripe, Paddle, Lemon Squeezy, and the rest now ship default flows that are at least DSA-adjacent. If your team is rolling its own because the hosted version 'converts worse,' you are explicitly buying the legal risk that the platform absorbed. Price that into your build-vs-buy.
The interesting question is whether the EU actually enforces. The DSA's first major dark-pattern case is expected to land in Q3 2026, and Ryanair is on the short list of likely targets along with Amazon and Booking.com. If the first fine is symbolic, expect the patterns to spread; if it's structural — meaning behavioral remedies, not just money — expect a year of frantic checkout redesigns across European e-commerce. Either way, the audit is the document of record. Bookmark it the next time someone on your team proposes a pre-checked box.
About 1/3 of their revenue is ancillary (the dark patterns are there to cause ancillary revenue).I just flew from Bournemouth to Alicante on Ryanair for £50. A similar flight in the US (DC to Miami, for example) would be easily 5x that, possibly 7-8x. The dark patterns took me about 10min to cl
Oh, don't get me started on Ryanair, but alas.You go through what seems the entire check-in process, you get what seems like a summary at the end, with a link to a UK government site where you need to go next to get a travel authorization, I spend an hour doing that, finally finish that, I show
And a last, most sneaky one: At checkout if you pay with credit/debit card don't use Ryanair's "guaranteed exhange rate" if the cost of the flight is not in your card's currency (ticket by default, at least two clicks to find and untick it). That's ~6% gap from mid
They managed to create a business model relying in some sort of "slot machine" where customers buy the ticket to discover later they are "stupid" not noticing some rule hidden in the meticulously engineered dark patterns and, to board now and do not miss the planned trip, they wi
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
That “Don’t Insure Me” option hidden in the middle of a country list is pure evil. I’m used to seeing dark patterns everywhere but that’s a first for me.From where I stand, it’s not fair to charge the hell out of people who fall for these tricks while giving steep discounts to the ones who don’t. Ma