Live data from Hacker News

Substack's UI and 1Password temporarily cost me $2k

timmyomahony.com

11–20 of 278 posts

Re: Substack's UI and 1Password temporarily cost me $2k

#11
post #3

Seems more accurate to say that 1Password not Substack did this? Also headline is not true?

I'd say the Substack UI is messed up if (a) there's a hidden input box that automatically changes the selection, even though the user cannot manually enter information there, and (b) there's no confirmation screen to confirm everything is correct. It shouldn't matter that a password manager exposed the problem.

Re: Substack's UI and 1Password temporarily cost me $2k

#13
post #3

Seems more accurate to say that 1Password not Substack did this? Also headline is not true?

Yeah it seems pretty clear that this was a 1Password flaw and didn't really have anything to do with Substack's UI. And yes, the first paragraph notes that no money was spent, so not really sure why multiple people have downvoted your comment.

I think the end of the article clearly admits that it's a little bit of both and actually gives really good advice to keep in mind while designing checkout flows.

Re: Substack's UI and 1Password temporarily cost me $2k

#15

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

Similar situation here. I use 1Password every day, but I only trust it to autofill simple login forms. Where something more complex is happening, I tend to copy information over field by field.

This was trained into me over the years as I saw 1Password do too many things that were wrong or even sometimes scary. The nominal benefit you get sometimes when it works properly isn't worth it.

And yes, web providers should give their web forms better names and better semantic information (e.g. ``), but even in 2021 it's just not always the case.

Re: Substack's UI and 1Password temporarily cost me $2k

#16
post #3

Seems more accurate to say that 1Password not Substack did this? Also headline is not true?

Yeah it seems pretty clear that this was a 1Password flaw and didn't really have anything to do with Substack's UI. And yes, the first paragraph notes that no money was spent, so not really sure why multiple people have downvoted your comment.

They were charged, but were able to get a refund from the publisher they subscribed to.

Re: Substack's UI and 1Password temporarily cost me $2k

#17
post #7

Earlier quoted context omitted.

Yeah it seems pretty clear that this was a 1Password flaw and didn't really have anything to do with Substack's UI. And yes, the first paragraph notes that no money was spent, so not really sure why multiple people have downvoted your comment.

because it would've probably failed with other password managers and probably browers (if there are people who save their card details to a browser) and it would probably also fail with tab.

If all the password managers in the world fail at this site, it's still a problem with the password managers. The fact that the field was looking as non-editable from the start has nothing to do with the fact that it filled the wrong field.

The user also had a chance to see how it filled the form and didn't bother checking.

Re: Substack's UI and 1Password temporarily cost me $2k

#18
post #3

Seems more accurate to say that 1Password not Substack did this? Also headline is not true?

Yeah it seems pretty clear that this was a 1Password flaw and didn't really have anything to do with Substack's UI. And yes, the first paragraph notes that no money was spent, so not really sure why multiple people have downvoted your comment.

If your UI can charge me $2023 instead of $250 without so much of a confirmation, your UI is just a minefield. Forget about auto fill, humans make typos in a free entry text box.

Re: Substack's UI and 1Password temporarily cost me $2k

#19
post #14

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

It’s not 1Password fault, but poor design and implementation. :-)

If it's not 1Password's fault, who's is it? Obviously this story had a happy ending, so it's not a terribly big issue, but 1Password's client ultimately passed along the unwanted data.

Re: Substack's UI and 1Password temporarily cost me $2k

#20
Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes).

This seems like another reason. It's not worth it. Keep the password manager in its own app and apply the tiny extra effort of pasting the password from there.

Post reply on HN