Live data from Hacker News

Substack's UI and 1Password temporarily cost me $2k

timmyomahony.com

21–30 of 278 posts

Re: Substack's UI and 1Password temporarily cost me $2k

#21

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

I once auto filled my way to enrolling a child that wasn't mine into school.

Re: Substack's UI and 1Password temporarily cost me $2k

#22
post #17
post #7

Earlier quoted context omitted.

because it would've probably failed with other password managers and probably browers (if there are people who save their card details to a browser) and it would probably also fail with tab.

If all the password managers in the world fail at this site, it's still a problem with the password managers. The fact that the field was looking as non-editable from the start has nothing to do with the fact that it filled the wrong field. The user also had a chance to see how it filled the form and didn't bother checking.

>it filled the wrong field

I agree, this is awful (I'd really like to know how on earth it decided that this field is where the expiration year belongs. It sounds like some extremely aggressive assumptions are being made).

>The user also had a chance to see how it filled the form and didn't bother checking.

It's impossible to overstate how wrongheaded, unproductive, and, frankly, lazy this sentiment is.

Re: Substack's UI and 1Password temporarily cost me $2k

#23

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

One of my online accounts has my city name as my first name because of autofill.

Re: Substack's UI and 1Password temporarily cost me $2k

#24

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

Similar situation here. I use 1Password every day, but I only trust it to autofill simple login forms. Where something more complex is happening, I tend to copy information over field by field. This was trained into me over the years as I saw 1Password do too many things that were wrong or even sometimes scary. The nominal benefit you get sometimes when it works properly isn't worth it. And yes, web providers should…

> And yes, web providers should give their web forms better names and better semantic information (e.g. ``), but even in 2021 it's just not always the case.

Well, there's no semantic input for "year" or "currency", so there's nothing the form designer could do to stop 1Password from picking the wrong field. This does kinda get to the root of the issue, which is that 1Password has to do a lot of "cognitive" analysis of the page to find the forms it wants which is simultaneously why it does better than most autofillers, and has worse false positives than most autofillers.

I am also a happy 1Password user, and I'll happily let it prefill a complex form for me, but I've caught enough of its mistakes in the past that I will always manually double check before submitting. I could also see myself making a similar mistake as this user on this form though (since it's so simple I might not manually double check).

Re: Substack's UI and 1Password temporarily cost me $2k

#25
post #3

Seems more accurate to say that 1Password not Substack did this? Also headline is not true?

Probably not fair to pin it fully on 1pw or substack.

1PW autofills based on common cc form names, year, credit_card[year] etc etc. Substack clearly named the field a name that could hit that, probably amount_per_year.

1PW can't account for every form on every website, just not realistic.

How's the headline not true? It's a UI/UX issue that caused him to be charged that amount?

Re: Substack's UI and 1Password temporarily cost me $2k

#27
post #14

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

It’s not 1Password fault, but poor design and implementation. :-)

The poor design and implementation of 1Password, you mean.

Re: Substack's UI and 1Password temporarily cost me $2k

#29
post #3

Seems more accurate to say that 1Password not Substack did this? Also headline is not true?

Probably not fair to pin it fully on 1pw or substack. 1PW autofills based on common cc form names, year, credit_card[year] etc etc. Substack clearly named the field a name that could hit that, probably amount_per_year. 1PW can't account for every form on every website, just not realistic. How's the headline not true? It's a UI/UX issue that caused him to be charged that amount?

1Pass can choose not to put CC information into hidden fields.

Re: Substack's UI and 1Password temporarily cost me $2k

#30
I've updated my blog post to include 1Password in the title as it contributed to the issue (I can't update the title here). That said, I've never experienced this before, having used 1Password on 100s of other payment forms so something is up.

I do think there are design issues with people being able to set subscription amounts manually without having a confirmation step when doing so.

Post reply on HN