Live data from Hacker News

Substack's UI and 1Password temporarily cost me $2k

timmyomahony.com

121–130 of 278 posts

Re: Substack's UI and 1Password temporarily cost me $2k

#121

Earlier quoted context omitted.

Similar situation here. I use 1Password every day, but I only trust it to autofill simple login forms. Where something more complex is happening, I tend to copy information over field by field. This was trained into me over the years as I saw 1Password do too many things that were wrong or even sometimes scary. The nominal benefit you get sometimes when it works properly isn't worth it. And yes, web providers should…

> And yes, web providers should give their web forms better names and better semantic information (e.g. ` `), but even in 2021 it's just not always the case. Well, there's no semantic input for "year" or "currency", so there's nothing the form designer could do to stop 1Password from picking the wrong field. This does kinda get to the root of the issue, which is that 1Password has to do a lot of "cognitive" analysis…

> Well, there's no semantic input for "year" or "currency", so there's nothing the form designer could do to stop 1Password from picking the wrong field.

This is how you mark up the expiry year in a credit card form:

    

Re: Substack's UI and 1Password temporarily cost me $2k

#122
post #114

Earlier quoted context omitted.

On a desktop, you can use KeePass and its variants to "auto-type". It'll switch focus to the last app you were in and type your username, a tab, your password, and then enter. No extensions or clipboard required. Just hit CTRL-SHIFT-V after highlighting the entry.

That's paste

> No extensions or clipboard required.

Paste draws from the clipboard.

Re: Substack's UI and 1Password temporarily cost me $2k

#123

Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…

There is no way I could have convinced the people I have to use a password manager without the browser extension. So for those people it was either same password on all sites or a password manager with a browser extension.

Re: Substack's UI and 1Password temporarily cost me $2k

#124
post #116

Earlier quoted context omitted.

Speaking from personal experience -- over about six years at this point -- there are many, many web sites on the internets that 1Password's autofill works perfectly well on, and many others where it doesn't work perfectly but fails gracefully (or at least non-destructively). "Here is one site where it makes a mistake that could be catastrophic if you don't catch it" is just not a slam-dunk proof of 1Password being "p…

Ths is an appeal to authority. It is a shortcoming of the product's design for it to autofill a hidden field.

It’s visually hidden for us to see, not for 1Password auto fill mechanism.

Re: Substack's UI and 1Password temporarily cost me $2k

#125
post #14

Earlier quoted context omitted.

It’s not 1Password fault, but poor design and implementation. :-)

If it's not 1Password's fault, who's is it? Obviously this story had a happy ending, so it's not a terribly big issue, but 1Password's client ultimately passed along the unwanted data.

This field should be clearly visible, even if 1Password would mistakenly input data in there.

Re: Substack's UI and 1Password temporarily cost me $2k

#126

Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…

Password managers aren't nearly intelligent enough to be used without copy and paste for sensitive forms. One example is how almost every password manager including the built-in one in most browsers will assume that if there's a type="password" field, then the previous sibling field must be the username. Sometimes they'll even pick a field far away in the DOM like your chatbox input to autofill with the username. So…

Lastpass used to have an option for autofill to only fill empty fields, not sure if it is still there as I moved on a year ago but it stopped a little of that annoyance.

Re: Substack's UI and 1Password temporarily cost me $2k

#127
post #34

Earlier quoted context omitted.

To counter this: if you happen to find yourself on the phishing domain facebo0k.com and you end up copying your password into that.. Browser extensions guard for this better than we can.

Yes, password managers are way safer than copy-pasting. You don't want something as sensitive as a password in your clipboard buffer, either.

Gah what then? I use strong passwords but almost all of them flow through my clipboard.

Re: Substack's UI and 1Password temporarily cost me $2k

#128
post #55

I use a prepaid card online, which would have been a good safety net against things like this Also he was able to get a refund, and i think in most places online, you can cancel the order

You can get a "refund" everywhere, because it's an unauthorized transaction. If the merchant will not refund, you simply call up the card company and explain how you agreed to a charge of $10 and were subsequently charged $2,000. The only reason the article was phrased as "costing" the author money is for clickbait.

Re: Substack's UI and 1Password temporarily cost me $2k

#129

Earlier quoted context omitted.

After learning about how every app in your PC has unfettered un monitored access to the clipboard why in gods name would you do that? I explicitly make a point to never copy any password to the clipboard!

Any password of sufficient strength would be slow and error-prone to copy manually. What’s the middle ground?

Xkcd to the rescue? https://xkcd.com/936/

Gfycat already generates memorable URLs so it’s definitely possible. I myself do it manually nowadays (ie generate phrase password to be stored in manager so I can copy it manually if needed)

Re: Substack's UI and 1Password temporarily cost me $2k

#130
post #18

Earlier quoted context omitted.

Yeah it seems pretty clear that this was a 1Password flaw and didn't really have anything to do with Substack's UI. And yes, the first paragraph notes that no money was spent, so not really sure why multiple people have downvoted your comment.

If your UI can charge me $2023 instead of $250 without so much of a confirmation, your UI is just a minefield. Forget about auto fill, humans make typos in a free entry text box.

Many many years ago I once made a $6900 payment on a $69 internet bill because of a misplaced decimal point, with no confirmation before the amount was debited from my bank account. Definitely partly my fault for missing it, but they also didn’t design that payment flow to stop it from happening or even to autofill the correct payment amount.

(I was super unlucky that it happened when I’d just received a big performance bonus, or the bank would have simply declined the transaction outright due to me not having anything remotely like that much money in my accounts)

It took a surprising number of customer service calls (and then weeks) to get that payment refunded. And more than once I had to explain to a service rep that no, I didn’t want to just leave my internet service account balance thousands of dollars in credit so I wouldn’t need to pay the monthly bill for the next decade. I mean, obviously.

Making rent was kind of challenging that month.

Post reply on HN