Earlier quoted context omitted.
Yes, password managers are way safer than copy-pasting. You don't want something as sensitive as a password in your clipboard buffer, either.
Mine clears the clipboard after 10 seconds.
Substack's UI and 1Password temporarily cost me $2k
131–140 of 278 posts
Re: Substack's UI and 1Password temporarily cost me $2k
#132I caught this when I got the confirmation email. I called the travel website, and they said since it was within 24 hours I could just cancel the tickets for free, or if I liked I could pay an outrageous fee to the airline to change the name on the ticket. Unsurprisingly I chose the former.
So, nor harm done, but if we’d gotten to the airport and my wife couldn’t come on holiday because I didn’t have a ticket for her... could have gone badly. :P
Re: Substack's UI and 1Password temporarily cost me $2k
#133Re: Substack's UI and 1Password temporarily cost me $2k
#134Earlier quoted context omitted.
Mine clears the clipboard after 10 seconds.
You do realize that in 10 seconds your computer can achieve a lot of stuffs right?
If there's some malicious desktop program running on your machine at the same time as the password manager then you're probably screwed regardless of whether the password passes through the clipboard - but maybe there's some subtleties I'm missing here.
Re: Substack's UI and 1Password temporarily cost me $2k
#135Earlier quoted context omitted.
Yeah it seems pretty clear that this was a 1Password flaw and didn't really have anything to do with Substack's UI. And yes, the first paragraph notes that no money was spent, so not really sure why multiple people have downvoted your comment.
If your UI can charge me $2023 instead of $250 without so much of a confirmation, your UI is just a minefield. Forget about auto fill, humans make typos in a free entry text box.
And obviously from their point of view, OP actually entered $ 2023 and was fully aware of what he was doing (they didn't know about the bug)
Re: Substack's UI and 1Password temporarily cost me $2k
#136Earlier quoted context omitted.
Speaking from personal experience -- over about six years at this point -- there are many, many web sites on the internets that 1Password's autofill works perfectly well on, and many others where it doesn't work perfectly but fails gracefully (or at least non-destructively). "Here is one site where it makes a mistake that could be catastrophic if you don't catch it" is just not a slam-dunk proof of 1Password being "p…
Ths is an appeal to authority. It is a shortcoming of the product's design for it to autofill a hidden field.
Re: Substack's UI and 1Password temporarily cost me $2k
#137Re: Substack's UI and 1Password temporarily cost me $2k
#138Earlier quoted context omitted.
That's paste
It looks like paste and it's almost the same from the user perspective, but the data never makes it to the clipboard, where it would be available to every running application.
[0] https://github.com/dlech/KeePass2.x/blob/VS2019/KeePassLib/N...