Substack's UI and 1Password temporarily cost me $2k
171–180 of 278 posts
Re: Substack's UI and 1Password temporarily cost me $2k
#172Re: Substack's UI and 1Password temporarily cost me $2k
#173Earlier quoted context omitted.
You do realize that in 10 seconds your computer can achieve a lot of stuffs right?
For example it could just read all the passwords from the password manager's UI.
Re: Substack's UI and 1Password temporarily cost me $2k
#174This is an example of a common antipattern in software: some piece of software fails to correctly implement something (here, modern HTML autocomplete="cc-exp-year"), and another piece of software goes through all kinds of contortions to work with incorrect or incomplete implementations with the result that it now behaves undesirably with a third piece of software. Specifically, 1Password has to do complicated guesses…
I have little faith site developers care about password managers. Many even try to block them from working due to some perceived notion that they are insecure.
I wrote to them pointing out the issue and apparently it was put on their backlog for the following year. I think I received an update about it a couple of years later.
Re: Substack's UI and 1Password temporarily cost me $2k
#175Earlier quoted context omitted.
I have little faith site developers care about password managers. Many even try to block them from working due to some perceived notion that they are insecure.
I remember using a company-mandated pension website which required a very long password with a comprehensive selection of complexity requirements. To log in, the password had to be entered twice, but they had disabled the ability to use a password manager to populate them (I forget the exact mechanism). To me this is the worst of all worlds. If you put people off using your website, you are less likely to have breach…
It plugs in as an HID so that passwords appear to have been typed in, not PW managed.
Useful little thing, it seems too good to be true.
Re: Substack's UI and 1Password temporarily cost me $2k
#176Earlier quoted context omitted.
If it's not 1Password's fault, who's is it? Obviously this story had a happy ending, so it's not a terribly big issue, but 1Password's client ultimately passed along the unwanted data.
Clearly Substack. A UI that let's you specify 10X a price with no confirmation is (unintentionally in this case) malicious. This story could have easily been written about a user who fat fingered an extra 0 in the field.
Re: Substack's UI and 1Password temporarily cost me $2k
#177Earlier quoted context omitted.
I remember using a company-mandated pension website which required a very long password with a comprehensive selection of complexity requirements. To log in, the password had to be entered twice, but they had disabled the ability to use a password manager to populate them (I forget the exact mechanism). To me this is the worst of all worlds. If you put people off using your website, you are less likely to have breach…
I recently got an OnlyKey. It plugs in as an HID so that passwords appear to have been typed in, not PW managed. Useful little thing, it seems too good to be true.
Edit: I'm also a bit uneasy about securing access to all by accounts by one single PIN that can be used to unlock a physical device that is easy for someone to steal unnoticed.
Re: Substack's UI and 1Password temporarily cost me $2k
#178This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.
And auto-fill always insists to fill out fields that have already been filled in - why can´t it just allow completion of a single form field, instead of putting in random information in all other fields. Before auto-fill, the fill-in suggestions for a single field actually used to be useful: start typing three letters and select the auto-suggested value.
Now, every time I fill out a form I use the autofill suggestions as a way to remember the information that needs to be filled in. But I have to watch out like a hawk to not actually let it "fill" that exact phone number I`m typing in, otherwise it'll fuck up the whole form and force me to start over.
Re: Substack's UI and 1Password temporarily cost me $2k
#179Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…
Re: Substack's UI and 1Password temporarily cost me $2k
#180Earlier quoted context omitted.
I have little faith site developers care about password managers. Many even try to block them from working due to some perceived notion that they are insecure.
I remember using a company-mandated pension website which required a very long password with a comprehensive selection of complexity requirements. To log in, the password had to be entered twice, but they had disabled the ability to use a password manager to populate them (I forget the exact mechanism). To me this is the worst of all worlds. If you put people off using your website, you are less likely to have breach…