Live data from Hacker News

Substack's UI and 1Password temporarily cost me $2k

timmyomahony.com

171–180 of 278 posts

Re: Substack's UI and 1Password temporarily cost me $2k

#173
post #139

Earlier quoted context omitted.

You do realize that in 10 seconds your computer can achieve a lot of stuffs right?

For example it could just read all the passwords from the password manager's UI.

Between Keepass, 1passwword, and lastpass I've never seen a password manager that just shows the password without the user explicitly choosing to reveal it

Re: Substack's UI and 1Password temporarily cost me $2k

#174
post #159

This is an example of a common antipattern in software: some piece of software fails to correctly implement something (here, modern HTML autocomplete="cc-exp-year"), and another piece of software goes through all kinds of contortions to work with incorrect or incomplete implementations with the result that it now behaves undesirably with a third piece of software. Specifically, 1Password has to do complicated guesses…

I have little faith site developers care about password managers. Many even try to block them from working due to some perceived notion that they are insecure.

I remember using a company-mandated pension website which required a very long password with a comprehensive selection of complexity requirements. To log in, the password had to be entered twice, but they had disabled the ability to use a password manager to populate them (I forget the exact mechanism). To me this is the worst of all worlds. If you put people off using your website, you are less likely to have breaches - security through misery.

I wrote to them pointing out the issue and apparently it was put on their backlog for the following year. I think I received an update about it a couple of years later.

Re: Substack's UI and 1Password temporarily cost me $2k

#175
post #159

Earlier quoted context omitted.

I have little faith site developers care about password managers. Many even try to block them from working due to some perceived notion that they are insecure.

I remember using a company-mandated pension website which required a very long password with a comprehensive selection of complexity requirements. To log in, the password had to be entered twice, but they had disabled the ability to use a password manager to populate them (I forget the exact mechanism). To me this is the worst of all worlds. If you put people off using your website, you are less likely to have breach…

I recently got an OnlyKey.

It plugs in as an HID so that passwords appear to have been typed in, not PW managed.

Useful little thing, it seems too good to be true.

Re: Substack's UI and 1Password temporarily cost me $2k

#176

Earlier quoted context omitted.

If it's not 1Password's fault, who's is it? Obviously this story had a happy ending, so it's not a terribly big issue, but 1Password's client ultimately passed along the unwanted data.

Clearly Substack. A UI that let's you specify 10X a price with no confirmation is (unintentionally in this case) malicious. This story could have easily been written about a user who fat fingered an extra 0 in the field.

Unintentional malice? What?

Re: Substack's UI and 1Password temporarily cost me $2k

#177

Earlier quoted context omitted.

I remember using a company-mandated pension website which required a very long password with a comprehensive selection of complexity requirements. To log in, the password had to be entered twice, but they had disabled the ability to use a password manager to populate them (I forget the exact mechanism). To me this is the worst of all worlds. If you put people off using your website, you are less likely to have breach…

I recently got an OnlyKey. It plugs in as an HID so that passwords appear to have been typed in, not PW managed. Useful little thing, it seems too good to be true.

OnlyKey looks interesting. A few things make me skeptical though: It only supports 24 accounts, which is two orders of magnitude fewer than I have in my password manager. And the hardware design doesn't look super convenient or durable. I bought a YubiKey a few years ago, and kept in on my keychain, and before I had even used it a dozen times, the entire thing disintegrated and became unusable.

Edit: I'm also a bit uneasy about securing access to all by accounts by one single PIN that can be used to unlock a physical device that is easy for someone to steal unnoticed.

Re: Substack's UI and 1Password temporarily cost me $2k

#178

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

Autofill is a hot mess. If you have more than one address, and also occasionally fill up info for your partner, or with your work phone, things can really escalate. I think my Chrome has 20 different combinations of 2 names, 2 addresses, 2 phone numbers.

And auto-fill always insists to fill out fields that have already been filled in - why can´t it just allow completion of a single form field, instead of putting in random information in all other fields. Before auto-fill, the fill-in suggestions for a single field actually used to be useful: start typing three letters and select the auto-suggested value.

Now, every time I fill out a form I use the autofill suggestions as a way to remember the information that needs to be filled in. But I have to watch out like a hawk to not actually let it "fill" that exact phone number I`m typing in, otherwise it'll fuck up the whole form and force me to start over.

Re: Substack's UI and 1Password temporarily cost me $2k

#179

Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…

I just have autofill disabled. To fill in the password, I need to actually click some buttons.

Re: Substack's UI and 1Password temporarily cost me $2k

#180
post #159

Earlier quoted context omitted.

I have little faith site developers care about password managers. Many even try to block them from working due to some perceived notion that they are insecure.

I remember using a company-mandated pension website which required a very long password with a comprehensive selection of complexity requirements. To log in, the password had to be entered twice, but they had disabled the ability to use a password manager to populate them (I forget the exact mechanism). To me this is the worst of all worlds. If you put people off using your website, you are less likely to have breach…

My broker asks for 4-5 random letters of my password each time, making password managers unusable as well. Thinking about it now, how would you encrypt a password using this method? Create hashes of every combination?
Post reply on HN