Live data from Hacker News

Substack's UI and 1Password temporarily cost me $2k

timmyomahony.com

261–270 of 278 posts

Re: Substack's UI and 1Password temporarily cost me $2k

#261

Earlier quoted context omitted.

I don't think a webpage can read clipboard without the user manually pasting. If there's some malicious desktop program running on your machine at the same time as the password manager then you're probably screwed regardless of whether the password passes through the clipboard - but maybe there's some subtleties I'm missing here.

I've accidentally pasted sensitive passwords enough times that I know the procedure is prone to errors. If I have to do it, I immediately copy something else right afterwards, to avoid an accidental paste later on.

10 seconds auto-clear (which is configurable) is short enough to prevent me accidentally pasting onto some other site.

Could be better if it auto-cleared after a paste, but not sure how feasible that would be.

Re: Substack's UI and 1Password temporarily cost me $2k

#262

Earlier quoted context omitted.

The testing burden is already enormous for things people want sites tested for.

Whats the solution for the busy engineer? Anyone know a Selenium plug in that let's you run with browser extensions or something? There's too many popular extensions to test manually.

Follow this guide: https://support.1password.com/compatible-website-design/. Even if you can't test, at least try. I find that few forms take the basic steps. Most importantly: don't fuck with paste!

Re: Substack's UI and 1Password temporarily cost me $2k

#263
post #124
post #116

Earlier quoted context omitted.

Ths is an appeal to authority. It is a shortcoming of the product's design for it to autofill a hidden field.

It’s visually hidden for us to see, not for 1Password auto fill mechanism.

That exactly correct, which is why the fault is with 1Password's fill mechanism.

A product has a bug when it does not produce output in-line with its stated purpose and process. Nobody would use a refrigerator that suddenly forgets to keep food cold when a carton of milk is placed on the shelf.

Re: Substack's UI and 1Password temporarily cost me $2k

#264

I see a lot of comments blaming either substack or 1password, but to me it seems the archaic transaction method of credit cards deserves most of the blame for these kinds of problems. If the transaction authentication takes place on a separate page hosted by your own bank (so after the amount has been finalised) these kinds of mistakes can't happen. Unless the user neglects to look at the shown amount, but then the u…

That's a good solution. The risks associated with many issues can be transferred to the user in a way that they retain operational control.

Re: Substack's UI and 1Password temporarily cost me $2k

#266
post #173
post #139

Earlier quoted context omitted.

For example it could just read all the passwords from the password manager's UI.

Between Keepass, 1passwword, and lastpass I've never seen a password manager that just shows the password without the user explicitly choosing to reveal it

1password has the option to do so and I do it on my home desktop computer. Obviously on mobile devices it would be a bad idea and on those I leave that option in it's default, disabled state :)

Re: Substack's UI and 1Password temporarily cost me $2k

#267
post #250

I had a similar 1Password moment. I was buying airline tickets; entered my name, my wife’s name, address, declined insurance, declined hotel offer, scroll scroll scroll... Then I let 1Password fill in my payment details, which it did perfectly fine. But... what it ALSO did, on a field now well off the top of the screen, was change my wife’s first name to my full name. I caught this when I got the confirmation email.…

> But... what it ALSO did, on a field now well off the top of the screen, was change my wife’s first name to my full name. I also had a similar experience yesterday, with less expensive purchases fortunately. The default behavior of 1Password auto-fill is wrong IMO. It should only fill fields after the field that currently has the focus. Not start filling whatever is available from the top of the page.

I had the opposite experience a few years ago: I was a new user of password managers and did not let mine autofill when booking my plane.

The air carrier form was not consistent with my country's name nomenclature: First, Middle, Last instead of First (+second and third) and Last name. I filled it wrongly and had to pay $40 at the check-in counter because there was no passenger registered to my name on the flight.

Tried again with my password manager (Dashlane) a few days later and realized that I should have trusted it. Also, I know that it only fills fields after the selected one, not those before.

Re: Substack's UI and 1Password temporarily cost me $2k

#268
post #29

Earlier quoted context omitted.

1Pass can choose not to put CC information into hidden fields.

Looking at the screen cap, it's not actually a hidden form, as much as a form field styled to look like text.

I didn't say it is a hidden form, but a hidden field.

Re: Substack's UI and 1Password temporarily cost me $2k

#269
post #84

I've put "temporarily" in the title because the post now says the money has been refunded. The article is worth leaving up because, unlike the typical riler-upper, it touches on a phenomenon which is interesting in its own right. But I don't think it's fair to leave up a title that implies that there's an uncorrected injustice to get angry about. If anyone has a better solution, we can do that instead.

hi dang, I propose a universal solution for similar instances like when a site was down or when another issue has been sorted out: the use of "[resolved]" appended to the title.

This will save you any future issues of having to find ways to reword a title to indicate an issue has been resolved while also allowing for a way for anyone who wants to analyse resolved problems an easy [resolved] tag to filter for.

I hope you don't mind this suggestion if it's feasible to standardise.

Re: Substack's UI and 1Password temporarily cost me $2k

#270
post #84

I've put "temporarily" in the title because the post now says the money has been refunded. The article is worth leaving up because, unlike the typical riler-upper, it touches on a phenomenon which is interesting in its own right. But I don't think it's fair to leave up a title that implies that there's an uncorrected injustice to get angry about. If anyone has a better solution, we can do that instead.

hi dang, I propose a universal solution for similar instances like when a site was down or when another issue has been sorted out: the use of "[resolved]" appended to the title. This will save you any future issues of having to find ways to reword a title to indicate an issue has been resolved while also allowing for a way for anyone who wants to analyse resolved problems an easy [resolved] tag to filter for. I hope…

That's a good idea. I'll try to remember it for next time!

Edit 3 weeks later: I used that on https://news.ycombinator.com/item?id=26815768. Hopefully will continue to remember.

Post reply on HN