Live data from Hacker News

Substack's UI and 1Password temporarily cost me $2k

timmyomahony.com

31–40 of 278 posts

Re: Substack's UI and 1Password temporarily cost me $2k

#31
post #29

Earlier quoted context omitted.

Probably not fair to pin it fully on 1pw or substack. 1PW autofills based on common cc form names, year, credit_card[year] etc etc. Substack clearly named the field a name that could hit that, probably amount_per_year. 1PW can't account for every form on every website, just not realistic. How's the headline not true? It's a UI/UX issue that caused him to be charged that amount?

1Pass can choose not to put CC information into hidden fields.

Looking at the screen cap, it's not actually a hidden form, as much as a form field styled to look like text.

Re: Substack's UI and 1Password temporarily cost me $2k

#34

Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…

To counter this: if you happen to find yourself on the phishing domain facebo0k.com and you end up copying your password into that.. Browser extensions guard for this better than we can.

Re: Substack's UI and 1Password temporarily cost me $2k

#35

I see replies blaming 1password being downvoted, so I'll ask a question instead. Why would 1password decide to fill out that particular input with the expiration date?

Because that one input had the word "year" in it. 1password confused "expiration year" for "$ / year".

It's a good bug.

Both substack and 1password are responsible to some degree, and it will be figured out, though I think 1password has more obligation to take action because it can happen with other websites too.

Re: Substack's UI and 1Password temporarily cost me $2k

#37
post #14

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

It’s not 1Password fault, but poor design and implementation. :-)

I don't trust autofill in what I use, either, Firefox or Keepass.

Re: Substack's UI and 1Password temporarily cost me $2k

#38
post #2

I wish sites would test their forms with popular password management systems. This kind of thing happens all too often (thought perhaps not with such a high cost). Why not make it easy for people who auto-fill with these programs -- don't fight them. (And I won't get into sites that won't let you paste passwords into their forms.)

The testing burden is already enormous for things people want sites tested for.

Whats the solution for the busy engineer? Anyone know a Selenium plug in that let's you run with browser extensions or something? There's too many popular extensions to test manually.

Re: Substack's UI and 1Password temporarily cost me $2k

#39

What's the point of hidden input there ? A bug ? A feature ?

It’s not “hidden” in the HTML form sense. It’s an input that is not styled as an obvious input field. The idea here is that if you want to, you can give the author more money as a “founding member”. You can the set the amount you’d like to give.

It is visible to the user, but it isn’t obvious that this is an adjustable value at all (at least on mobile). There are a number of UX issues at play here... but a poorly styled input isn’t an excuse for the password manager.

Re: Substack's UI and 1Password temporarily cost me $2k

#40
post #34

Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…

To counter this: if you happen to find yourself on the phishing domain facebo0k.com and you end up copying your password into that.. Browser extensions guard for this better than we can.

Yes, password managers are way safer than copy-pasting. You don't want something as sensitive as a password in your clipboard buffer, either.
Post reply on HN