Earlier quoted context omitted.
Probably not fair to pin it fully on 1pw or substack. 1PW autofills based on common cc form names, year, credit_card[year] etc etc. Substack clearly named the field a name that could hit that, probably amount_per_year. 1PW can't account for every form on every website, just not realistic. How's the headline not true? It's a UI/UX issue that caused him to be charged that amount?
1Pass can choose not to put CC information into hidden fields.
Substack's UI and 1Password temporarily cost me $2k
31–40 of 278 posts
Re: Substack's UI and 1Password temporarily cost me $2k
#32Did 1Password fill in the year twice? That would be a huge bug. Or will a fraud detection system ignore the missing year if everything else is fine?
Re: Substack's UI and 1Password temporarily cost me $2k
#33Re: Substack's UI and 1Password temporarily cost me $2k
#34Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…
Re: Substack's UI and 1Password temporarily cost me $2k
#35I see replies blaming 1password being downvoted, so I'll ask a question instead. Why would 1password decide to fill out that particular input with the expiration date?
It's a good bug.
Both substack and 1password are responsible to some degree, and it will be figured out, though I think 1password has more obligation to take action because it can happen with other websites too.
Re: Substack's UI and 1Password temporarily cost me $2k
#36Re: Substack's UI and 1Password temporarily cost me $2k
#37This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.
It’s not 1Password fault, but poor design and implementation. :-)
Re: Substack's UI and 1Password temporarily cost me $2k
#38I wish sites would test their forms with popular password management systems. This kind of thing happens all too often (thought perhaps not with such a high cost). Why not make it easy for people who auto-fill with these programs -- don't fight them. (And I won't get into sites that won't let you paste passwords into their forms.)
The testing burden is already enormous for things people want sites tested for.
Re: Substack's UI and 1Password temporarily cost me $2k
#39What's the point of hidden input there ? A bug ? A feature ?
It is visible to the user, but it isn’t obvious that this is an adjustable value at all (at least on mobile). There are a number of UX issues at play here... but a poorly styled input isn’t an excuse for the password manager.
Re: Substack's UI and 1Password temporarily cost me $2k
#40Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…
To counter this: if you happen to find yourself on the phishing domain facebo0k.com and you end up copying your password into that.. Browser extensions guard for this better than we can.