Live data from Hacker News

Substack's UI and 1Password temporarily cost me $2k

timmyomahony.com

41–50 of 278 posts

Re: Substack's UI and 1Password temporarily cost me $2k

#42
You are lucky. I was trying to get a refund from fax site where they let you enter a value into dropdown and then happily charge you default value.

I tried to dispute it with them, tried to dispute with Paypal and itdidn't protected me, even if I had evidence in a way of showing how the UI is not working and the charge - the answer was always "not enough documents provided". Luckily it was only $10, but maybe I should also have posted on HN

Re: Substack's UI and 1Password temporarily cost me $2k

#43
post #34

Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…

To counter this: if you happen to find yourself on the phishing domain facebo0k.com and you end up copying your password into that.. Browser extensions guard for this better than we can.

[deleted]

Re: Substack's UI and 1Password temporarily cost me $2k

#44

Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…

this is why I use a password manager that has no network connectivity whatsoever, and no browser integration. keepassx with a v2.0 keepass format file.

it works from a local file on disk. yes, it's more inconvenient if I am away from the computer it lives on, and I need to update a password, I have to connect the VPN to my home office, ssh to it, and run 'kpcli' (a keepass format command line program), or run keepassx in a vnc-over-ssh session.

but that hassle is worth it in my opinion.

Re: Substack's UI and 1Password temporarily cost me $2k

#45
post #14

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

It’s not 1Password fault, but poor design and implementation. :-)

1Password filled his card expiration date into the dollars field.

Re: Substack's UI and 1Password temporarily cost me $2k

#46
post #17
post #7

Earlier quoted context omitted.

because it would've probably failed with other password managers and probably browers (if there are people who save their card details to a browser) and it would probably also fail with tab.

If all the password managers in the world fail at this site, it's still a problem with the password managers. The fact that the field was looking as non-editable from the start has nothing to do with the fact that it filled the wrong field. The user also had a chance to see how it filled the form and didn't bother checking.

> The user also had a chance to see how it filled the form and didn't bother checking.

So ... you're saying it's the their own fault and Substack should keep the money?

Re: Substack's UI and 1Password temporarily cost me $2k

#47
Here's another report today of someone wrongly paying $2023 per year for a Substack newsletter: https://twitter.com/jessesingal/status/1374019267147018243/p...

Maybe it's the same subscriber and/or same publisher as in this blog post? If not, that would either be a very unhappy coincidence or a strong signal to Substack that they need to fix this issue.

Re: Substack's UI and 1Password temporarily cost me $2k

#49
post #14

Earlier quoted context omitted.

It’s not 1Password fault, but poor design and implementation. :-)

If it's not 1Password's fault, who's is it? Obviously this story had a happy ending, so it's not a terribly big issue, but 1Password's client ultimately passed along the unwanted data.

Clearly Substack. A UI that let's you specify 10X a price with no confirmation is (unintentionally in this case) malicious.

This story could have easily been written about a user who fat fingered an extra 0 in the field.

Re: Substack's UI and 1Password temporarily cost me $2k

#50
Just because a lot of people are commenting on this without seeing the form, if you go here[1] you can see it in action (no association with the page, it was the first one that turned up on Google).

A couple of takeaways missed by various comments:

The hidden input box can in fact be manually edited, and if the user selects "Founding member" that fact is highlighted (the cursor is inserted into the textbox).

The hidden input's name attribute is "value". The guess that 1Password is basing its guess on the "/year" text is probably accurate.

[1] https://nonlinearproject.com/subscribe

Post reply on HN