Substack's UI and 1Password temporarily cost me $2k
41–50 of 278 posts
Re: Substack's UI and 1Password temporarily cost me $2k
#42I tried to dispute it with them, tried to dispute with Paypal and itdidn't protected me, even if I had evidence in a way of showing how the UI is not working and the charge - the answer was always "not enough documents provided". Luckily it was only $10, but maybe I should also have posted on HN
Re: Substack's UI and 1Password temporarily cost me $2k
#43Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…
To counter this: if you happen to find yourself on the phishing domain facebo0k.com and you end up copying your password into that.. Browser extensions guard for this better than we can.
Re: Substack's UI and 1Password temporarily cost me $2k
#44Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…
it works from a local file on disk. yes, it's more inconvenient if I am away from the computer it lives on, and I need to update a password, I have to connect the VPN to my home office, ssh to it, and run 'kpcli' (a keepass format command line program), or run keepassx in a vnc-over-ssh session.
but that hassle is worth it in my opinion.
Re: Substack's UI and 1Password temporarily cost me $2k
#45This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.
It’s not 1Password fault, but poor design and implementation. :-)
Re: Substack's UI and 1Password temporarily cost me $2k
#46Earlier quoted context omitted.
because it would've probably failed with other password managers and probably browers (if there are people who save their card details to a browser) and it would probably also fail with tab.
If all the password managers in the world fail at this site, it's still a problem with the password managers. The fact that the field was looking as non-editable from the start has nothing to do with the fact that it filled the wrong field. The user also had a chance to see how it filled the form and didn't bother checking.
So ... you're saying it's the their own fault and Substack should keep the money?
Re: Substack's UI and 1Password temporarily cost me $2k
#47Maybe it's the same subscriber and/or same publisher as in this blog post? If not, that would either be a very unhappy coincidence or a strong signal to Substack that they need to fix this issue.
Re: Substack's UI and 1Password temporarily cost me $2k
#48Re: Substack's UI and 1Password temporarily cost me $2k
#49Earlier quoted context omitted.
It’s not 1Password fault, but poor design and implementation. :-)
If it's not 1Password's fault, who's is it? Obviously this story had a happy ending, so it's not a terribly big issue, but 1Password's client ultimately passed along the unwanted data.
This story could have easily been written about a user who fat fingered an extra 0 in the field.
Re: Substack's UI and 1Password temporarily cost me $2k
#50A couple of takeaways missed by various comments:
The hidden input box can in fact be manually edited, and if the user selects "Founding member" that fact is highlighted (the cursor is inserted into the textbox).
The hidden input's name attribute is "value". The guess that 1Password is basing its guess on the "/year" text is probably accurate.