Live data from Hacker News

Substack's UI and 1Password temporarily cost me $2k

timmyomahony.com

71–80 of 278 posts

Re: Substack's UI and 1Password temporarily cost me $2k

#71
post #32

I don't doubt the story, but if the expiry year was in the wrong field, why did the payment go through? Did 1Password fill in the year twice? That would be a huge bug. Or will a fraud detection system ignore the missing year if everything else is fine?

If you look at the video of them clicking autocomplete it autofills both the amount field and the proper year field (even formatted to YY)

Re: Substack's UI and 1Password temporarily cost me $2k

#72
post #17

Earlier quoted context omitted.

If all the password managers in the world fail at this site, it's still a problem with the password managers. The fact that the field was looking as non-editable from the start has nothing to do with the fact that it filled the wrong field. The user also had a chance to see how it filled the form and didn't bother checking.

>it filled the wrong field I agree, this is awful (I'd really like to know how on earth it decided that this field is where the expiration year belongs. It sounds like some extremely aggressive assumptions are being made). >The user also had a chance to see how it filled the form and didn't bother checking. It's impossible to overstate how wrongheaded, unproductive, and, frankly, lazy this sentiment is.

[deleted]

Re: Substack's UI and 1Password temporarily cost me $2k

#73
post #17

Earlier quoted context omitted.

If all the password managers in the world fail at this site, it's still a problem with the password managers. The fact that the field was looking as non-editable from the start has nothing to do with the fact that it filled the wrong field. The user also had a chance to see how it filled the form and didn't bother checking.

> The user also had a chance to see how it filled the form and didn't bother checking. So ... you're saying it's the their own fault and Substack should keep the money?

It's definitely not Substack's fault. They presented the user a form to fill, the user used some tool to fill it and it failed.

Whether Substack should keep the money is a matter of goodwill, it's no different from the user fat-fingering an extra zero.

Re: Substack's UI and 1Password temporarily cost me $2k

#75
post #14

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

It’s not 1Password fault, but poor design and implementation. :-)

Substack. A payment form should NOT allow you to enter any price in text fields, hidden or not.

Re: Substack's UI and 1Password temporarily cost me $2k

#77
post #2

I wish sites would test their forms with popular password management systems. This kind of thing happens all too often (thought perhaps not with such a high cost). Why not make it easy for people who auto-fill with these programs -- don't fight them. (And I won't get into sites that won't let you paste passwords into their forms.)

Or 1Pass does a little bit more smart in checking before randomly entering text? It wouldn't be difficult to catch this

The problem is that all of these autofillers are already way too complex, because almost no one uses the optimal markup (adding the attribute autocomplete="cc-exp-year", in this case)—almost no one has even heard of the proper autocomplete markup here (I remember being in a conference room with two or three hundred other web developers a couple of years back, and the speaker asked who knew about autocomplete="new-password" and the likes; only three of us raised our hands: I and my coworker, and one other).

They’re already complex enough that it’s a disaster trying to figure anything out. You say it wouldn’t be difficult to catch this, but either it’ll be a special case finely tuned for this particular site, or it’ll break another site, causing expiry year to no longer be filled out where previously it was and should be.

Re: Substack's UI and 1Password temporarily cost me $2k

#79

Earlier quoted context omitted.

I find that both Bitwarden (personal use) and 1password (work use) do a very good job of filling in login forms.

1Password was one of my test extensions and the one I use every day. It works most of the time because username/password combos are the most common autofill configurations. So common that most password managers don't consider the case where you want to autofill a password without a matching username field on the page. "Password confirmation" being the classic example. They just don't handle anything other than the ma…

Interesting. The weirdest site I use on a regular basis is Mailgun and it has this scrolling form which isolates entry for email/password/2fa (which, as an aside, I hate) and it gets it right every time. I can't remember any instances of it going wrong, actually.

Re: Substack's UI and 1Password temporarily cost me $2k

#80

This is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.

The autofill in Safari that uses your contact info is pretty reliable but I always triple check when I use it.
Post reply on HN