Yikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app an…
Substack's UI and 1Password temporarily cost me $2k
81–90 of 278 posts
Re: Substack's UI and 1Password temporarily cost me $2k
#82Seems more accurate to say that 1Password not Substack did this? Also headline is not true?
I'd say the Substack UI is messed up if (a) there's a hidden input box that automatically changes the selection, even though the user cannot manually enter information there, and (b) there's no confirmation screen to confirm everything is correct. It shouldn't matter that a password manager exposed the problem.
Re: Substack's UI and 1Password temporarily cost me $2k
#83Earlier quoted context omitted.
The testing burden is already enormous for things people want sites tested for.
Whats the solution for the busy engineer? Anyone know a Selenium plug in that let's you run with browser extensions or something? There's too many popular extensions to test manually.
Re: Substack's UI and 1Password temporarily cost me $2k
#84Re: Substack's UI and 1Password temporarily cost me $2k
#85Earlier quoted context omitted.
Or 1Pass does a little bit more smart in checking before randomly entering text? It wouldn't be difficult to catch this
The problem is that all of these autofillers are already way too complex, because almost no one uses the optimal markup (adding the attribute autocomplete="cc-exp-year", in this case)—almost no one has even heard of the proper autocomplete markup here (I remember being in a conference room with two or three hundred other web developers a couple of years back, and the speaker asked who knew about autocomplete="new-pas…
Re: Substack's UI and 1Password temporarily cost me $2k
#86Seems more accurate to say that 1Password not Substack did this? Also headline is not true?
Re: Substack's UI and 1Password temporarily cost me $2k
#87Seems more accurate to say that 1Password not Substack did this? Also headline is not true?
Yeah it seems pretty clear that this was a 1Password flaw and didn't really have anything to do with Substack's UI. And yes, the first paragraph notes that no money was spent, so not really sure why multiple people have downvoted your comment.
The UI is styled to make it so that a form input is completely indistinguishable from surrounding text, to such an extent that even people who know it's a form input in this thread have incorrectly assumed that it's not manually editable.
I can't comprehend how anyone could defend deliberately misleading UI design in a form that is asking for your credit card information. This is a problem with Substack. 1Password can definitely do better to guard against it happening, but the only reason it did happen is because Substack actively tried to hide important information from users in a payment screen.
Re: Substack's UI and 1Password temporarily cost me $2k
#88I wish sites would test their forms with popular password management systems. This kind of thing happens all too often (thought perhaps not with such a high cost). Why not make it easy for people who auto-fill with these programs -- don't fight them. (And I won't get into sites that won't let you paste passwords into their forms.)
Re: Substack's UI and 1Password temporarily cost me $2k
#89Earlier quoted context omitted.
The problem is that all of these autofillers are already way too complex, because almost no one uses the optimal markup (adding the attribute autocomplete="cc-exp-year", in this case)—almost no one has even heard of the proper autocomplete markup here (I remember being in a conference room with two or three hundred other web developers a couple of years back, and the speaker asked who knew about autocomplete="new-pas…
Where are these various autocompletes detailed?
Re: Substack's UI and 1Password temporarily cost me $2k
#90Earlier quoted context omitted.
You don't get cash back bonuses with a pre-paid card. In fact, they cost money. I am not going to give up saving 3% on everything I buy just to avoid this rare error that was easily corrected for no lost money.
Where are you getting 3% back on all transactions?