23 ms·
Substack's UI and 1Password temporarily cost me $2k
- tedyoung 6y agoI wish sites would test their forms with popular password management systems. This kind of thing happens all too often (thought perhaps not with such a high cost). Why not make it easy for people who auto-fill with these programs -- don't fight them. (And I won't get into sites that won't let you paste passwords into their forms.)
- s3cur3 6y agoThis. If your form is broken with autofill, your form is broken.
- MattGaiser 6y agoThe testing burden is already enormous for things people want sites tested for.
- thanksforfish 6y agoWhats the solution for the busy engineer? Anyone know a Selenium plug in that let's you run with browser extensions or something? There's too many popular extensions to test manually.
- MattGaiser 6y agoThis is probably so far down the list that I would be interested to hear of any kind of testing of extensions at all for non-extension companies.
- enjoylife 6y agoHaven't seen this automated, but I have seen internal issues raised by folks within large orgs when their extension started breaking things. But it's only once you have 50+ to 100's of engineers working on a product, each with a subset of extensions installed, that you can rely on the cross product of engineers and their installed extensions for realistic coverage.
- MattGaiser 6y agoI've never worked on a team of more than 7 on a product, so even testing on Firefox is considered too much work for testing. Put in dollars, it probably costs 5-10 million a year (if not more) to test extensions even haphazardly.
- edoceo 6y agoI feel like I could get pretty far building this, with that budget.
- clintonb 6y agoFollow this guide: https://support.1password.com/compatible-website-design/ https://support.1password.com/compatible-website-design/. Even if you can't test, at least try. I find that few forms take the basic steps. Most importantly: don't fuck with paste!
- deleted 6y ago[deleted]
- murermader 6y agoI mean what is there to test, really? Just use the the different input types and mark your fields as "email", "password" and so on. There is nothing to test really. If a password manager does not work when given clear hints / type description of what is expected, then that is the fault of the password manager.
- onelovetwo 6y agoOr 1Pass does a little bit more smart in checking before randomly entering text? It wouldn't be difficult to catch this
- chrismorgan 6y agoThe problem is that all of these autofillers are already way too complex, because almost no one uses the optimal markup (adding the attribute autocomplete="cc-exp-year", in this case)—almost no one has even heard of the proper autocomplete markup here (I remember being in a conference room with two or three hundred other web developers a couple of years back, and the speaker asked who knew about autocomplete="new-password" and the likes; only three of us raised our hands: I and my coworker, and one other). They’re already complex enough that it’s a disaster trying to figure anything out. You say it wouldn’t be difficult to catch this, but either it’ll be a special case finely tuned for this particular site, or it’ll break another site, causing expiry year to no longer be filled out where previously it was and should be.
- bombcar 6y agoWhere are these various autocompletes detailed?
- throwanem 6y agoMDN has a good list: https://developer.mozilla.org/en-US/docs/Web/HTML/Attributes/autocomplete https://developer.mozilla.org/en-US/docs/Web/HTML/Attributes...
- JimDabell 6y agoHTML 5.2 § 4.10.18.7. Autofill: https://www.w3.org/TR/html52/sec-forms.html#sec-autofill https://www.w3.org/TR/html52/sec-forms.html#sec-autofill
- lamontcg 6y agoI wonder how many of those devs use a password manager and just thought it was magic they didn't need to worry about when they were writing those kinds of forms. I assumed that kind of markup had to exist, but its not my job to do web development at all, so time being finite, I'd never seen those. But I always assumed that they'd have to exist if I ever went looking. Why do people whose job it is to know these things not bother checking?
- deleted 6y ago[deleted]
- kiririn 6y agoI’d settle for login forms that don’t hide the password box until you enter your username/email. I don’t see how they benefit real users in any way, and my password manager can’t understand it, requiring manual copy/paste entry
- jaywalk 6y agoThis is (generally) done because they offer SSO functionality, and need to know whether to redirect the user to their corporate SSO page or show the password prompt.
- petulla 6y agoSeems more accurate to say that 1Password not Substack did this? Also headline is not true?
- CGamesPlay 6y agoYeah it seems pretty clear that this was a 1Password flaw and didn't really have anything to do with Substack's UI. And yes, the first paragraph notes that no money was spent, so not really sure why multiple people have downvoted your comment.
- merb 6y agobecause it would've probably failed with other password managers and probably browers (if there are people who save their card details to a browser) and it would probably also fail with tab.
- jojobas 6y agoIf all the password managers in the world fail at this site, it's still a problem with the password managers. The fact that the field was looking as non-editable from the start has nothing to do with the fact that it filled the wrong field. The user also had a chance to see how it filled the form and didn't bother checking.
- happytoexplain 6y ago>it filled the wrong field I agree, this is awful (I'd really like to know how on earth it decided that this field is where the expiration year belongs. It sounds like some extremely aggressive assumptions are being made). >The user also had a chance to see how it filled the form and didn't bother checking. It's impossible to overstate how wrongheaded, unproductive, and, frankly, lazy this sentiment is.
- deleted 6y ago[deleted]
- jojobas 6y agoI'd say it's more like 1Password cost you $2,023.
- ALittleLight 6y agoI think it's both. 1Password shouldn't have filled in that amount and Substack should have had a clear confirmation - "Are you sure you want to pay *2,023 dollars* a year?"
- tadfisher 6y agoEvery single other website I've purchased from has a "confirm your order" page. Instantly charging the customer's card after submitting the payment form is a headache for both customers and merchants, because it's easy to make mistakes.
- oceliker 6y agoMy guess is that 1password filled it with the year because it saw the “/year” part of that input box…
- readflaggedcomm 6y agoThis is exactly why I don't trust autofill. How many times has it passed along information you didn't intend, but without any obvious errors? Nobody knows.
- monkin 6y agoIt’s not 1Password fault, but poor design and implementation. :-)
- neolog 6y ago1Password filled his card expiration date into the dollars field.
- smoldesu 6y agoIf it's not 1Password's fault, who's is it? Obviously this story had a happy ending, so it's not a terribly big issue, but 1Password's client ultimately passed along the unwanted data.
- freewilly1040 6y agoClearly Substack. A UI that let's you specify 10X a price with no confirmation is (unintentionally in this case) malicious. This story could have easily been written about a user who fat fingered an extra 0 in the field.
- ThePowerOfFuet 6y agoUnintentional malice? What?
- monkin 6y agoThis field should be clearly visible, even if 1Password would mistakenly input data in there.
- IncRnd 6y agoThe poor design and implementation of 1Password, you mean.
- shubik22 6y agoInteresting bug. Appreciate the post and the disclaimer at the top but IMO the headline should be updated too. Right now it’s a bit clickbaity and also inaccurate.
- TechBro8615 6y agoYikes. I love my password manager, but I decided when I got it that I was never going to use the browser extensions. Putting your password manager anywhere near your web browser just seems like insanity to me (all the exploit write-ups I recall about password managers were related to browser extensions and sandbox escapes). This seems like another reason. It's not worth it. Keep the password manager in its own app and apply the tiny extra effort of pasting the password from there.
- walrus01 6y agothis is why I use a password manager that has no network connectivity whatsoever, and no browser integration. keepassx with a v2.0 keepass format file. it works from a local file on disk. yes, it's more inconvenient if I am away from the computer it lives on, and I need to update a password, I have to connect the VPN to my home office, ssh to it, and run 'kpcli' (a keepass format command line program), or run keepassx in a vnc-over-ssh session. but that hassle is worth it in my opinion.
- askmike 6y agoTo counter this: if you happen to find yourself on the phishing domain facebo0k.com and you end up copying your password into that.. Browser extensions guard for this better than we can.
- juancampa 6y agoI see replies blaming 1password being downvoted, so I'll ask a question instead. Why would 1password decide to fill out that particular input with the expiration date?
- lopatin 6y agoBecause that one input had the word "year" in it. 1password confused "expiration year" for "$ / year". It's a good bug. Both substack and 1password are responsible to some degree, and it will be figured out, though I think 1password has more obligation to take action because it can happen with other websites too.
- revskill 6y agoWhat's the point of hidden input there ? A bug ? A feature ?
- mbreese 6y agoIt’s not “hidden” in the HTML form sense. It’s an input that is not styled as an obvious input field. The idea here is that if you want to, you can give the author more money as a “founding member”. You can the set the amount you’d like to give. It is visible to the user, but it isn’t obvious that this is an adjustable value at all (at least on mobile). There are a number of UX issues at play here... but a poorly styled input isn’t an excuse for the password manager.
- edaemon 6y agoIt is hidden in the HTML form sense. <input name="amount" type="hidden" value="15000"> It doesn't become visible to the user until you click the radio button.
- kalleboo 6y agoThat hidden input element contains the normalized value in cents, if that got filled out he would have only gotten charged $20. Right before it in the DOM is the stylized user-input field which does not get hidden (and populates the hidden field via JS) <input class="variable-amount-input" type="text" style="width: 27px;">
- tomahony 6y agoI've updated my blog post to include 1Password in the title as it contributed to the issue (I can't update the title here). That said, I've never experienced this before, having used 1Password on 100s of other payment forms so something is up. I do think there are design issues with people being able to set subscription amounts manually without having a confirmation step when doing so.
- codesnik 6y ago1password payment form filling works fine so rarely for me, I usually copy just number by hand. I wonder if that's somehow specific to Russia (field names are still in english, but it doesn't seem to help much)
- ectopod 6y agoI don't doubt the story, but if the expiry year was in the wrong field, why did the payment go through? Did 1Password fill in the year twice? That would be a huge bug. Or will a fraud detection system ignore the missing year if everything else is fine?
- viceroyalbean 6y agoIf you look at the video of them clicking autocomplete it autofills both the amount field and the proper year field (even formatted to YY)
- deleted 6y ago[deleted]
- millstone 6y agoWhy do browser need to guess at autofill? Isn't it to everyone's advantage for forms to just tag their fields explicitly?
- kjrose 6y agoWhoa. That's absolutely insane. And yet now that someone has demonstrated it I can see this turning into a dark pattern that a variety of less scrupulous sites will use in the foreseeable future.
- galkk 6y agoYou are lucky. I was trying to get a refund from fax site where they let you enter a value into dropdown and then happily charge you default value. I tried to dispute it with them, tried to dispute with Paypal and itdidn't protected me, even if I had evidence in a way of showing how the UI is not working and the charge - the answer was always "not enough documents provided". Luckily it was only $10, but maybe I should also have posted on HN
- hyperrail 6y agoHere's another report today of someone wrongly paying $2023 per year for a Substack newsletter: https://twitter.com/jessesingal/status/1374019267147018243/photo/1 https://twitter.com/jessesingal/status/1374019267147018243/p... Maybe it's the same subscriber and/or same publisher as in this blog post? If not, that would either be a very unhappy coincidence or a strong signal to Substack that they need to fix this issue.
- flemhans 6y agoThe author knew from the beginning it wouldn't "cost them $2023", but that it would most likely be solved by a simple support request. The title is misleading.
- wyattpeak 6y agoJust because a lot of people are commenting on this without seeing the form, if you go here[1] you can see it in action (no association with the page, it was the first one that turned up on Google). A couple of takeaways missed by various comments: The hidden input box can in fact be manually edited, and if the user selects "Founding member" that fact is highlighted (the cursor is inserted into the textbox). The hidden input's name attribute is "value". The guess that 1Password is basing its guess on the "/year" text is probably accurate. [1] https://nonlinearproject.com/subscribe https://nonlinearproject.com/subscribe
- tomxor 6y agoWhy are those fields not overridden in the backend?... If the back-end doesn't check those fields are what they should be for each option then the reverse could also be true (free membership)
- DangitBobby 6y agoWhat do you mean? The goal of that subscription option is to allow the user to pay a custom amount. I guarantee you the custom amount cannot be less than the yearly membership.
- Gaelan 6y agoI assume it's an intentional feature (pay what you want, as long as its above the "standard" price, to give the author additional support).
- systems 6y agoI use a prepaid card online, which would have been a good safety net against things like this Also he was able to get a refund, and i think in most places online, you can cancel the order
- cortesoft 6y agoYou don't get cash back bonuses with a pre-paid card. In fact, they cost money. I am not going to give up saving 3% on everything I buy just to avoid this rare error that was easily corrected for no lost money.
- r00fus 6y agoWhere are you getting 3% back on all transactions?
- throwanem 6y agoPresumably on a credit card, which would also have more robust chargeback rights than debit cards typically do. Between that and the likely relatively high value of a customer qualifying for 3% cash back on every transaction, I doubt it'd be more than a minor inconvenience to have the transaction reversed, even if the acquirer declined to refund it - which didn't happen here, in any case.
- cortesoft 6y agoCiti double rewards card
- boring_twenties 6y agoCiti lets you create virtual numbers with custom dollar amount limits and/or expiration dates: https://www.cardbenefits.citi.com/Products/Virtual-Account-Numbers https://www.cardbenefits.citi.com/Products/Virtual-Account-N...
- r00fus 6y agoI hate to be pedantic, but Citi gives 2% IIRC, not 3%.
- gkoberger 6y agoIt's interesting Substack is getting the blame here rather than 1Password. Ultimately, though, I think it's two separate systems doing the best they can to work together, and failing. Payments should be handled by the browser, like how mobile phones do it. I loathe giving Google or Apple more power/control, but this is a situation where I'm still genuinely shocked how rudimentary payments online are.
- davelacy 6y agoOhhhhh nooooooooo! (facepalm)
- deleted 6y ago[deleted]
- notsureaboutpg 6y ago>values from the front-end form for any fields that are not pay what you can That's exactly what this field was though, a pay-what-you-can field (hidden because its visibility is conditional, possibly)
- dang 6y agoI've put "temporarily" in the title because the post now says the money has been refunded. The article is worth leaving up because, unlike the typical riler-upper, it touches on a phenomenon which is interesting in its own right. But I don't think it's fair to leave up a title that implies that there's an uncorrected injustice to get angry about. If anyone has a better solution, we can do that instead.
- behindsight 6y agohi dang, I propose a universal solution for similar instances like when a site was down or when another issue has been sorted out: the use of "[resolved]" appended to the title. This will save you any future issues of having to find ways to reword a title to indicate an issue has been resolved while also allowing for a way for anyone who wants to analyse resolved problems an easy [resolved] tag to filter for. I hope you don't mind this suggestion if it's feasible to standardise.
- dang 6y agoThat's a good idea. I'll try to remember it for next time! Edit 3 weeks later: I used that on https://news.ycombinator.com/item?id=26815768 https://news.ycombinator.com/item?id=26815768. Hopefully will continue to remember.
- guru4consulting 6y agoany security issues with using browser's inbuilt password manager when compared to dedicated password managers?
- acjohnson55 6y agoOSs need to provide credential management with APIs to let users choose their password manager, and then browsers can use OS support. Only then can we stop the madness.
- pimlottc 6y agoJust wanted to add some detail on how the 1Password extension operates here, since the term "autofill" can be ambiguous: 1. The "autofill" function only fills in the credit number when the user specifically tells it to; it does not proactively fill forms with no user intervention. 2. "autofill" does not automatically submit the form after filling (although certain forms may be implemented to submit automatically once complete); in this particular case, the user still has a chance to review the completed form before manually clicking the subscribe button.
- gorkish 6y agoAll of this isn't particularly relevant if the function is abysmally terrible at filling the correct fields with the correct data, which in the case of 1Password certainly seems to be the case. In the example posted here, it happily completed fields for the credit card expiration year TWICE on the same form, one of which was pre-populated with a value that could not possibly have been a year. The apparent cause is because the substring 'year' appeared in the field name. Levenshtein distance of 12 for a 4 letter word? Yep, looks good! I mean, it's a result so certain there's no need to prompt the user, highlight changed fields or anything, right?
- Imagenuity 6y agoAn article on HN a few years ago on how easy it is to steal data using auto form fill. https://news.ycombinator.com/item?id=13329525 https://news.ycombinator.com/item?id=13329525 For this reason, never use auto form fill.
- jwalton 6y agoI had a similar 1Password moment. I was buying airline tickets; entered my name, my wife’s name, address, declined insurance, declined hotel offer, scroll scroll scroll... Then I let 1Password fill in my payment details, which it did perfectly fine. But... what it ALSO did, on a field now well off the top of the screen, was change my wife’s first name to my full name. I caught this when I got the confirmation email. I called the travel website, and they said since it was within 24 hours I could just cancel the tickets for free, or if I liked I could pay an outrageous fee to the airline to change the name on the ticket. Unsurprisingly I chose the former. So, nor harm done, but if we’d gotten to the airport and my wife couldn’t come on holiday because I didn’t have a ticket for her... could have gone badly. :P
- DangerousPie 6y agoI had a similar story a few years ago, except it changed my birthdate rather than my name. Luckily I looked at the confirmation email for some reason and noticed it. Was a total nightmare to get that changed, although I didn't end up paying in the end.
- DavidMankin 6y agoA few years ago they wouldn’t let me board a flight from SFO to Australia because my visa said I was born in 1921 when my passport didn’t agree. After a good bit of hassle we just had me go and apply for (and pay for) another visa on the electronic application site and this time I noticed that it’s exactly what happened: 1Password (IIRC) used my Visa expiration year for my visa birthday. I’m lucky that my status meant it was an automatic approval for the second visa!
- heavenlyblue 6y agoIt's amazing though that they literally gave a visa to some other random person without any issue at all (i.e. not even cross-checking some values in your passport).
- voiper1 6y ago
- deleted 6y ago[deleted]
- dawnerd 6y ago1Pass definitely needs to add some kind of notice or alert when it fills in hidden fields. And it really needs to not overwrite a field that’s already been filled in. It’s really frustrating when it decides to h do everything you typed in.
- SulphurCrested 6y agoThis is an example of a common antipattern in software: some piece of software fails to correctly implement something (here, modern HTML autocomplete="cc-exp-year"), and another piece of software goes through all kinds of contortions to work with incorrect or incomplete implementations with the result that it now behaves undesirably with a third piece of software. Specifically, 1Password has to do complicated guesses of what to fill where because many sites don't set autocomplete properly, so inevitably it will guess wrongly sometimes. Other examples are problems with lock files and file versioning (because programs tried to roll their own when the operating system didn't provide them), and the complexity of parsing "HTML soup" and emails with all kinds of bizarre invalid syntaxes. I can't offer a general solution, but if password managers simply refused to autofill to any field other than the one with the matching standard autocomplete attribute, web developers might start doing the right thing. (Do Safari, Chrome and Edge already do this? Only they have the clout to make it happen.) The user could still fill out a text box lacking the standard autocomplete attribute by right-clicking and manually selecting the correct field. Password managers should also get cheaper because their vendors would not need armies of developers adding workarounds for popular sites. Somehow this kind of nonsense has become culturally acceptable in the software industry. If the car industry worked this way you'd have to take your car back to the dealer once a month to be patched to take account of constantly changing fuel formulations. Standards exist for a reason.
- yoz-y 6y agoI have little faith site developers care about password managers. Many even try to block them from working due to some perceived notion that they are insecure.
- tweetle_beetle 6y agoI remember using a company-mandated pension website which required a very long password with a comprehensive selection of complexity requirements. To log in, the password had to be entered twice, but they had disabled the ability to use a password manager to populate them (I forget the exact mechanism). To me this is the worst of all worlds. If you put people off using your website, you are less likely to have breaches - security through misery. I wrote to them pointing out the issue and apparently it was put on their backlog for the following year. I think I received an update about it a couple of years later.
- vbezhenar 6y agoThat's one of the reasons I don't want to use 1Password and instead I'm just using old KeePass. KeePass fills what field I've selected. 1Password does its own magic and I don't like magic. KeePass might be slower, but I'm not filling those forms every day, so I can live with it. Basically KeePass does simple thing and does it well. 1Password might be good at doing complex things, but it does not have AI.
- djamrozik 6y agoI just use the native app from 1Password for that reason (getting pw from toolbar). Slower, but at least I know what's happening.
- mleonhard 6y agoThat order form has poor usability. 1. It uses placeholder text instead of a label. See "Placeholders in Form Fields Are Harmful" https://www.nngroup.com/articles/form-design-placeholders/ https://www.nngroup.com/articles/form-design-placeholders/ 2. It hides the fact that the "$250/year" is actually a text box. See "Long-Term Exposure to Flat Design: How the Trend Slowly Decreases User Efficiency" https://www.nngroup.com/articles/flat-design-long-exposure/ https://www.nngroup.com/articles/flat-design-long-exposure/ 3. The app makes the text box into a button plus text box. As a button, it modifies its parent widget, the radio button. This is unexpected behavior. The app would be better to show the text box after the user selects the "Founding Member" radio button. That would make the text box subordinate to the radio button and reduce user errors. See "8 Design Guidelines for Complex Applications - 6. Reduce Clutter Without Reducing Capability" https://www.nngroup.com/articles/complex-application-design/ https://www.nngroup.com/articles/complex-application-design/
- groundCode 6y agoI only let my password manager fill in passwords. It’s less efficient for sure but my cc details are in muscle memory and filling out my name and address doesn’t really bother me too much.
- progx 6y agoDid anyone try to set -100 Dollar? ;-)
- raesene9 6y agoThat was my first thought, where's the server-side validation that the amount submitted is in-line with what the UI showed. In this case it was higher than the UI stated, but what happens if it was lower...
- alibarber 6y agoThis story reminded me of my experiences working in a bar (in the UK, chip-and-pin was a thing but contactless was only just rolling out) It was mainly a student bar so basically every card was a debit card... I occasionally would come across declined card receipts from the machine for some 6 figure amount that had been attempted to charge. Was concerned at first but what had happened was clearly the staff member had forgotten to press enter after typing in the amount, the customer still saw the amount - put in their pin, enter, now it says type pin, try again, then panic when their bank declines it. Luckily the only bad thing that would come out of this is that they should go to the ATM and change the pin, after running the transaction again properly.
- royroyroys 6y agoHas anyone noticed that NameCheap's login page makes the newsletter field get filled in when you use a password manager to autofill the login page?
- aetherspawn 6y agoNevermind that, does that mean that their billing has an exploit and I can buy Substack Founder for $1? Or can I convince their system to bill me -$1 for that matter.
- rawoke083600 6y agoHonest Question: Why do you guys use PW and not just Chrome build-in pw ? Assuming you neutral or not anti-google in the first place.
- xuki 6y agoWhat if I want to use another browser? What if I want to use the same password on my iPhone? What if I manage a team and need to share certain passwords with my teammates?
- pnt12 6y agoIt can't login to other applications, such as steam and discord clients. It can't create passwords based on random words. If for some reason I can't use the password manager directly, I Can quickly check that the password is staples-horse-battery-correct and type it manually. (I'm a Firefox user using keepassXC, but it's basically the same situation)
- benhurmarcel 6y agoYou can store any number of fields, rather than just 1 username and password per website. I typically have notes, maybe one-time passwords, a PIN, the email I signed up with, whether they have my address, various URL if they share the login, etc.
- this_was_posted 6y agoI see a lot of comments blaming either substack or 1password, but to me it seems the archaic transaction method of credit cards deserves most of the blame for these kinds of problems. If the transaction authentication takes place on a separate page hosted by your own bank (so after the amount has been finalised) these kinds of mistakes can't happen. Unless the user neglects to look at the shown amount, but then the user is clearly at fault.
- dsr12 6y agoThis is the way it happens in India. We have to enter an OTP to authenticate the transaction. The OTP comes as a SMS and it tells the amount.Some merchants tie up with bank and we can enter the OTP on the merchant's site or choose to go to the bank's site to enter OTP. In any case the OTP page is a new page and the amount is displayed.
- IncRnd 6y agoThat's a good solution. The risks associated with many issues can be transferred to the user in a way that they retain operational control.
- vintagedave 6y agoIt was not expensive, merely inconvenient, but 1Password and Waze combined to give me a two hours of frustration in December. At the end I went back to the beginning and reported the experience here. I wrote on twitter, "Let's follow a trail of really Bad Tech Decisions between Waze and 1Password." -- https://twitter.com/cpp_delphi_dave/status/1335639039295303681 https://twitter.com/cpp_delphi_dave/status/13356390392953036... to read more. It's short. Of the two, 1Password did reach out, but Support emails went nowhere. Waze never reached out at all.
- pnt12 6y agoThe abominable UX in this situation is that users need to give free access to their credit card for payment, at the promise that the other party will play nice. This is backed by strong laws, but still absurd. The control should be inversed: the 3rd party should request payment from your bank and you would be able to confirm it from the bank website or app. This is already possible in Portugal with an app where you can give a seller your phone number and it prompts you for payment. (might be something of a privacy issue, but it beats a possible fraud issue)
- Xelbair 6y agoPoland has a neat system - you input one time code into the sellers payment processor, and then you get to confirm the payment in your app. Code is one time use, valid for 2 minutes - and you can see all the details in the confirmation that comes from your banking app. you can also use the same system to tie your phone number to your bank acc, letting other people in this system send you money instantly without extra fees between different banks - and you only need to share your phone number.
- Nextgrid 6y agoSome countries have their own variations of this but they all feel half-assed to me and often rely on phone numbers or something equally stupid. We already have an industry standard for access delegation: OAuth, which has been battle-tested over 10 years and supports different flows for various applications (browser, mobile app, etc).
- filleduchaos 6y ago3-D Secure was introduced in 2001. Additionally, I don't quite think making a payment is within the problem domain of OAuth. Most often I'm explicitly not trying to give the site access to my account - I'm trying to fulfil one request.
- Nextgrid 6y ago> I don't quite think making a payment is within the problem domain of OAuth OAuth is merely a way to authorize access. Depending on which scopes are requested, it could be a one-off request. Typically in webapps, access is assumed to be a one-off unless the "offline_access" scope is requested for example. Furthermore OAuth would improve recurring payments - the website can request a max payment amount or frequency and the user (on their bank's authentication page) can further constrain those settings if needed.
- egoisticalgoat 6y agoIt's been a while, but a similar thing happened to me. The delivery address form was on the same page as the cart, and my autofill put my zip code into the article amount. A little shocking at first to see a bill of 65,000€ instead of 12€, but at least it took less than an hour to resolve.
- aranw 6y agoThis is why I don't have my credit cards stored for "easy" input and submission and instead always enter them manually I really wish Dashlane would let me disable the reminded to save my credit card details as this is a feature I do not care for
- qwertox 6y agoAlso, after I finished entering it, I hit Ctrl-F and manually enter it again in the search popup to see if it matches what I typed into the field.
- adav 6y agoIt may not convert as well, but this is why I really appreciate the payment confirmation type screen before the charge is actually made.
- paultopia 6y agoThe deeper problem here is that credit card numbers are obsolete. Websites should be using Apple Pay and similar stored payment info APIs that don't go through an unnecessary error-prone user-facing interface. (Yes, Apple etc. are oligopolists, but so are Visa/MasterCard)
- zeptonaut22 6y agoIronically, the founder of my company and I spent over an hour breaking apart this exact page yesterday talking about its UI. There are a lot of really good things that this page does right (shows tradeoffs between different tiers in a way that's not confusing at every tier), but... yikes. Sorry to hear about this.
- jonnycomputer 6y agoOne of my utilities likes to add an extra bit of login confirmation with a question, like, "What is your favorite sport's team?". Every time, my password manager prompts me to overwrite my site password with answers to those questions. It's like walking over a railroad bridge that's falling apart.
- lucideer 6y agoGreat to hear that this got resolved and fair play to Substack for that, but this is inarguably a 1Password bug. If there had been any issue with resolution, they'd be the party I'd be chasing. Other commenters here have bemoaned the need for these kind of heuristics in dealing with compat with bad HTML form implementations, but there's an easy fix to that: origin-based compat lists. Browsers do this for quirksmode/website compat fixes: they apply heuristics to a specifically tested list of sites. And browsers need to work with a much larger set of webpages than 1Password, so there's no reason 1Password couldn't do the same. There isn't really any good excuse for applying heuristics blindly by default to a wide range of websites you have not tested those heuristics against. There might be an argument if it increased overall compat with the web IF these weren't highly sensitive pages (1Password saves credit card details!), but in this case there isn't really any excuse. The cost of achieving "blind" compat with smaller sites is too high in this case.
- andix 6y agoThat's why your credit card should be using 2FA for authorizing payments (via App or SMS-TAN). Visa Secure Code or MasterCard Identity Check.
- racl101 6y agoAfter seeing 1Password's automatic form filling behavior in action almost a decade ago I decided not to use it just in case of this sort of thing. I'm happy to use for storing my passwords and maybe logging in but that's about it.
- Avi-D-coder 6y agoSimilar experience on Firefox mobile