Hacker News new | ask | show | jobs
by grizzles 3065 days ago
I have a (maybe) interesting twitter related anecdote. 5-6 weeks back I went to the twitter website and I was greeted with a login screen. I couldn't remember my password and didn't feel like finding it so I went off to look at other sites. That happened a few times, until I went back and POOF, I am automatically logged back in again. I've never seen a site un-invalidate an auth token before. Cool beans.
1 comments

I had something similarly weird with amazon.

I got a new iPhone and on iOS Safari I needed to sign in to all my accounts.

Except for some reason Amazon recognised me with one-click enabled. I never used one-click to buy anything before and accidentally bought a kindle book while browsing the site.

More strangely, when I went to turn off one-click in my settings I was forced to log in.

So I could one-click buy without explicitly authenticating, but needed to authenticate to disable it. Very strange and/or shady.

Btw - is there an easy way to cancel an accidental one-click buy? In my case it was a local author I wanted to support anyway, so I’ll keep the purchase. But surprised it’s so easy to accidentally purchase something from the mobile site if you swipe to scroll on the wrong place.

FYI Kindle purchases can only be made via one-click. I hated when Amazon forced me to enable it to get a copy of Traction.