1Password to Add Telemetry
11–20 of 353 posts
Re: 1Password to Add Telemetry
#12Telemetry to inform product decisions is fine, in fact I think it's necessary to have confidence that software is performing in the wild (e.g. crash reporting), or that customers know how to use it. What is not ok is opt-out telemetry for personalisation for advertising, or over-reaching personal data collection, in 1Password's case data from your vault. There is however a grey area in the middle – data about the per…
> No customer vault data can be seen or collected. We’re only interested in how people use the app itself, what features and screens they interact with – not what they store in their vaults, what sites they autofill on, or anything like that.
This seems contradictory to me. How can the code see what screen is open without interacting with the app? This implies there is some kind of sandboxing layer. How can the 1Password software engineers possibly be confident enough in this sandboxing to assert that "no customer data can be seen?" That may be their intent, but bugs happen, especially in code that runs at a layer above the app to analyze how users interact with it.
I will be opting out. Hopefully the opt-out mechanism doesn't have a bug in it either. And when there is inevitably a bug in the telemetry, I hope 1Password is okay with admitting that their opt-out system created two classes of users: those who did nothing, and thus remained vulnerable to bugs in the telemetry layer, and those who opted out of it.
Re: 1Password to Add Telemetry
#13Great products get built by someone with a vision to create them, mediocre products gets created by product managers justifying their positions with data they've gleaned by spying on users.
Re: 1Password to Add Telemetry
#14Re: 1Password to Add Telemetry
#15Seems fine to me. Opt out is reasonable, I trust 1password to not fuck this up versus, say, LastPass. If you already trust 1password to store your credentials, I see little to no impact to your risk exposure by having them collect anonymized telemetry. Curious if others have thoughts here? Their UI has changed a lot in recent years, maybe this will enable them to make more informed design decisions so that one day gr…
I don't, so I'm never upgrading to 1Password 8. The telemetry news only validates my decision. What I consider important in a security product and what AgileBits considers important diverged a while ago and that's ok I guess.
Re: 1Password to Add Telemetry
#16Telemetry to inform product decisions is fine, in fact I think it's necessary to have confidence that software is performing in the wild (e.g. crash reporting), or that customers know how to use it. What is not ok is opt-out telemetry for personalisation for advertising, or over-reaching personal data collection, in 1Password's case data from your vault. There is however a grey area in the middle – data about the per…
Opt-out telemetry is also not ok for product decisions. It's a dark pattern that shows no respect for user privacy.
Re: 1Password to Add Telemetry
#17At risk of sounding dumb: what's in the telemetry data?
> we’ll be able to gather only a small set of general events and interactions within our apps. Things like when you unlock the app, when you create a new item (but not its contents!), or when you use autofill (but not what sites you use it on!).
Re: 1Password to Add Telemetry
#18Re: 1Password to Add Telemetry
#19Seems fine to me. Opt out is reasonable, I trust 1password to not fuck this up versus, say, LastPass. If you already trust 1password to store your credentials, I see little to no impact to your risk exposure by having them collect anonymized telemetry. Curious if others have thoughts here? Their UI has changed a lot in recent years, maybe this will enable them to make more informed design decisions so that one day gr…
> If you already trust 1password to store your credentials I don't, so I'm never upgrading to 1Password 8. The telemetry news only validates my decision. What I consider important in a security product and what AgileBits considers important diverged a while ago and that's ok I guess.
Re: 1Password to Add Telemetry
#20Telemetry to inform product decisions is fine, in fact I think it's necessary to have confidence that software is performing in the wild (e.g. crash reporting), or that customers know how to use it. What is not ok is opt-out telemetry for personalisation for advertising, or over-reaching personal data collection, in 1Password's case data from your vault. There is however a grey area in the middle – data about the per…