Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

41–50 of 353 posts

Re: 1Password to Add Telemetry

#41
post #27
post #17

Earlier quoted context omitted.

The post only mentions a few things: > we’ll be able to gather only a small set of general events and interactions within our apps. Things like when you unlock the app, when you create a new item (but not its contents!), or when you use autofill (but not what sites you use it on!).

call me stupid; but I'm not sure how those numbers are helpful for them?

[deleted]

Re: 1Password to Add Telemetry

#42
post #19

Earlier quoted context omitted.

> If you already trust 1password to store your credentials I don't, so I'm never upgrading to 1Password 8. The telemetry news only validates my decision. What I consider important in a security product and what AgileBits considers important diverged a while ago and that's ok I guess.

1password 8 definitely feels like a massive UX downgrade over v7. Though I can’t put why into words.

Only one word needed: Electron

Re: 1Password to Add Telemetry

#43

Earlier quoted context omitted.

> What is not ok is opt-out telemetry for personalisation for advertising Opt-out telemetry is also not ok for product decisions. It's a dark pattern that shows no respect for user privacy.

What's the difference between telemetry from the client side, and aggregate logs of server api endpoints? Assume no PII, what's the difference? What do you mean by dark pattern?

I would say server side logging is one of the many downsides to SaaS based products and makes a great argument for running things locally. Any additional tracking of users exacerbates the problem.

Re: 1Password to Add Telemetry

#44

Earlier quoted context omitted.

I'd accept making it opt-in, but opt-out is ridiculous. I can't imagine how they're going to get this past EU regulators. I love (although loved more in the past) 1Password and have deployed it in two separate companies. Between this and recent UI updates (well, over the last couple of years), maybe it's time to look at alternatives.

What about anonymous logging of which buttons people click on is illegal in the EU? Citation needed on this one. That would make any dashboard that showed which api endpoints are the most popular also illegal. Anomyous telemetry is not PII. GDPR is personal data.

As long as there's no "session identifier," even if unique and completely unmarriable to the PII, it doesn't matter. Any session ID where an ID represents one person runs afoul. Makes meaningful telemetry really hard without consent.

Everyone just consents anyway...

Re: 1Password to Add Telemetry

#45
My history with 1Password:

- Purchase a stand-alone license, getting well-performing and feature-complete native clients with several options for vault sync that are under my control.

- Upgrade to 1Password 8, a version that sounds great, but has quietly removed local sync unless you checked forum and blog posts before buying.

- Watch the clients go from being native to Electron and losing many, many features. Get forced into using the web app for simple things like seeing history.

- Watch browser integrations get progressively worse (check out the reviews on the Firefox extension, oh boy)

- Even if you've been using 1password 7 (the version you paid a good chunk of change on for, in 1Password's own words, a life-time license), you won't be able to use it with browsers at all soon https://support.1password.com/kb/202303/.

- Get popups and unwanted opt-out integration with social media logins, when I've gone out of my way to purge garbage like "login with google" from my internet experience.

- Get unwanted opt-out telemetry forced on you, which regardless of their assurance will eventually leak PII like it always does. People make mistakes, c'est la vie. I would have no issue with opt-in telemetry.

I think this is it for me. Forced telemetry is a small thing, but it's just one of many poor decisions. I'm sure it's a smart business decision and their investors will be happy finding more and more ways to extract value out of users. I just want a simple password manager, so after a decade this is it for my family and myself.

Re: 1Password to Add Telemetry

#47

Telemetry to inform product decisions is fine, in fact I think it's necessary to have confidence that software is performing in the wild (e.g. crash reporting), or that customers know how to use it. What is not ok is opt-out telemetry for personalisation for advertising, or over-reaching personal data collection, in 1Password's case data from your vault. There is however a grey area in the middle – data about the per…

> What is not ok is opt-out telemetry for … data from your vault.

If I’m reading correctly, they’re pretty clear and intentional about not collecting data from your vault (regardless of opt-in or opt-out). It’s simply usage patterns of the UI.

Do you see anything that suggests otherwise?

Re: 1Password to Add Telemetry

#48
While I am very allergic to such data collection, if you're going to do it, this seems like the way to do it.

I'm not a 1Password user (and won't become one), but if I were, I wouldn't necessarily be in a huge rush to stop as a result of this.

Re: 1Password to Add Telemetry

#49
I hope they fix all the issues with unlocking. Sometimes it takes ~20sec to unlock 1Password. Sometimes unlocking the browser plugin causes the app to pop up, other times not. Sometimes it just doesn’t unlock. I think there are two kinds of browser extension, which is confusing. All very frustrating at times and only getting worse.
Post reply on HN