Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

51–60 of 353 posts

Re: 1Password to Add Telemetry

#51

Earlier quoted context omitted.

100% agreement from me. People have trouble believing this, but software existed before telemetry existed. We didn’t have trouble understanding where user pain points were back then, because we actually performed user studies, and offered the ability for users to provide feedback if they wanted to. The field of UX wasn’t born the moment someone wrote the first telemetry library.

> We didn’t have trouble understanding where user pain points were back then If anything, people seem to have much more difficulty understanding user pain points right now.

Because of telemetry we know what brings in the most money.

So while telemetry might show that moving an item from one group to another (just making something up) takes > 1s, fixing this will not bring in $.

So when we then do Sprint Planning all of that gets pushed to the ice box.

Re: 1Password to Add Telemetry

#52
post #25
post #22

Earlier quoted context omitted.

Where are those "ridiculous amounts of money"? The price of 1password seems very moderate so they must selling enormous number of licenses to amass so much money.

2022: "1Password with $620M Series C, now valued at $6.8B" https://techcrunch.com/2022/01/19/1password-series-c-funding... (following a $200M Series A and a $100M Series B in 2019/2021)

Hence the ”must monetize” part. The investors expect to wring at least 5x their money, and selling $49 lifelong licenses does not net you billions

Re: 1Password to Add Telemetry

#53
post #2

I've been a 1Password customer for many years. Their product is super solid. The family plan is very generous. I personally don't have an issue with them collecting some telemetry to improve the product. And they've stated they'll offer ways to opt-out.

It's enough to make me at least look for alternatives. If I'm paying for something, I'd strongly prefer to do so on my terms. I use Microsoft office in spite of the fact that it's basically just an industrial spying platform, because I don't have any other options. If I can find a password manager that's easy to switch too that doesn't spy on me, I'll do so. We shouldn't be rewarding companies for this.

Re: 1Password to Add Telemetry

#54

Earlier quoted context omitted.

I'd accept making it opt-in, but opt-out is ridiculous. I can't imagine how they're going to get this past EU regulators. I love (although loved more in the past) 1Password and have deployed it in two separate companies. Between this and recent UI updates (well, over the last couple of years), maybe it's time to look at alternatives.

What about anonymous logging of which buttons people click on is illegal in the EU? Citation needed on this one. That would make any dashboard that showed which api endpoints are the most popular also illegal. Anomyous telemetry is not PII. GDPR is personal data.

> Anomyous telemetry is not PII.

That depends. First, no data collection is "anonymous" when it is transmitted. Any anonymity must come later, and then is only possible if the company aggregates the data with other users and deletes the original data that was collected.

PII/Personal Data are squishy terms. In the US, anyway, the legal definitions of what counts as "PII" leaves out an awful lot of actual PII -- so any claims that "no PII is being collected" is meaningless without additional explanation of what data items are being collected.

Re: 1Password to Add Telemetry

#55

Opt-out telemetry is unacceptable, this also signals that the product team has no vision and the organization is riddled with bureaucracy. Great products get built by someone with a vision to create them, mediocre products gets created by product managers justifying their positions with data they've gleaned by spying on users.

100% agreement from me. People have trouble believing this, but software existed before telemetry existed. We didn’t have trouble understanding where user pain points were back then, because we actually performed user studies, and offered the ability for users to provide feedback if they wanted to. The field of UX wasn’t born the moment someone wrote the first telemetry library.

Because before js became popular, every web app had access to every single event execpt what, scroll and mouse position.

Telemetry has been the default for networked applications since longer than I've been alive. Think of a terminal connecting to a mainframe, how much telemetry it has access to, all of it, of course.

Re: 1Password to Add Telemetry

#56
post #45

My history with 1Password: - Purchase a stand-alone license, getting well-performing and feature-complete native clients with several options for vault sync that are under my control. - Upgrade to 1Password 8, a version that sounds great, but has quietly removed local sync unless you checked forum and blog posts before buying. - Watch the clients go from being native to Electron and losing many, many features. Get fo…

Migrated to Bitwarden for the opensource years ago.

Stayed for cheaper price, linux support, simplicity and "out of my way" philosophy. Never looked back to 1password.

Re: 1Password to Add Telemetry

#57

Telemetry to inform product decisions is fine, in fact I think it's necessary to have confidence that software is performing in the wild (e.g. crash reporting), or that customers know how to use it. What is not ok is opt-out telemetry for personalisation for advertising, or over-reaching personal data collection, in 1Password's case data from your vault. There is however a grey area in the middle – data about the per…

> or that customers know how to use it.

Telemetry that is detailed enough to reveal how I use a product is too invasive for my tastes.

Re: 1Password to Add Telemetry

#58
post #56
post #45

My history with 1Password: - Purchase a stand-alone license, getting well-performing and feature-complete native clients with several options for vault sync that are under my control. - Upgrade to 1Password 8, a version that sounds great, but has quietly removed local sync unless you checked forum and blog posts before buying. - Watch the clients go from being native to Electron and losing many, many features. Get fo…

Migrated to Bitwarden for the opensource years ago. Stayed for cheaper price, linux support, simplicity and "out of my way" philosophy. Never looked back to 1password.

Same, though I just use the free Bitwarden, not sure what the paid one provides.

It's been good. Very simple and reliable. Has barely changed in years of use and hasn't needed to.

Re: 1Password to Add Telemetry

#59

Telemetry to inform product decisions is fine, in fact I think it's necessary to have confidence that software is performing in the wild (e.g. crash reporting), or that customers know how to use it. What is not ok is opt-out telemetry for personalisation for advertising, or over-reaching personal data collection, in 1Password's case data from your vault. There is however a grey area in the middle – data about the per…

Do any developers collect usage statistics by sampling rather than a persistent data stream? I think it would possibly reassure privacy-conscious users that anonymized & aggregated telemetry really is what it claims to be if the phoning home only happens at random intervals. Otherwise that detailed record of usage is too tempting a target for the surveillance capitalists.

That wouldn't reassure me at all. Just because an application is phoning home at random intervals in no way means that the data wasn't being continuously collected.

What would reassure me is if the data were all in human-readable form and given to me to transmit myself.

Re: 1Password to Add Telemetry

#60

Earlier quoted context omitted.

I'd accept making it opt-in, but opt-out is ridiculous. I can't imagine how they're going to get this past EU regulators. I love (although loved more in the past) 1Password and have deployed it in two separate companies. Between this and recent UI updates (well, over the last couple of years), maybe it's time to look at alternatives.

If you don’t collect any identifiable data, then the EU has nothing to say about it.

Unless they have a non-IP based communication system, then they'll fall afoul of the same thing all online analytics services do - they'll be collecting, at least ephemerally, personal data under the EU definition.
Post reply on HN