Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

61–70 of 353 posts

Re: 1Password to Add Telemetry

#61

Seems fine to me. Opt out is reasonable, I trust 1password to not fuck this up versus, say, LastPass. If you already trust 1password to store your credentials, I see little to no impact to your risk exposure by having them collect anonymized telemetry. Curious if others have thoughts here? Their UI has changed a lot in recent years, maybe this will enable them to make more informed design decisions so that one day gr…

> Opt out is reasonable

I strongly disagree with this and think much less of companies who do it that way. That said, that battle is already lost anyway.

Re: 1Password to Add Telemetry

#62
post #38

The only reason we're talking about this is that 1Password wrote a blog post about it. They're not dumb, they know that this is the reaction they can expect from a blog post about how they're doing telemetry. They compete with a raft of products that not only use telemetry, but do it sneakily and with SAAS vendors that add attack surface to their products. But nobody talks about telemetry in those products, because t…

> But nobody talks about telemetry in those products

Sure they do, and a lot. But they don't talk about with with the companies doing it. What would be the point?

Re: 1Password to Add Telemetry

#63
post #56
post #45

My history with 1Password: - Purchase a stand-alone license, getting well-performing and feature-complete native clients with several options for vault sync that are under my control. - Upgrade to 1Password 8, a version that sounds great, but has quietly removed local sync unless you checked forum and blog posts before buying. - Watch the clients go from being native to Electron and losing many, many features. Get fo…

Migrated to Bitwarden for the opensource years ago. Stayed for cheaper price, linux support, simplicity and "out of my way" philosophy. Never looked back to 1password.

Same. When I started using 1p, the vault was stored locally, and it was possible to decrypt it at the command line using openssl. They prided themselves on this. They moved to cloud-based, and at one point I went to check if data export worked, and it did not. I opened a support ticket, and before even offering any actual help they wanted to know why I wanted to export my data anyway. Then they wanted me to download and run some telemetry binary to collect info about my system. I figured out the problem myself without them, and told them why I felt this meant they now had a value set that meant I could not rely on them going forward. They offered me a discount code.

Bitwarden is great.

Re: 1Password to Add Telemetry

#64
post #18

If telemetry can tell them 1Password 8 UX is a downgrade from 7, I’m all for it.

What would they even do with that information?

“It is difficult to get a man to understand something, when his salary depends on his not understanding it.” - Upton Sinclair

Re: 1Password to Add Telemetry

#66

Earlier quoted context omitted.

What's the difference between telemetry from the client side, and aggregate logs of server api endpoints? Assume no PII, what's the difference? What do you mean by dark pattern?

I would say server side logging is one of the many downsides to SaaS based products and makes a great argument for running things locally. Any additional tracking of users exacerbates the problem.

For a password manager I'm in full agreement, but the gap between running something like SAP Cloud vs On-Premises is very costly. There are tradeoffs where it's worth it.

Re: 1Password to Add Telemetry

#67
post #38

The only reason we're talking about this is that 1Password wrote a blog post about it. They're not dumb, they know that this is the reaction they can expect from a blog post about how they're doing telemetry. They compete with a raft of products that not only use telemetry, but do it sneakily and with SAAS vendors that add attack surface to their products. But nobody talks about telemetry in those products, because t…

Exactly. Just look at Bitwarden's privacy policy, for example:

> We use data for analytics and measurement to understand how our the Site and Bitwarden Service are used. For example, we analyze data about your visits to our Site to do things like optimize product design. We use a variety of tools to do this, including Google Analytics. When you visit the Site using Google Analytics, we and Google may link information about your activity from that site with activity from other sites that use Google Analytics services.

Re: 1Password to Add Telemetry

#68
It sounds like they're planning it to be as general as possible (more just "how much is each feature used"), but it'll also be fully opt-in:

> And, of course, once this functionality rolls out to customers, you’ll be able to control whether or not telemetry is active on your account.

("account" sounds like you can turn it off family-wide or even organization-wide)

[ Reposted my comment from duplicate post: https://news.ycombinator.com/item?id=35685170 ]

Re: 1Password to Add Telemetry

#69
post #61

Seems fine to me. Opt out is reasonable, I trust 1password to not fuck this up versus, say, LastPass. If you already trust 1password to store your credentials, I see little to no impact to your risk exposure by having them collect anonymized telemetry. Curious if others have thoughts here? Their UI has changed a lot in recent years, maybe this will enable them to make more informed design decisions so that one day gr…

> Opt out is reasonable I strongly disagree with this and think much less of companies who do it that way. That said, that battle is already lost anyway.

Opt in is the same as not doing it at all. TFA explains their approach decently well and it seems sane to me.

It's not like this is telemetry in some open source thing for nefarious reasons. It's literally for their customers. They already know who you are, it's not like they're using this for targeted ads.

Re: 1Password to Add Telemetry

#70
post #54

Earlier quoted context omitted.

What about anonymous logging of which buttons people click on is illegal in the EU? Citation needed on this one. That would make any dashboard that showed which api endpoints are the most popular also illegal. Anomyous telemetry is not PII. GDPR is personal data.

> Anomyous telemetry is not PII. That depends. First, no data collection is "anonymous" when it is transmitted. Any anonymity must come later, and then is only possible if the company aggregates the data with other users and deletes the original data that was collected. PII/Personal Data are squishy terms. In the US, anyway, the legal definitions of what counts as "PII" leaves out an awful lot of actual PII -- so any…

We are talking EU and I specifically asked for Citation needed, and I realize you aren't the poster but this doesn't really answer my question.

Are we assuming 1Password is lying about anonymisation?

My point is they didn't "sneak it past the regulators", it's plainly legal to do this under GDPR, and if it isn't I need a citation.

Post reply on HN