Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

71–80 of 353 posts

Re: 1Password to Add Telemetry

#71
> Over the years, we’ve relied on our own usage in conjunction with your feedback to inform our decision making. This presents a challenge, though: we don’t know when you run into trouble unless you tell us. And sure, we have an extensive user research program, and listen to all of the feedback you share online and in conversations with our team.

> But there are millions of people using 1Password now, often in cool and innovative ways! If we’re going to keep improving 1Password, we can no longer rely on our own usage and your direct feedback alone.

I wish I were in the room when these arguments were being made. I would like to see the data that led them to this conclusion. I used to work at 1P, I was a happy user before I started working there and I continue to be a happy user. But I can remember so many conversations about telemetry and how we’d never use it…

Re: 1Password to Add Telemetry

#72
post #45

My history with 1Password: - Purchase a stand-alone license, getting well-performing and feature-complete native clients with several options for vault sync that are under my control. - Upgrade to 1Password 8, a version that sounds great, but has quietly removed local sync unless you checked forum and blog posts before buying. - Watch the clients go from being native to Electron and losing many, many features. Get fo…

I purchased 1Password 3 10 years ago. The license transfered for free up to 1Password 6, so that's the one I continue to use. I sync the vault myself.

Purchasing licenses in those times before everything moved to subscriptions was a good deal.

Re: 1Password to Add Telemetry

#73
post #56

Earlier quoted context omitted.

Migrated to Bitwarden for the opensource years ago. Stayed for cheaper price, linux support, simplicity and "out of my way" philosophy. Never looked back to 1password.

Same, though I just use the free Bitwarden, not sure what the paid one provides. It's been good. Very simple and reliable. Has barely changed in years of use and hasn't needed to.

I pay them for the TOTP authentication alone, so that I don't have to never ever use google authenticator ever again, but it also feels good to be able to support such an awesome project, even if it's only a little.

Re: 1Password to Add Telemetry

#74
post #54

Earlier quoted context omitted.

What about anonymous logging of which buttons people click on is illegal in the EU? Citation needed on this one. That would make any dashboard that showed which api endpoints are the most popular also illegal. Anomyous telemetry is not PII. GDPR is personal data.

> Anomyous telemetry is not PII. That depends. First, no data collection is "anonymous" when it is transmitted. Any anonymity must come later, and then is only possible if the company aggregates the data with other users and deletes the original data that was collected. PII/Personal Data are squishy terms. In the US, anyway, the legal definitions of what counts as "PII" leaves out an awful lot of actual PII -- so any…

> First, no data collection is "anonymous"

Because no network connection is anonymous but as long as you aren't handling PII, GDPR has nothing to say about it.

I could sell an app in the EU that just pinged my server once a day. As long as I wasn't keeping a record of who pinged what when, there is no PII.

Otherwise everything is PII and you would need consent before every TCP handshake.

Re: 1Password to Add Telemetry

#75
post #56
post #45

My history with 1Password: - Purchase a stand-alone license, getting well-performing and feature-complete native clients with several options for vault sync that are under my control. - Upgrade to 1Password 8, a version that sounds great, but has quietly removed local sync unless you checked forum and blog posts before buying. - Watch the clients go from being native to Electron and losing many, many features. Get fo…

Migrated to Bitwarden for the opensource years ago. Stayed for cheaper price, linux support, simplicity and "out of my way" philosophy. Never looked back to 1password.

Same. I think here is a good place to shout out to Vaultwarden:

https://github.com/dani-garcia/vaultwarden

Your password data, back under your own control.

Re: 1Password to Add Telemetry

#76
The 1Password "no local/standalone vaults" "upgrade" in 7->8 is what got me to leave it after 15 years or so. They're killing the extensions used by Chrome/Brave/etc. in 3 months, so it became critical to move off Version 7 (which is probably not getting much security maintenance now, either). RIP.

Re: 1Password to Add Telemetry

#77
post #44

Earlier quoted context omitted.

What about anonymous logging of which buttons people click on is illegal in the EU? Citation needed on this one. That would make any dashboard that showed which api endpoints are the most popular also illegal. Anomyous telemetry is not PII. GDPR is personal data.

As long as there's no "session identifier," even if unique and completely unmarriable to the PII, it doesn't matter. Any session ID where an ID represents one person runs afoul. Makes meaningful telemetry really hard without consent. Everyone just consents anyway...

My position is they can indeed get meaningful telemetry with opt-out anonymised data and that the GDPR does not prevent this.

I am countering the position of the parent poster and asking for a citation that would indicate you don't need to sneak this around the EU regulators to do it.

Re: 1Password to Add Telemetry

#78
I've had issues where 1Password wouldn't save my new logins properly, lasting for over a day. Maybe that's why they need the telemetry.

Do 1Password do security/privacy audits the way Mullvad do? That's a pretty decent way of building goodwill over time when it comes to decisions like this. It's probably a fine decision, but they should probably have gone to greater lengths to write this blog post in more exhaustive detail.

Re: 1Password to Add Telemetry

#79
post #44

Earlier quoted context omitted.

What about anonymous logging of which buttons people click on is illegal in the EU? Citation needed on this one. That would make any dashboard that showed which api endpoints are the most popular also illegal. Anomyous telemetry is not PII. GDPR is personal data.

As long as there's no "session identifier," even if unique and completely unmarriable to the PII, it doesn't matter. Any session ID where an ID represents one person runs afoul. Makes meaningful telemetry really hard without consent. Everyone just consents anyway...

> Everyone just consents anyway...

Unless you don't lie to them and don't use every dark pattern in the book to trick them into clicking the checkbox.

Re: 1Password to Add Telemetry

#80
post #61

Earlier quoted context omitted.

> Opt out is reasonable I strongly disagree with this and think much less of companies who do it that way. That said, that battle is already lost anyway.

Opt in is the same as not doing it at all. TFA explains their approach decently well and it seems sane to me. It's not like this is telemetry in some open source thing for nefarious reasons. It's literally for their customers. They already know who you are, it's not like they're using this for targeted ads.

> It's literally for their customers.

This is said by every company that does telemetry.

Post reply on HN