Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

81–90 of 353 posts

Re: 1Password to Add Telemetry

#81

Seems fine to me. Opt out is reasonable, I trust 1password to not fuck this up versus, say, LastPass. If you already trust 1password to store your credentials, I see little to no impact to your risk exposure by having them collect anonymized telemetry. Curious if others have thoughts here? Their UI has changed a lot in recent years, maybe this will enable them to make more informed design decisions so that one day gr…

> little to no impact to your risk exposure by having them collect anonymized telemetry

The key word there is "anonymized". What is the risk of the collected data accidentally being less anonymous than intended? What is the risk of accidentally collecting more data than intended? Microsoft has already had both types of accident [1][2], so I think it's fair to assume a risk close to 100% over time.

Even if users opt out, what is the risk of the opt-out mechanism at some point containing a bug that causes it to fail? Or the risk of the user at some point failing to properly configure the opt-out mechanism?

Is the company going to put as much effort into minimizing these risks as the end user would like? Is anonymization of telemetry going to be the top priority for the company?

[1] https://github.com/dotnet/sdk/issues/6145#issuecomment-22010...

[2] https://news.ycombinator.com/item?id=23260548

Re: 1Password to Add Telemetry

#82
post #54

Earlier quoted context omitted.

> Anomyous telemetry is not PII. That depends. First, no data collection is "anonymous" when it is transmitted. Any anonymity must come later, and then is only possible if the company aggregates the data with other users and deletes the original data that was collected. PII/Personal Data are squishy terms. In the US, anyway, the legal definitions of what counts as "PII" leaves out an awful lot of actual PII -- so any…

> First, no data collection is "anonymous" Because no network connection is anonymous but as long as you aren't handling PII, GDPR has nothing to say about it. I could sell an app in the EU that just pinged my server once a day. As long as I wasn't keeping a record of who pinged what when, there is no PII. Otherwise everything is PII and you would need consent before every TCP handshake.

> Because no network connection is anonymous but as long as you aren't handling PII

It's not the network connection that eliminates anonymity (although that, too), but the data itself. Even if there's no single piece of PII involved, fingerprinting is still a thing. That's why, if you want a hope at anonymity, you have to add the collected data into an aggregate collection and delete the original data records.

Re: 1Password to Add Telemetry

#83
Telemetry in a "trust us, this closed-source application which contains all your secrets, which we provide you and which we update periodically, is only contacting us for "privacy protecting telemetry" and not exfiltration, intentionally or not, of your most sensitive of all data" application is a hard pass for me. This seems like an IQ test kind of question.

(So many times error reporting, etc. have accidentally leaked highly sensitive data, which was then the source of a major compromise, in other systems. Maybe 1Password won't get it wrong, maybe 1Password will never be subject to any pressure to get it wrong...)

Re: 1Password to Add Telemetry

#84
post #54

Earlier quoted context omitted.

> Anomyous telemetry is not PII. That depends. First, no data collection is "anonymous" when it is transmitted. Any anonymity must come later, and then is only possible if the company aggregates the data with other users and deletes the original data that was collected. PII/Personal Data are squishy terms. In the US, anyway, the legal definitions of what counts as "PII" leaves out an awful lot of actual PII -- so any…

We are talking EU and I specifically asked for Citation needed, and I realize you aren't the poster but this doesn't really answer my question. Are we assuming 1Password is lying about anonymisation? My point is they didn't "sneak it past the regulators", it's plainly legal to do this under GDPR, and if it isn't I need a citation.

> Are we assuming 1Password is lying about anonymisation?

I wouldn't put it that way. Rather, I'd say that you shouldn't assume something is true just because a company claims it is. Especially when that thing can have a material effect on their profit margin.

Re: 1Password to Add Telemetry

#85
post #45

My history with 1Password: - Purchase a stand-alone license, getting well-performing and feature-complete native clients with several options for vault sync that are under my control. - Upgrade to 1Password 8, a version that sounds great, but has quietly removed local sync unless you checked forum and blog posts before buying. - Watch the clients go from being native to Electron and losing many, many features. Get fo…

Bought full license some time in 2014. Watched them disintegrate into subscription hell while making the apps worse. Moved everything to Firefox and Apple Passkeys. They integrate better with my workflow anyway.

Re: 1Password to Add Telemetry

#86
post #61

Earlier quoted context omitted.

> Opt out is reasonable I strongly disagree with this and think much less of companies who do it that way. That said, that battle is already lost anyway.

Opt in is the same as not doing it at all. TFA explains their approach decently well and it seems sane to me. It's not like this is telemetry in some open source thing for nefarious reasons. It's literally for their customers. They already know who you are, it's not like they're using this for targeted ads.

> it's not like they're using this for targeted ads.

Prove it. Right, you can't, because once telemetry runs you have no insight or control over what happens with the data. And trust is definitely not an option anymore after all that happened over the years.

Re: 1Password to Add Telemetry

#87

> Over the years, we’ve relied on our own usage in conjunction with your feedback to inform our decision making. This presents a challenge, though: we don’t know when you run into trouble unless you tell us. And sure, we have an extensive user research program, and listen to all of the feedback you share online and in conversations with our team. > But there are millions of people using 1Password now, often in cool a…

The quote isn't a reflection of the conversation they were having; it's merely a justification they're using for the decision they made.

Re: 1Password to Add Telemetry

#88

Earlier quoted context omitted.

> We didn’t have trouble understanding where user pain points were back then If anything, people seem to have much more difficulty understanding user pain points right now.

Because of telemetry we know what brings in the most money. So while telemetry might show that moving an item from one group to another (just making something up) takes > 1s, fixing this will not bring in $. So when we then do Sprint Planning all of that gets pushed to the ice box.

This already starts from a big mistake, because telemetry can't tell you the value of any work you haven't done yet.

The question whether it can tell you the value of anything at all is a hard one that needs plenty of context, and nobody seems interested on answering. But your reasoning doesn't need this answer.

Re: 1Password to Add Telemetry

#89
post #65

This is very simple: Present a one-time prompt asking to opt-in. Explain to me how my admittedly naive solution fails to deliver for all consenting parties.

It doesn't deliver for the company. Opt in telemetry is the same as not doing telemetry. Not because people are morally against telemetry but most people just click through. You might say that is a good thing or that is how it should be but that is exactly why it doesn't deliver the desired result for the company.

Re: 1Password to Add Telemetry

#90

Earlier quoted context omitted.

I'd accept making it opt-in, but opt-out is ridiculous. I can't imagine how they're going to get this past EU regulators. I love (although loved more in the past) 1Password and have deployed it in two separate companies. Between this and recent UI updates (well, over the last couple of years), maybe it's time to look at alternatives.

What about anonymous logging of which buttons people click on is illegal in the EU? Citation needed on this one. That would make any dashboard that showed which api endpoints are the most popular also illegal. Anomyous telemetry is not PII. GDPR is personal data.

> Anomyous telemetry is not PII. GDPR is personal data.

How are you exactly going to submit it anonymously? Will it connect over Tor? Because if you just send it over your internet connection, it arrives with your IP address on the packets, which is PII, which makes it data processing of PII, which makes it require a legal basis to process. And it is legally uncertain that 'legitimate interest' is a valid ground for telemetry data, leaving only opt-in consent.

Post reply on HN