Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

111–120 of 353 posts

Re: 1Password to Add Telemetry

#111

Earlier quoted context omitted.

The worry about telemetry in a product like this is how it's implemented. It's more code that could have bugs in it. What assurances do we have that it will execute safely in a way that it can't possibly access the password database, even in the event of (for example) compromise of the CI pipeline that builds the telemetry SDK? > No customer vault data can be seen or collected. We’re only interested in how people use…

They do separate the UI application from the kernel that manages access to the data. I guess the biggest risk would be that you click reveal, which has the kernel expose a password to the UI, and then the UI phones home with its entire raw contents.

Surely the UI code is what responds to clicking "reveal" and therefore, if compromised, could fetch the secret even without a click?

Re: 1Password to Add Telemetry

#112
post #76

The 1Password "no local/standalone vaults" "upgrade" in 7->8 is what got me to leave it after 15 years or so. They're killing the extensions used by Chrome/Brave/etc. in 3 months, so it became critical to move off Version 7 (which is probably not getting much security maintenance now, either). RIP.

This is the issue I'm having as well. I've been a standalone customer that's been paying since 2007, if I can't host my own vault either locally or in Dropbox - I'm out.

I was hoping to use 1P 7 for as long as I can, but with the Chrome extension dying it's going to become unusable. What have you found as an alternative?

Re: 1Password to Add Telemetry

#113

Earlier quoted context omitted.

They do separate the UI application from the kernel that manages access to the data. I guess the biggest risk would be that you click reveal, which has the kernel expose a password to the UI, and then the UI phones home with its entire raw contents.

Surely the UI code is what responds to clicking "reveal" and therefore, if compromised, could fetch the secret even without a click?

Good point. I don’t know what 1Password could do to prevent the telemetry from issuing control commands to the rest of the app outside of trying to prevent malicious code from being checked in and deployed.

Re: 1Password to Add Telemetry

#114

Opt-out telemetry is unacceptable, this also signals that the product team has no vision and the organization is riddled with bureaucracy. Great products get built by someone with a vision to create them, mediocre products gets created by product managers justifying their positions with data they've gleaned by spying on users.

Its a world of diminishing returns still looking for that 100x payday. A product is no longer a product once the end user becomes part of that product. It makes me sad and long for the days when I was excited to see what amazing new software was being posted every day to HN, can't remember the last time I went wow.

Re: 1Password to Add Telemetry

#115

> Over the years, we’ve relied on our own usage in conjunction with your feedback to inform our decision making. This presents a challenge, though: we don’t know when you run into trouble unless you tell us. And sure, we have an extensive user research program, and listen to all of the feedback you share online and in conversations with our team. > But there are millions of people using 1Password now, often in cool a…

> But there are millions of people using 1Password now, often in cool and innovative

It's a password manager, what's "cool" about it?

1Pwd always rubbed me the wrong way in the way they "take themselves too seriously" and overrate their importance

It's a password manager. They wouldn't even sync to cloud at first iirc, no?

The more boring the better

Re: 1Password to Add Telemetry

#116

Earlier quoted context omitted.

Because of telemetry we know what brings in the most money. So while telemetry might show that moving an item from one group to another (just making something up) takes > 1s, fixing this will not bring in $. So when we then do Sprint Planning all of that gets pushed to the ice box.

This already starts from a big mistake, because telemetry can't tell you the value of any work you haven't done yet. The question whether it can tell you the value of anything at all is a hard one that needs plenty of context, and nobody seems interested on answering. But your reasoning doesn't need this answer.

> telemetry can't tell you the value of any work you haven't done yet

But it can allow you to extrapolate from the value of things already done and usage patterns around them?

Re: 1Password to Add Telemetry

#117

Opt-out telemetry is unacceptable, this also signals that the product team has no vision and the organization is riddled with bureaucracy. Great products get built by someone with a vision to create them, mediocre products gets created by product managers justifying their positions with data they've gleaned by spying on users.

Another company having no issue with blatant and in the open breach of GDPR by refusing to comply with the required default of rejection.

Re: 1Password to Add Telemetry

#118
post #5

I have my issues with what 1Password has become as a product, but this seems like a very good stance to take. As a product owner, it's essential to know what and how people are using the product, collecting some straightforward telemetry that's anonymized and doesn't contain and Vault data strikes me as reasonable.

> As a product owner, it's essential to know what and how people are using the product

You can ask the users. You can apply some common sense (which 1Password team increasingly doesn't). They can look at the support forums listing the many issues (especially with UX) which are condescendingly dismissed. Etc.

Re: 1Password to Add Telemetry

#119

Earlier quoted context omitted.

100% agreement from me. People have trouble believing this, but software existed before telemetry existed. We didn’t have trouble understanding where user pain points were back then, because we actually performed user studies, and offered the ability for users to provide feedback if they wanted to. The field of UX wasn’t born the moment someone wrote the first telemetry library.

> We didn’t have trouble understanding where user pain points were back then If anything, people seem to have much more difficulty understanding user pain points right now.

It's also often the case that they understand a user pain point but don't fix it because they put it there with intent and purpose.

Re: 1Password to Add Telemetry

#120

> Over the years, we’ve relied on our own usage in conjunction with your feedback to inform our decision making. This presents a challenge, though: we don’t know when you run into trouble unless you tell us. And sure, we have an extensive user research program, and listen to all of the feedback you share online and in conversations with our team. > But there are millions of people using 1Password now, often in cool a…

> But there are millions of people using 1Password now, often in cool and innovative It's a password manager, what's "cool" about it? 1Pwd always rubbed me the wrong way in the way they "take themselves too seriously" and overrate their importance It's a password manager. They wouldn't even sync to cloud at first iirc, no? The more boring the better

You can use it for a lot more than just passwords, which IMO is what makes it stand apart from Bitwarden. You can store notes, credit cards, photocopies of IDs, software licenses, key pairs, etc. You get 1GB of storage. They really have turned it into a "vault" for anything digital.
Post reply on HN