Earlier quoted context omitted.
The worry about telemetry in a product like this is how it's implemented. It's more code that could have bugs in it. What assurances do we have that it will execute safely in a way that it can't possibly access the password database, even in the event of (for example) compromise of the CI pipeline that builds the telemetry SDK? > No customer vault data can be seen or collected. We’re only interested in how people use…
They do separate the UI application from the kernel that manages access to the data. I guess the biggest risk would be that you click reveal, which has the kernel expose a password to the UI, and then the UI phones home with its entire raw contents.
1Password to Add Telemetry
111–120 of 353 posts
Re: 1Password to Add Telemetry
#112The 1Password "no local/standalone vaults" "upgrade" in 7->8 is what got me to leave it after 15 years or so. They're killing the extensions used by Chrome/Brave/etc. in 3 months, so it became critical to move off Version 7 (which is probably not getting much security maintenance now, either). RIP.
I was hoping to use 1P 7 for as long as I can, but with the Chrome extension dying it's going to become unusable. What have you found as an alternative?
Re: 1Password to Add Telemetry
#113Earlier quoted context omitted.
They do separate the UI application from the kernel that manages access to the data. I guess the biggest risk would be that you click reveal, which has the kernel expose a password to the UI, and then the UI phones home with its entire raw contents.
Surely the UI code is what responds to clicking "reveal" and therefore, if compromised, could fetch the secret even without a click?
Re: 1Password to Add Telemetry
#114Opt-out telemetry is unacceptable, this also signals that the product team has no vision and the organization is riddled with bureaucracy. Great products get built by someone with a vision to create them, mediocre products gets created by product managers justifying their positions with data they've gleaned by spying on users.
Re: 1Password to Add Telemetry
#115> Over the years, we’ve relied on our own usage in conjunction with your feedback to inform our decision making. This presents a challenge, though: we don’t know when you run into trouble unless you tell us. And sure, we have an extensive user research program, and listen to all of the feedback you share online and in conversations with our team. > But there are millions of people using 1Password now, often in cool a…
It's a password manager, what's "cool" about it?
1Pwd always rubbed me the wrong way in the way they "take themselves too seriously" and overrate their importance
It's a password manager. They wouldn't even sync to cloud at first iirc, no?
The more boring the better
Re: 1Password to Add Telemetry
#116Earlier quoted context omitted.
Because of telemetry we know what brings in the most money. So while telemetry might show that moving an item from one group to another (just making something up) takes > 1s, fixing this will not bring in $. So when we then do Sprint Planning all of that gets pushed to the ice box.
This already starts from a big mistake, because telemetry can't tell you the value of any work you haven't done yet. The question whether it can tell you the value of anything at all is a hard one that needs plenty of context, and nobody seems interested on answering. But your reasoning doesn't need this answer.
But it can allow you to extrapolate from the value of things already done and usage patterns around them?
Re: 1Password to Add Telemetry
#117Opt-out telemetry is unacceptable, this also signals that the product team has no vision and the organization is riddled with bureaucracy. Great products get built by someone with a vision to create them, mediocre products gets created by product managers justifying their positions with data they've gleaned by spying on users.
Re: 1Password to Add Telemetry
#118I have my issues with what 1Password has become as a product, but this seems like a very good stance to take. As a product owner, it's essential to know what and how people are using the product, collecting some straightforward telemetry that's anonymized and doesn't contain and Vault data strikes me as reasonable.
You can ask the users. You can apply some common sense (which 1Password team increasingly doesn't). They can look at the support forums listing the many issues (especially with UX) which are condescendingly dismissed. Etc.
Re: 1Password to Add Telemetry
#119Earlier quoted context omitted.
100% agreement from me. People have trouble believing this, but software existed before telemetry existed. We didn’t have trouble understanding where user pain points were back then, because we actually performed user studies, and offered the ability for users to provide feedback if they wanted to. The field of UX wasn’t born the moment someone wrote the first telemetry library.
> We didn’t have trouble understanding where user pain points were back then If anything, people seem to have much more difficulty understanding user pain points right now.
Re: 1Password to Add Telemetry
#120> Over the years, we’ve relied on our own usage in conjunction with your feedback to inform our decision making. This presents a challenge, though: we don’t know when you run into trouble unless you tell us. And sure, we have an extensive user research program, and listen to all of the feedback you share online and in conversations with our team. > But there are millions of people using 1Password now, often in cool a…
> But there are millions of people using 1Password now, often in cool and innovative It's a password manager, what's "cool" about it? 1Pwd always rubbed me the wrong way in the way they "take themselves too seriously" and overrate their importance It's a password manager. They wouldn't even sync to cloud at first iirc, no? The more boring the better