Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

131–140 of 353 posts

Re: 1Password to Add Telemetry

#131
post #76

The 1Password "no local/standalone vaults" "upgrade" in 7->8 is what got me to leave it after 15 years or so. They're killing the extensions used by Chrome/Brave/etc. in 3 months, so it became critical to move off Version 7 (which is probably not getting much security maintenance now, either). RIP.

Little worse is that the manifest deprecation was delayed into 2024, but that hasn't stopped them from killing the extensions in 3 months.

I loathe having to migrate out of 1P 7, but there really is no choice now.

Re: 1Password to Add Telemetry

#132

Earlier quoted context omitted.

100% agreement from me. People have trouble believing this, but software existed before telemetry existed. We didn’t have trouble understanding where user pain points were back then, because we actually performed user studies, and offered the ability for users to provide feedback if they wanted to. The field of UX wasn’t born the moment someone wrote the first telemetry library.

Because before js became popular, every web app had access to every single event execpt what, scroll and mouse position. Telemetry has been the default for networked applications since longer than I've been alive. Think of a terminal connecting to a mainframe, how much telemetry it has access to, all of it, of course.

> Because before js became popular, every web app had access to every single event execpt what, scroll and mouse position.

Huh? No, they had access to basically nothing unless the user did something that triggered a network request. What did you type in that form, but delete before submitting? No visibility. Which parts of the page did you linger on the longest? Which parts of the text did you highlight? No visibility.

They could see when you requested/submitted stuff, but that was about it. Pages couldn't sit there looking over your shoulder while you were using the page.

Re: 1Password to Add Telemetry

#133
post #124
post #76

The 1Password "no local/standalone vaults" "upgrade" in 7->8 is what got me to leave it after 15 years or so. They're killing the extensions used by Chrome/Brave/etc. in 3 months, so it became critical to move off Version 7 (which is probably not getting much security maintenance now, either). RIP.

This is my stance as well. I have not chosen a successor yet, but I’ll have a look at Bitwarden, Keepass and the recently released Proton Pass. Trusting Dropbox for sync (which I did) meant trusting a cloud service, too, but IMO it is a less lucrative target for hacks than a server that stores _nothing but_ credentials. Also, using DB made me less dependent on connectivity (LAN sync) and would let me switch providers…

I'm going to try KeePassXC & syncthing. I assume its going to be no where near as good as 1P, but between no extension support, no local vaults, secret security ops, I don't see a choice.

Re: 1Password to Add Telemetry

#134
> At that point, we’ll also provide guidance on how you can opt out if you’d like to.

Well, at least there is opt out. Probably, will be on account-by-account basis, not family/organization-wide.

Re: 1Password to Add Telemetry

#135

Earlier quoted context omitted.

> What is not ok is opt-out telemetry for personalisation for advertising Opt-out telemetry is also not ok for product decisions. It's a dark pattern that shows no respect for user privacy.

What's the difference between telemetry from the client side, and aggregate logs of server api endpoints? Assume no PII, what's the difference? What do you mean by dark pattern?

Server logs can't watch your every move, even when you're not intentionally creating network requests. "Telemetry" is spyware, full stop.

Re: 1Password to Add Telemetry

#136

Opt-out telemetry is unacceptable, this also signals that the product team has no vision and the organization is riddled with bureaucracy. Great products get built by someone with a vision to create them, mediocre products gets created by product managers justifying their positions with data they've gleaned by spying on users.

100% agreement from me. People have trouble believing this, but software existed before telemetry existed. We didn’t have trouble understanding where user pain points were back then, because we actually performed user studies, and offered the ability for users to provide feedback if they wanted to. The field of UX wasn’t born the moment someone wrote the first telemetry library.

Of course it existed. It's just a lot cheaper with telemetry.

This is why companies like Microsoft cram it down our throats.

Re: 1Password to Add Telemetry

#137
post #130

I've been a 1Password customer for five years. The move to 1password 8 has been beyond disastrous: terrible extension integration, browser constantly crashing when trying to log into the web panel, and the mobile app integration hardly works with mobile browsers. Add the recent announcements that the company will no longer support their last stable version -- 7 -- and move to using telemetry -- I'm out. I've jumped t…

i have literally over 5,000 passwords going back almost 30 years in a dozen vaults in 1P. How easy was it to migrate to Bitwarden? Any issues with Windows, Android, Linux, i(Pad)OS with the move? thanks!

Re: 1Password to Add Telemetry

#138

> Over the years, we’ve relied on our own usage in conjunction with your feedback to inform our decision making. This presents a challenge, though: we don’t know when you run into trouble unless you tell us. And sure, we have an extensive user research program, and listen to all of the feedback you share online and in conversations with our team. > But there are millions of people using 1Password now, often in cool a…

"1Password Unlocks $620M Round, Reaches $6.8B Valuation" would be my guess.

Re: 1Password to Add Telemetry

#139
post #83

Telemetry in a "trust us, this closed-source application which contains all your secrets, which we provide you and which we update periodically, is only contacting us for "privacy protecting telemetry" and not exfiltration, intentionally or not, of your most sensitive of all data" application is a hard pass for me. This seems like an IQ test kind of question. (So many times error reporting, etc. have accidentally lea…

Without telemetry it is a closed-source application that contains all your secrets, is updated periodically, and is already storing encrypted copies of all your secrets on their servers. If they wanted to intentionally exfiltrate your data they could already do it easily.

I don't see how adding telemetry makes any significant difference.

Re: 1Password to Add Telemetry

#140
post #5

I have my issues with what 1Password has become as a product, but this seems like a very good stance to take. As a product owner, it's essential to know what and how people are using the product, collecting some straightforward telemetry that's anonymized and doesn't contain and Vault data strikes me as reasonable.

If it is so essential, how have they been so successful since 1P was released nearly 20 years ago?

They didn't have an army of UX fuccbois back then. Now they do and this is an endless stream of makework to justify themselves.
Post reply on HN