Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

151–160 of 353 posts

Re: 1Password to Add Telemetry

#151
post #61

Earlier quoted context omitted.

> Opt out is reasonable I strongly disagree with this and think much less of companies who do it that way. That said, that battle is already lost anyway.

Opt in is the same as not doing it at all. TFA explains their approach decently well and it seems sane to me. It's not like this is telemetry in some open source thing for nefarious reasons. It's literally for their customers. They already know who you are, it's not like they're using this for targeted ads.

> Opt in is the same as not doing it at all.

That is more of a statement about the detestability of telemetry as a concept than anything else.

Re: 1Password to Add Telemetry

#152

Earlier quoted context omitted.

You can use it for a lot more than just passwords, which IMO is what makes it stand apart from Bitwarden. You can store notes, credit cards, photocopies of IDs, software licenses, key pairs, etc. You get 1GB of storage. They really have turned it into a "vault" for anything digital.

You can store anything you want in it, as long as you are ok with seeing just the first 15 or so characters of the name you give it. Because the column that contains the contents of the vault is thin and non-resizable. Probably because they didn’t have telemetry so they didn’t know.

It's resizable for me.

Re: 1Password to Add Telemetry

#153
What a coincidence. Just yesterday I was discussing 1pwd’s series A with a friend and I remembered about a podcast the founder (David Teare) did with DHH (Rework Podcast). In it, he literally cites this. He says they raised money for a bunch of things, and one, was to add metrics, but he wanted them to make them anonymous. We’ll see how it plays out.

Podcast: https://open.spotify.com/episode/6RZm7V8IcvuMuaCmVBE4EG?si=v...

Re: 1Password to Add Telemetry

#154
post #83

Telemetry in a "trust us, this closed-source application which contains all your secrets, which we provide you and which we update periodically, is only contacting us for "privacy protecting telemetry" and not exfiltration, intentionally or not, of your most sensitive of all data" application is a hard pass for me. This seems like an IQ test kind of question. (So many times error reporting, etc. have accidentally lea…

Especially since it's operated from a Five Eyes country. The problem is its always been there. Telemetry provides more noise to hide exfiltration of sensitive data, but the risk has always been there from the start for the reasons you laid out. It's a closed source product in a surveilence heavy country. Telemetry or not, it's risky.

If they were going to "de-identify" the data for their telemetry, then I'd need to see some rigorous mathematical proof of it, to have any trust in their promises. You will eventually compromise the individual datapoints in a dataset, given enough queries. There is in fact a field of research that specifically studies just this. The PMs at 1password haven't done their homework, they're just waving their hands, and it is worrying for users.

Re: 1Password to Add Telemetry

#155
Are there any password managers that provide a similar UX on mobile phones/iOS? If so, I'll move there in an instant.

> At that point, we’ll also provide guidance on how you can opt out if you’d like to.

Better than nothing. But they're moving away from being the #1 choice and a great product step-by-step...

Re: 1Password to Add Telemetry

#156
I wouldn't object to Apple driving another small nail into 1Password's coffin by coming up with a scheme to enable Firefox and Chrome to access iCloud Keychain for certain web site passwords (but not all of them!)

Supporting it on Windows could be another nail.

Re: 1Password to Add Telemetry

#157

Earlier quoted context omitted.

> Because before js became popular, every web app had access to every single event execpt what, scroll and mouse position. Huh? No, they had access to basically nothing unless the user did something that triggered a network request. What did you type in that form, but delete before submitting? No visibility. Which parts of the page did you linger on the longest? Which parts of the text did you highlight? No visibilit…

> What did you type in that form, but delete before submitting? No visibility. Well maybe I deleted it because I thought twice about what I wanted to send you.

Yes—to be clear, that's a good thing, and the direction modern software has gone is incredibly gross, to put it mildly.

Re: 1Password to Add Telemetry

#158
The writing has been on the wall for some time. It's clear that they are focused on growing the company and maximizing revenue. Nothing wrong with that, but my family's needs aren't going to satisfy a hungry capitalistic company. So I've had plenty of time to have alternatives, which I've been using. 1Password has been in parallel with another password manager and once they end support for 1Password 7 my family will turn this one off and switch.

The experience with 1Password 7 isn't all that great right now anyway, so I'm not losing much really. The syncing is super useful, but there is a solution to that too.

It's been a good ride. Now it's good riddance.

Re: 1Password to Add Telemetry

#159
post #83

Telemetry in a "trust us, this closed-source application which contains all your secrets, which we provide you and which we update periodically, is only contacting us for "privacy protecting telemetry" and not exfiltration, intentionally or not, of your most sensitive of all data" application is a hard pass for me. This seems like an IQ test kind of question. (So many times error reporting, etc. have accidentally lea…

The default for anything in that setting should be that phoning out (or trying to do so) is qualified as a security incident. Especially if it happens right after you've entered your credentials.

Re: 1Password to Add Telemetry

#160

> Over the years, we’ve relied on our own usage in conjunction with your feedback to inform our decision making. This presents a challenge, though: we don’t know when you run into trouble unless you tell us. And sure, we have an extensive user research program, and listen to all of the feedback you share online and in conversations with our team. > But there are millions of people using 1Password now, often in cool a…

> But there are millions of people using 1Password now, often in cool and innovative It's a password manager, what's "cool" about it? 1Pwd always rubbed me the wrong way in the way they "take themselves too seriously" and overrate their importance It's a password manager. They wouldn't even sync to cloud at first iirc, no? The more boring the better

I agree in principle. Password managers should follow the KISS principle to extremes for the sake of security.

I’ve tried to get bitwarden in the enterprise but my boss is old school and has denied the request 4 years running.

Even after they added oauth and account switching to switch between personal and ent vaults.

Post reply on HN