The 1Password "no local/standalone vaults" "upgrade" in 7->8 is what got me to leave it after 15 years or so. They're killing the extensions used by Chrome/Brave/etc. in 3 months, so it became critical to move off Version 7 (which is probably not getting much security maintenance now, either). RIP.
1Password to Add Telemetry
221–230 of 353 posts
Re: 1Password to Add Telemetry
#222The writing has been on the wall for some time. It's clear that they are focused on growing the company and maximizing revenue. Nothing wrong with that, but my family's needs aren't going to satisfy a hungry capitalistic company. So I've had plenty of time to have alternatives, which I've been using. 1Password has been in parallel with another password manager and once they end support for 1Password 7 my family will…
Re: 1Password to Add Telemetry
#223Users: We want standalone non-subscription licenses! 1Password: I really wish we knew what users wanted. Users: Please don't move to Electron, I don't want Chrome bugs in my password manager. 1Password: I'm just baffled. We never hear from users. Users: Please, for the love of God, give us control over our vaults. Don't go cloud-only, we're begging you! 1Password: Better turn on telemetry. It's the only way to solve…
Users: The UI/UX of 1Password 7 is pretty good. We're happy. 1Password: Yeah, but we're bored. So, we'll release an abomination as 1Password 8 and then spend years trying to figure out why people hate it.
Worse than that. They had completely dysfunctional internal processes that they decided to solve by going people shiny toys to play with (Rust and Electron): https://blog.1password.com/1password-8-the-story-so-far/
Re: 1Password to Add Telemetry
#224Earlier quoted context omitted.
> password is provided to the server to partially unlock so a malware server or MITM could get the password That is completely false. "The Master Password is cleared from memory after usage and never transmitted over the Internet to Bitwarden servers, therefore there is no way to recover the password in the event that you forget it."[0] [0]: https://bitwarden.com/help/bitwarden-security-white-paper/
Bitwarden does some of the KDF operations server-side which means that a portion of the password (even if it's been through some KDF operations) is sent to the server. EDIT: https://palant.info/2023/01/23/bitwarden-design-flaw-server-...
What that article is saying (rightfully, mind you) is that an attacker can mostly ignore the server side round of encryption, because if they have a copy of your local vault, they can just perform the client side rounds and then see if they can decrypt the vault.
This is a problem mostly if you see their claims of 100000 rounds server side, and decide "oh that's fast enough, I'll drop the client side rounds to 5 so my vault is fast to open)"
Re: 1Password to Add Telemetry
#225They’re going CrashPlan. You were all dog-fooders and beta testers all these years for their eventual destination - the enterprise. Yes, of course you’ll be able to buy at $XXX/year with a minimum 10 users plan while you are all still singing paeans in the tune of - “oh it has gone shites, but it’s great, happy customer here!” Mac/Apple only customers have this strong inclination for some kind of Stockholm syndrome w…
It's exactly the opposite of what you wrote. Mac users abhor the software that turns shitty. However, as on all modern platforms, there's no choice: all software is turning shitty.
Re: 1Password to Add Telemetry
#226Earlier quoted context omitted.
> But there are millions of people using 1Password now, often in cool and innovative It's a password manager, what's "cool" about it? 1Pwd always rubbed me the wrong way in the way they "take themselves too seriously" and overrate their importance It's a password manager. They wouldn't even sync to cloud at first iirc, no? The more boring the better
1Password is one of the best products I've ever used and removed tons of friction from my life when I switched from KeePass. It's a fantastic, exciting product. ...which is why this decision is extra infuriating.
Re: 1Password to Add Telemetry
#227Earlier quoted context omitted.
They're focusing of the enterprise market. Those users are now what matters, because that's where the money is. Individual and family customers will still get their tier of product, but ain't no company-wide business decisions gonna be catered to their whims. And particularly with standalone perpetual licences, which I'm still clinging on to. Sync via DropBox, share a vault with family, and another one with my small…
To give 1Password some credit, they haven't broken the standalone licenses yet. Every time the iOS app updates, I suffer from an anxiety attack that sync via dropbox might break. Unsure about a reasonable alternative.
Re: 1Password to Add Telemetry
#228Telemetry to inform product decisions is fine, in fact I think it's necessary to have confidence that software is performing in the wild (e.g. crash reporting), or that customers know how to use it. What is not ok is opt-out telemetry for personalisation for advertising, or over-reaching personal data collection, in 1Password's case data from your vault. There is however a grey area in the middle – data about the per…
> What is not ok is opt-out telemetry for personalisation for advertising Opt-out telemetry is also not ok for product decisions. It's a dark pattern that shows no respect for user privacy.
It may not work correctly, and there's some risk there, but it's pretty low risk. A poor implementation may cause UX regressions, but the company have incentive to not do that.
Re: 1Password to Add Telemetry
#229Earlier quoted context omitted.
How and is 1Password 8 an abomination?
Currently literally consuming 1.4GiB memory on my machine... for a password manager?
Re: 1Password to Add Telemetry
#230Opt-out telemetry is unacceptable, this also signals that the product team has no vision and the organization is riddled with bureaucracy. Great products get built by someone with a vision to create them, mediocre products gets created by product managers justifying their positions with data they've gleaned by spying on users.
Another company having no issue with blatant and in the open breach of GDPR by refusing to comply with the required default of rejection.
> This data will be gathered from a randomized selection of accounts, de-identified, and processed in aggregate