Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

221–230 of 353 posts

Re: 1Password to Add Telemetry

#221
post #76

The 1Password "no local/standalone vaults" "upgrade" in 7->8 is what got me to leave it after 15 years or so. They're killing the extensions used by Chrome/Brave/etc. in 3 months, so it became critical to move off Version 7 (which is probably not getting much security maintenance now, either). RIP.

They're killing their browser extension for the world's most popular browser?

Re: 1Password to Add Telemetry

#222

The writing has been on the wall for some time. It's clear that they are focused on growing the company and maximizing revenue. Nothing wrong with that, but my family's needs aren't going to satisfy a hungry capitalistic company. So I've had plenty of time to have alternatives, which I've been using. 1Password has been in parallel with another password manager and once they end support for 1Password 7 my family will…

What have you been using as an alternative? Especially for a family use case.

Re: 1Password to Add Telemetry

#223
post #169

Users: We want standalone non-subscription licenses! 1Password: I really wish we knew what users wanted. Users: Please don't move to Electron, I don't want Chrome bugs in my password manager. 1Password: I'm just baffled. We never hear from users. Users: Please, for the love of God, give us control over our vaults. Don't go cloud-only, we're begging you! 1Password: Better turn on telemetry. It's the only way to solve…

Users: The UI/UX of 1Password 7 is pretty good. We're happy. 1Password: Yeah, but we're bored. So, we'll release an abomination as 1Password 8 and then spend years trying to figure out why people hate it.

> Yeah, but we're bored.

Worse than that. They had completely dysfunctional internal processes that they decided to solve by going people shiny toys to play with (Rust and Electron): https://blog.1password.com/1password-8-the-story-so-far/

Re: 1Password to Add Telemetry

#224
post #182
post #181

Earlier quoted context omitted.

> password is provided to the server to partially unlock so a malware server or MITM could get the password That is completely false. "The Master Password is cleared from memory after usage and never transmitted over the Internet to Bitwarden servers, therefore there is no way to recover the password in the event that you forget it."[0] [0]: https://bitwarden.com/help/bitwarden-security-white-paper/

Bitwarden does some of the KDF operations server-side which means that a portion of the password (even if it's been through some KDF operations) is sent to the server. EDIT: https://palant.info/2023/01/23/bitwarden-design-flaw-server-...

They send the hash of the master key password after it's been encrypted to the server. They then encrypt the hash on the sever side to auth you. They don't send the password itself.

What that article is saying (rightfully, mind you) is that an attacker can mostly ignore the server side round of encryption, because if they have a copy of your local vault, they can just perform the client side rounds and then see if they can decrypt the vault.

This is a problem mostly if you see their claims of 100000 rounds server side, and decide "oh that's fast enough, I'll drop the client side rounds to 5 so my vault is fast to open)"

Re: 1Password to Add Telemetry

#225

They’re going CrashPlan. You were all dog-fooders and beta testers all these years for their eventual destination - the enterprise. Yes, of course you’ll be able to buy at $XXX/year with a minimum 10 users plan while you are all still singing paeans in the tune of - “oh it has gone shites, but it’s great, happy customer here!” Mac/Apple only customers have this strong inclination for some kind of Stockholm syndrome w…

> Mac/Apple only customers have this strong inclination for some kind of Stockholm syndrome when it comes to software and devs going shitty and hostile.

It's exactly the opposite of what you wrote. Mac users abhor the software that turns shitty. However, as on all modern platforms, there's no choice: all software is turning shitty.

Re: 1Password to Add Telemetry

#226
post #203

Earlier quoted context omitted.

> But there are millions of people using 1Password now, often in cool and innovative It's a password manager, what's "cool" about it? 1Pwd always rubbed me the wrong way in the way they "take themselves too seriously" and overrate their importance It's a password manager. They wouldn't even sync to cloud at first iirc, no? The more boring the better

1Password is one of the best products I've ever used and removed tons of friction from my life when I switched from KeePass. It's a fantastic, exciting product. ...which is why this decision is extra infuriating.

What was your usecase that you were unsatisfied with keepass?

Re: 1Password to Add Telemetry

#227

Earlier quoted context omitted.

They're focusing of the enterprise market. Those users are now what matters, because that's where the money is. Individual and family customers will still get their tier of product, but ain't no company-wide business decisions gonna be catered to their whims. And particularly with standalone perpetual licences, which I'm still clinging on to. Sync via DropBox, share a vault with family, and another one with my small…

To give 1Password some credit, they haven't broken the standalone licenses yet. Every time the iOS app updates, I suffer from an anxiety attack that sync via dropbox might break. Unsure about a reasonable alternative.

If you don't need shared vaults, Secrets [0] is excellent and feels a lot like the last good version of 1Password before they started down their current path of destroying both their product and their reputation.

[0] https://outercorner.com/secrets-mac/

Re: 1Password to Add Telemetry

#228

Telemetry to inform product decisions is fine, in fact I think it's necessary to have confidence that software is performing in the wild (e.g. crash reporting), or that customers know how to use it. What is not ok is opt-out telemetry for personalisation for advertising, or over-reaching personal data collection, in 1Password's case data from your vault. There is however a grey area in the middle – data about the per…

> What is not ok is opt-out telemetry for personalisation for advertising Opt-out telemetry is also not ok for product decisions. It's a dark pattern that shows no respect for user privacy.

Why? If everything works as it is supposed to then the only result is a better product.

It may not work correctly, and there's some risk there, but it's pretty low risk. A poor implementation may cause UX regressions, but the company have incentive to not do that.

Re: 1Password to Add Telemetry

#229

Earlier quoted context omitted.

How and is 1Password 8 an abomination?

Currently literally consuming 1.4GiB memory on my machine... for a password manager?

This doesn't match with my personal experience. On Windows10 1Password is using locked about 5MB Ram, unlocked 30MB when idle. It shoots up to 150MB when actively being used, but as soon as I close the window, it's back to normal. Firefox extension takes about 1MB of Ram.

Re: 1Password to Add Telemetry

#230

Opt-out telemetry is unacceptable, this also signals that the product team has no vision and the organization is riddled with bureaucracy. Great products get built by someone with a vision to create them, mediocre products gets created by product managers justifying their positions with data they've gleaned by spying on users.

Another company having no issue with blatant and in the open breach of GDPR by refusing to comply with the required default of rejection.

If the telemetry is anonymized and no personal data is transmitted, then there is no breach of GDPR:

> This data will be gathered from a randomized selection of accounts, de-identified, and processed in aggregate

Post reply on HN