Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

301–310 of 353 posts

Re: 1Password to Add Telemetry

#301

Seems fine to me. Opt out is reasonable, I trust 1password to not fuck this up versus, say, LastPass. If you already trust 1password to store your credentials, I see little to no impact to your risk exposure by having them collect anonymized telemetry. Curious if others have thoughts here? Their UI has changed a lot in recent years, maybe this will enable them to make more informed design decisions so that one day gr…

I wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897

tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it.

-Ben, 1Password

Re: 1Password to Add Telemetry

#302

Telemetry to inform product decisions is fine, in fact I think it's necessary to have confidence that software is performing in the wild (e.g. crash reporting), or that customers know how to use it. What is not ok is opt-out telemetry for personalisation for advertising, or over-reaching personal data collection, in 1Password's case data from your vault. There is however a grey area in the middle – data about the per…

> What is not ok is opt-out telemetry for personalisation for advertising Opt-out telemetry is also not ok for product decisions. It's a dark pattern that shows no respect for user privacy.

I wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897

tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it.

-Ben, 1Password

Re: 1Password to Add Telemetry

#303
post #2

I've been a 1Password customer for many years. Their product is super solid. The family plan is very generous. I personally don't have an issue with them collecting some telemetry to improve the product. And they've stated they'll offer ways to opt-out.

I'd accept making it opt-in, but opt-out is ridiculous. I can't imagine how they're going to get this past EU regulators. I love (although loved more in the past) 1Password and have deployed it in two separate companies. Between this and recent UI updates (well, over the last couple of years), maybe it's time to look at alternatives.

I wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897

tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it.

-Ben, 1Password

Re: 1Password to Add Telemetry

#304

It sounds like they're planning it to be as general as possible (more just "how much is each feature used"), but it'll also be fully opt-in: > And, of course, once this functionality rolls out to customers, you’ll be able to control whether or not telemetry is active on your account. ("account" sounds like you can turn it off family-wide or even organization-wide) [ Reposted my comment from duplicate post: https://ne…

Explicitly opt-out sadly. It bothers me quite a bit to read that we’ve normalized telemetry as much as we have. If you’d asked more or less any random hacker 10 years ago if any of this was remotely OK they’d all be slack-jawed to learn what has happened. Where did all the privacy conscious hackers go? Did they all get replaced when JavaScript and Electron became the norm?

I wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897

tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it.

-Ben, 1Password

Re: 1Password to Add Telemetry

#305
post #78

I've had issues where 1Password wouldn't save my new logins properly, lasting for over a day. Maybe that's why they need the telemetry. Do 1Password do security/privacy audits the way Mullvad do? That's a pretty decent way of building goodwill over time when it comes to decisions like this. It's probably a fine decision, but they should probably have gone to greater lengths to write this blog post in more exhaustive…

If they could use telemetry to deduce which websites were not auto-filling correctly then I'm all aboard.

I love that idea. We'd have to be super careful with the de-identification of associated data (which we're doing anyway), but having automation behind figuring out filling failures could be a huge boon. I'll share the thought with the team.

-Ben, 1Password

Re: 1Password to Add Telemetry

#306
post #249

Earlier quoted context omitted.

It’s the item’s UUID. You can verify this by using their `op` CLI tool and searching for the specific item.

Good to know. What is it used for? Is there a way to disable it?

It tells the extension which item you've selected to fill. It isn't possible to use the Open & Fill feature without it. If you navigate to the website in your web browser and then fill from 1Password's inline menu, instead of using Open & Fill, you can avoid it. Hope that helps. Please drop us an email if you have further questions: support at 1password dot com

-Ben, 1Password

Re: 1Password to Add Telemetry

#307
post #38

The only reason we're talking about this is that 1Password wrote a blog post about it. They're not dumb, they know that this is the reaction they can expect from a blog post about how they're doing telemetry. They compete with a raft of products that not only use telemetry, but do it sneakily and with SAAS vendors that add attack surface to their products. But nobody talks about telemetry in those products, because t…

I was an advocate for putting out the blog post early, despite the fact that we're currently only testing this with our employees. As you say, we knew it would be something the community would have questions about, rightfully so, and wanted to be as transparent as possible.

-Ben, 1Password

Re: 1Password to Add Telemetry

#308

Hi folks, Thank you for the comments on this important topic. 1Password's mission is to help people safeguard their most important information and to do that, we have always taken a human-centric approach to security. In order to deliver the exceptional product experience our users expect from us, we need to better understand how they use 1Password. And while our goal is to deliver better 1Password products, we won’t…

I don't like opt-out telemetry but I get it. I hate and do not get local vault elimination. I've been using 1P since 2008 and I'm out once the 1P7 browser extensions stop working.

Re: 1Password to Add Telemetry

#309

Earlier quoted context omitted.

They're focusing of the enterprise market. Those users are now what matters, because that's where the money is. Individual and family customers will still get their tier of product, but ain't no company-wide business decisions gonna be catered to their whims. And particularly with standalone perpetual licences, which I'm still clinging on to. Sync via DropBox, share a vault with family, and another one with my small…

I just got a notification from 1Password today that the chrome extension will stop working on July 1 and that I need to upgrade. I don’t know if I can continue to use the version I paid for once that happens and might need to move to the subscription. I hope that’s not the case but haven’t looked into it yet. Does anyone know if it will be possible to continue using 1Password past July 1 without a subscription?

The Firefox extension still works for the moment.
Post reply on HN