Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

101–110 of 353 posts

Re: 1Password to Add Telemetry

#101

Earlier quoted context omitted.

> First, no data collection is "anonymous" Because no network connection is anonymous but as long as you aren't handling PII, GDPR has nothing to say about it. I could sell an app in the EU that just pinged my server once a day. As long as I wasn't keeping a record of who pinged what when, there is no PII. Otherwise everything is PII and you would need consent before every TCP handshake.

> I could sell an app in the EU that just pinged my server once a day. As long as I wasn't keeping a record of who pinged what when, there is no PII. Data processing is not just about 'keeping a record'. Processing even for a millisecond is also processing. > Otherwise everything is PII and you would need consent before every TCP handshake. Consent is not the only ground for data processing. Normally, it would just b…

I still haven't got my citation of how the GDPR someone applies to non-PII, which is the entire point of what 1P is saying they are collecting.

Data processing of personal data is what the GDPR is concerned about.

I'm sorry for getting frustrated but for fucks sake, someone cite me something that proves my original point about the opt-out being illegal.

I don't care if I'm wrong but I'm not taking downvotes for questioning someone flatly accusing 1P of bypassing EU regulations.

Re: 1Password to Add Telemetry

#102
post #84

Earlier quoted context omitted.

We are talking EU and I specifically asked for Citation needed, and I realize you aren't the poster but this doesn't really answer my question. Are we assuming 1Password is lying about anonymisation? My point is they didn't "sneak it past the regulators", it's plainly legal to do this under GDPR, and if it isn't I need a citation.

> Are we assuming 1Password is lying about anonymisation? I wouldn't put it that way. Rather, I'd say that you shouldn't assume something is true just because a company claims it is. Especially when that thing can have a material effect on their profit margin.

In simplest terms.

1P says they are collecting non-PII.

Higher poster in this thread says "I can't imagine how they're going to get this past EU regulators."

I'm saying there is no problem, and someone needs to provide proof that the opt-out here is illegal.

Re: 1Password to Add Telemetry

#103
post #97
post #45

My history with 1Password: - Purchase a stand-alone license, getting well-performing and feature-complete native clients with several options for vault sync that are under my control. - Upgrade to 1Password 8, a version that sounds great, but has quietly removed local sync unless you checked forum and blog posts before buying. - Watch the clients go from being native to Electron and losing many, many features. Get fo…

> Watch browser integrations get progressively worse (check out the reviews on the Firefox extension, oh boy) This doesn't align with my experience, and I've been using their app/service for years (the Windows & Mac apps, along with the Chrome and Firefox extensions). I don't mean to sound harsh but I'm scrolling through the negative reviews on the Firefox extension page as you suggested, and it's hard to take the ma…

I have enjoyed how quickly 1Password was adopting new technology and features while still staying stable. It just worked. Lately, that hasn't been the case. Recently, the browser extension, which is my main interface for 1Password, has been acting up.

I use browser extension in Edge on macOS. I am on a page signing up for a new website and want to save credentials. It doesn't. Keeps erroring out. Disabling and re-enabling extension, and then refreshing the tab finally fixes it. I reached out to customer support and they told me to sign out to force refresh the cache. I did it, but the problem wasn't fixed.

1Password needs to fix the bugs that their customers are already reporting, instead of alienating their users with telemetry. I don't think the learnings from telemetry will be worth the damage it will cause to their brand.

Re: 1Password to Add Telemetry

#104

Earlier quoted context omitted.

Why does it need a server? Does bitwarden have the ability to just use a local vault?

If you're looking for something that's offline first go for pass [0], gopass [1], or any keepass-compatible [2][3][4] password manager and sync the database yourself. [0]: https://www.passwordstore.org/ [1]: https://www.gopass.pw/ [2]: https://keepassxc.org/ [3]: https://www.keepassdx.com/ [4]: https://strongboxsafe.com/

I'd add Keepassium for iOS, I think it's free for a single database.

https://keepassium.com/

Re: 1Password to Add Telemetry

#105

Earlier quoted context omitted.

What about anonymous logging of which buttons people click on is illegal in the EU? Citation needed on this one. That would make any dashboard that showed which api endpoints are the most popular also illegal. Anomyous telemetry is not PII. GDPR is personal data.

> Anomyous telemetry is not PII. GDPR is personal data. How are you exactly going to submit it anonymously? Will it connect over Tor? Because if you just send it over your internet connection, it arrives with your IP address on the packets, which is PII, which makes it data processing of PII, which makes it require a legal basis to process. And it is legally uncertain that 'legitimate interest' is a valid ground for…

That would make any EU company running a server in a country without an EU data processing treaty illegal, because the IP address would be in the TCP handshake.

Edit: It would also violate using any networks that transit such countries, because TLS and TCP handshake info might be PII too. I find that such a ridiculous position to have re GDPR.

1P already has consent from users for its apps to use the network to connect to their services.

They do not need an additional agreement ie opt-in consent. If they are collecting non-PII they can use the current opt out.

Re: 1Password to Add Telemetry

#106
post #83

Telemetry in a "trust us, this closed-source application which contains all your secrets, which we provide you and which we update periodically, is only contacting us for "privacy protecting telemetry" and not exfiltration, intentionally or not, of your most sensitive of all data" application is a hard pass for me. This seems like an IQ test kind of question. (So many times error reporting, etc. have accidentally lea…

Imagine for a minute that you have a hammer. This hammer is a very useful tool and you have never had a problem with it. You don't know what is in the hammer -- could be steel, could be titanium, could be uranium (you're not a scientist!) -- but you know that it has always worked for you. Your experience with the hammer is so positive, you would buy another hammer from the company again, without question.

One day, the company that makes this hammer says that they will be updating it to automatically tell the company a bunch of information about the hammer's use -- when it's used, where it's used, what the environment is like around the hammer, how many times it's used, what it's used for. They assure you that they don't care about who is using the hammer, but obviously it will be YOUR hammer reporting the information, so at some level it will be associated with you.

Why are they doing this? Well, they know that sometimes their hammers break. They only know this, though, because sometimes their hammers break for their own employees and sometimes customers tell them hammers break. They would really like to know ALL the times their hammers break, though, so that can try to fix all the problems with their hammers, and not just the ones they see or get reported to them. They say this will be best for their customers and that's why customers should be on board with the change.

No one would ever buy that hammer again, right?

Regardless of the privacy implications of the company knowing everything about your usage of the hammer, the company is basically saying that their hammers break so much that many of their customers don't bother telling them and just go use someone's hammer. In other words, their product is bad and their customers don't value it enough to deal with it.

Don't even get me started on paying monthly for that hammer ...

Re: 1Password to Add Telemetry

#107
post #45

My history with 1Password: - Purchase a stand-alone license, getting well-performing and feature-complete native clients with several options for vault sync that are under my control. - Upgrade to 1Password 8, a version that sounds great, but has quietly removed local sync unless you checked forum and blog posts before buying. - Watch the clients go from being native to Electron and losing many, many features. Get fo…

I have a similar history. The biggest loss for me on v7 -> v8 is 1Password Mini - that's a wonderful little 'browser extension for the desktop', and quick access is just awful to use in comparison. It's not helped by their responses basically always being "but we like this, so it's better!" - they don't listen to customer feedback any more, and they pair it with their 'quirky' comms style that just comes off as conde…

This so much! I hate hate hate how there is no context anymore for filling in logins and how it has to all happen inside the browser. It's normal for me to have 5-6 different logins for websites. In v8 I can only use the tiny bar in the webbrowser to select one. But it doesn't let me search or give me information on which login is which.

In v7 with 1Password Mini I can do a fuzzy search outside of the browser and then just press enter to fill the details.

I'm still holding on to v7, but apparently we just can't have nice things. Sounds like it may be time to move on soon. :'(

Re: 1Password to Add Telemetry

#108

Earlier quoted context omitted.

Same. I think here is a good place to shout out to Vaultwarden: https://github.com/dani-garcia/vaultwarden Your password data, back under your own control.

Why does it need a server? Does bitwarden have the ability to just use a local vault?

Bitwarden is cloud-based with synchronization to local caches. If you want total control over your data with Bitwarden you will need to run the server/cloud side. I'd caution that running a Bitwarden server is not for everyone, as one could make the security worse than the Bitwarden-company-hosted cloud service.

I run Vaultwarden on my LAN, with no public/Internet facing service, and sync only on my LAN.

Re: 1Password to Add Telemetry

#109
post #83

Telemetry in a "trust us, this closed-source application which contains all your secrets, which we provide you and which we update periodically, is only contacting us for "privacy protecting telemetry" and not exfiltration, intentionally or not, of your most sensitive of all data" application is a hard pass for me. This seems like an IQ test kind of question. (So many times error reporting, etc. have accidentally lea…

Especially since it's operated from a Five Eyes country.

The problem is its always been there. Telemetry provides more noise to hide exfiltration of sensitive data, but the risk has always been there from the start for the reasons you laid out.

It's a closed source product in a surveilence heavy country. Telemetry or not, it's risky.

Re: 1Password to Add Telemetry

#110
post #56

Earlier quoted context omitted.

Migrated to Bitwarden for the opensource years ago. Stayed for cheaper price, linux support, simplicity and "out of my way" philosophy. Never looked back to 1password.

Same, though I just use the free Bitwarden, not sure what the paid one provides. It's been good. Very simple and reliable. Has barely changed in years of use and hasn't needed to.

I pay them for the family plan. Being able to share items with my wife and kids (particularly joint accounts) is extremely useful, and they do it without creating two classes of passwords (like LastPass, my previous vault).

BTW, the paid accounts provide TOTP code storage, more comprehensive password health reports, emergency vault access for others, hardware key support, someone to call with problems[0], and encrypted file sending.[0]

[0] https://bitwarden.com/pricing/

Post reply on HN