Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

121–130 of 353 posts

Re: 1Password to Add Telemetry

#121

Earlier quoted context omitted.

If you're looking for something that's offline first go for pass [0], gopass [1], or any keepass-compatible [2][3][4] password manager and sync the database yourself. [0]: https://www.passwordstore.org/ [1]: https://www.gopass.pw/ [2]: https://keepassxc.org/ [3]: https://www.keepassdx.com/ [4]: https://strongboxsafe.com/

I'd add Keepassium for iOS, I think it's free for a single database. https://keepassium.com/

[deleted]

Re: 1Password to Add Telemetry

#122
post #92
post #2

I've been a 1Password customer for many years. Their product is super solid. The family plan is very generous. I personally don't have an issue with them collecting some telemetry to improve the product. And they've stated they'll offer ways to opt-out.

> Their product ~~is~~ used to be super solid. Don't get me wrong, it's still light years ahead of the Bitwarden clients and extensions, and that's why I stay, but I for sure would not use the present tense for their quality

> it's still light years ahead of the Bitwarden clients and extensions

I’m quite possible a simpleton but I can’t see how it’s light years ahead of Bitwarden. Can you provide an example of such difference?

Every time I used to check 1password (before the Great Purge of local vaults) I always arrived at the same conclusion. It’s a bit more beautiful but not 3x or 4x (whatever the price is) more beautiful then Bitwarden.

Functionality wise I couldn’t see much of a difference. Both save passwords, both share passwords, both generate passwords and both have Totp support.

Re: 1Password to Add Telemetry

#123
post #106
post #83

Telemetry in a "trust us, this closed-source application which contains all your secrets, which we provide you and which we update periodically, is only contacting us for "privacy protecting telemetry" and not exfiltration, intentionally or not, of your most sensitive of all data" application is a hard pass for me. This seems like an IQ test kind of question. (So many times error reporting, etc. have accidentally lea…

Imagine for a minute that you have a hammer. This hammer is a very useful tool and you have never had a problem with it. You don't know what is in the hammer -- could be steel, could be titanium, could be uranium (you're not a scientist!) -- but you know that it has always worked for you. Your experience with the hammer is so positive, you would buy another hammer from the company again, without question. One day, th…

> No one would ever buy that hammer again, right?

I mean, you might not, but I don't see telemetry as such an evil. It does help make the product better. So "no one" is a bit too strong here, try "no one with my mindset" ;)

Re: 1Password to Add Telemetry

#124
post #76

The 1Password "no local/standalone vaults" "upgrade" in 7->8 is what got me to leave it after 15 years or so. They're killing the extensions used by Chrome/Brave/etc. in 3 months, so it became critical to move off Version 7 (which is probably not getting much security maintenance now, either). RIP.

This is my stance as well. I have not chosen a successor yet, but I’ll have a look at Bitwarden, Keepass and the recently released Proton Pass.

Trusting Dropbox for sync (which I did) meant trusting a cloud service, too, but IMO it is a less lucrative target for hacks than a server that stores _nothing but_ credentials. Also, using DB made me less dependent on connectivity (LAN sync) and would let me switch providers quite easily.

Re: 1Password to Add Telemetry

#125

Earlier quoted context omitted.

> But there are millions of people using 1Password now, often in cool and innovative It's a password manager, what's "cool" about it? 1Pwd always rubbed me the wrong way in the way they "take themselves too seriously" and overrate their importance It's a password manager. They wouldn't even sync to cloud at first iirc, no? The more boring the better

You can use it for a lot more than just passwords, which IMO is what makes it stand apart from Bitwarden. You can store notes, credit cards, photocopies of IDs, software licenses, key pairs, etc. You get 1GB of storage. They really have turned it into a "vault" for anything digital.

Fairly sure Bitwarden has done all that for some time. Having had to use both at work, I can't see any killer features that 1Password has in my use case and there are various small things that slow me down when using it.

Re: 1Password to Add Telemetry

#127

Telemetry to inform product decisions is fine, in fact I think it's necessary to have confidence that software is performing in the wild (e.g. crash reporting), or that customers know how to use it. What is not ok is opt-out telemetry for personalisation for advertising, or over-reaching personal data collection, in 1Password's case data from your vault. There is however a grey area in the middle – data about the per…

The worry about telemetry in a product like this is how it's implemented. It's more code that could have bugs in it. What assurances do we have that it will execute safely in a way that it can't possibly access the password database, even in the event of (for example) compromise of the CI pipeline that builds the telemetry SDK? > No customer vault data can be seen or collected. We’re only interested in how people use…

> The worry about telemetry in a product like this is how it's implemented.

Exactly. They are enlarging the attack surface of a security device. For their own benefit. One buffer overflow and there's a backdoor.

That this is happening means their marketing people have more power than their security people. This is a very bad thing for a security company.

Start migrating away from 1Password. Now.

Re: 1Password to Add Telemetry

#129

Opt-out telemetry is unacceptable, this also signals that the product team has no vision and the organization is riddled with bureaucracy. Great products get built by someone with a vision to create them, mediocre products gets created by product managers justifying their positions with data they've gleaned by spying on users.

100% agreement from me. People have trouble believing this, but software existed before telemetry existed. We didn’t have trouble understanding where user pain points were back then, because we actually performed user studies, and offered the ability for users to provide feedback if they wanted to. The field of UX wasn’t born the moment someone wrote the first telemetry library.

I was genuinely shocked at how fast this crap was normalized. This was unequivocally not fucking OK unless you were some shady-ass malware vendor, not even that long ago. Then, in a span of seemingly a handful of years, it became normal and everyone was doing it and they all act confused when we say it's very, super, extremely, not even close to OK.

Re: 1Password to Add Telemetry

#130
I've been a 1Password customer for five years. The move to 1password 8 has been beyond disastrous: terrible extension integration, browser constantly crashing when trying to log into the web panel, and the mobile app integration hardly works with mobile browsers.

Add the recent announcements that the company will no longer support their last stable version -- 7 -- and move to using telemetry -- I'm out.

I've jumped to Bitwarden; open source, cheap, and competitive features. It was a no-brainer.

Post reply on HN