Live data from Hacker News

1Password to Add Telemetry

blog.1password.com

171–180 of 353 posts

Re: 1Password to Add Telemetry

#171

Earlier quoted context omitted.

You can use it for a lot more than just passwords, which IMO is what makes it stand apart from Bitwarden. You can store notes, credit cards, photocopies of IDs, software licenses, key pairs, etc. You get 1GB of storage. They really have turned it into a "vault" for anything digital.

> which IMO is what makes it stand apart from Bitwarden. You can store notes, credit cards, photocopies of IDs, software licenses, key pairs, etc. How is that any different than Bitwarden?

Bitwarden only has a few types by default. Are there ways to add other types? Perhaps I am just not aware. I only use Bitwarden for a few things.

Re: 1Password to Add Telemetry

#172
post #130

I've been a 1Password customer for five years. The move to 1password 8 has been beyond disastrous: terrible extension integration, browser constantly crashing when trying to log into the web panel, and the mobile app integration hardly works with mobile browsers. Add the recent announcements that the company will no longer support their last stable version -- 7 -- and move to using telemetry -- I'm out. I've jumped t…

I have no idea why they removed the 1Password android keyboard. It was such a convenient fallback. Autofill is extremely unreliable.

Pity they can't gather telemetry on something that they have removed.

Re: 1Password to Add Telemetry

#173
post #139
post #83

Telemetry in a "trust us, this closed-source application which contains all your secrets, which we provide you and which we update periodically, is only contacting us for "privacy protecting telemetry" and not exfiltration, intentionally or not, of your most sensitive of all data" application is a hard pass for me. This seems like an IQ test kind of question. (So many times error reporting, etc. have accidentally lea…

Without telemetry it is a closed-source application that contains all your secrets, is updated periodically, and is already storing encrypted copies of all your secrets on their servers. If they wanted to intentionally exfiltrate your data they could already do it easily. I don't see how adding telemetry makes any significant difference.

The version I use(d) doesn’t connect to their servers, it stores a local password vault, and uses WebDAV to sync. I mostly moved away from passwords, and moved important passwords to a different system (Bitwarden/vaultwarden), but still kept random low value/legacy stuff in 1Password, which is why I am annoyed vs merely disappointed by their product changes.

Re: 1Password to Add Telemetry

#174
post #83

Telemetry in a "trust us, this closed-source application which contains all your secrets, which we provide you and which we update periodically, is only contacting us for "privacy protecting telemetry" and not exfiltration, intentionally or not, of your most sensitive of all data" application is a hard pass for me. This seems like an IQ test kind of question. (So many times error reporting, etc. have accidentally lea…

The default for anything in that setting should be that phoning out (or trying to do so) is qualified as a security incident. Especially if it happens right after you've entered your credentials.

Yeah, LittleSnitch helps with that.

I’d be fine with telemetry if it recorded locally in a way which was fully inspectable and human readable and which I could send IFF I wanted to, but with a password manager I’d be scared even of just a long list of events; passwords and keys themselves are so low entropy vs long lists that you could easily encode something…

Re: 1Password to Add Telemetry

#175

Users: We want standalone non-subscription licenses! 1Password: I really wish we knew what users wanted. Users: Please don't move to Electron, I don't want Chrome bugs in my password manager. 1Password: I'm just baffled. We never hear from users. Users: Please, for the love of God, give us control over our vaults. Don't go cloud-only, we're begging you! 1Password: Better turn on telemetry. It's the only way to solve…

Even more hilarious: I have recorded customer service events specifically stating against all three of those.

I liked 1Password when it was an amazing Mac-only app. Now it's just another Electron app I can throw away and discard for different Electron app, there's nothing special about it.

The problem is that I don't see any particular alternative. I don't like Bitwarden's security (password is provided to the server to partially unlock so a malware server or MITM could get the password) and LastPass has known issues.

EDIT: And standalone apps are neat and cool, but doesn't let me share the Netflix password with my family.

Re: 1Password to Add Telemetry

#176
post #92

Earlier quoted context omitted.

> Their product ~~is~~ used to be super solid. Don't get me wrong, it's still light years ahead of the Bitwarden clients and extensions, and that's why I stay, but I for sure would not use the present tense for their quality

> it's still light years ahead of the Bitwarden clients and extensions I’m quite possible a simpleton but I can’t see how it’s light years ahead of Bitwarden. Can you provide an example of such difference? Every time I used to check 1password (before the Great Purge of local vaults) I always arrived at the same conclusion. It’s a bit more beautiful but not 3x or 4x (whatever the price is) more beautiful then Bitwarde…

I often regret any contact I have with the Bitwarden fanbase, because whooo they are rabid, but I guess I used to be a rabid fan of 1P so maybe fair's fair :-D Anyway ...

- https://github.com/bitwarden/clients/issues/1620 was created 2021, after it was migrated from the issue that was open even longer in the other repo, and now they've locked the issue because they're tired of people complaining about the extension losing their credentials

- there are a ton more Item types in 1Password, which some people consider just cosmetic ("you can create your own fields") but https://bitwarden.com/help/managing-items/ compared to https://support.1password.com/item-categories/ is night and day, setting aside the native support for SSH agent that's built into 1P nowadays

and here starts the list of even more highly subjective items, which I acknowledge are highly subjective

- the folder based item management in Bitwarden is highly inferior to the tags based management in 1P. Creating folders itself is a major PITA, whereas creating tags in 1P is ... just type the new tag name. Maybe people enjoy putting the "tags" in there item's names or whatever, and doing away with folders in Bitwarden, but ... the fact they're trying to implement tagging on the cheap indicates they want tags but Bitwarden doesn't see the world that way

- I find the attachment management process cumbersome in Bitwarden, whereas in 1P there are actually two orthogonal ways of managing attachments: they can be first class Items (called "Document" items) meaning that is the whole secret that one would care about, and they can also be arbitrarily attached to other Items in kind of a supporting role. I have scans of my passport attached to the Passport item type because so many places ask me to upload a scan of my passport. Same for my driver's license on the formal Driver's License item type

- in the theme of "finding it cumbersome," I find that 1Password seems to care a lot more about UX than Bitwarden. Now, of late I am having to qualify any such statement because yikes that 1P 8 rewrite was catastrophic. But, rewrite-induced-self-inflicted-harm aside, I still think 1P cares a lot more about UX than Bitwarden

- also subjective, but I really enjoy the `op run` https://developer.1password.com/docs/cli/reference/commands/...> and its ability to resolve specially formatted env-vars https://developer.1password.com/docs/cli/secret-references> in the sub-process. That process seems to be the basis of their shell plugins system https://developer.1password.com/docs/cli/shell-plugins> but TBH I find just having env-vars lying around to be more convenient than their shell plugin system for my workflow. The fact that the `op` binary is smart enough to use DBus to auth to my desktop session means I can also use it as an implementation of pinentry

A perfectly reasonable question may be "well, it's open source, why not start fixing bugs?" The things about using folders and the lack of item types indicates to me that they're just rowing in a different direction than what I would like, and the fact that they're a commercial company means unless I directly would benefit from fixing a bug means I am not incentivized to contribute free labor

Re: 1Password to Add Telemetry

#177
post #175

Users: We want standalone non-subscription licenses! 1Password: I really wish we knew what users wanted. Users: Please don't move to Electron, I don't want Chrome bugs in my password manager. 1Password: I'm just baffled. We never hear from users. Users: Please, for the love of God, give us control over our vaults. Don't go cloud-only, we're begging you! 1Password: Better turn on telemetry. It's the only way to solve…

Even more hilarious: I have recorded customer service events specifically stating against all three of those. I liked 1Password when it was an amazing Mac-only app. Now it's just another Electron app I can throw away and discard for different Electron app, there's nothing special about it. The problem is that I don't see any particular alternative. I don't like Bitwarden's security (password is provided to the server…

>password is provided to the server

What is this you say?

Re: 1Password to Add Telemetry

#178

Earlier quoted context omitted.

> Opt in is the same as not doing it at all. That is more of a statement about the detestability of telemetry as a concept than anything else.

No, it's about defaults in behavioral economics. The vast majority of people won't change the default settings on their devices. https://www.centenecenter.wustl.edu/by-the-power-of-default-...

That's beside the point. If you don't have consent you don't have consent.

Re: 1Password to Add Telemetry

#179
They’re going CrashPlan. You were all dog-fooders and beta testers all these years for their eventual destination - the enterprise. Yes, of course you’ll be able to buy at $XXX/year with a minimum 10 users plan while you are all still singing paeans in the tune of - “oh it has gone shites, but it’s great, happy customer here!”

Mac/Apple only customers have this strong inclination for some kind of Stockholm syndrome when it comes to software and devs going shitty and hostile. I find this weird kind of loyalty added to software as well that somehow starts as Mac only and that loyalty stays even after they go crap. Often blown out of proportion.

I mean I always wonder what is the reason that these people don’t even want to acknowledge BitWarden.

Re: 1Password to Add Telemetry

#180
post #175

Users: We want standalone non-subscription licenses! 1Password: I really wish we knew what users wanted. Users: Please don't move to Electron, I don't want Chrome bugs in my password manager. 1Password: I'm just baffled. We never hear from users. Users: Please, for the love of God, give us control over our vaults. Don't go cloud-only, we're begging you! 1Password: Better turn on telemetry. It's the only way to solve…

Even more hilarious: I have recorded customer service events specifically stating against all three of those. I liked 1Password when it was an amazing Mac-only app. Now it's just another Electron app I can throw away and discard for different Electron app, there's nothing special about it. The problem is that I don't see any particular alternative. I don't like Bitwarden's security (password is provided to the server…

> password is provided to the server

No, it’s not? I can unlock my offline vault with no internet access at all.

Post reply on HN