Applies to much more MS products than just Office these days. I personally stopped being able to justify Office when they moved to subscription and iWork moved to bundled and already installed.
I still have Office on my work Mac and boy is it laggy typing as it analyzes the words and sends them to who knows where.
I love (although loved more in the past) 1Password and have deployed it in two separate companies. Between this and recent UI updates (well, over the last couple of years), maybe it's time to look at alternatives.
It seems likely that the same reasoning will apply here.
Citation needed on this one.
That would make any dashboard that showed which api endpoints are the most popular also illegal.
Anomyous telemetry is not PII. GDPR is personal data.
Everyone just consents anyway...
I am countering the position of the parent poster and asking for a citation that would indicate you don't need to sneak this around the EU regulators to do it.
Unless you don't lie to them and don't use every dark pattern in the book to trick them into clicking the checkbox.
That depends. First, no data collection is "anonymous" when it is transmitted. Any anonymity must come later, and then is only possible if the company aggregates the data with other users and deletes the original data that was collected.
PII/Personal Data are squishy terms. In the US, anyway, the legal definitions of what counts as "PII" leaves out an awful lot of actual PII -- so any claims that "no PII is being collected" is meaningless without additional explanation of what data items are being collected.
Are we assuming 1Password is lying about anonymisation?
My point is they didn't "sneak it past the regulators", it's plainly legal to do this under GDPR, and if it isn't I need a citation.
I wouldn't put it that way. Rather, I'd say that you shouldn't assume something is true just because a company claims it is. Especially when that thing can have a material effect on their profit margin.
1P says they are collecting non-PII.
Higher poster in this thread says "I can't imagine how they're going to get this past EU regulators."
I'm saying there is no problem, and someone needs to provide proof that the opt-out here is illegal.
However, Recital 30 (Online Identifiers for Profiling and Identification) clearly shows that IP addresses are personal data;
> Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. 2This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.
There is plenty of case law to show that processing IP addresses (even if you discard them later) is processing personal data. For example, an Italian court included as part of a ruling:
> In this respect, it is worth pointing out that the IP address constitutes personal data insofar as it makes it possible to identify an electronic communication device, thus indirectly making the data subject identifiable as a user (see Article 29 Working Party, WP 136 - Opinion No 4/2007 on the concept of personal data, of 20 June 2007, p. 16). This is especially so where, as in the present case, the IP is associated with other information relating to the browser used and the date and time of browsing (see recital 30 of the Regulation).
Source: https://gdprhub.eu/index.php?title=Garante_per_la_protezione...
Because no network connection is anonymous but as long as you aren't handling PII, GDPR has nothing to say about it.
I could sell an app in the EU that just pinged my server once a day. As long as I wasn't keeping a record of who pinged what when, there is no PII.
Otherwise everything is PII and you would need consent before every TCP handshake.
It's not the network connection that eliminates anonymity (although that, too), but the data itself. Even if there's no single piece of PII involved, fingerprinting is still a thing. That's why, if you want a hope at anonymity, you have to add the collected data into an aggregate collection and delete the original data records.
Data processing is not just about 'keeping a record'. Processing even for a millisecond is also processing.
> Otherwise everything is PII and you would need consent before every TCP handshake.
Consent is not the only ground for data processing. Normally, it would just be performance of a contract, as the user wants something from you.
Data processing of personal data is what the GDPR is concerned about.
I'm sorry for getting frustrated but for fucks sake, someone cite me something that proves my original point about the opt-out being illegal.
I don't care if I'm wrong but I'm not taking downvotes for questioning someone flatly accusing 1P of bypassing EU regulations.
It is clear that the EU does not consider telemetry to be strictly necessary and while there can be times when telemetry is allowable with the legitimate interest legal basis (for example, to prevent fraud or to comply with legal obligations), there is already plenty of case law across the EU that shows that the legitimate interest legal basis will not be accepted for user analytics.
For this reason, it seems unlikely that the proposed telemetry will be compliant in the EU.
How are you exactly going to submit it anonymously? Will it connect over Tor? Because if you just send it over your internet connection, it arrives with your IP address on the packets, which is PII, which makes it data processing of PII, which makes it require a legal basis to process. And it is legally uncertain that 'legitimate interest' is a valid ground for telemetry data, leaving only opt-in consent.
Edit: It would also violate using any networks that transit such countries, because TLS and TCP handshake info might be PII too. I find that such a ridiculous position to have re GDPR.
1P already has consent from users for its apps to use the network to connect to their services.
They do not need an additional agreement ie opt-in consent. If they are collecting non-PII they can use the current opt out.
Yes, and this is the current situation with the US following Schrems II. Obviously, lots of companies are non-compliant as everyone is waiting for a diplomatic solution following the ruling against Privacy Shield.
> 1P already has consent from users for its apps to use the network to connect to their services.
They probably rely on the strictly necessary legal basis for network connections that are required to run the service. However, each purpose much have its own legal basis and you cannot bundle purposes. For example, you cannot gain consent to process given personal data for one purpose and then process it for another purpose.
Consent must be bound to one or several specified purposes which must then be sufficiently explained.
tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it.
-Ben, 1Password
https://bucket.agilebits.com/ben/telemetry-consent-draft.png
Don't get me wrong, it's still light years ahead of the Bitwarden clients and extensions, and that's why I stay, but I for sure would not use the present tense for their quality
I’m quite possible a simpleton but I can’t see how it’s light years ahead of Bitwarden. Can you provide an example of such difference?
Every time I used to check 1password (before the Great Purge of local vaults) I always arrived at the same conclusion. It’s a bit more beautiful but not 3x or 4x (whatever the price is) more beautiful then Bitwarden.
Functionality wise I couldn’t see much of a difference. Both save passwords, both share passwords, both generate passwords and both have Totp support.
- https://github.com/bitwarden/clients/issues/1620 was created 2021, after it was migrated from the issue that was open even longer in the other repo, and now they've locked the issue because they're tired of people complaining about the extension losing their credentials
- there are a ton more Item types in 1Password, which some people consider just cosmetic ("you can create your own fields") but https://bitwarden.com/help/managing-items/ compared to https://support.1password.com/item-categories/ is night and day, setting aside the native support for SSH agent that's built into 1P nowadays
and here starts the list of even more highly subjective items, which I acknowledge are highly subjective
- the folder based item management in Bitwarden is highly inferior to the tags based management in 1P. Creating folders itself is a major PITA, whereas creating tags in 1P is ... just type the new tag name. Maybe people enjoy putting the "tags" in there item's names or whatever, and doing away with folders in Bitwarden, but ... the fact they're trying to implement tagging on the cheap indicates they want tags but Bitwarden doesn't see the world that way
- I find the attachment management process cumbersome in Bitwarden, whereas in 1P there are actually two orthogonal ways of managing attachments: they can be first class Items (called "Document" items) meaning that is the whole secret that one would care about, and they can also be arbitrarily attached to other Items in kind of a supporting role. I have scans of my passport attached to the Passport item type because so many places ask me to upload a scan of my passport. Same for my driver's license on the formal Driver's License item type
- in the theme of "finding it cumbersome," I find that 1Password seems to care a lot more about UX than Bitwarden. Now, of late I am having to qualify any such statement because yikes that 1P 8 rewrite was catastrophic. But, rewrite-induced-self-inflicted-harm aside, I still think 1P cares a lot more about UX than Bitwarden
- also subjective, but I really enjoy the `op run` <https://developer.1password.com/docs/cli/reference/commands/...> and its ability to resolve specially formatted env-vars <https://developer.1password.com/docs/cli/secret-references> in the sub-process. That process seems to be the basis of their shell plugins system <https://developer.1password.com/docs/cli/shell-plugins> but TBH I find just having env-vars lying around to be more convenient than their shell plugin system for my workflow. The fact that the `op` binary is smart enough to use DBus to auth to my desktop session means I can also use it as an implementation of pinentry
A perfectly reasonable question may be "well, it's open source, why not start fixing bugs?" The things about using folders and the lack of item types indicates to me that they're just rowing in a different direction than what I would like, and the fact that they're a commercial company means unless I directly would benefit from fixing a bug means I am not incentivized to contribute free labor
None of your issues I personally experienced or particularly bother me, this is probably a statement to how different people experience different pain points, but your list of complaints was exactly what I was trying to understand. Thank you for taking the time for such a thoroughly response.
As I said, my needs are extremely simple for my password manager. Just keep my data safe, searchable, available on all my devices, generate some strong password and that's it. But I completely understand if you need more. Different strokes for different folks and all that.