1Password rolling out “privacy-preserving” telemetry system
blog.1password.com
blog.1password.com
The fact that they're doing this at all, as well as that they're dangling it as a "we may alter the agreement", makes me more hesitant to buy a team/business subscription to 1Password.
> We know that in the technology industry, “analytics” and “usage data” can be an excuse to invade your privacy.
In this case, it seems like unnecessary leakage and implementation complexity in a "you had ONE job" highly security-sensitive service.
I think it was 7 or 8 years ago, I bought it for $50 (since moved on to another)... but it was a one-time payment with on-going rights.
Y'all have some pathologically high tolerance to subscription load or something.
For the record, I had to give up on it when they offered no self-hosted sync mechanisms... I don't trust the cloud services with my passwords, even if they are encrypted. And then I found the forum comment where they were bitching about webdav, and I just knew that it was never not going to be a shitshow.
I hate coffee, keyboard and software "subscriptions" which are just overpriced purchases but to me, this ain't it.
One particular rant of mine for 1Password is that its iOS app seemingly doesn’t remember any context whatsoever. It doesn’t matter how recently you entered your password, it will prompt you for it again if the auto paste went wrong or some other trivial thing caused the entry of credentials to not go correctly.
https://techcrunch.com/2022/09/06/open-source-password-manag...
I'm definitely switch away from Bitwarden.
Are there any alternative password management tools that folks here have had a good experience with at a 100+ headcount org with varying levels of technical expertise?
It has served me and my family well for years now.
Yikes! Here are some quotes:
> we analyze data about your visits to our Site to do things like optimize product design. We use a variety of tools to do this, including Google Analytics. When you visit the Site using Google Analytics, we and Google may link information about your activity from that site with activity from other sites that use Google Analytics services.
> Bitwarden may use the Personal Information collected by the Site to provide you with services, ..., including: For research and development to improve the Bitwarden Service, Site and other Bitwarden services;
The short version of the story is that I used a mess of tooling to get a KeePass-based workflow going, and it resulted in data loss that I had to recover.
I stored my database on a cloud storage provider, and then I would read that database with various clients on my various platforms. At that time, just about none of the (good) clients were cross-platform (KeePassXC that you brought up has no mobile apps).
At that time, an open-source Mac client had a bug that caused some extra fields to be cleared/not saved. I put some important information in those notes and they were lost due to this one client being buggy. Luckily, my cloud provider kept a backup of previous database files.
That's when I realized that having someone else manage all this was way better than saving a few bucks.
I've used 1Password through a lot of new version changes and complete rewrites and I can't recommend it enough. It integrates deeply with all my devices, supports the latest developer frameworks on those devices (e.g., delivering a Safari for iOS extension as soon as extensions were added to iOS), and it's packed full of features that I never dreamed of having with KeePass.
This optional opt-in telemetry seems way more reasonable and respectful than comparable SaaS services and commercial applications, but, alas, "telemetry" is a boogie-man word. Maybe that KeePass app that dropped my data could have used some telemetry to spot that error a bit faster.
The progression seems to be: No telemetry -> Opt-in telemetry -> Opt-out telemetry -> Always on telemetry -> Yeah we sell whatever data you give to us to the highest bidder, what are you going to do about it?
Speaking as someone who has this deployed at work and would be loathe to go through the trouble of having to swap this out, we need to send them a strong enough message at this stage so that they stop experimenting with this further.
1Password isn't going to sell data for completely morally neutral business reasons. They would get peanuts compared to the up to $8/month they get from each user in exchange for a legal, compliance, and security nightmare resulting in a bunch of lost customers.
It's most likely that they just want to make it easier to develop the product. That's where the slope ends.
They will go down that slope until going lower won’t make them any more money. Any money that they make from the sale of data will be profit on top of the 8/mo that they are currently getting.
If there are enough users, getting the legal and compliance stuff sorted might be worth it since that would be a one-off cost to create a whole new revenue stream.
Again, just making the case as to why they could do it, not why they should or will do it.
I used to have 3 copies of the same file so that in case I forgot to sync I would not overwrite some passwords.
At some point I realised what I was doing was not much better than a glorified spreadsheet with passwords and moved on.
writing down passwords isn't equivalent to owning a machine shop and having the skilled labor required to facilitate manufacture of a door lock, regardless of how hard the companies that profit from selling these kind of services tell you it might be.
but i am constantly tinkering on my workflow and pass seems to be really cool so who knows when i switch again!
The only way it preserves privacy is if it defaults to off. Anything else is a lie in service of a fraud.
> You’ll see this message when you open 1Password on mobile and desktop when it’s time for you to choose whether you would like to participate [...] The choice to share your data is yours. We won’t collect anything unless you’ve confirmed you’re happy to share in-app usage data moving forward.
> Later this summer, you’ll see the option to participate in our telemetry system and help improve 1Password. You don’t need to take any action right now, and we won’t collect any usage data without your awareness and consent first.
Developing modern software without being able to observe its operation is simply not realistic. Telemetry of this sort is an important driver of software quality and product improvement.
I’m convinced that people who talk this way are not recognizing the important distinctions between google-analytics-style tracking software that is just trying to squeeze more money out of users and observability-style tracking that is a key part of the software development lifecycle. If you refuse to acknowledge any value in the latter then you deserve the buggy software that results.
Go manages to do it, as does Linux, and Debian.
I think this sort of thinking is poisonous. Just because it is common does not make it ethical or justified.
Linux has a lot of telemetry features which businesses can use to aggregate data on how it is operating. These businesses if they identify problems submit patches to fix them.
>and Debian
Debian has telemtry on what packages people install.
The point people are making is that the one place you probably don't want telemetry software is your system critical password manager. There is a lot of potential for an "oopsie" where something accidentally gets sent that shouldn't get sent, and that's what people have an issue with.
> We’ve designed our telemetry system to collect data on “events”. An event is essentially an action, like: Finishing our in-app onboarding, Unlocking 1Password, Creating a new item, Filling an item in a website or app.
> We won’t be collecting your saved passwords, passkeys, usernames, and any URLs associated with your items. Your private information is just that – private.
With it also being opt-in I dont see an issue with collecting basic numbers for how often people use the plugin or app, as long as they're telling the truth, I think it's fine.
Also due to things like lack of ESNI and lack of onion routing to obscure client IP address, it leaks other information to the vendor and ISP like your travel history over time (via client IP geolocation) and waking/sleeping/working hours.
Software that exfiltrates this information without advance consent is stealing it.
> Software that exfiltrates this information without advance consent is stealing it.
I’m not sure who you are arguing with when you keep repeating this. I pointed out that the post clearly states they will obtain this consent. At any rate, you are obviously not a customer so why are you so mad?
The data doesn't belong to anyone. The data is just a fact of what happened. No one owns the fact that George Washington was the first US president.
We're dealing with quite a serious matter here.
I believe the reality is they need telemetry so they can use it to validate their own decisions. They can produce nice charts and tell each other they're doing a great job and feel good about it, even if users are complaining about it (or just silently accepting it, until some last straw causes them to leave).
If you were to measure my metrics, they'd still look the same as in v7, and they'd tell them nothing about the fact that I think v8 is crap, and that v8 means that one day I might just wake up and say "yeah let's try that bitwarden that HN always talks about".
But, the fact that they don't mention anything other than "All event data will be de-identified and processed in aggregate before it’s used for analysis" leads me to believe it's an in-house solution for a very complicated problem, if one chooses to do it correctly.
Even if I believe it's completely benign, I don't want my password manager phoning home.
I still don't think BitWarden is quite as nice to use as 1Password, but it's close, and my self-hosted bitwarden-rs (now VaultWarden) instance has been pretty hassle free for quite a while now.
or rather technical people making decisions instead of product manager type people.
password management is as simple of a feature set as you can get. less is generally more.
all of the information you would ever need to know can be gathered from a user survey. the people involved would need skillsets for interacting with users though.
this sounds like it's developers trying to gather this data, and this data will tell them absolutely nothing and only piss people off that they are even thinking about wanting it.