Privacy-preserving usage data: Under the hood
blog.1password.com
blog.1password.com
This heading is followed by several paragraphs that don't explain at all why they're collecting several of these data points.
If the IP address is dropped in the de-identification pipeline, why is it stored in the "raw events"? If you don't need an exact timestamp, why are you storing it? Why does the app send all of this identifying data to be stored for 21 days instead of "de-identifying" it beforehand?
"Hey there, I just read the "under the hood" blog post about telemetry and have some questions.
First of all, the section "But why collect these data points in the first place?" does not really answer the question. There is no explanation given about why e.g. IP-addresses are collected when, as by your schematics, they are never really used and completely anyway. So why store them in the first place, even if only for 21 days?
Another question I have is, why the de-identification of some items takes place in your AWS environment instead of on device. For example, when talking about the IP-address, it is not used later on anyway. And the timestamp could easily be truncated by the batcher on device, couldn't it?
Looking forward to hearing from you!"
Thanks for your thoughtful questions and for your patience as we connected with our engineers over the weekend.
*Why are IP addresses collected?*
Currently, IP addresses are an unavoidable part of the telemetry data process because the event transmission occurs over the TCP/IP protocol. The library we use as the web server automatically parses IP addresses from that transmission, but we've implemented a step to entirely remove that field from the data before it's processed for analytics. We currently don't require or desire IP information for telemetry; we’re early in our telemetry journey and will consider improving our handling of IP addresses as a future enhancement.
*Why do we de-identify server-side rather than on the device?*
De-identifying server-side allows us to enrich the raw event data with additional metadata elements that aren't stored on your device. These elements are non-identifying pieces of information like the type of account and whether or not the trial period is active. The entire server-side enrichment pipeline is hosted entirely within 1Password's own infrastructure.
*Could the timestamp be truncated by the batcher on the device?*
The timestamp being truncated on the device is possible – our primary concern here is the loss of visibility into latency in our pipeline. This can have a significant impact on data quality and understanding the health of our pipeline.
Our goal as we roll this out is to provide transparency on how we prioritize customer privacy while building a better 1Password. We hope this helps answer some of your questions and we’re here to help if you have anything else you’d like to know.
Will be interesting to see if they roll this out in the EU (especially with the "Share analytics" box being checked by default).
Data collection for aggregate analysis that discards personally identifiable information in a non-recoverable way similarly does not require explicit consent.
Sounds to me like what they say they're doing is compliant, does not require explicit consent under the GDPR anyway, and therefore whether or not the checkbox defaults to checked or not is moot from the point of view of the GDPR.
I understand some people might not want to trust them, their processes or their competence regardless, but that's a matter that's outside the scope of the GDPR. The GDPR is about what they are doing and for what purposes, not whether you trust them.
The basic feature set already works great. I hope having more usage data will let them keep tweaking the product for users.
Or they might just sell it all to data brokers. Who knows these days, lol.
I respectfully suggest they pull some devs off inventing new telemetry techniques and put some work into the backlog instead, particularly this embarrassing date display issue that's causing actual problems for a solid group of their users: https://1password.community/discussion/131071/incorrect-date...
How does usage data fix this?
Have you considered just sending them feature requests and bug reports?
I've never really had feature requests acted on by a company before. Small one person software shops, yes, but companies? Never. I don't think their feature pipelines actually care what customers want.
But if some product owner in their org uses it to make even one improvement, it's worth it to me. I really don't mind them collecting usage data (heck, they don't even have to anonymize it for me) as long as my passwords remain encrypted.
Edit: I mean, I trust this company with my entire online existence, including major financial and government functions. It's closed source and I take their word (and reputation) for it. Surely I can trust them to monitor which buttons I push...
Over that time I observed that they were very aggressively repositioning the cloud offering as the only one, or as one that was the most secure for every use case. New users eventually only saw the standalone options as a small link.
I was in various public and beta test groups for 1Password 6-8, and 7 felt like the sweet spot, but somewhere around 7.4, they started rapidly changing onboarding screens and release note screens to feature only 1Password.com.
Only after doing that did they start discussing how many “new users were signing up for the cloud, and skipping standalone.”
I felt that was disingenuous because I saw them constructing that very outcome. I even discussed it with them, but actually saying that aloud seemed to be like taking a leak on the third rail. I’m not arguing with your logic, but as someone who was close to it at the time, this outcome was very carefully constructed over a non-trivial period of time.
All that said, my big gripe is that when you try to talk to them about backups, they refuse to talk about anything but sync. They still don’t have actual account-wide backups. They have CSV and 1PUX exports that only capture vaults currently present on the exporting client.
1pass - take a hint from apples privacy preserving photo scanning snafu last year - if you’re upsetting loyal users, take a step back, and rethink the system.
I really like Bitwarden (after moving from Lastpass) but haven’t tried 1Password. Am I missing out?
"Our telemetry system cannot, by design, have insight into the end-to-end encrypted data you store in 1Password."
It can't by design... but can it by accident? And will they secretly change the design at the request of the CIA?
They're saying they've designed the system, so it's separated from access to your vault. This is their way of trying to reassure users they have considered user privacy.
Obviously, they could be secretly collecting things this entire time. But also, why would they need the telemetry system to view your vault? If they wanted to view that, they could do that "secretly"
1Password don’t need to an analytics platform to steal your passwords. They could just straight up modify their client to send back your decrypted passwords to them. Analytics doesn’t make a jot of difference to the difficulty of doing that.
The point is, that they are wanting to intentionally collect data about me now. It's quite easy to see how that could be data that I don't want collected.
Your question is like asking why it bothers me that all my neighbors have Ring doorbells now recording my walks, when they could just look out their window and spy on my anyway. It's a step along the slippery slope that makes the likelihood of privacy invasion much higher as time goes on. Ignore the CIA if you want, but I'm pretty sure they'll have an easier time collecting data they might want now that it exists. But leaving that to the side, collecting data accidentally is a known problem that keeps cropping up.
Then this change doesn’t impact you. There’s no indication 1Password have any interest in back-porting analytics to older versions of 1Password.
> Your question is like asking why it bothers me that all my neighbors have Ring doorbells now recording my walks…
No, my question is quite simple. Either you trust the entire 1Password client or you don’t. Telemetry might change a persons stance on that trust, but holding up the boogy man CIA as reason for not liking telemetry is ridiculous. If the CIA could and wanted to force 1Password to hand over your encrypted data, then not having telemetry isn’t going to slow them down.
If your argument is you don’t like telemetry, full stop. Then make that argument. Throwing in FUD about shady CIA activities does more to undermine your argument than strengthen it.
Wealthsimple actually did something like that when they purchased SimpleTax. Logging into your account after the acquisition resulted in them in decrypting and migrating data (I think it was opt-out by default, it's been a few years).
Any system running inside your password manager's process can in theory be used to extract your data. Ideally the surface area stays small.