"Our telemetry system cannot, by design, have insight into the end-to-end encrypted data you store in 1Password."
It can't by design... but can it by accident? And will they secretly change the design at the request of the CIA?
"Our telemetry system cannot, by design, have insight into the end-to-end encrypted data you store in 1Password."
It can't by design... but can it by accident? And will they secretly change the design at the request of the CIA?
They're saying they've designed the system, so it's separated from access to your vault. This is their way of trying to reassure users they have considered user privacy.
Obviously, they could be secretly collecting things this entire time. But also, why would they need the telemetry system to view your vault? If they wanted to view that, they could do that "secretly"
1Password don’t need to an analytics platform to steal your passwords. They could just straight up modify their client to send back your decrypted passwords to them. Analytics doesn’t make a jot of difference to the difficulty of doing that.
The point is, that they are wanting to intentionally collect data about me now. It's quite easy to see how that could be data that I don't want collected.
Your question is like asking why it bothers me that all my neighbors have Ring doorbells now recording my walks, when they could just look out their window and spy on my anyway. It's a step along the slippery slope that makes the likelihood of privacy invasion much higher as time goes on. Ignore the CIA if you want, but I'm pretty sure they'll have an easier time collecting data they might want now that it exists. But leaving that to the side, collecting data accidentally is a known problem that keeps cropping up.
Then this change doesn’t impact you. There’s no indication 1Password have any interest in back-porting analytics to older versions of 1Password.
> Your question is like asking why it bothers me that all my neighbors have Ring doorbells now recording my walks…
No, my question is quite simple. Either you trust the entire 1Password client or you don’t. Telemetry might change a persons stance on that trust, but holding up the boogy man CIA as reason for not liking telemetry is ridiculous. If the CIA could and wanted to force 1Password to hand over your encrypted data, then not having telemetry isn’t going to slow them down.
If your argument is you don’t like telemetry, full stop. Then make that argument. Throwing in FUD about shady CIA activities does more to undermine your argument than strengthen it.
Wealthsimple actually did something like that when they purchased SimpleTax. Logging into your account after the acquisition resulted in them in decrypting and migrating data (I think it was opt-out by default, it's been a few years).
Any system running inside your password manager's process can in theory be used to extract your data. Ideally the surface area stays small.