6 ms·
I've been a 1Password customer for many years. Their product is super solid. The family plan is very generous. I personally don't have an issue with them collec
by adoxyz 3y ago
I've been a 1Password customer for many years. Their product is super solid. The family plan is very generous. I personally don't have an issue with them collecting some telemetry to improve the product. And they've stated they'll offer ways to opt-out.
- closewith 3y agoI'd accept making it opt-in, but opt-out is ridiculous. I can't imagine how they're going to get this past EU regulators. I love (although loved more in the past) 1Password and have deployed it in two separate companies. Between this and recent UI updates (well, over the last couple of years), maybe it's time to look at alternatives.
- Negitivefrags 3y agoIf you don’t collect any identifiable data, then the EU has nothing to say about it.
- closewith 3y agoUnless they have a non-IP based communication system, then they'll fall afoul of the same thing all online analytics services do - they'll be collecting, at least ephemerally, personal data under the EU definition.
- Negitivefrags 3y agoIt is my understanding that if you do not log the IPs that connect, then you are not collecting personal data.
- closewith 3y agoLast year, a German court fined a website for using Google Fonts as it was providing the IP address to Google without authorization and without a legitimate reason for doing so. It seems likely that the same reasoning will apply here.
- abigail95 3y agoWhat about anonymous logging of which buttons people click on is illegal in the EU? Citation needed on this one. That would make any dashboard that showed which api endpoints are the most popular also illegal. Anomyous telemetry is not PII. GDPR is personal data.
- nness 3y agoAs long as there's no "session identifier," even if unique and completely unmarriable to the PII, it doesn't matter. Any session ID where an ID represents one person runs afoul. Makes meaningful telemetry really hard without consent. Everyone just consents anyway...
- abigail95 3y agoMy position is they can indeed get meaningful telemetry with opt-out anonymised data and that the GDPR does not prevent this. I am countering the position of the parent poster and asking for a citation that would indicate you don't need to sneak this around the EU regulators to do it.
- alpaca128 3y ago> Everyone just consents anyway... Unless you don't lie to them and don't use every dark pattern in the book to trick them into clicking the checkbox.
- JohnFen 3y ago> Anomyous telemetry is not PII. That depends. First, no data collection is "anonymous" when it is transmitted. Any anonymity must come later, and then is only possible if the company aggregates the data with other users and deletes the original data that was collected. PII/Personal Data are squishy terms. In the US, anyway, the legal definitions of what counts as "PII" leaves out an awful lot of actual PII -- so any claims that "no PII is being collected" is meaningless without additional explanation of what data items are being collected.
- abigail95 3y ago
- bwoodruff 3y agoI wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897 https://news.ycombinator.com/item?id=35706897 tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it. -Ben, 1Password
- closewith 3y agoThat's much more reasonable than the wording on the linked page. Thanks for your response.
- bwoodruff 3y agoHappy to help. In addition, while we're in the early stages and this design is likely to change, it may help to visualize how we're thinking about this process: https://bucket.agilebits.com/ben/telemetry-consent-draft.png https://bucket.agilebits.com/ben/telemetry-consent-draft.png
- version_five 3y agoIt's enough to make me at least look for alternatives. If I'm paying for something, I'd strongly prefer to do so on my terms. I use Microsoft office in spite of the fact that it's basically just an industrial spying platform, because I don't have any other options. If I can find a password manager that's easy to switch too that doesn't spy on me, I'll do so. We shouldn't be rewarding companies for this.
- webworker 3y ago> industrial spying platform Applies to much more MS products than just Office these days. I personally stopped being able to justify Office when they moved to subscription and iWork moved to bundled and already installed. I still have Office on my work Mac and boy is it laggy typing as it analyzes the words and sends them to who knows where.
- mdaniel 3y ago> Their product ~~is~~ used to be super solid. Don't get me wrong, it's still light years ahead of the Bitwarden clients and extensions, and that's why I stay, but I for sure would not use the present tense for their quality
- arepublicadoceu 3y ago> it's still light years ahead of the Bitwarden clients and extensions I’m quite possible a simpleton but I can’t see how it’s light years ahead of Bitwarden. Can you provide an example of such difference? Every time I used to check 1password (before the Great Purge of local vaults) I always arrived at the same conclusion. It’s a bit more beautiful but not 3x or 4x (whatever the price is) more beautiful then Bitwarden. Functionality wise I couldn’t see much of a difference. Both save passwords, both share passwords, both generate passwords and both have Totp support.
- mdaniel 3y agoI often regret any contact I have with the Bitwarden fanbase, because whooo they are rabid, but I guess I used to be a rabid fan of 1P so maybe fair's fair :-D Anyway ... - https://github.com/bitwarden/clients/issues/1620 https://github.com/bitwarden/clients/issues/1620 was created 2021, after it was migrated from the issue that was open even longer in the other repo, and now they've locked the issue because they're tired of people complaining about the extension losing their credentials - there are a ton more Item types in 1Password, which some people consider just cosmetic ("you can create your own fields") but https://bitwarden.com/help/managing-items/ https://bitwarden.com/help/managing-items/ compared to https://support.1password.com/item-categories/ https://support.1password.com/item-categories/ is night and day, setting aside the native support for SSH agent that's built into 1P nowadays and here starts the list of even more highly subjective items, which I acknowledge are highly subjective - the folder based item management in Bitwarden is highly inferior to the tags based management in 1P. Creating folders itself is a major PITA, whereas creating tags in 1P is ... just type the new tag name. Maybe people enjoy putting the "tags" in there item's names or whatever, and doing away with folders in Bitwarden, but ... the fact they're trying to implement tagging on the cheap indicates they want tags but Bitwarden doesn't see the world that way - I find the attachment management process cumbersome in Bitwarden, whereas in 1P there are actually two orthogonal ways of managing attachments: they can be first class Items (called "Document" items) meaning that is the whole secret that one would care about, and they can also be arbitrarily attached to other Items in kind of a supporting role. I have scans of my passport attached to the Passport item type because so many places ask me to upload a scan of my passport. Same for my driver's license on the formal Driver's License item type - in the theme of "finding it cumbersome," I find that 1Password seems to care a lot more about UX than Bitwarden. Now, of late I am having to qualify any such statement because yikes that 1P 8 rewrite was catastrophic. But, rewrite-induced-self-inflicted-harm aside, I still think 1P cares a lot more about UX than Bitwarden - also subjective, but I really enjoy the `op run` <https://developer.1password.com/docs/cli/reference/commands/run https://developer.1password.com/docs/cli/reference/commands/...> and its ability to resolve specially formatted env-vars <https://developer.1password.com/docs/cli/secret-references https://developer.1password.com/docs/cli/secret-references> in the sub-process. That process seems to be the basis of their shell plugins system <https://developer.1password.com/docs/cli/shell-plugins https://developer.1password.com/docs/cli/shell-plugins> but TBH I find just having env-vars lying around to be more convenient than their shell plugin system for my workflow. The fact that the `op` binary is smart enough to use DBus to auth to my desktop session means I can also use it as an implementation of pinentry A perfectly reasonable question may be "well, it's open source, why not start fixing bugs?" The things about using folders and the lack of item types indicates to me that they're just rowing in a different direction than what I would like, and the fact that they're a commercial company means unless I directly would benefit from fixing a bug means I am not incentivized to contribute free labor