1password implementing privacy-preserving telemetry system

"We won’t be collecting your saved passwords, passkeys, usernames, and any URLs associated with your items. Your private information is just that – private.

All event data will be de-identified and processed in aggregate before it’s used for analysis. "

It sounds like they plan on releasing the technical details in the coming days/weeks. I'm curious how its de-identified and processed.

Jeze3D,

I recently switched from Bitwarden to 1Password and don't regret it one bit. Their app is substantially improved over Bitwarden. Layout is significantly more intuitive and autofill works better than Bitwarden on iOS/macOS.

Spellbind0127,
@Spellbind0127@mstdn.social avatar

@Jeze3D @wet_lettuce I have demo 1 passwords for around a day and still not sure if I should make the switch. Is the extra secret code a usability issue compared to just the master password.

Jeze3D,

It's not for me, no. I guess it depends if you're going to be logging in on random computers frequently (I do not). I printed out a hardcopy of their "recovery kit" which has your secret code and put it in my firesafe. It's a nice extra layer of protection vs only a single master password which can be sniffed especially since it contains the credentials to my entire life.

Also I always have my phone on me which is logged in to 1Password, and I can view my secret key from there wherever I am.

chaotic_goody,

Just leaving a comment here since I haven't seen anybody else mention it: participation is optional for Individual and Family plans, and at this time it will not be applied to Team and Business plans.

lilweeb,

Sigh. What’s a good alternative for iOS?

Tywele,

BitWarden is excellent

renard_roux,

I switched from 1Pass (no subscriptions, please) to BitWarden recently, and I'm super happy with it ❤️

sunbeam60,

Come on - this is 1Password we are talking about; I think they’ve earned a little bit of goodwill given their past behaviour. Transparency is key. Keep in mind that they could do almost whatever they want without telling us.

chaotic_goody, (edited )

If you're not willing to trust what they say about the anonymity of the telemetry system, or to opt out, then I think you wouldn't be happy trusting them with all your passwords in the first place!

If you're willing to stick to Safari, then I think using Apple Keychain is best, especially since they'll be adding sharing this year.

sunbeam60,

Yeah this is what I don’t get. They already hold your most precious secrets and now you don’t trust them with a telemetry system?! Seems an odd order of concerns to me.

ironsoap,

Telemetry, even scrubbed, can provide enough meta data to de-anonomize the user. If the goal is to reduce your threat vectors, than it's a valid concern.

Given data breeches are increasing, the less data that is collected the better.

Screak42,
@Screak42@lemmy.ml avatar

I’m happy with enpass myself for s few years now. it has all kind of sync options and wifi p2p sync if you want to be offline. they offer subscription shit, but luckily also a normal software license to buy.

ZickZack,

You can use keepassXC and "self-host" your passwords on any cloud-storage you want (it's just a file after all), but if you are using 1Pass at the moment, I don't see an opt-in anonymized telemetry system as a reason to switch.

mainfrog,

This seems transparent, well thought out, and opt-in. The headline concerned me but once I read the article this seems fine. I moved from LastPass to 1Password because of the horrible communication around breaches in the last few years.

qazwsxedcrfv000,

It is no doubt a good thing for them to at least try to be "transparent". I hope it is really their intention. I was a customer but I have migrated to selfhost Bitwarden (with Vaultwarden) already.

Screak42,
@Screak42@lemmy.ml avatar

Isn’t 1passwoed subscription only? If I remember correctly that’s what drove me away from a once great application.

and now they want to collect data from paying customers?? excuse me? are you insane?

crash and burn.

sunbeam60,

Huh? They are interested in improving their app - to do that, understanding what choices people make (which buttons do they press, which so they miss etc) is helpful. They’re not trying to monetise your behaviour for goodness sake, but give you a better experience.

g0nz0li0,

Tough place for 1Password, who clearly want to be able to collect data to maintain a competitive edge, but have an audience of security conscious users who may not be comfortable with this. But as always transparency is appreciated.

wet_lettuce,

It's also incredibly important to note that they are making this explicitly opt-in. So none of that 'dark pattern' mumbo jumbo with the tyranny of the default--where companies opt you in and most users dont realize they have to opt-out.

All in all they are going about this the right way it seems. The devil will be in the de-identifying technical details imo.

OsrsNeedsF2P,

Telemetry is one more attack vector, and it’s not a small one at that.

Product owners need to be laid off to stop the enshittification of these apps. Extremely disappointed in this move.

PBJ, (edited )

deleted_by_author

  • Loading...
  • OsrsNeedsF2P,

    opt-out

    Lol

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • [email protected]
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • SuperSentai
  • oklahoma
  • Socialism
  • KbinCafe
  • TheResearchGuardian
  • KamenRider
  • feritale
  • All magazines