If better data had been available to us, we would've been able to make a more informed decision. We've decided that privacy-preserving telemetry is one of the ways worth exploring to improve that data for the next time. If it is something we roll out to customers, customers will have the choice to participate. We will not collect any telemetry data unless we've obtained consent.
HN user
bwoodruff
My name is Ben Woodruff and I work for 1Password.
Nobody was questioning how popular the Apple Watch is. The question was how many people were using it to access their 1Password data. The evidence that we had at the time suggested very few. Better data would've helped us make a better judgement.
1Password for iOS does not use Electron. It uses Apple's SwiftUI. Our iOS app is what contains the Apple Watch app.
The point was if we'd had telemetry while prioritizing this work, we would've known it was something many people were actually using. The little data we had showed that was not likely the case. Had we known, we would've prioritized differently.
I'm sorry to hear that has been your experience with 1Password. I appreciate the comment. I've shared that feedback with our design team.
Happy to help. In addition, while we're in the early stages and this design is likely to change, it may help to visualize how we're thinking about this process:
https://bucket.agilebits.com/ben/telemetry-consent-draft.png
You're not going to have to hunt around in the settings to consent to telemetry, no, but we're also not going to collect without consent. We're in the early stages, so this is subject to change. Still, our design team shared this mockup that may help visualize the direction we plan on taking if we move forward with a customer-facing rollout of telemetry.
https://bucket.agilebits.com/ben/telemetry-consent-draft.png
The designs for what the screen will look like have not been completed yet. I couldn't say exactly what the language will be. From what I've seen thus far it will be clear that there is a choice to be made, but the default selection will be to enable telemetry.
Here is a draft of what we're considering: https://bucket.agilebits.com/ben/telemetry-consent-draft.png
Does that help clarify what the experience will be?
I was an advocate for putting out the blog post early, despite the fact that we're currently only testing this with our employees. As you say, we knew it would be something the community would have questions about, rightfully so, and wanted to be as transparent as possible.
-Ben, 1Password
It tells the extension which item you've selected to fill. It isn't possible to use the Open & Fill feature without it. If you navigate to the website in your web browser and then fill from 1Password's inline menu, instead of using Open & Fill, you can avoid it. Hope that helps. Please drop us an email if you have further questions: support at 1password dot com
-Ben, 1Password
I love that idea. We'd have to be super careful with the de-identification of associated data (which we're doing anyway), but having automation behind figuring out filling failures could be a huge boon. I'll share the thought with the team.
-Ben, 1Password
I wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897
tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it.
-Ben, 1Password
I wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897
tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it.
-Ben, 1Password
I wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897
tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it.
-Ben, 1Password
I wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897
tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it.
-Ben, 1Password
I wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897
tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it.
-Ben, 1Password
I wrote more about the consent aspect here: https://news.ycombinator.com/item?id=35706897
tl;dr If we roll this out to customers, we'll be asking for consent, and won't be collecting telemetry data unless we have it.
-Ben, 1Password
As our CTO, Pedro, discussed in his blog post (https://blog.1password.com/privacy-preserving-app-telemetry/), we have only rolled out telemetry to our employee base. We will be analyzing the results of this internal-only roll-out before implementing this functionality more broadly.
This functionality will have a prominent in-app message that will ask Individual and Family account users to choose whether they prefer to keep telemetry on or off their account. Nothing gets collected until they’ve made this choice, and users will be able to change their preferences whenever they would like.
-Ben, 1Password
One anecdote as to why it has become clear telemetry is needed:
When prioritizing what we needed in order to launch 1Password 8 we did not prioritize an Apple Watch app. We rarely heard from customers about Apple Watch, and so the assumption was that very few people were using it. When we launched without it, it quickly became apparent that was a poor assumption. People came out of the woodwork to ask where our Apple Watch app went. If we'd had telemetry, we could've known that lots of people were using the Watch app, and just didn't have a reason to write to us about it.
-Ben, 1Password
Hi folks,
Thank you for the comments on this important topic. 1Password's mission is to help people safeguard their most important information and to do that, we have always taken a human-centric approach to security. In order to deliver the exceptional product experience our users expect from us, we need to better understand how they use 1Password.
And while our goal is to deliver better 1Password products, we won’t require our community to help us if they don't want to. We're fully committed to transparency and will provide updates coming out of our research and development period. When we are ready for a wider rollout of this functionality, we will provide clear, in-app messaging, and you’ll be able to control whether or not telemetry is active on your account.
In the meantime, thank you for sharing your feedback – these discussions are always valuable to us, and we appreciate your constructive candor.
-Ben, 1Password
We're definitely taking a close look at how folks will decide to participate (or not participate). As much as possible, we de-identify the data we’re gathering through this project. This data will help us prioritize our overall efforts for our customers. We are not looking to analyze data on individual users. - Ben, 1Password
1Password will not sell telemetry data to third parties, nor will identifiable data be sent to third parties. Our business model is to sell 1Password to you, not to sell information about you to others. Any identifiable data will be stored solely within our environment, as we’re self-hosting the telemetry collection and processing infrastructure. - Ben, 1Password
Thanks for the input. I've shared it with our Product team. We’re actively exploring the specifics of how this experience will operate for a range of use cases. We’re fully committed to ongoing transparency, and will provide clear guidance once additional details are available from our research and development period. - Ben, 1Password
Great question! Limiting telemetry to those who opt into beta/pre-releases limits our data to those already most likely to write in with feedback. With this initiative we’re hoping to learn more from other audiences — particularly those not inclined toward beta software. - Ben, 1Password
Hi there!
Not quite. An attacker would need either your account password AND an already authorized device, OR they would need both your account password AND Secret Key. If you have 2FA enabled for your 1Password account, and the attacker doesn't have one of your authorized devices, they would also need your second factor (TOTP or hardware key).
Additionally our Principal Security Architect, Jeff Goldberg, wrote some thoughts on this subject, here: https://blog.1password.com/totp-for-1password-users/
- Ben, 1Password
Can confirm. 1pux includes attachments. It should essentially be lossless if where you're going has a good importer. -Ben, 1Password
Another really cool integration we have now is the SSH agent. https://developer.1password.com/docs/ssh -Ben, 1Password
We have a deeper level of integration with the Mac than we've ever had. For example, 1Password 8 can now fill into many non-browser 3rd party apps, which was never possible before. https://support.1password.com/mac-universal-autofill/ -Ben, 1Password
Hey — we'd love to chat about your feedback on the browser extensions. There are some settings that may help. Please shoot us an email. <3 -Ben, 1Password
Spoken like someone who did not use the "drag this window on top of the QR code on your screen" feature
This feature still exists, and it is even easier to use. You no longer have to drag any windows around. The QR code just has to be on screen and you press the button. :) If you're having trouble with it please reach out as we'd like to troubleshoot.
nor its ability to detect native application's bundle-id and fill in passwords based on the application currently in focus
1Password 7 didn't do this? It didn't fill in any 3rd party apps except browsers that had our browser extension installed. 1Password 8 actually not only detects these apps but also fills in them. https://support.1password.com/mac-universal-autofill/ If that is not working for you, please reach out.
To include Windows users in this fun, previously one could invoke a hotkey and 1P would offer to auto-type into almost any Windows dialog on the screen. Poof, gone
Agreed. I miss the one too. I'm hopeful we're going to be able to bring it back soon.
-Ben, 1Password
We have templates for both software licenses and wireless routers. :) Custom templates have indeed been on the wish list for a long time. It has proven to be a much more difficult to deliver feature than anticipated. We actually built it, and it is in beta (available to 1Password Business memberships), but we couldn't get buy-in on the implementation. It is something I continue to advocate that we re-evaluate, but I couldn't say if or when it'll happen. -Ben, 1Password