HN user

bwoodruff

120 karma

My name is Ben Woodruff and I work for 1Password.

Posts0
Comments145
View on HN
No posts found.

If better data had been available to us, we would've been able to make a more informed decision. We've decided that privacy-preserving telemetry is one of the ways worth exploring to improve that data for the next time. If it is something we roll out to customers, customers will have the choice to participate. We will not collect any telemetry data unless we've obtained consent.

Nobody was questioning how popular the Apple Watch is. The question was how many people were using it to access their 1Password data. The evidence that we had at the time suggested very few. Better data would've helped us make a better judgement.

1Password for iOS does not use Electron. It uses Apple's SwiftUI. Our iOS app is what contains the Apple Watch app.

The point was if we'd had telemetry while prioritizing this work, we would've known it was something many people were actually using. The little data we had showed that was not likely the case. Had we known, we would've prioritized differently.

I'm sorry to hear that has been your experience with 1Password. I appreciate the comment. I've shared that feedback with our design team.

I was an advocate for putting out the blog post early, despite the fact that we're currently only testing this with our employees. As you say, we knew it would be something the community would have questions about, rightfully so, and wanted to be as transparent as possible.

-Ben, 1Password

It tells the extension which item you've selected to fill. It isn't possible to use the Open & Fill feature without it. If you navigate to the website in your web browser and then fill from 1Password's inline menu, instead of using Open & Fill, you can avoid it. Hope that helps. Please drop us an email if you have further questions: support at 1password dot com

-Ben, 1Password

I love that idea. We'd have to be super careful with the de-identification of associated data (which we're doing anyway), but having automation behind figuring out filling failures could be a huge boon. I'll share the thought with the team.

-Ben, 1Password

As our CTO, Pedro, discussed in his blog post (https://blog.1password.com/privacy-preserving-app-telemetry/), we have only rolled out telemetry to our employee base. We will be analyzing the results of this internal-only roll-out before implementing this functionality more broadly.

This functionality will have a prominent in-app message that will ask Individual and Family account users to choose whether they prefer to keep telemetry on or off their account. Nothing gets collected until they’ve made this choice, and users will be able to change their preferences whenever they would like.

-Ben, 1Password

One anecdote as to why it has become clear telemetry is needed:

When prioritizing what we needed in order to launch 1Password 8 we did not prioritize an Apple Watch app. We rarely heard from customers about Apple Watch, and so the assumption was that very few people were using it. When we launched without it, it quickly became apparent that was a poor assumption. People came out of the woodwork to ask where our Apple Watch app went. If we'd had telemetry, we could've known that lots of people were using the Watch app, and just didn't have a reason to write to us about it.

-Ben, 1Password

Hi folks,

Thank you for the comments on this important topic. 1Password's mission is to help people safeguard their most important information and to do that, we have always taken a human-centric approach to security. In order to deliver the exceptional product experience our users expect from us, we need to better understand how they use 1Password.

And while our goal is to deliver better 1Password products, we won’t require our community to help us if they don't want to. We're fully committed to transparency and will provide updates coming out of our research and development period. When we are ready for a wider rollout of this functionality, we will provide clear, in-app messaging, and you’ll be able to control whether or not telemetry is active on your account.

In the meantime, thank you for sharing your feedback – these discussions are always valuable to us, and we appreciate your constructive candor.

-Ben, 1Password

We're definitely taking a close look at how folks will decide to participate (or not participate). As much as possible, we de-identify the data we’re gathering through this project. This data will help us prioritize our overall efforts for our customers. We are not looking to analyze data on individual users. - Ben, 1Password

1Password will not sell telemetry data to third parties, nor will identifiable data be sent to third parties. Our business model is to sell 1Password to you, not to sell information about you to others. Any identifiable data will be stored solely within our environment, as we’re self-hosting the telemetry collection and processing infrastructure. - Ben, 1Password

Thanks for the input. I've shared it with our Product team. We’re actively exploring the specifics of how this experience will operate for a range of use cases. We’re fully committed to ongoing transparency, and will provide clear guidance once additional details are available from our research and development period. - Ben, 1Password

Hi there!

Not quite. An attacker would need either your account password AND an already authorized device, OR they would need both your account password AND Secret Key. If you have 2FA enabled for your 1Password account, and the attacker doesn't have one of your authorized devices, they would also need your second factor (TOTP or hardware key).

Additionally our Principal Security Architect, Jeff Goldberg, wrote some thoughts on this subject, here: https://blog.1password.com/totp-for-1password-users/

- Ben, 1Password

Spoken like someone who did not use the "drag this window on top of the QR code on your screen" feature

This feature still exists, and it is even easier to use. You no longer have to drag any windows around. The QR code just has to be on screen and you press the button. :) If you're having trouble with it please reach out as we'd like to troubleshoot.

nor its ability to detect native application's bundle-id and fill in passwords based on the application currently in focus

1Password 7 didn't do this? It didn't fill in any 3rd party apps except browsers that had our browser extension installed. 1Password 8 actually not only detects these apps but also fills in them. https://support.1password.com/mac-universal-autofill/ If that is not working for you, please reach out.

To include Windows users in this fun, previously one could invoke a hotkey and 1P would offer to auto-type into almost any Windows dialog on the screen. Poof, gone

Agreed. I miss the one too. I'm hopeful we're going to be able to bring it back soon.

-Ben, 1Password

We have templates for both software licenses and wireless routers. :) Custom templates have indeed been on the wish list for a long time. It has proven to be a much more difficult to deliver feature than anticipated. We actually built it, and it is in beta (available to 1Password Business memberships), but we couldn't get buy-in on the implementation. It is something I continue to advocate that we re-evaluate, but I couldn't say if or when it'll happen. -Ben, 1Password