Skip to content
This repository has been archived by the owner on Jun 24, 2022. It is now read-only.

💬 Discussion | Ease to use vs privacy/analytics #722

Open
Mikaela opened this issue Jan 15, 2019 · 6 comments
Open

💬 Discussion | Ease to use vs privacy/analytics #722

Mikaela opened this issue Jan 15, 2019 · 6 comments

Comments

@Mikaela
Copy link
Contributor

Mikaela commented Jan 15, 2019

I cannot format this so I would be happy with it, but I am wondering how important is privacy or something having analytics compared to it being easy to use?

For example Bitwarden was said to have Google Analytics enabled in https://github.com/privacytoolsIO/privacytools.io/issues/719 which led to it being removed in https://github.com/privacytoolsIO/privacytools.io/pull/720 (and I am happy to see GA being removed and it coming back in https://github.com/privacytoolsIO/privacytools.io/pull/721).

Everyone has a lot of usernames and passwords. Everyone is told that they should use a password manager. Bitwarden handles syncing the passwords between devices, while the other proposed solution, KeePass, leaves that for the user.

I haven't been able to make my family use Bitwarden and I often feel frustated when I listen to them having no idea what their passwords are somewhere or I hear them reusing passwords and me saying that I am not even supposed to know their password isn't heard.

I hope you can understand my question, how much does ease to use weight when compared to privacy or Google Analytics? I don't know how to format this better as obviously privacy weights, but I am assuming everyone understands that if something did something very evil, it wouldn't be on PrivacyTools.io, and I am probably desensitivized towards analytics.

I am mainly thinking of comparing Bitwarden to KeePass, if I cannot make my family use even Bitwarden, do I have any hope of getting them to use KeePass and sync the database onto their phones and all devices they use etc. (while I am not doing that either)?

I personally moved from KeePassX to LastPass probably more than ten years ago as it was easier than resolve sync conflicts of the database and when Firefox Quantum was in beta I moved to Bitwarden while having issues with LastPass who also wasn't updating their extension for Quantum until it became stable.

@ghost
Copy link

ghost commented Jan 15, 2019

I agree. Ease of use is very important, which is why we recommend Signal as the first IM tool.

In some cases, such as the IM section, a reasonably secure, yet easy-to-use tool is better than some tool that's somewhat more secure but difficult to use.

However, when it comes to analytics (especially Google Analytics), I think it would be against our principles to recommend such tools. I personally wouldn't mind using for example BitWarden with GA but I don't think it's a good idea to recommend such tools on PTIO.

@Mikaela
Copy link
Contributor Author

Mikaela commented Jan 15, 2019

I haven't researched passwords managers much, but are there any as easy alternatives/equivalents to Bitwarden or is it the "Signal of passowrd managers"?

@danarel
Copy link
Contributor

danarel commented Jan 15, 2019

@Mikaela IMO, Bitwarden is the easiest to use for newcomers. Sure, there are "easier" ones like 1password, LastPass, but their support for Linux is terrible, but also, they are focused on a bigger for-profit model over privacy and security.

I certainly think apps like KeyPass are the best way to go, but they are certainly not as clean and user friendly when you're trying to get new people on board with taking privacy seriously.

@AshTex
Copy link
Contributor

AshTex commented Jan 15, 2019

I agree that we should include Bitwarden somewhere (such as the "worth mentioning" list) as it fits the FOSS, encrypted at rest, and has had a third party security audit. Much like @Shifterovich I don't mind using Bitwarden (I'm a paying subscriber of it!) with analytics turned off but I think it's against the ethos of PTIO.

@ghost
Copy link

ghost commented Jan 15, 2019

Again, the analytics have been removed from BitWarden.

@AshTex
Copy link
Contributor

AshTex commented Jan 15, 2019

Ah sorry! I didn't see the comment on the original PR. That's great news. :)

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

3 participants