(So many times error reporting, etc. have accidentally leaked highly sensitive data, which was then the source of a major compromise, in other systems. Maybe 1Password won't get it wrong, maybe 1Password will never be subject to any pressure to get it wrong...)
One day, the company that makes this hammer says that they will be updating it to automatically tell the company a bunch of information about the hammer's use -- when it's used, where it's used, what the environment is like around the hammer, how many times it's used, what it's used for. They assure you that they don't care about who is using the hammer, but obviously it will be YOUR hammer reporting the information, so at some level it will be associated with you.
Why are they doing this? Well, they know that sometimes their hammers break. They only know this, though, because sometimes their hammers break for their own employees and sometimes customers tell them hammers break. They would really like to know ALL the times their hammers break, though, so that can try to fix all the problems with their hammers, and not just the ones they see or get reported to them. They say this will be best for their customers and that's why customers should be on board with the change.
No one would ever buy that hammer again, right?
Regardless of the privacy implications of the company knowing everything about your usage of the hammer, the company is basically saying that their hammers break so much that many of their customers don't bother telling them and just go use someone's hammer. In other words, their product is bad and their customers don't value it enough to deal with it.
Don't even get me started on paying monthly for that hammer ...
I think you came to the wrong conclusion. Lots of people might still buy the hammer, and lots of people might knowingly buy the hammer, and even more, lots of people might knowingly buy the hammer and like that the hammer is being fixed when it breaks. I honestly don't understand why so many people oppose telemetry, especially when it's anonymous.
I mean, you might not, but I don't see telemetry as such an evil. It does help make the product better. So "no one" is a bit too strong here, try "no one with my mindset" ;)
I had this belief before, that it helps makes the product better.
But I realized that telemetry is used against us. It helps the company push their own agenda, and manipulate the user.
For example, I'm used to update my Android apps manually. Google made it more and more difficult, version by version, to access the corresponding screen in the Google play app, in order to push for auto-update. They analyzed this through telemetry.
I use 1password and generally like it. Their moves towards typical Product Owner monetization BS has me starting to look to other options.
I don't see how adding telemetry makes any significant difference.
The problem is its always been there. Telemetry provides more noise to hide exfiltration of sensitive data, but the risk has always been there from the start for the reasons you laid out.
It's a closed source product in a surveilence heavy country. Telemetry or not, it's risky.
I’d be fine with telemetry if it recorded locally in a way which was fully inspectable and human readable and which I could send IFF I wanted to, but with a password manager I’d be scared even of just a long list of events; passwords and keys themselves are so low entropy vs long lists that you could easily encode something…