AgileBits in Toronto offers 1Password, a password manager available to both private individuals and businesses, touting a unique approach to multi-factor authentication to improve security.
$2.99
per month
Hypersocket
Score 8.0 out of 10
N/A
Hypersocket (formerly Nervepoint) enables organizations to efficiently manage and administer end users and their access to disparate systems by empowering end users to manage their own accounts across multiple systems both on-premise and in the cloud, while allowing IT to gain control over user sprawl, cut support and gain in-depth business insight.
1password is the best solution for storing your passwords and other sensitive data as well as sharing it with employees of your company easily and efficiently. It has a web interface for managing your passwords and users as well as user groups. 1password can be installed on almost any OS and integrated with all popular web browsers
It has great flexibility with multiple domains, and the ability to sync or not sync passwords between primary and secondary accounts. I'd like to see a more granular set of permissions for the help desk role tied to an OU path rather than a whole directory. You can [create this] by defining multiple directories based on OUs but is less flexible this way.
1Password's Watchtower service is a real value add - 1Password monitors the security news for evidence of security breaches containing your credentials and alerts you if you have been impacted. That is a huge value as it enables you to get out in front of a security breach and be proactive in protecting yourself.
1Password's core strength is that it makes it easy to practice good security hygiene by using strong, unique passwords for each site you interact with. This is something that all password managers do now, but offering an easy experience is key.
1Password's password sharing features makes it easy to share team credentials with other team members, and to decide who amongst the team gets access to the designated credentials.
1Password is so secure, that it lacks a self-managed "forget your password" functionality which means that as a manager, I have to approve password resets which may slow down some users.
On Chrome, the extension sometimes stops working when the browser is updated.
Help-Desk functionality similar to OneIdentity Self-Service Password Manager, as it provides additional users that do not require administrative access to assist with managing end-users who may have locked themselves out of HyperSocket Access Manager by forgetting their own security questions.
Too many features which become unusable and feel like the payment plans are not flexible since it's an all-in-one product with one price. It is not necessarily a bad thing as most subscription-based pricing forces a buyer to pay more for an integral service that is only available on the highest price-plan. You really do get what you pay for, but we found many of our use-case scenarios limited the product.
This isn't necessarily against the product, just a personal opinion around Multi-Factor authentication which is always primarily driven mobile devices. Not all companies or end-users have access to a multi-factor device, (or in our case, are allowed to have access to a cell phone while servicing members/clients). This creates a shortfall to allow multi-factor functionality to extend to all users unless there are hardware tokens, which can be miss placed or left out more easily as most users don't treat it the same way they would their personal smartphone.
1Password is a great password manager and it helps us a lot in our every day duties at the company. Since implementing this solution we also feel way more secure when it comes to our own data or the data of our Clients.
The 1Password app design is top notch, much better than a couple other password managers I've looked at. The app and service are very flexible, allowing for many different types of data storage. The browser extensions generally work very well, allowing for easy access to login information while using pretty much any modern web browser.
I haven't had to use the support team since using the product, so that's saying something. But I did reference the FAQs and information materials to help with the initial setup. All in all, I found all of the information and clarity I needed to get set up and begin fully using the platform.
I do have LastPass set up for our front office workers since their free version does fine for managing the few passwords they have. Since that computer is in an area accessed by most of the staff and visible to the public, I didn't want sticky notes with sensitive passwords laying around. The main advantage of that usage is that it does offer a free version, and with so little to manage, the paid 1Password would not be a good value for us there. But it does, of course, have its limitations. The interface is a bit clunky, and we don't have any desktop or mobile versions set up to try to sync with, just the one web browser based version, so I can't speak to the accessibility, but it does not "feel" as robust and easy to use as 1Password.
One Identity is a great self-service password management system, however, it is limited to just that. As it stacks against the competition, Hypersocket isn't modular, it's an all-in-one which most other systems aren't. One Identity is what we use today for self-service, and migrated to KeePass for users centralized password manager. This probably wasn't the best move but this was all driven by cost and budgetary constraints.
Our business has over 500 different passwords that are required to log into other websites for billing. Allowing easy login to the different entities saves time and money.
1Password encrypts all the passwords, protects them, preventing hackers from obtaining all of the information and causing disruption to the business.
Having multi-users save time and money because everyone will have access to all passwords at the tip of the finger without having to ask request passwords from other employees. Furthermore, employees who require the passwords on the field will also have access to the password. Furthermore, our IT department requires access to passwords to employee's computers in order to assist with troubleshooting. This allows the IT department to access computers remotely without asking for passwords receiving passwords over the internet.
As with any IT Service or Solution, the investment will always be seen as a sunk cost. The only ROI would be the time and resources spent elsewhere rather than with Password Management through an IT Department or similar department. I found that the time spent on password management was about the same, as many users who are frequently forgetting a password are also forgetting their security question & answers.
There are some positives, as it was able to help manage the bulk of their non-windows passwords or passwords related to another online service. The centralized password manager doesn't feel like a true single sign-on but for most users, it replaces a hand-written copy they have taped to a monitor.
It can help with automating some of the active directory workflows with its own user provisioning functionality. Took more time to set up than it was to manage on its own.