Apple May Add Secure Password Suggestions to Safari with OS X Mountain Lion

1Password is a popular password service which offers apps and browser plug-ins for a number of platforms, including Mac, Windows, iOS and Android. The service automatically generates strong, unique passwords whenever a login is needed, keeping them in a keychain under a master password. Once authorized, 1Password can then automatically fill in user names and passwords when needed without the user having to know the often complex passwords created for maximum security.

But with Apple continuing to push out developer betas of OS X Mountain Lion and Safari 5.2, it is now becoming apparent that the company is looking to bake similar functionality directly into Safari.

safari 5 2 password pane
"Passwords" preference pane in Safari 5.2

One of the more visible changes in the Safari 5.2 developer builds has been a new "Passwords" pane in the application's preferences, offering a way for users to access stored user names and passwords for various sites and services. As currently deployed, the pane is essentially a more convenient way to view passwords already stored and accessible through the dedicated Keychain Access application.

safari 5 2 password suggest string
Text string addressing unique password suggestions in Safari 5.2

But text strings associated with the last several builds of Safari 5.2 point to more extensive password functionality for Safari, including an ability to suggest unique passwords rather than simply storing user-created ones. Specifically, one of those strings which is present in Safari 5.2 but not currently used in a public-facing context reads:

Safari can automatically suggest and remember unique, secure passwords for websites you choose.

With Mountain Lion's focus on taking greater advantage of iCloud services to keep data synced across devices, it seems reasonable to speculate that Apple has plans to roll this password functionality out to iCloud and iOS as well. The move would allow "unique, secure passwords" created on one device to be automatically available for use on another device without having to manually record or insecurely copy and paste password information for transfer.

Apple has already revealed its plans to use iCloud to integrate browser activity across devices, as evidenced by Safari tab syncing making its way into test builds. And interestingly, Apple previously offered keychain syncing across devices with .Mac and MobileMe, but discontinued the feature with the transition to iCloud. It now appears that the functionality was removed while Apple worked to revamp and expand it to increase its functionality.

icloud safari syncing lion mountain lion
iCloud's Safari syncing entry in System Preferences in Lion (left) and Mountain Lion (right)

Apple has also signaled its intention to broaden the browser syncing features of Safari with the iCloud preference pane in System Preferences under Mountain Lion. While the Safari section has been titled "Bookmarks" under Lion, with the addition of browser tab syncing and perhaps new user name and password syncing the section has now simply been retitled "Safari".

But while Apple certainly seems to have all of the pieces in place for higher security unique password generation and syncing across platforms via iCloud, the feature has not yet been introduced for testing in developer builds of OS X Mountain Lion. The feature has also not been seen in iOS builds, although the company has yet to begin developer testing on either iOS 6 or an interim iOS 5.2 update.

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Rumored to Use Same Rear Chassis as iPhone 16

Friday July 19, 2024 7:16 am PDT by
Apple will adopt the same rear chassis manufacturing process for the iPhone SE 4 that it is using for the upcoming standard iPhone 16, claims a new rumor coming out of China. According to the Weibo-based leaker "Fixed Focus Digital," the backplate manufacturing process for the iPhone SE 4 is "exactly the same" as the standard model in Apple's upcoming iPhone 16 lineup, which is expected to...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Just Two Months Away: Everything We Know

Monday July 15, 2024 4:44 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
iphone 14 lineup

Cellebrite Unable to Unlock iPhones on iOS 17.4 or Later, Leak Reveals

Thursday July 18, 2024 4:18 am PDT by
Israel-based mobile forensics company Cellebrite is unable to unlock iPhones running iOS 17.4 or later, according to leaked documents verified by 404 Media. The documents provide a rare glimpse into the capabilities of the company's mobile forensics tools and highlight the ongoing security improvements in Apple's latest devices. The leaked "Cellebrite iOS Support Matrix" obtained by 404 Media...
tinypod apple watch

TinyPod Turns Your Apple Watch Into an iPod

Wednesday July 17, 2024 3:18 pm PDT by
If you have an old Apple Watch and you're not sure what to do with it, a new product called TinyPod might be the answer. Priced at $79, the TinyPod is a silicone case with a built-in scroll wheel that houses the Apple Watch chassis. When an Apple Watch is placed inside the TinyPod, the click wheel on the case is able to be used to scroll through the Apple Watch interface. The feature works...
bsod

Crowdstrike Says Global IT Outage Impacting Windows PCs, But Mac and Linux Hosts Not Affected

Friday July 19, 2024 3:12 am PDT by
A widespread system failure is currently affecting numerous Windows devices globally, causing critical boot failures across various industries, including banks, rail networks, airlines, retailers, broadcasters, healthcare, and many more sectors. The issue, manifesting as a Blue Screen of Death (BSOD), is preventing computers from starting up properly and forcing them into continuous recovery...
Apple Watch Series 9

2024 Apple Watch Lineup: Key Changes We're Expecting

Tuesday July 16, 2024 7:59 am PDT by
Apple is seemingly planning a rework of the Apple Watch lineup for 2024, according to a range of reports from over the past year. Here's everything we know so far. Apple is expected to continue to offer three different Apple Watch models in five casing sizes, but the various display sizes will allegedly grow by up to 12% and the casings will get taller. Based on all of the latest rumors,...

Top Rated Comments

Small White Car Avatar
160 months ago
I think I'm the only person in the world who tried and didn't like 1Password, so I'll be interested to see if Apple somehow does it differently.
Score: 9 Votes (Like | Disagree)
manu chao Avatar
160 months ago
I really am not liking the way Apple has "upgraded" the password thing for my apple account. It used to be just a password. Now if someone answers five questions about me that can probably easily be phished through casual conversation (what school did you go to?) they defeat my password.

My only alternative is to use false answers for those questions. Which means I need to keep track of my answers, which means I need something like 1password and if the password for that gets cracked, the keys to the kingdom are truly compromised.
.
You could use your existing password as answer to all questions. That way you are back to one password only.
Score: 5 Votes (Like | Disagree)
AdeFowler Avatar
160 months ago
As the Keychain App already has the ability to suggest and create secure passwords I guess this is a logical move. However, until they can be synced between devices, 1Password have nothing to fear.
Score: 4 Votes (Like | Disagree)
3282868 Avatar
160 months ago
And interestingly, Apple previously offered keychain syncing across devices with .Mac and MobileMe, but discontinued the feature with the transition to iCloud. It now appears that the functionality was removed while Apple worked to revamp and expand it to increase its functionality.
If this is true, I'd be ecstatic. I was disappointed when keychain syncing was removed, but if this was done to improve it, I'm game. Now if Apple works on Documents as a possible replacement for iDisk (using Dropbox now which is great), I'd be a happy camper with iCloud.
Score: 3 Votes (Like | Disagree)
DavidLeblond Avatar
160 months ago
I love 1password. I'll probably stick with them since they sync to my work Windows machine as well.
Score: 3 Votes (Like | Disagree)
leukotriene Avatar
160 months ago
That’s where they are now if you’re using DropBox. The encryption is good though.

I'm a 1password user and I use Dropbox for syncing, but here's a serious security risk:

Any app that you grant Dropbox permission to has access to your 1password database. A malicious app developer could, for example, put an app on the App Store that masquerades as a text editor that syncs with Dropbox. At a given time interval months from now (so as to evade App Store rejection), it uploads your 1password database to their server. At that point the developer can brute force the 1password database (could take days to years depending on your password strength) and have access I all your passwords. Even if 80% of 1password users use a strong enough password to make brute forcing a non-worthwhile endeavor, it's the unfortunate 20% who would get their password exposed by this sort of attack, and thus make this attack a profitable venture for a black hat. It's a very feasible scenario.

On the other hand, with Apple's hypothetical solution, it sounds like your master password would be sandboxed away from app developers whose apps access iCloud. My understanding of the iCloud APIs is that an app can only access data inside its own sandbox. Personally, if Apple comes up with a password syncing solution, I'll certainly switch.
Score: 2 Votes (Like | Disagree)