Apple May Add Secure Password Suggestions to Safari with OS X Mountain Lion

1Password is a popular password service which offers apps and browser plug-ins for a number of platforms, including Mac, Windows, iOS and Android. The service automatically generates strong, unique passwords whenever a login is needed, keeping them in a keychain under a master password. Once authorized, 1Password can then automatically fill in user names and passwords when needed without the user having to know the often complex passwords created for maximum security.

But with Apple continuing to push out developer betas of OS X Mountain Lion and Safari 5.2, it is now becoming apparent that the company is looking to bake similar functionality directly into Safari.

safari 5 2 password pane
"Passwords" preference pane in Safari 5.2

One of the more visible changes in the Safari 5.2 developer builds has been a new "Passwords" pane in the application's preferences, offering a way for users to access stored user names and passwords for various sites and services. As currently deployed, the pane is essentially a more convenient way to view passwords already stored and accessible through the dedicated Keychain Access application.

safari 5 2 password suggest string
Text string addressing unique password suggestions in Safari 5.2

But text strings associated with the last several builds of Safari 5.2 point to more extensive password functionality for Safari, including an ability to suggest unique passwords rather than simply storing user-created ones. Specifically, one of those strings which is present in Safari 5.2 but not currently used in a public-facing context reads:

Safari can automatically suggest and remember unique, secure passwords for websites you choose.

With Mountain Lion's focus on taking greater advantage of iCloud services to keep data synced across devices, it seems reasonable to speculate that Apple has plans to roll this password functionality out to iCloud and iOS as well. The move would allow "unique, secure passwords" created on one device to be automatically available for use on another device without having to manually record or insecurely copy and paste password information for transfer.

Apple has already revealed its plans to use iCloud to integrate browser activity across devices, as evidenced by Safari tab syncing making its way into test builds. And interestingly, Apple previously offered keychain syncing across devices with .Mac and MobileMe, but discontinued the feature with the transition to iCloud. It now appears that the functionality was removed while Apple worked to revamp and expand it to increase its functionality.

icloud safari syncing lion mountain lion
iCloud's Safari syncing entry in System Preferences in Lion (left) and Mountain Lion (right)

Apple has also signaled its intention to broaden the browser syncing features of Safari with the iCloud preference pane in System Preferences under Mountain Lion. While the Safari section has been titled "Bookmarks" under Lion, with the addition of browser tab syncing and perhaps new user name and password syncing the section has now simply been retitled "Safari".

But while Apple certainly seems to have all of the pieces in place for higher security unique password generation and syncing across platforms via iCloud, the feature has not yet been introduced for testing in developer builds of OS X Mountain Lion. The feature has also not been seen in iOS builds, although the company has yet to begin developer testing on either iOS 6 or an interim iOS 5.2 update.

Popular Stories

iPhone 17 Pro Colors

Apple Announces iPhone 17 Pro and Pro Max With New Design, Larger Battery, and More

Tuesday September 9, 2025 10:59 am PDT by
Apple today introduced the iPhone 17 Pro and iPhone 17 Pro Max. Both devices feature a new aluminum unibody design, with the Ceramic Shield now protecting both the front and back sides. Apple says the front side is now Ceramic Shield 2, which offers 3x better scratch resistance, while the rear Ceramic Shield is advertised as 4x more resistant to cracks compared to the back glass on previous...
iPhone 17 Pro Colors

iPhone 17 and iPhone 17 Pro Models Are eSIM-Only in These Countries

Tuesday September 9, 2025 12:23 pm PDT by
Apple continues to phase out the physical SIM card tray on iPhones, with the latest models relying solely on eSIM technology in more countries. The new iPhone 17, iPhone 17 Pro, and iPhone 17 Pro Max support eSIMs only in these countries and regions, according to Apple: Bahrain Canada Guam Japan Kuwait Mexico Oman Qatar Saudi Arabia United Arab Emirates Un...
airpods translate

AirPods Live Translation Blocked for EU Users With EU Apple Accounts

Thursday September 11, 2025 4:01 am PDT by
Apple's new Live Translation feature for AirPods will be off-limits to millions of European users when it arrives next week, with strict EU regulations likely holding back its rollout. Apple says on its feature availability webpage that "Apple Intelligence: Live Translation with AirPods" won't be available if both the user is physically in the EU and their Apple Account region is in the EU....
iPhone 17 Pro Colors

iPhone 17 and iPhone 17 Pro: Release Date and Pre-Orders

Wednesday September 10, 2025 12:30 am PDT by
Apple held its annual iPhone event on Tuesday, September 9, to unveil the iPhone 17, ultra-thin iPhone Air, iPhone 17 Pro, and iPhone 17 Pro Max. All of the new iPhone models will be available to pre-order starting Friday, September 12 at 5 a.m. Pacific Time / 8 a.m. Eastern Time in the U.S. and dozens of other countries, according to Apple. The release date for the devices is one week...
iPhone 17 Pro Cosmic Orange

Skipping the iPhone 17 Pro? Here's What's Rumored for iPhone 18 Pro

Wednesday September 10, 2025 8:33 am PDT by
While the iPhone 18 Pro and iPhone 18 Pro Max are still a year away, there are already a few rumors about the devices that offer an early look ahead. If you are skipping the iPhone 17 Pro and want to know about what to expect from the iPhone 18 Pro models, we have recapped a few of the key rumors below. Under-Screen Face ID In April 2023, display industry analyst Ross Young shared a...
better iphone 17 lineup

Apple Lists iPhone 17, iPhone Air, and iPhone 17 Pro Battery Capacities

Tuesday September 9, 2025 1:25 pm PDT by
Apple has confirmed the battery capacities for the iPhone 17, iPhone Air, iPhone 17 Pro, and iPhone 17 Pro Max models that were announced earlier today. Apple is required to publish energy labels on its iPhone product pages in the EU, and they reveal the official mAh battery capacities for the devices. Here are the battery capacities for each model, according to Apple: iPhone 17:...
iPhone 17 Pro Colors

Didn't Pre-Order a New iPhone Yet? Here's How Long the Wait is Now

Friday September 12, 2025 6:11 am PDT by
iPhone 17, iPhone 17 Pro, iPhone 17 Pro Max, and iPhone Air pre-orders began at 5 a.m. Pacific Time in the U.S. and many other countries today. If you have yet to place a pre-order, you might face a longer wait now, depending on your desired configuration. As of shortly after 6 a.m. Pacific Time today, nearly all iPhone 17 Pro Max configurations on Apple's online store in the U.S. are facing ...

Top Rated Comments

Small White Car Avatar
175 months ago
I think I'm the only person in the world who tried and didn't like 1Password, so I'll be interested to see if Apple somehow does it differently.
Score: 9 Votes (Like | Disagree)
manu chao Avatar
175 months ago
I really am not liking the way Apple has "upgraded" the password thing for my apple account. It used to be just a password. Now if someone answers five questions about me that can probably easily be phished through casual conversation (what school did you go to?) they defeat my password.

My only alternative is to use false answers for those questions. Which means I need to keep track of my answers, which means I need something like 1password and if the password for that gets cracked, the keys to the kingdom are truly compromised.
.
You could use your existing password as answer to all questions. That way you are back to one password only.
Score: 5 Votes (Like | Disagree)
AdeFowler Avatar
175 months ago
As the Keychain App already has the ability to suggest and create secure passwords I guess this is a logical move. However, until they can be synced between devices, 1Password have nothing to fear.
Score: 4 Votes (Like | Disagree)
3282868 Avatar
175 months ago
And interestingly, Apple previously offered keychain syncing across devices with .Mac and MobileMe, but discontinued the feature with the transition to iCloud. It now appears that the functionality was removed while Apple worked to revamp and expand it to increase its functionality.
If this is true, I'd be ecstatic. I was disappointed when keychain syncing was removed, but if this was done to improve it, I'm game. Now if Apple works on Documents as a possible replacement for iDisk (using Dropbox now which is great), I'd be a happy camper with iCloud.
Score: 3 Votes (Like | Disagree)
DavidLeblond Avatar
175 months ago
I love 1password. I'll probably stick with them since they sync to my work Windows machine as well.
Score: 3 Votes (Like | Disagree)
leukotriene Avatar
175 months ago
That’s where they are now if you’re using DropBox. The encryption is good though.

I'm a 1password user and I use Dropbox for syncing, but here's a serious security risk:

Any app that you grant Dropbox permission to has access to your 1password database. A malicious app developer could, for example, put an app on the App Store that masquerades as a text editor that syncs with Dropbox. At a given time interval months from now (so as to evade App Store rejection), it uploads your 1password database to their server. At that point the developer can brute force the 1password database (could take days to years depending on your password strength) and have access I all your passwords. Even if 80% of 1password users use a strong enough password to make brute forcing a non-worthwhile endeavor, it's the unfortunate 20% who would get their password exposed by this sort of attack, and thus make this attack a profitable venture for a black hat. It's a very feasible scenario.

On the other hand, with Apple's hypothetical solution, it sounds like your master password would be sandboxed away from app developers whose apps access iCloud. My understanding of the iCloud APIs is that an app can only access data inside its own sandbox. Personally, if Apple comes up with a password syncing solution, I'll certainly switch.
Score: 2 Votes (Like | Disagree)