Apple Launches Open Source Project to Let Password Management Apps Create Strong Passwords

Apple today informed developers that it has launched a new open source project that's designed to let those who develop password management apps create strong passwords compatible with popular websites.


The new Password Manager Resources open source project allows password management apps to integrate website-specific requirements used by the iCloud Keychain password manager to generate strong, unique passwords.

Many password managers generate strong, unique passwords for people, so that they aren't tempted to create their own passwords by hand, which leads to easily guessed and reused passwords. Every time a password manager generates a password that isn't actually compatible with a website, a person not only has a bad experience, but a reason to be tempted to create their own password. Compiling password rule quirks helps fewer people run into issues like these while also documenting that a service's password policy is too restrictive for people using password managers, which may incentivize the services to change.

The project also features a collection of websites known to share a sign-in system, links to website pages where users can change passwords, and more, with full details available on GitHub.

Apple says that having password managers collaborate on resources like password rules and change password URLs allows all password management apps to improve their quality with less work, plus it encourages websites to use standards or emerging standards to improve their compatibility with password managers.

Top Rated Comments

(View all)
Avatar
5 weeks ago
Any reason why the article shows the password generator from 1Password without references? :)
Score: 21 Votes (Like | Disagree)
Avatar
5 weeks ago
The thing I’d really like to see is password generation in safari for 3rd party apps.

It’s a bit of a pain to create new accounts in 1Password with the proper url. You have to go back and forth between the app and 1Password a time or two. It’d be nice if it was more streamlined for 3rd party apps kind of like it is for keychain.
Score: 14 Votes (Like | Disagree)
Avatar
5 weeks ago


there's still going to be (and are) plenty of websites that create their own stupid password rules that no password manager that generates strong passwords will be able to comply. People are still going to have to roll their own- kinda taking away the spark of this project. - But at least it's a step in the right direction.

From the way I read it, that is the goal of this project. Once enough password managers add this feature, it should not matter (from a password generation POV), what the requirements are. The password manager will know BEFORE it generates a password.

Take an example from one of the existing websites in the password-rules.json:

According to the JSON, bhphotovideo.com has a requirement of a password max length of 15 characters. Pretend you go to that website and attempt to create an account. You use the Password Generator in Safari (or any password manager), BEFORE the password generator attempts to create a complex password, it reads the JSON and finds the bhphotovideo.com URL. It then reads the requirements (Max length 15). It immediate creates a password that fits that requirement, regardless of what your defaults are. No action needed on your part to manually change the requirements (which may not be obvious on the webpage.)

The key is (a) the list of password requirements is kept up to date. Since this is published on GitHub, anyone can make a PULL request to update. I wonder what Apple's merge requirements are going to be.

(b) Password managers integrate this in to there workflow.
Score: 14 Votes (Like | Disagree)
Avatar
5 weeks ago


Any reason why the article shows the password generator from 1Password without references? :)

I'd guess that if they did reference it, people on here would be asking why they'd singled out 1Password to feature over other PWMs
Score: 13 Votes (Like | Disagree)
Avatar
5 weeks ago


Sure. Give hackers the open source code to help people generate passwords. What can go wrong? :rolleyes:

Openness enables collaboration. Black boxes maintained by a single company aren't usually the best method for strong security. I want security that shows you exactly what its doing, has been vetted by a community of security experts, and dares the hackers to break it.
Score: 9 Votes (Like | Disagree)
Avatar
5 weeks ago
It would be great if websites would have some consistency in their input validation and database schemas. I know one company that allows almost every special character but a comma - and the error message doesn't tell you which special character is the disallowed one. I used 1password and had to go through the generated password and remove each special character 1-by-1 to figure out which one was problematic.
"Hrm, octothorp? Nope. Modulus? Nope. Pipe? Nope. Asterisk? Nope. Greater than symbol? Nope. That just leaves the comma. What?! Seriously?"
It really is an awful experience and I can see why other users would resort to weak and/or reused passwords.
I've see other sites with very specific character length guidelines and other weird combinations. One site, which has since updated to something more secure, even once required 8-15 characters, letters and numbers only. If I were trying to brute force or guess a potentially weak password, wouldn't that make the dictionary size much smaller and thus easier to crack?
Score: 7 Votes (Like | Disagree)

Top Stories

5.4-Inch iPhone 12 Model Size Compared to Original iPhone SE and iPhone 7

Saturday July 4, 2020 9:44 pm PDT by
iPhone 12 dummy models based on leaked schematics have been starting to circulate online and in online marketplaces. Not happy with the circulating size comparisons between the rumored 5.4" iPhone 12 and the original iPhone SE models, MacRumors forum user iZac took matters into his own hands and purchased his own 5.4" dummy model to provide more detailed size comparisons between the original...

Top Stories: iPhone 12 Rumors, Apple's A12Z-Based Mac mini, Leaked iMac, and More!

Saturday July 4, 2020 6:00 am PDT by
With WWDC now behind us, our attention this week largely turned back to rumors, led by increasing claims that Apple controversially won't be including a power adapter in the box with the iPhone 12. We also saw a few other iPhone 12 rumors, signs of an upcoming iMac update, and some more information on timing of updates for Apple's smaller iPads. The other big topic this week was Apple's...

Apple Survey Asks iPhone Users What They Do With Old Power Adapters

Friday July 3, 2020 10:13 am PDT by
Amid multiple reports that Apple will no longer include a power adapter in its iPhone boxes starting with the iPhone 12 later this year, it appears Apple is surveying recent iPhone buyers to ask about what they've done with the power adapters that came with their previous iPhones. Screenshot via Twitter user @bedabb_ Apple's surveys typically cover numerous aspects of its products, but...

Tom Hanks Discusses 'Heartbreaking' Shift of WWII Film Greyhound From Theatrical Blockbuster to Apple TV+ Exclusive

Monday July 6, 2020 7:53 am PDT by
Tom Hanks' WWII drama "Greyhound" is set to premiere on Apple TV+ this Friday, July 10, and ahead of that debut the actor gave an interview with The Guardian discussing the film. "Greyhound" was originally planned to see a theatrical release this summer, and was repeatedly delayed in the wake of the ongoing Covid-19 pandemic. Apple won the streaming rights to the film, and in the new...

Shipping Estimates for 27-Inch iMac Continue to Slip, Now Into September

Monday July 6, 2020 6:55 am PDT by
Amid rumors and hints of a forthcoming update for the iMac, supplies of Apple's current 27-inch iMac continue to dwindle with mid- and high-end stock configurations now seeing shipping estimates pushed back into September. The 27-inch iMac has seen tight supplies and extended shipping estimates for months now, but the situation has been gradually worsening to the point where new buyers can...

Apple Officially Obsoletes First MacBook Pro With a Retina Display

Wednesday July 1, 2020 3:40 am PDT by
As expected, Apple's first MacBook Pro with a Retina display is now officially classed as "obsolete" worldwide, just over eight years after its release. In a support document, Apple notes that obsolete products are no longer eligible for hardware service, with "no exceptions." This means that any mid-2012 Retina MacBook Pro 15-inch models still out there that require a battery or other...

First Arm-Based Macs to Be 13-Inch MacBook Pro and Redesigned iMac, Launches Coming in Late 2020 or Early 2021

Sunday June 21, 2020 9:18 am PDT by
Apple plans to introduce its Arm-based custom designed chips for Macs at WWDC, Apple analyst Ming-Chi Kuo said in a note to investors today, agreeing with an earlier report from Bloomberg. Kuo says that the first Mac models to adopt Arm-based chips will be the 13.3-inch MacBook Pro and an iMac with a redesigned form factor, with Apple planning to launch the new models in the in fourth...

Hands On With iPhone 12 Models Showing New Sizes and Design

Monday July 6, 2020 2:04 pm PDT by
Ahead of the launch of new iPhones we often see dummy models created based on leaked schematics and specifications, with those models designed to let case makers create cases for the new devices ahead of their release. We got our hands on a set of dummy models that represent the iPhone 12 lineup, giving us our first close look at the iPhone 4-style design and the different size options. Subscri ...

EU Advertisers Criticize New App Tracking Privacy Controls in iOS 14

Friday July 3, 2020 3:44 am PDT by
A Google-backed group of European digital advertising associations has criticized Apple for requiring apps in iOS 14 to seek additional permission from users before tracking them across other apps and websites, reports Reuters. Sixteen marketing associations, some of which are backed by Facebook and Alphabet's Google, faulted Apple for not adhering to an ad-industry system for seeking user...

LinkedIn Says iOS App Reading Clipboard With Every Keystroke is a Bug, Fix Coming

Friday July 3, 2020 1:08 pm PDT by
iOS 14 introduces a feature that alerts users when apps access their clipboards, and tons of apps have been caught clipboard snooping. LinkedIn is one of the iOS apps that has been reading user clipboards, and iPhone owners have complained that the app copies the contents of the clipboard with every keystroke. LinkedIn is copying the contents of my clipboard every keystroke. IOS 14 allows ...