(Translated by https://www.hiragana.jp/)
Apple Launches Open Source Project to Let Password Management Apps Create Strong Passwords - MacRumors
The Wayback Machine - https://web.archive.org/web/20200608164539/https://www.macrumors.com/2020/06/05/apple-open-source-password-management-project/

Apple Launches Open Source Project to Let Password Management Apps Create Strong Passwords

Apple today informed developers that it has launched a new open source project that's designed to let those who develop password management apps create strong passwords compatible with popular websites.


The new Password Manager Resources open source project allows password management apps to integrate website-specific requirements used by the iCloud Keychain password manager to generate strong, unique passwords.

Many password managers generate strong, unique passwords for people, so that they aren't tempted to create their own passwords by hand, which leads to easily guessed and reused passwords. Every time a password manager generates a password that isn't actually compatible with a website, a person not only has a bad experience, but a reason to be tempted to create their own password. Compiling password rule quirks helps fewer people run into issues like these while also documenting that a service's password policy is too restrictive for people using password managers, which may incentivize the services to change.

The project also features a collection of websites known to share a sign-in system, links to website pages where users can change passwords, and more, with full details available on GitHub.

Apple says that having password managers collaborate on resources like password rules and change password URLs allows all password management apps to improve their quality with less work, plus it encourages websites to use standards or emerging standards to improve their compatibility with password managers.

Top Rated Comments

(View all)
Avatar
2 days ago at 09:26 am
Any reason why the article shows the password generator from 1Password without references? :)
Score: 20 Votes (Like | Disagree)
Avatar
2 days ago at 09:33 am
The thing I’d really like to see is password generation in safari for 3rd party apps.

It’s a bit of a pain to create new accounts in 1Password with the proper url. You have to go back and forth between the app and 1Password a time or two. It’d be nice if it was more streamlined for 3rd party apps kind of like it is for keychain.
Score: 14 Votes (Like | Disagree)
Avatar
2 days ago at 09:44 am


there's still going to be (and are) plenty of websites that create their own stupid password rules that no password manager that generates strong passwords will be able to comply. People are still going to have to roll their own- kinda taking away the spark of this project. - But at least it's a step in the right direction.

From the way I read it, that is the goal of this project. Once enough password managers add this feature, it should not matter (from a password generation POV), what the requirements are. The password manager will know BEFORE it generates a password.

Take an example from one of the existing websites in the password-rules.json:

According to the JSON, bhphotovideo.com has a requirement of a password max length of 15 characters. Pretend you go to that website and attempt to create an account. You use the Password Generator in Safari (or any password manager), BEFORE the password generator attempts to create a complex password, it reads the JSON and finds the bhphotovideo.com URL. It then reads the requirements (Max length 15). It immediate creates a password that fits that requirement, regardless of what your defaults are. No action needed on your part to manually change the requirements (which may not be obvious on the webpage.)

The key is (a) the list of password requirements is kept up to date. Since this is published on GitHub, anyone can make a PULL request to update. I wonder what Apple's merge requirements are going to be.

(b) Password managers integrate this in to there workflow.
Score: 13 Votes (Like | Disagree)
Avatar
2 days ago at 09:28 am


Any reason why the article shows the password generator from 1Password without references? :)

I'd guess that if they did reference it, people on here would be asking why they'd singled out 1Password to feature over other PWMs
Score: 12 Votes (Like | Disagree)
Avatar
2 days ago at 10:44 am


Sure. Give hackers the open source code to help people generate passwords. What can go wrong? :rolleyes:

Openness enables collaboration. Black boxes maintained by a single company aren't usually the best method for strong security. I want security that shows you exactly what its doing, has been vetted by a community of security experts, and dares the hackers to break it.
Score: 8 Votes (Like | Disagree)
Avatar
2 days ago at 10:01 am
It would be great if websites would have some consistency in their input validation and database schemas. I know one company that allows almost every special character but a comma - and the error message doesn't tell you which special character is the disallowed one. I used 1password and had to go through the generated password and remove each special character 1-by-1 to figure out which one was problematic.
"Hrm, octothorp? Nope. Modulus? Nope. Pipe? Nope. Asterisk? Nope. Greater than symbol? Nope. That just leaves the comma. What?! Seriously?"
It really is an awful experience and I can see why other users would resort to weak and/or reused passwords.
I've see other sites with very specific character length guidelines and other weird combinations. One site, which has since updated to something more secure, even once required 8-15 characters, letters and numbers only. If I were trying to brute force or guess a potentially weak password, wouldn't that make the dictionary size much smaller and thus easier to crack?
Score: 7 Votes (Like | Disagree)

Top Stories

iPhone 13 Prototype Mockup Depicts Notch-Free Design and USB-C Port

Thursday June 4, 2020 10:07 am PDT by
We still have a few months to go before Apple unveils the iPhone 12, but rumors about the iPhone 13, coming in fall 2021, are already circulating. Japanese site Mac Otakara today shared a rough 3D printed mockup of a 5.5-inch iPhone said to be coming in 2021, which is from "Alibaba sources." The model may be built on leaked specifications and rumors, but where the info comes from is unclear. ...

Apple's Stock Price Hits a New All-Time High [Updated]

Friday June 5, 2020 7:06 am PDT by
Roughly four months after hitting an all-time high just before financial markets and economies faltered in the face of the current public health crisis, Apple's stock price has returned to those levels and has set a new all-time high today. Apple's previous intraday high of $327.85 was set on January 29, and that high-water mark was surpassed just a few minutes ago as it hit $328.00 before...

Apple's Attempts to Automate Product Assembly Have Met With Limited Success

Thursday June 4, 2020 7:38 am PDT by
The Information today published a detailed look at the difficulties Apple has faced trying to assemble its products with robots rather than humans. The report claims that, beginning in 2012, Apple assembled a team of robotics and automation specialists at a secret lab in Sunnyvale, California to search for ways to reduce the number of workers on its production lines. However, the team is...

Deals: Amazon Discounts Apple Watch Series 5 Models by $100, Now Starting at $299

Friday June 5, 2020 7:51 am PDT by
Amazon today kicked off a new sale on Apple Watch Series 5 models, starting with the 40mm GPS device for $299.00, down from $399.00. This discount matches the previous all-time-low price for this Apple Watch on Amazon, and is one of the best you'll find online right now. Note: MacRumors is an affiliate partner with these vendors. When you click a link and make a purchase, we may receive a...

Some iPhone 11 Users Complain of Display With Odd Green Tint

Friday June 5, 2020 12:31 pm PDT by
Some iPhone 11, 11 Pro, and 11 Pro Max owners have been noticing an unusual green tint to their iPhone displays when first unlocking the device, based on complaints shared on Reddit and the MacRumors forums. Image of green tint appearing briefly on the right, from MacRumors reader Oceannn It's not clear what's going on, but almost all of the affected users say that the green tint is visible ...

Code in iOS 13.5.5 Suggests Apple is Working on Services Bundle

Wednesday June 3, 2020 5:04 pm PDT by
Rumors have suggested Apple is working on a services bundle that will offer multiple Apple services like Apple TV+ and Apple Music for one flat monthly rate, and according to 9to5Mac, code found in iOS 13.5.5 seemingly confirms Apple's bundle plans. Files in iOS 13.5.5 reference a "bundle offer" and a "bundle subscription," and these files weren't in earlier versions of iOS. The files are...

Apple Launches Open Source Project to Let Password Management Apps Create Strong Passwords

Friday June 5, 2020 9:20 am PDT by
Apple today informed developers that it has launched a new open source project that's designed to let those who develop password management apps create strong passwords compatible with popular websites. The new Password Manager Resources open source project allows password management apps to integrate website-specific requirements used by the iCloud Keychain password manager to generate...

iPad Pro With A14X Chip, 5G, and Mini-LED Display Expected in First Half of 2021

Wednesday June 3, 2020 6:22 am PDT by
Apple plans to launch new iPad Pro models with an A14X chip, 5G connectivity, and a Mini-LED display in the first or second quarter of 2021, according to the increasingly reliable Twitter account L0vetodream. The leaker claims that the new iPad Pro models will be equipped with Qualcomm's Snapdragon X55 modem, which supports both mmWave and sub-6GHz. mmWave is a set of 5G frequencies that...

Apple Planning Interest-Free Apple Card Payment Plans for Macs, AirPods, iPads and More

Saturday June 6, 2020 1:51 pm PDT by
Apple plans to debut interest-free payment plan options for customers who purchase iPads, AirPods, Macs, and more using Apple Card, allowing them to pay for purchases over several months. According to Bloomberg, Apple will roll out the Apple Card feature in the coming weeks, with customers given up to 12 months to pay for their products before interest is due. The 12 month plan will be...

Five Mac Apps Worth Checking Out - June 2020

Tuesday June 2, 2020 2:25 pm PDT by
Apps developed for the Mac often don't receive as much coverage as apps designed for iPhones and iPads, so we have a series at MacRumors that highlights interesting Mac apps that are worth taking a look at. This month's apps are designed to make working from home a little bit easier. Subscribe to the MacRumors YouTube channel for more videos. Meeter (Free) - Working from home often...