Tuesday, June 16, 2026

Agentic Password Updates

Hartley Charlton (9To5Mac):

Apple today announced that the Passwords app can now automatically update weak and compromised passwords using Apple Intelligence and Safari to take action on a user’s behalf.

[…]

Apple describes the system as agentic, with Apple Intelligence and Safari securely navigating through websites, signing in, and upgrading accounts to strong passwords without the user needing to intervene beyond an initial tap.

Craig Hockenberry:

Raise your hand if you’re going to trust an AI agent with your passwords.

Maybe it’s architected so that the agent doesn’t see the actual passwords, but I find the idea of this ghost surfing through sites, logged in as me, really creepy.

Rob Mathers:

I still see Safari failing to save generated passwords in some cases.

Previously:

Update (2026-07-15): Dan Moren:

Passwords has an agentic AI feature that will scan your list of compromised passwords and then present you with a list of the ones it believes it can update for you. Even on that subset though, my experience was uneven, with just 5 of 18 updated. It’s a very cool idea, and should hopefully see improvements as the technology progresses, but right now it’s hit or miss.

16 Comments RSS · Twitter · Mastodon


Joel Norvell

But what could go wrong? 😂


I get why people like us are creeped out by this. But I'm thinking of all the people I know who aren't even using Passwords in the first place, don't even know what it is. These are the people who need this help.

As long as the email password reset works, and this doesn't manage to lock them out of their email account to which all their accounts are tied (probably with the same password as the email account because they don't understand the conceptual difference) then this isn't all that dangerous.


I didn't think about it, but that's a great point. Something as important as passwords is probably one of the last things AI should be touching at this point


@bart How do you know it won’t accidentally perform some other non-password-related action while logged into your account?


Everything about their approach to passwords is the opposite of what I want.

Passkeys that I don't control? Nope.
My credentials handled by anyone else, including agents? Nope.

I'd rather physically write credentials on lined paper like it's 1998 than use any of this crap. Far better than Asskeys or Agentic Passwords.


Passkeys are so good, people have to be forced to use them.

Granted, most tech companies (and from the fact they actively participate in it, tech company employees) think drinking something they slipped a roofie into counts as consent.


Will never let this feature within a 1000 metaphorical feet of my passwords but having worked with enough people and seen their password-setting habits, which is the kindest way I can write that, I'm not mad it exists. (Assuming it works.)


Who wants to guess when the first report of someone having an account irrevocably deleted by this will be?


@bart

DEAR CUSTOMER USER,

YOUR REQUESTING TO RESET PASSWORD.

http://verygoodwebsite.com/resetpassword.asp?action=54ewrefdcfv

THE LINK NEXT DELETE ALL OF YOUR ACCOUNT¿ CLICK THE LINK BELOW TO RESET YOUR PASSWORD.

http://verygoodwebsite.com/resetpassword.asp?action=hjku5t4rre

TO UNSUBSCRIBE, CLICK THE 3RD LINK. FOLLOWS IS TO RESET.

http://verygoodwebsite.com/resetpassword.asp?action=jjkjytersfsd

THANK!


I'm confused, weren't we just all going nuts about OpenClaw?

@Michael I don't. The same way I don't really know what Apple's doing with any of the data of mine they have access to, other than what they say.

We don't have technical details yet, but for one thing this likely only works when the entry contains a URL. We already consider password managers to be a safety feature via matching https URLs and not phishing ones.

Siracusa suspects this only works on websites which support a specific password reset format and I'm inclined to agree.

We haven't seen any tech specs yet, but knowing Apple they will be conservative.

And remember my main point, this is not for us. This is for the people who are one unlucky day from having their accounts compromised anyway due to terrible password mangement practices (or a complete lack thereof.)


@bart

The same way I don't really know what Apple's doing with any of the data of mine they have access to, other than what they say.

Well, I think there’s a big different between trusting that Apple isn’t lying to us and trusting their AI to do something that many humans have trouble with.

We don't have technical details yet, but for one thing this likely only works when the entry contains a URL.

It only logs into web sites for web site password entries? I'm not sure what your point is.

Siracusa suspects this only works on websites which support a specific password reset format and I'm inclined to agree.

IIRC, his initial guess was like mine, and then he was horrified to learn that it was actually AI-driven scraping.


> knowing Apple they will be conservative

They're letting an LLM change your passwords. That's at the opposite end of "conservative."

This whole approach to just integrating LLMs into everything and giving them access to everything is deeply concerning. This is "SMB in Windows 95" levels of carelessness. I believe it's only a matter of time until this is widely exploited by phishing attacks.

Hey, upgrade to this new version of the OS and get your fancy Internet-accessible rootkit for absolutely free!



@Mike Yeah, I looked into that, and maybe they’re using it when available. But (a) it’s not an API for changing the password, just a way to point the AI where to start, and (b) I’m not sure it’s widely used enough, and so they may just start surfing at the root URL as a fallback in order to support more sites.


Like everything on the web there is a standard for it. Does that mean that any reasonable number of sites supports it? No.

I'd love for there to be a standard API for password changes, and places supporting it, so password managers like 1Password or Apple Passwords could programmatically rotate passwords, but an AI trying to figure out arcane websites to change passwords? No, thanks.


@Michael I meant that if the entry in the password manager contains a URL to the legitimate login page, the password manager will autofill for that page and not phishing impersonations.

I was implying that the password change feature could use that to identify services it knows it works with.

On the other hand, based on subsequent comments, if they really are just letting the AI figure it out with no particular guardrails, that seems wild and unsafe.

With the lack of more specific information, it seemed more likely to me they would do the former than the latter.

I won't be using this, none of us on this forum will. My only point is that for people who barely even know what a password is but did manage to store their bad passwords in the app, this could be better than nothing.

Leave a Comment