frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Apple's AI Can Now Change Your Passwords. What Could Possibly Go Wrong?

https://www.kylereddoch.me/blog/apples-ai-can-now-change-your-passwords-what-could-possibly-go-wrong/
68•speckx•2h ago

Comments

drob518•2h ago
Yea, I saw that during the WWDC keynote and physically cringed. As the article says, what could go wrong?
cyanydeez•1h ago
It's good to know Apples not immune from the insecure by design hype machine; just late to the game!
coldtea•8m ago
Nothing much different than e.g. Chrome suggesting a password and saving it?
dewey•1h ago
There's this standard that is being worked on by the people working on the Passwords app at Apple (They are active on Mastodon, and often talking about that) which will probably be helpful for this feature too: https://www.w3.org/TR/change-password-url/
thallavajhula•42m ago
Thank you for this resource. I'm reading up on this spec and it seems like an interesting direction.

For anybody else trying to know what else the .well-known URI can hold: https://en.wikipedia.org/wiki/Well-known_URI#List_of_well-kn...

SquareWheel•24m ago
I know that an uncommon name needed to be chosen, but something about the hyphenated /.well-known/ just turns me off.

I'd have really preferred another term: registered, reserved, defined, meta -- or really anything else.

genghisjahn•28m ago
got any of them mastodon links?
ThejaCH•59m ago
I mean isn't it either to complex to implement or not a good implementation kind off thing?

A good chunk of people do use devices other than apple eco system one's and if they try to login and then suddenly, you can't!

TylerE•34m ago
Isn't that a completely defeating attitude? V1.0 is rarely anything close to perfect.
Schiendelman•21m ago
If they already use devices outside the Apple ecosystem, they're not using the Passwords app, or they're using the plugins that get you access to it in other ecosystems.
TechRemarker•33m ago
Yes, also immediately thought of all the endless ways this could go wrong and end with someone losing access to their account, which depending on their account could be trivial or life altering, especially if their loss ends up being someone else's gain. Apple takes baby steps so I'm sure this will be limited in nature and most likely will get delayed until fully tested, but I'd definitely avoid testing during betas (with any real accounts that is).
dotcoma•31m ago
Can it be turned off ?
eblume•30m ago
As per the demo, in order for Siri to rotate your passwords "for you", you have to open the Password app, go to their dashboard on weak or exposed passwords, and click a button asking it to rotate your password account by account.

So yes. It's off by default. You have to affirmatively use the feature. (This is purely based on what I remember from the demo, mind you. I have not used the feature.)

srik•18m ago
This one is getting a lot of undue flak. Not only does it require explicit confirmation, it’s also contained entirely within the passwords app which already has access to all your passwords because you chose to trust it.

If you use this app, open it and look at how many entries fall under the “security” section. Everyday another password is compromised and added to the list, just too many to keep up. So, albeit apprehensively, I for one appreciate this feature.

throwaway85825•31m ago
People already have a hard time remembering passwords without them being automatically changed.
Schiendelman•22m ago
You should not be trying to remember your passwords. That's what autofill is for, so you can use passwords that are actually secure.
john_strinlai•18m ago
people should not really be remembering any password other than the master password for their password manager.

this also requires the passwords app to even function. so this should be a non-issue.

mikestew•14m ago
I can remember two passwords: the one that gets me into my laptop, and the one that gets me into my password manager. And this feature requires one to use Apple's default password manager, ergo...

And I shouldn't remember the first one, I just haven't gotten 'round to setting up the Yubikey on the laptop just yet.

Petersipoi•8m ago
If you're trying to remember passwords, you're already doing it wrong
thewebguyd•8m ago
That's the point of the password manager. You shouldn't be remembering individual passwords, they should largely be random.
AshamedCaptain•30m ago
Call me when it can _delete the account_ from all those websites, which is likely the primary reason the user has not updated the password yet.
vablings•20m ago
This could have nuclear level consequences. Imagine somehow your keychain is compromised. Using a change password URL means an attacker could literally lock you out of every account at the same time
john_strinlai•15m ago
this only really changes things for obscure sites. there's already automation readily available for all the popular social media, banks, crypto sites, etc.
micromacrofoot•15m ago
I already let 1Password generate all my passwords, so as long as they're just invoking tools with AI rather than having it attempt manually, it doesn't seem like such a big deal?
pokstad•13m ago
I’ve had the iOS password app think that it changed my password, when it did not, and then lose my old password.
tcoff91•7m ago
It doesn't retain all previous passwords??? that's crazy.
hmokiguess•12m ago
https://xkcd.com/2044/
zerobees•7m ago
This article appears to be 100% AI. I guess there's some irony that a company ships an AI feature and someone else uses AI to come up with criticisms of that feature. But the article... doesn't actually say anything?

It's just full of weird, generic short-sentence LLMisms ("Detection is observation.", "Changing the password is authority.", "The security benefit is real.", "That is a meaningful improvement.", "This is not just text generation. It is an agent taking action with a sensitive credential.", ...).

doodlebugging•5m ago
I wonder whether the AI generated password that you allow to be created on your iPhone in the Passwords app can be recovered and added to whatever password manager you might be using on Windows or Linux desktop.

It seems like this is a great way to lock oneself out of access to an account on some of the devices that they own that do not have access to the Passwords data storage.

I can see where this can be a benefit in helping users secure their accounts with stronger passwords but I think that there is a lot of potential for this to become a real problem.

nikisweeting•5m ago
Very curious if they're implementing browser driving themselves or using an off-the-shelf library like stagehand, browser-use, etc. to drive the DOM. Hopefully they open source it if it's in Swift.

A11y-tree alone is not enough for many sites because lots of auth stuff happens in OOPIF frames that need special handling/stitching/interactive element filtering.

economistbob•3m ago
Do terms of service apply to a robot clicking buttons and typing stuff?

Claude Fable 5

https://www.anthropic.com/news/claude-fable-5-mythos-5
1272•Philpax•3h ago•1044 comments

Ultrafast machine learning on FPGAs via Kolmogorov-Arnold Networks

https://aarushgupta.io/posts/kan-fpga/
49•ag2718•1h ago•9 comments

Google's 20% 'project' has become AI's 120% 'attention'

https://joe.dev/posts/new-20pct-time/
22•scottdbuchanan•50m ago•3 comments

Making Graphics Like it's 1993

https://staniks.github.io/articles/catlantean-3d-blog-1/
656•sklopec•10h ago•108 comments

Test-case reducers are underappreciated debugging tools

https://tratt.net/laurie/blog/2026/test_case_reducers_are_underappreciated_debugging_tools.html
28•ltratt•9h ago•3 comments

A giant star may have destroyed itself in one of the rarest explosions

https://phys.org/news/2026-05-giant-star-destroyed-universe-rarest.html
112•wglb•23h ago•14 comments

Microsoft's open source tools were hacked to steal passwords of AI developers

https://techcrunch.com/2026/06/08/microsofts-open-source-tools-were-hacked-to-steal-passwords-of-...
500•raffael_de•13h ago•171 comments

Flat Datacenter Networks at Scale at Amazon

https://perspectives.mvdirona.com/2026/06/flat-datacenter-networks-at-scale/
30•tanelpoder•17h ago•2 comments

CEOs Who Think AI Replaces Their Employees Are Just Bad CEOs

https://www.techdirt.com/2026/06/09/ceos-who-think-ai-replaces-their-employees-are-just-bad-ceos/
119•speckx•2h ago•38 comments

Apple decided not to roll out Siri in EU after denied request for exemption

https://www.reuters.com/business/apple-failed-make-its-ai-tool-comply-eu-regulations-eu-commissio...
282•flanged•4h ago•480 comments

The LD_DEBUG environment variable (2012)

https://bnikolic.co.uk/blog/linux-ld-debug.html
33•tanelpoder•3h ago•1 comments

Biff.core: system composition for Clojure web apps

https://biffweb.com/p/core/
89•jacobobryant•4h ago•16 comments

Ask HN: Are you still using a Vision Pro?

74•y1n0•2h ago•75 comments

OpenCV 5 Is Here: The Biggest Leap in Years for Computer Vision

https://opencv.org/opencv-5/
618•ternaus•3d ago•109 comments

FCC wants to kill burner phones by forcing telecoms to get all customers' IDs

https://www.404media.co/fcc-wants-to-kill-burner-phones-by-forcing-telecoms-to-get-all-customers-...
318•berlianta•5h ago•209 comments

Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]

https://letsencrypt.org/documents/LE-SA-v1.7-June-04-2026-diff.pdf
222•piskov•22h ago•172 comments

Launch HN: Transload (YC P26) – Measuring freight items with CCTV

27•nils_spatial•4h ago•6 comments

Is Grep All You Need? How Agent Harnesses Reshape Agentic Search

https://arxiv.org/abs/2605.15184
96•Anon84•7h ago•43 comments

What it feels like to work with Mythos

https://www.oneusefulthing.org/p/what-it-feels-like-to-work-with-mythos
107•swolpers•3h ago•99 comments

Blaise v0.10.0: Native Back End, Threads and Incremental Compilation

https://github.com/graemeg/blaise/discussions/82
7•mariuz•1d ago•0 comments

Where is the AI jobs crisis?

https://www.apollo.com/wealth/the-daily-spark/where-is-the-ai-jobs-crisis
103•bwestergard•3h ago•145 comments

The iPhone's Last Stand?

https://stratechery.com/2026/the-iphones-last-stand/
144•swolpers•10h ago•187 comments

Show HN: Gravity – interactive solar-system simulator, from Newton to Einstein

https://qunabu.github.io/Gravity/
117•qunabu•9h ago•29 comments

Emerge Career (YC S22) Is Hiring a Founding Growth Marketer

https://www.ycombinator.com/companies/emerge-career/jobs/v0S1AEG-founding-growth-marketer
1•gabesaruhashi•8h ago

Can LLMs Beat Classical Hyperparameter Optimization Algorithms?

https://arxiv.org/abs/2603.24647
79•galsapir•5h ago•12 comments

Show HN: GentleOS – A pair of hobby OSes for vintage 32-bit and 16-bit PCs

https://github.com/luke8086/gentleos32
72•luke8086•2d ago•85 comments

Show HN: Cost.dev (YC W21) – making agents cost-aware and cheaper to call

https://cost.dev/
41•akh•5d ago•23 comments

GPT-2: Too Dangerous To Release (2019)

https://naokishibuya.github.io/blog/2022-12-30-gpt-2-2019/
206•AbuAssar•2h ago•74 comments

Unified Controllable and Faithful Text-to-CAD Generation with LLMs

https://arxiv.org/abs/2604.19773
54•PaulHoule•6h ago•16 comments

Forever Young: how one molecule can lock plants in a youthful state (2025)

https://omnia.sas.upenn.edu/story/biologist-scott-poethig-plants-never-age
112•bryanrasmussen•12h ago•67 comments