apple / password-manager-resources

A place for creators and users of password managers to collaborate on resources to make password management better.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

‘Reused password’ warning for URL's that use the same account.

jonatanvdh opened this issue · comments

I have a feature request for iCould keychain’s security recommendations system. It would be nice if URL's like Flickr.com and Yahoo.com are treaded like one account. Currently I get a ‘Reused password’ warning.

Examples of URL's that are different but use the same account:
flickr.com & yahoo.com
atlassian.com & trello.com
alibaba.com & aliexpress.com
bol.com & kobo.com

So the problem is that there is one account used for multiple websites and the iCould keychain’s differentiates between items in your keychain by URL. It is smart enough to understand subdomains like account.google.com and google.com. But not smart enough to know about the connection between Flickr and Yahoo.

Screenshot 2022-02-09 at 17 06 03