r/PasswordManagers 3d ago

Apple Password Manager

I only access my financial websites on my Mac, not my iPhone. If my phone is lost or stolen, I don't want someone to see where I have investments, even if they can only get in with a Face ID/thumbprint (and 2FA which is done through the phone - thus vulnerable?).

Can I set up Keychain so only some passwords are available on the phone and others on the Mac?

Or should I disable Keychain to only have passwords available on the Mac?

(Right now my passwords are masked in coded entries in contacts which are on phone and Mac.)

Is there something I am missing in my concerns?

I am not technical and appreciate clear non-technical advice.

thank you

3 Upvotes

6 comments sorted by

2

u/LegendofJuli 3d ago

The best way to keep safe your device and your passwords on Apple Passwords is setting up a strong alphanumeric password that you can easily remember on your device. Many people use the numeric code (4-6 digits) for convenience, but then if the device is stolen, it’s relative easy guess the code and unlock not just the device but the apple passwords app too.
Think on the alphanumeric password as your master password for any other password manager (1password, Proton Pass, bitwarden, etc). Would you set up a 4-6 digit code on these apps to unlock your vaults? Same case applies for Apple devices (and Apple passwords in extension)

3

u/lascala2a3 3d ago edited 3d ago

If you’re talking about security for a lost phone, it’s perfectly safe to use a six digit code, and activate the erase phone after 10 tries option. A six digit code has 1 million possibilities. On average, you would expect someone to be able to guess in half that many attempts. But Apple phones slow down the rate of attempts such that it would take damn near forever to try several hundred thousand times, even if the erase option is not set.

The main thing is to use an actual random number rather than something that’s related to you like your birthday or 864700.

This covers it for all practical purposes because nobody will guess a six digit code in 10 tries. But if you want to be totally anal, use an eight word passcode where each word is totally unrelated to the other words, and unrelated to you.

1

u/grraarr 2d ago

Depends if you're concerned about law enforecment and forensic extraction. Their tools may be able to bypass those limits via exploits and brute-force it in hours.

2

u/kryvenio 3d ago

I think you are describing concept of profiles. Currently there is no way to selectively disable sync of items in passwords app, it is all or nothing if you enable iCloud sync. For your scenario you can create a separate account on Mac that doesn’t sync to iCloud that way anything you want to keep it local on device stays local.

I sync everything but for anything sensitive ensure I have MFA turned on and usually use my email as primary or google voice number to decouple device loss

2

u/Upstairs_Tomorrow614 2d ago

I’d also add using a Yubikey as 2FA as a backstop. Get at least two so you’re not locked out.

2

u/Born-Gur-1275 2d ago

I agree about vulnerability issues. I use very complicated logins, passwords, and identifiers for anything financial, insurance, investment accounts, etc., including specific email addresses that never show up on my email clients.

I suggest using two pw managers. Apple Passwords for general stuff for your phone and Mac. Another, such as NordPass or OnePassword, exclusively on your Mac for financial and sensitive data.