Safari's Security Features Aren't Up To Snuff

Lisa Hoover 0 Tallied Votes 353 Views Share

Although Mozilla's Firefox and Google's Chrome browsers get a lot of attention in the media, Apple's Safari browser is not too shabby in comparison. The one thing it unfortunately lacks is robust security.

Given that so much computer activity revolves around the browser these days, security is the last place you'd want to see sub-standard features. InfoWorld's Roger Grimes took and and says that even though it has strong pop-up blocking and anti-phishing tools, it's rife with numerous security flaws.

"[S]ecurity is not Safari's strong point. Unfortunately, 26 separate vulnerabilities have been announced since March 2008, one-third of which would allow complete system access. Plus, there simply isn't a lot of security granularity to Safari," he writes.

Grimes also notes that while Safari warns of invalid digital certificates -- a method of verifying online identity -- it's alert mechanism is so subtle it could easily be overlooked. Furthermore, Safari's password management system failed all but 2 of 21 tests to check it's safety and effectiveness.

Although Grimes doesn't give Safari a ringing endorsement, he doesn't suggest anyone should avoid it all together. "Safari passed all of my browser and JavaScript security exams, negotiating my predefined lab trials, test suites on the Internet (including scanit and ), and real-world exposure to known-malicious Web sites without allowing any malware to be automatically installed (Safari's competitors fared just as well)."

Dani AI

Generated

As observed in the original thread, Safari in 2009 lacked some of the security granularity found in competitors. That criticism was reasonable then. Since that time Apple and the WebKit project have added multiple platform-level protections (privacy-oriented tracking prevention, stronger autofill/keychain encryption, process isolation and faster security responses) so the browser’s threat model and mitigations look very different today. (See WebKit’s Intelligent Tracking Prevention history.)
WebKit — Intelligent Tracking Prevention

Safari’s phishing/malware checks are now routed through vetted services (Google Safe Browsing and, regionally, Tencent) via Apple’s proxy, and the Fraudulent Website Warning and pop‑up controls are surfaced in Safari settings on iOS and macOS. Those checks reduce leakage of full URLs while still allowing blacklist-style warnings. Extension permissions, cross-site tracking controls and an iCloud+ “Hide IP Address” option add further privacy layers.
Safari & Privacy (Apple)
Block pop‑up ads and windows in Safari (Apple Support)

Password handling has been overhauled: iCloud Keychain now syncs encrypted credentials (passwords, passkeys, cards, verification codes) and Safari supports passkeys (WebAuthn) and improved Password AutoFill, reducing reliance on weak saved passwords. For non‑Apple cross‑platform needs, third‑party password managers remain a valid option.
Set up iCloud Keychain (Apple Support)
About the security of passkeys (Apple Support)

Two operational realities remain important. First, WebKit and Safari still receive occasional high‑severity WebKit bugs; Apple’s Rapid Security Responses let critical WebKit/Safari fixes be pushed faster between major OS releases. Second, Safari’s engine and process model emphasize sandboxing and IPC separation — a strong mitigation but not an absolute. Practical mitigations implied by the thread: keep macOS/iOS and Safari updated (allow Rapid Security Responses), keep Fraudulent Website Warning and Prevent Cross‑Site Tracking enabled, audit/remove untrusted extensions, prefer passkeys/iCloud Keychain or a well‑maintained password manager, and consult Apple’s developer and WebKit posts for the current feature list.
Rapid Security Responses (Apple Platform Security)
Using alternative browser engines in the EU — security requirements (Apple Developer)

Note: ’s request for a concise “features list” is reasonable — Apple’s Safari & Privacy and WebKit blog posts above provide the most current, authoritative summaries.

rockyrat12 -3 Newbie Poster

Thank you very much but this was absalutly no help to what i was looknig for. I hope in future you will have what goole says you have and will learn to stick to saying about what you prophes to say. Eg: When i ask for Safari security fetures i hope i will get information on Safari Security features. Thank you very much for reading this and i hope you havea nice day

xxxx
rockyrat12

commented: Thanks for your absolutely useless rant about a 2-year-old post. -3
Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.