UCF STIG Viewer Logo

The macOS system must be configured to prevent displaying password hints.


Overview

Finding ID Version Rule ID IA Controls Severity
V-257231 APPL-13-003012 SV-257231r905326_rule Medium
Description
Password hints leak information about passwords in use and can lead to loss of confidentiality.
STIG Date
Apple macOS 13 (Ventura) Security Technical Implementation Guide 2023-08-28

Details

Check Text ( C-60916r905324_chk )
Verify the macOS system is configured to prevent displaying passwords hints with the following command:

/usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep "RetriesUntilHint"

RetriesUntilHint = 0;

If "RetriesUntilHint" is not set to "0", this is a finding.
Fix Text (F-60857r905325_fix)
Configure the macOS system to prevent displaying password hints by installing the "Login Window Policy" configuration profile.