UCF STIG Viewer Logo

The password-related hint field must not be used.


Overview

Finding ID Version Rule ID IA Controls Severity
V-25307 OSX00335 M6 SV-38532r1_rule IAAC-1 High
Description
If a hint is provided, the user is presented with the hint after three failed authentication attempts. Password-related information provided in the field could compromise the integrity of the password. Adding contact information for your organization’s technical support is convenient and does not compromise password integrity.
STIG Date
MAC OSX 10.6 Workstation Security Technical Implementation Guide 2013-04-09

Details

Check Text ( C-37745r1_chk )
1. Open System Preferences->Accounts Panel, for each account.
2. Click 'reset password' (Change Password for current user).
3. Ensure no data exists in the password hints field.
4. Click Cancel.
If any accounts have hints data, this is a finding.
NOTE: The password hints field may include contact information for the organization's technical support.
Fix Text (F-32989r1_fix)
1. Open System Preferences -> Accounts Panel, for each account.
2. Click 'reset password' (Change Password for current user).
3. Remove any data in the password hints field.
NOTE: The password hints field may include contact information for the organization's technical support.