Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-15774 | DTBF140 | SV-16713r1_rule | ECSC-1 | Medium |
Description |
---|
In order to protect privacy and sensitive data, Firefox provides the ability to configure Firefox such that data entered into forms is not saved. This mitigates the risk of a website gleaning private information from prefilled information. |
STIG | Date |
---|---|
Mozilla Firefox | 2015-12-30 |
Check Text ( C-16619r1_chk ) |
---|
Type "about:config" in the address bar, verify that the preference name “browser.formfill.enable" is set to “false” and locked. Criteria: If the parameter is set incorrectly, then this is a finding. If the setting is not locked, then this is a finding. |
Fix Text (F-15991r1_fix) |
---|
Ensure the preference “browser.formfill.enable" is set and locked to the value of “False”. |