UCF STIG Viewer Logo

Auto-complete must be disabled


Overview

Finding ID Version Rule ID IA Controls Severity
V-57681 DTBF-0032 SV-72091r1_rule Medium
Description
This AutoComplete feature suggests possible matches when users are filling in forms and searches. It is possible that this feature will cache sensitive data and store it in the user's profile, where it might not be protected as rigorously as required by organizational policy. If you enable this setting or do not set a value, Auto-complete will remain under the control of the user. This will allow them to configure this setting, and switch Auto-complete on or off at their own discretion.
STIG Date
Mozilla Firefox 2017-03-22

Details

Check Text ( C-58503r1_chk )
Procedure:
In about:config, verify that the setting for the following Preference Name’s are set and locked.

"browser.urlbar.autocomplete.enabled”, set to “false”.

Criteria:
If the parameter is set incorrectly, then this is a finding. If the setting is not locked, then this is a finding.
Fix Text (F-62883r1_fix)
Set and lock the following preferences using the “Mozilla.cfg” file:
"browser.urlbar.autocomplete.enabled”, set to “false”.