5.14 Do not enter a password-related hint

Information

Password hints help the user recall their passwords for various systems and/or accounts. In most cases, password hints are simple and closely related to the user's password. Password hints that are closely related to the user's password are a security vulnerability, especially in the social media age. Unauthorized users are more likely to guess a user's password if there is a password hint. The password hint is very susceptible to social engineering attacks and information exposure on social media networks

Solution

Open System Preferences Select Users & Groups Highlight the user Select Change Password Verify that no text is entered in the Pas sword hint box

See Also

https://workbench.cisecurity.org/files/299

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-6

Plugin: Unix

Control ID: 5b4eaf029ee47555918d4cd05da619c72c9c5e1352c6207868a93fe5a602b2c4