1.123 APPL-14-003014

Information

The macOS system must remove password hints from user accounts.

GROUP ID: V-259544RULE ID: SV-259544r958470

User accounts must not contain password hints. Password hints leak information about passwords that are currently in use and can lead to loss of confidentiality.

Solution

Configure the macOS system to remove password hints from user accounts with the following command:

for u in $(/usr/bin/dscl . -list /Users UniqueID | /usr/bin/awk '$2 > 500 {print $1}'); do/usr/bin/dscl . -delete /Users/$u hintdone

See Also

https://workbench.cisecurity.org/benchmarks/24070

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-6, CAT|II, CCI|CCI-000206, Rule-ID|SV-259544r958470_rule, STIG-ID|APPL-14-003014, Vuln-ID|V-259544

Plugin: Unix

Control ID: 11b5a4103bf7b1dc32aa5ab9340d76fdd0af5807e50a268e5606c8041568d40b