1.8 Ensure 'Show passwords' is set to 'Disabled'

Information

This setting controls whether passwords typed into a user's Android device are visible on screen or hidden. When this setting is disabled, the password is concealed, and only the most recent character is visible for a short time after it has been pressed.

The recommended state for this setting is: Disabled.

Rationale:

Disabling this setting prevents potential shoulder surfing attacks.

Impact:

Disabling the show passwords feature on Android may make it harder for users to enter passwords accurately on the small on-screen keyboard. Without visual feedback, users may have to rely solely on memory, potentially leading to increased frustration, errors, and login attempts.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Show passwords:

Open phone's Settings app.

Tap Privacy.

Toggle Show passwords to OFF position.

Default Value:

By default, passwords are visible.

See Also

https://workbench.cisecurity.org/benchmarks/23192

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: MDM

Control ID: 27c0c84d56609853b123a8c54cf91c4fa5914ec2543f0e4138cc8134866d813d