4.1 (L2) Ensure 'AutoFill user names and passwords' is 'Disabled'

Information

Safari can utilize a user-level keychain for credential storage, and then access that information when revisiting websites on the same domain. By disabling this feature the user will be prompted to manually enter their credentials when they visit a website.

Rationale:

If this setting is enabled, users can have Safari store and retrieve passwords through the user-level Keychain and provide them automatically the next time they log in to a site. An intruder who has unrestricted access to your computer for even a minute can gain access to secure site areas.

Solution

Follow the below steps to set AutoFill user names and passwords to Disabled:

1. Click Safari.
2. Click Preferences.
3. Click Passwords.
4. Uncheck the AutoFill user names and passwords checkbox.

To configure the plist follow the below steps:

1. Open the com.apple.Safari.plist.
2. Find the token <key>AutoFillPasswords</key>
3. Ensure this token is immediately followed by <false/>

Default Value:
Enabled.

See Also

https://workbench.cisecurity.org/files/1822

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|13

Plugin: Unix

Control ID: 7fa223a1b69b24b636a6569cfae8a939048045aae4b31928e1af2b57b3aa06a0