1.1.41 (L1) Ensure 'Offer to save logins' is set to 'Disabled'

Information

Firefox allows for credentials to be stored in its credential store for certain websites.

The recommended state for this setting is: Disabled

Stored credentials may be harvested by an adversary that gains local privileges equal to or greater than the principal running Firefox, which may increase the scope and impact of a breach. However, preventing Firefox from storing credentials will not prevent such an adversary from harvesting credentials used while compromised.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Offer to save logins

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

Credentials will not be stored on websites.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-11, 800-53|SI-12

Plugin: Windows

Control ID: 96c43187c4dc83d327f7918eeb310e54a12ee0f5a393802a19dec78bdc9f1606