6.1.2 Disable 'Show password hints'

Information

Password hints make it easier for unauthorized persons to gain access to systems by providing information to anyone that the user provided to assist remembering the password. This info could include the password itself or other information that might be readily discerned with basic knowledge of the end user.

Solution

Perform the following to implement the prescribed state:
1. Open System Preferences
2. Select Users & Groups
3. Select Login Options
4. Uncheck Show password hints
Alternatively:
1. Run the following command in Terminal:
sudo defaults write /Library/Preferences/com.apple.loginwindow RetriesUntilHint -int 0

See Also

https://workbench.cisecurity.org/files/301

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-6

Plugin: Unix

Control ID: 5263cb38bc0decdd02b68714e5f563f3ed3180b100fb6e2541a0f2a81de7809b