Rule ID
SV-268539r1034557_rule
Version
V1R7
CCIs
Password hints must be disabled. Password hints leak information about passwords that are currently in use and can lead to loss of confidentiality.
Verify the macOS system is configured to disable password hints with the following command:
/usr/bin/osascript -l JavaScript << EOS
$.NSUserDefaults.alloc.initWithSuiteName('com.apple.loginwindow')\
.objectForKey('RetriesUntilHint').js
EOS
If the result is not "0", this is a finding.Configure the macOS system to disable password hints by installing the "com.apple.loginwindow" configuration profile.