Information
Password hints are user-created text displayed when an incorrect password is used for an account.
Password hints make it easier for unauthorized persons to gain access to systems by displaying information provided by the user to assist in remembering the password. This info could include the password itself or other information that might be readily discerned with basic knowledge of the end user.
Solution
Run the following command to disable password hints:
% /usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.loginwindow RetriesUntilHint -int 0
Impact:
The user can set the hint to any value, including the password itself or clues that allow trivial social engineering attacks.
Item Details
Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION
References: 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1
Control ID: b6f1d3d86329c8e3531a258fc9a1587039d73a2a6acc859c81054a0598578d4e