Information
Disable pattern visibility if using a pattern as device lock mechanism.
Rationale:
Keeping device unlock pattern visible during device unlock can reveal the pattern and is vulnerable to shoulder surfing attack. Hence, do not make the device unlock pattern visible.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To disable device unlock pattern visibility, follow the below steps:
* Tap System Settings Gear Icon.
* Scroll to Personal section.
* Tap Security.
* If Screen lock has Pattern underneath the text, follow further steps. If not, then this recommendation is not applicable.
* Tap the Gear Icon in the Screen lock.
* Toggle Make pattern visible to Off position.
Impact:
The user would have to be careful while entering the device unlock pattern since visual feedback would not provide any clues for tracing pattern input.