1.3 Ensure 'Make pattern visible' is set to Disabled (if using a pattern as device lock mechanism)

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Disable pattern visibility if using a pattern as device lock mechanism.

Rationale:

Keeping device unlock pattern visible during device unlock can reveal the pattern and is vulnerable to shoulder surfing attack. Hence, do not make the device unlock pattern visible.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To disable device unlock pattern visibility, follow the below steps:

* Tap System Settings Gear Icon.
* Scroll to Personal section.
* Tap Security.
* If Screen lock has Pattern underneath the text, follow further steps. If not, then this recommendation is not applicable.
* Tap the Gear Icon in the Screen lock.
* Toggle Make pattern visible to Off position.

Impact:

The user would have to be careful while entering the device unlock pattern since visual feedback would not provide any clues for tracing pattern input.

See Also

https://workbench.cisecurity.org/files/2076