1.8 Ensure 'Show passwords' is set to Disabled

Information

Disable password visibility during input.

Rationale:

This setting controls whether passwords typed into your Android device should be visible
on screen, or hidden by replacing the letters with dots. When this setting is off, the
password is obscured by dots, and only the most recent key pressed is visible for a short
time after it has been pressed. When this setting is on, the entire password can be viewed
in plain text, if desired.

Disabling this setting protects you against shoulder surfing attacks.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Show passwords:

1. Tap Settings Gear Icon.
2. Tap Security & Location.
3. Scroll to the Privacy section.
4. Toggle Show passwords to Off position.

Impact:

Given the relative difficulty of typing letters accurately on a small on-screen keyboard, it
can be helpful to get visual feedback on-screen that you have typed all the letters of your
password correctly. Disabling password visibility might impact user experience.

Default Value:

By default, passwords are visible.

See Also

https://workbench.cisecurity.org/files/2076