3.1 (L2) Ensure 'AutoFill web forms: User names and passwords' is 'Disabled'

Information

Safari can utilize a user-level keychain for credential storage, and then access that information when revisiting websites on the same domain. By disabling this feature the user will be prompted to manually enter their credentials when they visit a website.

Rationale:

If this setting is enabled, users can have Safari store and retrieve passwords through a user-level keychain and provide them automatically the next time they visit a site. An intruder who has unrestricted access to your computer can gain access to secure site areas.

Solution

Follow the below steps to set AutoFill web forms: User names and passwords to Disabled:

1. Click Safari.
2. Click Preferences.
3. Click AutoFill.
4. Uncheck AutoFill web forms: User names and passwords.

To configure the plist follow the below steps:

1. Open the com.apple.Safari.plist.
2. Find the token <key>AutoFillPasswords</key>
3. Ensure this token is immediately followed by <false/>

Default Value:
Enabled.

See Also

https://workbench.cisecurity.org/files/1822

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|13

Plugin: Unix

Control ID: 5cfa2adf8acc0e1040f99722ad6e3b5fd1a9f759733cfb93c4a4d6376b2c6f2c