1.1.31 (L2) Ensure 'Disable Form History' is set to 'Enabled'

Information

Form Fill Assistance allows Firefox to save data that has been entered into forms by users so that future operations are performed faster.

The recommended state for this setting is: Enabled

This mitigates the risk of websites extracting information from prefilled text fields.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Disable Form History

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

Prefilled text fields will not be enabled.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-11, 800-53|SI-12

Plugin: Windows

Control ID: 8df8bf68ff261093ab0c8a94bb6698c8c447030dcfc8d1b499eecd9d9641775c