5.15 Do not enter a password-related hint

Information

Password hints that are closely related to the user's password are a security vulnerability, especially in the social media age. Unauthorized users are more likely to guess a user's password if there is a password hint. The password hint is very susceptible to social engineering attacks and information exposure on social media networks

Solution

1. Open System Preferences
2. Select Users & Groups
3. Highlight the user
4. Select Change Password
5. Verify that no text is entered in the Password hint box

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.9_Benchmark_v1.0.0.pdf

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-6

Plugin: Unix

Control ID: b18cacf96d90ff565d1d4d3e0cac7bfcf335cddb6c7172a3af037be8d3ad8bd8