New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CCE-28307-7] retries_until_hint #8

Closed
macosforgebot opened this Issue May 29, 2013 · 3 comments

Comments

@macosforgebot
Copy link

macosforgebot commented May 29, 2013

@DewSecGitHub originally submitted this as ticket:7

  • Version: Beta
  • Keywords: Settings, Review

CCE#: CCE-28307-7
Setting Name: retries_until_hint
Description:
Controls when, and if, a password hint is given the user, based on the number of failed login attempts.

Parameters: N / A
Technical Mechanism: In loginwindow.plist, set the RetriesUntilHint key = X to show a hint after X login failures, or set the key = 0 to disable hints.

Reference: OSX 10.6 DISA STIG, NIST SCM rules, CIS Security Configuration benchmark for 10.6.

Function: Authentication

Rationale: N / A.


SOHO: disable hints
Enterprise: disable hints
SSLF: disable hints


Additional Mechanism: N / A


OVAL Content: N / A


Comment:

@macosforgebot

This comment has been minimized.

Copy link

macosforgebot commented May 29, 2013

@DewSecGitHub originally submitted this as comment:1:⁠ticket:7

  • Status changed from new to accepted
@macosforgebot

This comment has been minimized.

Copy link

macosforgebot commented Jun 6, 2013

plink53@… originally submitted this as comment:2:⁠ticket:7


I question this setting. It used to be FileVault wouldn't give the message about entering the FV master password if someone failed three times if the hint wasn't turned on. Is this still true? Does FV2 give an admin the ability to reset a user's password if they forget it with the hint disabled?

Is there a vulnerability or attack vector enabled by enabling hints?

I don't believe there's a NIST 800-53 setting for this.

@macosforgebot

This comment has been minimized.

Copy link

macosforgebot commented Aug 6, 2014

blank@… originally submitted this as comment:4:⁠ticket:7

  • Status changed from accepted to closed
  • Resolution set to R8 - Completed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment