Check: WINCC-000147
Windows Vista STIG:
WINCC-000147
(in versions v6 r42 through v6 r41)
Title
The touch keyboard or input panel must not highlight keys as passwords are entered. (Cat III impact)
Discussion
The touch keyboard or input panel may highlight keys as passwords are entered, providing visibility to nearby persons, and compromising them.
Check Content
If the system does not have a touch screen, this is NA. If the system has a touch screen and the following registry values do not exist or are not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry path: \SOFTWARE\Policies\Microsoft\TabletTip\1.7\ Value Name: PasswordSecurityState Type: REG_DWORD Value: 1 Value Name: PasswordSecurity Type: REG_DWORD Value: 4 or 5 (1, 2, or 3 are a finding)
Fix Text
If the system does not have a touch screen, this is NA. Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Tablet PC -> Input Panel -> "Turn off password security in Input Panel" to at least "Enabled: Medium High".
Additional Identifiers
Rule ID: SV-70675r1_rule
Vulnerability ID: V-56421
Group Title: WINCC-000147
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000206 |
The information system obscures feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals. |
Controls
Number | Title |
---|---|
IA-6 |
Authenticator Feedback |