HomeControl Library › 3.5.11
3.5 Identification & Authentication1 ptPOA&M-eligible

3.5.11 — Obscure authentication feedback

Obscure feedback of authentication information.

Password fields show dots, not the characters typed.

What it actually means

The simplest control in the family: login interfaces must mask authentication input (the classic password dots) so it isn't exposed on screen. Standard on every modern system — the task is confirming no custom login form leaks it.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library