4 ms·
No, this is fine. If anyone malicious wanted to find out if an email address is registered they could simply try to create a new account using it.
by highace 9y ago
No, this is fine. If anyone malicious wanted to find out if an email address is registered they could simply try to create a new account using it.
- sitepodmatt 9y agoNo, I don't think it is fine. But I do take your point that most signup flows would have this information leak too, and probably with less effect - i.e. target wouldn't get a password reset email. The information leak as a whole though does probably mandates better patterns. I can see it being used by gray hat competitors - 'Hey before you offer X pricing check if he's already a customer of Y and so on'. Weekend project: Scrap HN for emails, run them through redtube which also has this information leak (someone told me), publish them, charge $5 per deletion. (Not serious, but hey feasible right)