6 ms·
default to privacy though, please
by pqh 9y ago
default to privacy though, please
- ryanbrunner 9y agoNot really. "Default to privacy" is what gives you insane useless UXes like the one in the article, where you're making login (already a frustrating experience) more painful with absolutely zero gain in security. Default to knowing your threat model. Default to balancing security concerns with UX, and make an informed decision instead of blindly following best practices.
- perfmode 9y agoI don’t want others to know all of the places where I have accounts. That’s an easy way to be targeted.
- stordoff 9y agoThat's the point of the article though - for a large percentage of services, if you know the username/email address you are targeting, you can just try to register them and see if it works. Obfuscating the login process makes little difference.
- testvox 9y agoWhich is why they shouldn't leak this information on the registration page... Instead they should pretend the registration always succeeds and then disallow login until the email has been verified.
- mnarayan01 9y agoThe point is that sites generally leak this anyway via signup. With github it's even easier, e.g. https://github.com/someuser https://github.com/someuser -- I looked through my settings and their doesn't appear to be any way to "be invisible", though I could be missing something. When you can do a simple query like that, sacrificing UI at sign-in seems totally pointless.
- cjwhite 9y agoYou're missing the point. Fix the signup form instead of just giving up.