4 ms·
That's a security failing - you shouldn't let the website user know that a given account exists. The right way to do this is have a log in form (one or two pag
by NLips 8y ago
That's a security failing - you shouldn't let the website user know that a given account exists.
The right way to do this is have a log in form (one or two pages - doesn't matter) and a separate create account form. You can try to log into a non-existant account, which will fail in exactly the same way as a wrong password. You can try to create an already existing account, which will result in exactly the same behaviour to the webpage user as creating a non-existing account - a page saying "An email has been sent to the email address <foo>".
- nickles 8y ago> That's a security failing - you shouldn't let the website user know that a given account exists. It's not an issue if you let users pick their own username. There's simply no way to get around this (apart from assigning usernames). In other cases, usernames being publicly available is a desired feature. [0] https://imgur.com/a/qCupYyQ https://imgur.com/a/qCupYyQ
- astura 8y agoIt really depends on what the site is and what the user ID is. For example, I know the account "NLips" exists on hacker news, that's not a "security failing," nor can that information be hidden, however, it would be a security issue if I could put my boss's email into a porn site to see if he has an account.