3 ms·
>If someone is an actual security expert, I'd like to know why (1) is an acceptable practice. So your issue here is that Google tells you whether it's a valid
by indecisive_user 8y ago
>If someone is an actual security expert, I'd like to know why (1) is an acceptable practice.
So your issue here is that Google tells you whether it's a valid email address before you enter in a password?
You could validate email addresses yourself by sending out a ton of emails to different permutations of *@gmail.com and seeing which ones come back as undeliverable. An email address on its own isn't inherently private so this doesn't seem to be a security risk to me unless I'm missing something.
- deathanatos 8y agoI interpreted the parent's complaint in (1) as the login form having the username/password entries split across two screens, not as a complaint that it tells you the account doesn't exist. AIUI, splitting the entry across two screens like that breaks a lot of password managers, as they can't handle it. This hampers the adoption of password managers, which would largely help the average Joe's security. Google supports external auth in some cases¹, and to know whether they need to redirect to that auth, they first need your username / email. Then, you're either redirected or you're shown the password entry prompt. I don't know of any banks that do this, so this might not be applicable to them. (Theirs might just be bad design.) ¹GSuite, not consumer GMail, but I assume the flows are the same
- godelski 8y agoYou both addressed different parts to my complaint, so thank you both. I'm definitely dumb enough to not realize that email login might be a special case because you can check username validity another way (sending emails). And I didn't know that GSuite had external auth. These split pages don't actually break lastpass, at least for me. One field is still called username and another is called password, so they fill properly.