12 ms·
You can remove username enumeration from login and password reset, but it's much harder to remove it from signup. And this is pretty much an all or nothing, the
by latch 4y ago
You can remove username enumeration from login and password reset, but it's much harder to remove it from signup. And this is pretty much an all or nothing, there's no point giving cryptic error messages (in the case of forgot password) to users when hackers will just use the signup form anyways. Want a good example? Hacker News: "That username is taken. Please choose another." I just tried on github, generic error message on login, explicit "email in use" error on signup. Amazon? Same thing.
I'd wager that 99% of website allow username enumeration. The very few cases that don't, typically shield their signup with additional steps (captchas, mobile OTP (e.g. paypal, ...)). None of which are foolproof and all of which are a compromise not just from a security point of view but also from a usability point of view.
Until someone gives me a great way to do this with signups, I'm going to stick with the much more usable forgot password error message.
- jaxn 4y agoHow about email validation as a first step and send the "this email is in use" message via email instead of on the sign up form. Adds friction to signup, but would work when it's really important to not leak account existence.
- latch 4y agoI think this is a good idea. It's essentially what I mentioned with Paypal requiring OTP before the signup process starts up. But as you said, it adds a lot of friction to something most companies want to be as frictionless as possible: signups. So it's a compromise. I don't expect many companies will opt for it, except, as you say, those where it's particularly important. I stand by my reply, since my parent implied that username enumeration was rare (i.e. "every so often") and some awful security practice (i.e. "I don't even")
- tialaramex 4y agoHacker News has username enumeration anyway because it has per-user profile links which, like Reddit's, are cool URLs (ie the URL has the username in it, as a parameter, not some UUID minted by a machine at random). Also, and again like (most of) Reddit, Hacker News is public anyway, it's outright weird to have a HN user, choose a distinct name for it when you didn't have to, and then be angry that HN reveals the existence of your user. However, if sites have distinct username and email then getting one doesn't give you the other.