|
|
|
|
|
by netsec_burn
3333 days ago
|
|
This isn't an issue, you can do the same thing with the main login form and a number of undocumented APIs. I've never seen anyone else acknowledge "confirmation of email address existence" as a security issue and I don't see why Google should be the first. |
|
It's usually called "username enumeration" and there's plenty of pen testing firms that include this as a standard part of their process.