|
|
|
|
|
by laurencei
3331 days ago
|
|
I see companies trying to solve a similar issue on their password reset forms. They ask you to enter an email address - then give you a reply "if that email exists, we have sent a password reminder there". The problem is these sames sites have a self-signup, using a unique email as your login. So you can already find out if an email address is in use or not. If you've going to 'leak' the data one way or another, dont sacrifice UX for the sake of it. |
|