Hacker News new | ask | show | jobs
by highace 3165 days ago
No, this is fine. If anyone malicious wanted to find out if an email address is registered they could simply try to create a new account using it.
1 comments

No, I don't think it is fine. But I do take your point that most signup flows would have this information leak too, and probably with less effect - i.e. target wouldn't get a password reset email. The information leak as a whole though does probably mandates better patterns. I can see it being used by gray hat competitors - 'Hey before you offer X pricing check if he's already a customer of Y and so on'.

Weekend project: Scrap HN for emails, run them through redtube which also has this information leak (someone told me), publish them, charge $5 per deletion. (Not serious, but hey feasible right)