Hacker News new | ask | show | jobs
by pgeorgi 3102 days ago
As the post demonstrates, you simply go to the login form to validate the presence of accounts.

Few sites remember to anonymize that, which might be the real PSA: in such a case, if you require an email confirmation anyway, just send the "recover password" email internally, but let it look like the regular sign-up flow.

If you don't requite email confirmation, anonymous membership isn't possible (just try to sign up with that account, what is the site supposed to do that looks legit without giving away information?)