|
|
|
|
|
by martius
1297 days ago
|
|
There is also the question of leaking whether a given user has an account on a website or not. Maybe I don't want my employer to know that I have an account on competitor-service.com, or my partner to know that I have an account on kinky-thing.website. It might not be a security issue, but it could be a privacy issue. |
|
> 99.9% of websites on the Internet will only let you create one account for each email address. So if you want to see if an email address has an account, try signing up for a new account with the same email address.
This point is undermined by the sign-up workflow informing of whether an account is registered under a given username.