|
|
|
|
|
by savolai
683 days ago
|
|
It can indeed be incredibly confusing for users if that is not disclosed, bordering on hostile. It is a common pattern to reregister i.e. when in a hurry so you end up with multiple ids. If you also have userids in addition to email addresses, it can easily become a hard problem in itself to solve/remember which email/pw corresponds to which userid. Obfuscating user/password error messages can make this much worse. Techies often forget what a messy world non-engineers live in. Isn’t NOT disclosing that security by obscurity? |
|