Hacker News new | ask | show | jobs
Why forgotten password forms shouldn't tell you when the email doesn't exist (busted-app.herokuapp.com)
1 points by bartj3 4599 days ago
1 comments

Indeed.

Imagine a similar page to this that searched a whole bunch of NSFW sites doing the same trick - and then a site that feed your whole address book through them.

Imagine HR depts routinely feeding applicant's emails into such a system.

Hard to imagine that someone isn't already doing this sort of thing...