Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Even simpler than trying to sign up for a new account, many sites will tell you if you enter an unregistered email on their "forgot password" page.


Except that entering a registered email will likely result in the legitimate user receiving a password reset email that they did not request, thus immediately raising suspicions that someone may be attempting to access their account. Using the signup form is a much better approach.


Some sites don't. They instead say "if an account with that email address exists we've sent you an email with the reset link". That seems like a nice touch, but it's pointless if you can still find out that a given email address is a registered user in some other way (such as by trying to sign up with it). So it's just another variant of the "invalid username/password" message.


Yes, but that also alerts any valid account with an unexpected password reset.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: