Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While that's true. If the email is wrong, password reset isn't going to work for them anyways right? So may as well fix it for the majority of users who do know their email and typed it correctly but forgot their password. Usually even a "sorry that email address is not found" message is frowned upon in terms of security.

Also if you're app is sending reset passwords emails to emails that don't exist, that's a bigger issue.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: