I think I'll trust owasp and my own over 20 years of experience building commercial software but you do you
v_krishna
joined 2 years ago
This generally goes against security best practices as it can be used for attempted user enumeration. A better version would be "we'll send you an email with your account status if this user exists" but obviously that results in a fair amount more complexity (and cost) to implement
What kind of odd take is this. I agree Barbara Lee won't accomplish much in an interim mayor seat but she's mostly beyond reproach and definitely speaks for me!