Quantcast
Viewing all articles
Browse latest Browse all 4

Answer by Oded for Why does the Stack Overflow login form tell you whether a specific login exists or not?

As others in the comments said - Stack Overflow isn't a bank. We don't need to have the kind of security that a bank does.

Additionally (also mentioned in comments), there is a trade off between making something secure and making it easy to use.

In this case, we have chosen on the side of usability. In the worst case, we are leaking that someone is using the Stack Exchange network with that email address.


Viewing all articles
Browse latest Browse all 4

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>