Any site that has a message like that... avoid them. They do not know enough about security. Granted, it may be a secure site, but they don't consider the privacy of their users. You can put somebody's email in there and a message like that lets them know they are a member.
When I create login failure messages, I provide one and only one message... something like "Login Failed." And I leave it at that. And any password recovery attempts will always go through, no matter what email address they use. first, I look up that email address before doing the password recovery, then send it if I find it, and ignore it if I don't. The only possible error I may show is if the email address was not a properly formatted email address. My generic message would be something like "Your password reset request has been handled."
Sorry, done geeking out. This is just one of my pet peeves.
New head of defense appointment, for you
Brilliant
Time to geek out...
Any site that has a message like that... avoid them. They do not know enough about security. Granted, it may be a secure site, but they don't consider the privacy of their users. You can put somebody's email in there and a message like that lets them know they are a member.
When I create login failure messages, I provide one and only one message... something like "Login Failed." And I leave it at that. And any password recovery attempts will always go through, no matter what email address they use. first, I look up that email address before doing the password recovery, then send it if I find it, and ignore it if I don't. The only possible error I may show is if the email address was not a properly formatted email address. My generic message would be something like "Your password reset request has been handled."
Sorry, done geeking out. This is just one of my pet peeves.
Great Pedes think alike. KEK