Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How do you avoid 'leaking the user list' if you enforce unique usernames?


If you use email as username, you can make the sign up give the same "check your email to confirm your account" message for a new account and an existing account. This works well for new users and those who have already signed up but perhaps forgot, and leaks no information to someone who doesn't have access to that email account.

I'm not sure how to do this just for usernames, but usernames are less sensitive than emails anyway.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: