Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think the solution is pretty simple... just be transparent and say for security reasons you can't reveal whether or not the user exists.


Yes, just saying this should be sufficient - "If your email address is our database, you would shortly receive an email to reset your password".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: