You could provide the correct password to your account 'test', but not 'ttest'.
The server just tells you to check both instead, it's more semantically correct and offers some security improvements with user enumeration.
Imagine both 'dave' and 'davr' have an account. I'm 'dave', but I accidentally type 'davr' and my correct password. Now the site will tell me that my password is wrong. So I retype and retype my password over and over again and still can't log in, because the problem isn't the password like the error message says, but rather that I typed the wrong my username.
Of course the person may have multiple user accounts and he may have given the "wrong" password for the "right" username account, but he may also have given the "right" password for the "wrong" username.
For a rarely used web site, I honestly would have no idea if I registered as bonzini, pbonzini or bonzinip. Now my surname isn't particularly common, but smithj and jsmith might be easily confused.
It is absolutely common for users to supply the incorrect username/email.
Not accusing you BTW.
> To prevent attackers from knowing whether an account exists or not your signup must only take an email address and provide no feedback in the UI if the sign up succeeded or not. Instead the user would receive an email saying they’re signed up. The only way an attacker would know if an account exists is if they had access to the target’s email.
> Barring that, “username or password incorrect” is just bullshit.
What he means is the only way it would make sense is if and only if a website's account registration page responding with something like:
"You tried to sign up for me@example.com. If that account didn't already exist, a registration email has been sent to it."
But nobody does that! Registration pages just say "Sorry that email is already in use", which is what makes this whole thing bullshit.