Why can I log in to my Facebook account with a misspelled email/password?
security.stackexchange.com
security.stackexchange.com
how much do you trust facebook?
The top answer links https://www.youtube.com/watch?v=7dPRFoKteIU&feature=youtu.be..., which explains exactly what they do: try a number of different errors client-side.
They just hash common variations of the password (e.g. missing the last letter) to make it easier to login. Is that a good usability/security trade off? I think so but that's more debatable.