Point being be careful with your error messages they might give away your users anonymity.
Point being be careful with your error messages they might give away your users anonymity.
Thank to your twisted mind :p
Thats why I love HN you always find your way around ;)
The less data you give to users about state that isn't necessarily theirs, the better.
Maybe HN can work out a good solution collectively? I can only think of a secondary authentication piece, but then that's also possible to be forgotten.
It doesn't really solve the problem of figuring out which email address you used to create your account, but it allows you to provide feedback to the user that the account does/does not exist.
An alternative solution would be to just email whatever account you enter on the website, with the appropriate wording depending whether or not they have an existing account, but this approach seems like it'd be too easy to spam random people.
Though, I'm not sure if you can get e-mail from these, and making the users enter their e-mail after login would degrade the user experience.
If someone wants to reset their password, after they enter their email address say "Thanks. If that email address is in our database we will send a reset link."
Coincidentally, this is why I have a separate email address for any site that anyone may look down upon. Figuring out what sort of services you sign up for online is usually as trivial as trying to sign up a new account with your email address.
This is also why if my site enforces 1 user per email address, I make sure I do that check only if all other information is valid. In comparison, most sites let you enter a bunch of invalid information but a valid email address and will happily let you know that person already has an account. If you have to enter fully valid information, theres some risk you will sign the user up and let them know someone is using their email address for things.