“username or password incorrect” is bullshit
medium.com
medium.com
It is even worse when you are developing the client or trying to access a new server.
It could be a wrong user name. Or I should have used my email instead of the user name or the other way around. or the password or it could be that the account is expired or an expired certificate or maybe some negotiation of encryption codecs failed or an URL is wrong. or maybe the server-side DB was down. once it turned out to be a REST API that stopped accepting single-quoted strings generated by a client.
Then you click the "I forgot my password button" and nothing happens. You do not know if an email was sent. Or if an email was sent, to which email address is was sent. Or if it was stopped by a spam filter.
If there were targeted attack against a person sure, but IMHO this protects against simple brute force attack on the login page where the script just cycles through logins, finds a valid login, and then cycles through common passwords.
If the argument is that the attack scripts can also run against the registration page to correlate login, sure, but you've just made the life harder for the attacker.
1. Make the signup look like it was successful.
2. Tell the user to check their email.
3. If the account already exists, send an optional password reset email to the account owner (tailored to explain what happened if you prefer, throttled to prevent spam/abuse as you see fit).
4. If you want to go the extra mile, check for password reuse and make the password reset mandatory, or at least strongly encourage it in the email.
Obviously this is less convenient and arguably not a critical vulnerability for GitHub. The good news is, the registration page doesn't disclose which account an email address is associated with.
Well I guess they can figure that one out by signing up with my email. Cause when you do that websites tend to complain(I think).
But given my previous statement I guess I think that would be the flaw if anything should be seen as a flaw.
Even a registration form should not inform you that the email is already used. This information could be given ... by sending a mail.
While disclosure of the existence of an account with your email have minimal impact on Stripe or GitHub, what about a dating site ? What about a politic website ? How about some sensible professional tool ?
What if the user typed a wrong username that matches another existing user?
What you suggest shouldn't be possible because:
- multiple users can have the same password
- properly hashed passwords rely on per-user/per-hash random seed, which can be only determined after user is found in the database
just tell me which one is wrong dammit!!