This is the reason why attempting to sign up for an existing account generally fails right away, at least for online retailers.
This is the reason why attempting to sign up for an existing account generally fails right away, at least for online retailers.
I am only speaking to the typical signup flow that anyone can access signed out without putting in any information besides email/pw. If you are in a purchase flow where valid credit card info is already entered and is going to result in actual purchase $$, you've already excluded bots/hackers who would be trying to brute force account enumeration. It would be totally fine to confirm the existence of an account in a web form in this situation as it is not a flow that can be easily brute forced for free with little effort or info needed (like a credit card).
> vendors want
If security is not a priority for the vendor, then yes. Otherwise, no, the order will not go through anyway.
I'm very aware that in many many cases, the former is true in the real world, but that doesn't change the fact. This isn't a good justification for the op's dismissal of the practice.