Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It is certainly the case that there is a privacy issue here. However, that doesn't substantially undermine the strongest point presented in the article - that the email is already exposed, usually by refusing to create a new account if one exists with that email and it's sometimes also reported when you ask for a password reset email.

I agree with you that the thing to do is fix those issues, though, rather than abandon it here as well.



I think that could also be solved relatively easily. Just flash that you are sending an account activation email to the person trying to create an account and email the already registered user with a notification that someone tried to sign up with their email address.


I agree, neither issue is intractable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: