# Different password reset for wrong username/email

**URL:** https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909
**Category:** Feature
**Created:** [May 23, 2014, 2:16pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909 "2014-05-23T14:16:30Z")
**Posts on this page:** 20
**Page:** 3

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [March 16, 2015, 11:35pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/41 "2015-03-16T23:35:59Z")

</div>

> [@dustinmoris](#):
>
> Anyway, I wanted to raise awareness of this problem, but after all it is your product and you choose if you target only a specific audience or if you want to make it most usable for everyone.

Make sure you also tell Tumblr, Facebook, and Twitter about their vulnerability too. 😉

---

<div class="post-metadata">

### Author: ![supermathie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/supermathie/32/507518_2.png) [@supermathie](https://meta.discourse.org/u/supermathie)
#### Post date: [March 17, 2015, 2:45am UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/42 "2015-03-17T02:45:41Z")

</div>

> [@dustinmoris](#):
>
> Look, I don’t think there is a golden solution for everyone. Every product is different and requirements might be different.

Exactly why we have the option in site settings. It’s quite reasonable to expect a site administrator to review login settings.

Also, the default isn’t an exposure. All it says is that _someone_ created an account with that email. It could be an unverified, never-logged in email.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [March 17, 2015, 2:49am UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/43 "2015-03-17T02:49:44Z")

</div>

My point here is very simple, show me one popular website on the entire Internet that follows a strict no-emails-can-ever-be-disclosed policy.

---

<div class="post-metadata">

### Author: ![Mittineague](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mittineague/32/114259_2.png) [@Mittineague](https://meta.discourse.org/u/Mittineague)
#### Post date: [March 17, 2015, 2:57am UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/44 "2015-03-17T02:57:51Z")

</div>

Years ago I missed a renewal payment to my site host.

When I tried to login to the ACP I got an  
“Invalid Login” message.

I carefully checked my spelling and case but several repeat attempts continued to fail.

Much confused I eventually called support and was told the reason was because of a lapse in payment.  
It didn’t make sense to me at the time how this could be considered an invalid login.  
But after thinking about it, it kinda sorta did.

IMHO I would prefer a generic non-specific message, but as long as there is a configurable option I don’t see there being a problem for like minded Admins.

---

<div class="post-metadata">

### Author: ![elberet](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elberet/32/122404_2.png) [@elberet](https://meta.discourse.org/u/elberet)
#### Post date: [March 17, 2015, 12:02pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/45 "2015-03-17T12:02:14Z")

</div>

Wasn’t Discourse’s mission statement to not follow the trodden path and finding better ways to do things? 😁

_Anyhow…_

@dustinmoris raises a valid issue, but it’s based on the assumption that Discourse will be used heavily on sites where merely exposing the fact that you are a member is a critical privacy concern. Such sites do exist without a doubt, but they are a minority and perhaps Discourse just isn’t the right platform for them – _yet_.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [March 18, 2015, 4:50am UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/46 "2015-03-18T04:50:08Z")

</div>

My point here is that this setting has nothing much to do with the root problem that there is email disclosure when you register accounts. Nobody ever complained about this before and its a very common practice. In fact it is so common I have never seen a modern website that does not have this “vulnerability”

The behavior of “silently” allowing people to register accounts with incorrect/already registered emails and just doing nothing at the end of the process is odd and not something that should be a default.

For the super privacy conscious there are already 3 super common solutions

1. Don’t give third party sites your email address, use throw away accounts
2. Use gmail + addressing eg: [sam.saffron+someguid@gmail.com](mailto:sam.saffron+someguid@gmail.com)
3. Site operators can implement SSO and use whatever crazy auth system they want
4. If someone wants to work through a “enable\_tin\_foil\_hat” site setting I am open to it, but the core team are not going to work on this until a paying customer asks for it

---

<div class="post-metadata">

### Author: ![elberet](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elberet/32/122404_2.png) [@elberet](https://meta.discourse.org/u/elberet)
#### Post date: [March 18, 2015, 5:12am UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/47 "2015-03-18T05:12:39Z")

</div>

Oh I think you got that point across quite well, but the whole discussion here got _ **super** _ intense super quickly, and we’re suddenly spending more time on bickering than on thinking about if and how something useful could come from all this. And that’s a shame. 😄

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [March 18, 2015, 5:33am UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/48 "2015-03-18T05:33:58Z")

</div>

It got intense cause a brand new user told us we are “narrow minded” and “discriminatory”

Then the same new user said that site settings do not matter cause “no one will ever user it”

It just struck a huge nerve with me and made me super upset.

I felt like a condensending disappointed adult decended upon us to teach us the errors of our way. We agonized quite a lot about these defaults you know.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [March 19, 2015, 11:17pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/49 "2015-03-19T23:17:57Z")

</div>

> [@supermathie](#):
>
> All it says is that someone created an account with that email. It could be an unverified, never-logged in email.

Not quite, we deleted unverified accounts after 7 days.

I don’t think anything useful can come of a “no email shall ever be disclosed, even upon account signup” discussion @elberet. I mean, can you really point to _any_ other site on the Internet that works this way??

---

<div class="post-metadata">

### Author: ![elberet](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elberet/32/122404_2.png) [@elberet](https://meta.discourse.org/u/elberet)
#### Post date: [March 19, 2015, 11:35pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/50 "2015-03-19T23:35:37Z")

</div>

Off the top of my head? Nope. But I’ve read some news the other day about an open source project that’s intended to drive whistleblower sites… I didn’t check it out (or read past the article’s blurb), but not disclosing the users’ email addresses might be a pretty big deal there.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [March 19, 2015, 11:48pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/51 "2015-03-19T23:48:20Z")

</div>

I am fine with adding a mode like this, but someone else is going to have to work on it, it would actually be nice to get rid of `forgot password strict` and replace with an encompassing term that defines a “email never disclosed but registrations can be a bit of a pain in the ass” mode.

---

<div class="post-metadata">

### Author: ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)
#### Post date: [June 29, 2017, 3:29pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/52 "2017-06-29T15:29:04Z")

</div>

> [@sam](#):
>
> We aleady do something similar, point being, letting people go through the entire registration system without revealing they already have an account is insane and something I have never seen in the wild.

Me neither, until now. I just signed up (again, by accident) at Hipchat, and instead of the confirmation email they promised, I got this:

> Hi \*\*\*\*\*,
> 
> It looks like you’ve tried to create an Atlassian account for \*\*\*\*\* @ \*\*\*\*\*.  
> However, an account for that email address already exists.
> 
> You can reset your password if you’ve forgotten it.  
> If you didn’t try to create an account for \*\*\*\*\* @ \*\*\*\*\*, don’t worry - we haven’t done anything, and you can safely ignore this message.  
> Feel free to contact us if you’ve got any questions.
> 
> Cheers,  
> The Atlassians

This would be a pretty neat feature for Discourse if you ask me!

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [June 29, 2017, 7:55pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/53 "2017-06-29T19:55:27Z")

</div>

Er.. what? That feature already exists

 ![](https://global.discourse-cdn.com/meta/original/3X/1/c/1cffb845971bb06eca2ffb16a007e3a289de4064.png)

We could make this a bit easier by jumping them over to “reset password” at that point, I guess, but feels like a bit of a micro-optimization cc @neil

---

<div class="post-metadata">

### Author: ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)
#### Post date: [June 29, 2017, 8:36pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/54 "2017-06-29T20:36:51Z")

</div>

No..?. this is the opposite… it’s about never saying “email has been taken” and instead making it impossible to misuse the sign up process to see if there is an account using a specific e-mail address. Atlassian only discloses that in the “confirmation” email that is sent, not in the web interface.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [June 29, 2017, 8:39pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/55 "2017-06-29T20:39:14Z")

</div>

I see, so the disclosure is only via email, not in the UI. Well, there is an existing site setting to disable the UI disclosure, of course, and that’s _off by default_ … but there is no direct email response handling.

It seems to me the direct email only makes sense in the context of zero UI disclosure, though. Which is not our default.

---

<div class="post-metadata">

### Author: ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)
#### Post date: [June 29, 2017, 8:55pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/56 "2017-06-29T20:55:31Z")

</div>

Which site setting is that? I thought there only is one for the forgot password dialog, but that the sign up process would always disclose if an email address is being used already.

---

<div class="post-metadata">

### Author: ![neil](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neil/32/102150_2.png) [@neil](https://meta.discourse.org/u/neil)
#### Post date: [June 29, 2017, 9:16pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/57 "2017-06-29T21:16:24Z")

</div>

You’re right @michaeld that we don’t have a setting to hide “Email has already been taken”. I like what Hipchat does.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [June 29, 2017, 9:25pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/58 "2017-06-29T21:25:20Z")

</div>

Hmm, no, we do have this setting `forgot password strict` and have had it for a long while

 ![](https://global.discourse-cdn.com/meta/original/3X/6/d/6d6f735083cbb2109dce84a47870c72f33af6417.png)

I guess we could enhance it to also work that way on account creation, but I _don’t_ want to add another setting..

---

<div class="post-metadata">

### Author: ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)
#### Post date: [June 29, 2017, 9:54pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/59 "2017-06-29T21:54:01Z")

</div>

> [@codinghorror](#):
>
> but I don’t want to add another setting…

How about using the existing one for both the forgot password and signup processes, and eventually renaming it to “do not disclose email addresses in use” ?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [September 27, 2017, 9:57pm UTC](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909/60 "2017-09-27T21:57:46Z")

</div>

> [@codinghorror](#):
>
> we could enhance it to also work that way on account creation

@neil this one should be unified so we get coverage in both places.

[Previous page](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909.md?page=2)

[Next page](https://meta.discourse.org/t/different-password-reset-for-wrong-username-email/15909.md?page=4)
