# Email enumeration vulnerability on "Password Reset" dialogue

**URL:** https://meta.discourse.org/t/email-enumeration-vulnerability-on-password-reset-dialogue/273449
**Category:** UX
**Created:** [August 1, 2023, 7:37am UTC](https://meta.discourse.org/t/email-enumeration-vulnerability-on-password-reset-dialogue/273449 "2023-08-01T07:37:41Z")
**Posts on this page:** 1
**Showing post:** 22

<div class="post-metadata">

### Author: ![Moin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/moin/32/554653_2.png) [@Moin](https://meta.discourse.org/u/Moin)
#### Post date: [December 19, 2024, 11:19am UTC](https://meta.discourse.org/t/email-enumeration-vulnerability-on-password-reset-dialogue/273449/22 "2024-12-19T11:19:05Z")

</div>

> [@Hiding "e-mail taken" on sign-up by default](https://meta.discourse.org/t/hiding-e-mail-taken-on-sign-up-by-default/342599/1):
>
> Background Under the current default settings, when signing up for an account with an e-mail that has already been registered, the sign-up form will inform of that: We are changing the default setting to not give away this information. Instead, the sign-up form will look like this, regardless of whether the e-mail is already registered or not: This also affects password resets in similar ways. With the setting di…

---

_[View the full topic](https://meta.discourse.org/t/email-enumeration-vulnerability-on-password-reset-dialogue/273449)._
