Improve customer privacy by not indicating if email is associated with account
-
Hello all!
I am hoping to find the a reasonable way to help protect our customers privacy a bit more. I don’t like that someone can put any email address into our forgot password page and figure out if that email address has an account.
Right now, if you enter an email address that isn’t valid you get an error message “Invalid username or email.” Ideally, I’d like a new message to be “If this email address has an account with us a reset password will be sent”. This message should appear for inputted email accounts that do and do not have an account with us.
I was a bit shocked that there isn’t more documentation on this so I am worried I might just not be searching with the correct key words. If so, some kind direction would be appreciated!
The page I need help with: [log in to see the link]
- The topic ‘Improve customer privacy by not indicating if email is associated with account’ is closed to new replies.