Hacker News new | past | comments | ask | show | jobs | submit login

But don't you leak the same information during registration? What happens when a user tries to sign up with an already existing email address? Don't you return an error saying that email has already been used?



You could just email them a link to finalize registration. If it has already been used include that information in the email.


This actually argues in favor of only using social logins, which would not leak any clues about other users of the site.


Oh, I wasn't arguing either way. Personally I prefer social login, but I have no strong conviction either way.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: