Registration

When someone attempts to register an email address, do not give the web client user any feedback about whether or not the account is registered. Instead, send an email to the address and simply give the web user a message saying, "An email has been sent to the address provided."

If they have never registered, everything is normal. If they are already registered, the web user does not get informed that the email is already registered. Instead, an email is sent to the user's address informing them that the email is already registered. This will remind them they have an account already and they can use the password reset tool, or let them know something is suspicious and someone may be doing something malicious.

Be careful that ...

Get Security with Go now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.