January 2018
Intermediate to advanced
340 pages
8h 6m
English
Do not give the web user feedback about whether or not an email exists. You do not want someone to be able to try logging in with an email address and learn whether or not that address has an account just by the error message returned. For example, an attack could attempt to log in using a list of email addresses, and if the web server returns, "That password does not match," for some emails and "That email is not registered," for other emails, they can determine which emails are registered with your service.
Read now
Unlock full access