Earlier quoted context omitted.
Is there no longer a panic over letting an attacker know that an account does exist? I remember that being a thing for a while, but haven’t built user facing UI systems in a few years.
I haven't heard an update on that front for many years, so I'd assume it should still be a concern. Many of the same sites that do this will also have a recovery form that refuses to leak information.
[1] by “funny” I mean not funny