The article makes a good point, were it not for security auditors (SAs). SA: You leak information and therefore violate policy by disclosing on the login form whether an account exists or not! Me: Yeah, but figuring out if an account exists is really simple anyway: just a query to a different endpoint... SA: NEVERMIND, MY LAD: disclosing account existence upon login violates BEST PRACTICES! Me: OK, yeah, whatever, we…
To any SAs reading this: you're not secure because you're compliant.