Earlier quoted context omitted.
This is a real attack vector. It's called a timing attack: http://en.wikipedia.org/wiki/Timing_attack
I am familiar with timing attacks. The thought of someone attempting to apply it over the internet to verify whether an email is registered on a dating site seems laughable.
I assume that was the original point - that on risque dating sites, the recover password system tries to hide membership.