Join Slack
Powered by
when starting a recovery flow, is it possible to h...
# talk-kratos
d
dazzling-napkin-4938
06/08/2023, 12:57 AM
when starting a recovery flow, is it possible to have kratos show an error in the UI if the email address entered does not exist? Rather than configuring ory to send an email that recovery was attempted but the account doesn’t exist
b
billowy-soccer-77917
06/08/2023, 3:25 AM
My understanding is that this isn’t possible because it opens up account enumeration attacks. The
documentation
links to a blog post by Troy Hunt that describes the attack:
https://www.troyhunt.com/website-enumeration-insanity-how-our-personal-data-is-leaked/
d
dazzling-napkin-4938
06/08/2023, 4:31 AM
yeah that’s what I had assumed, thanks
Open in Slack
Previous
Next