On why telling users if it is the username or password that is incorrect they say...
But after some further consideration, we decided that it
was a false risk, as the username reminder form already
tells you if a username exists, and is not a significant
security risk for the bajilions of sites that have them.
Oh, damn i didn't realize bajilions of sites do this and yet are so secure. Next time, a better response i hope: "but instead we decided allow for error differentiation while also increasing the controls on the number of failed logins allowed and alerts to security staff in such cases."
<pulls out brute force scripts>
PS. just never let anyone from marketing, design or management discuss your security publicly without review.
<pulls out brute force scripts>
PS. just never let anyone from marketing, design or management discuss your security publicly without review.