Comment 7 for bug 457371

Revision history for this message
root (n-root-psiphon-ca) wrote :

Replying to [comment:5]:

                Made it so reset works if either username or email is entered. Updated the prompts to be a bit more helpful (although there's no negative feedback for invalid email or username). It's still using the Reset combo box thing on the Login page, and the whole thing still needs to be redone properly.

                > Let's be very careful not to make this very important feature unusable in the name of fixing an email email probing vulnerability.... As it's designed, 90% of users will try to enter their usernames into this form. Are we still going to provide a sufficiently-informative error message that they won't keep doing the same thing? (See comments in [/ticket/86 Ticket #86]).