Login in Security Username and Password
I noticed when attempting to login in to my Twitch account with the wrong password an error message stating "That password was incorrect. Please try again" appears. Also, in the case where there is no existing username the page displays, "This username does not exist." This is bad! Never do this! When the username or password is incorrect the page should display "Username or Password was incorrect. Please try again" or something to the same extent. The reason why the to warning should never be separate is a security issue. If an attacker were to try to get into someone's account, the error messages already gives the attacker more information then they should have. Please fix this as soon as possible, thank you!
You are right, but there is a quick workaround, unless I dont know about a anonymous function. They can just search for the account with twitch.com/username - one or the other way they will find out if there is an account with this particular name