[Action Advised] Enable email enumeration protection on all of your Firebase projects
...
| ||
We're writing to let you know that to increase the default protection against email enumeration attacks, all new projects created after September 15, 2023 will now have email enumeration protection enabled. Additionally, we recommend you to enable email enumeration protection on your existing projects as soon as possible. What do you need to know? Email enumeration is a type of brute-force attack in which a malicious actor attempts to guess or confirm users in a system by passing an email address to the API and checking the response. Starting September 15, 2023, we've enabled email enumeration protection on all new projects. Existing projects were unchanged, but it is recommended that you enable this protection on all existing projects to protect your apps against credential stuffing attacks. What do I need to do? We highly recommend enabling email enumeration protection on all your projects after testing with your app. If you currently utilize A full list of affected flows is also available for review. Additionally, FirebaseUI libraries first run One or more of your projects have Firebase Auth or Google Cloud Identity Platform enabled. We're here to help If you have any additional questions, please look through our documentation center. Thanks, Micah on behalf of the Firebase team | ||
You have received this mandatory service announcement to update you about important changes to Firebase or your account. | ||
|