Could this be used to perform some sort of distillation or exploit? e.g. reminds me of the OWASP guideline on attack vectors where knowing if an ID is present or not in the database can be a form of exploit, like in password resets where they will say 'email [email protected] not found' rather than 'If foo@bar exists we have sent an email to foo@bar' or some other generic equivalent