Does correcting a misspelled username and prompting the user with a valid username introduce a security risk?
I recently tried logging into facebook and misspelled my email. They prompted me with the message below.
Log in as {username}
{email}@gmail.com · Not You?
Please Confirm Password It looks like you entered a slight misspelling of your email or username. We've corrected it for you, but ask that you re-enter your password for added security.
I know usernames aren't really a secret but when a website fixes a misspelling to a correct one, they seem to be taking the 'not a secret' a little too far.