I'm working on a Drupal site where the organisations compliance department require that Drupal displays the same error message on the password reset form whether the username/email address exists or not. By default the error appears to be different depending on if the user exists, doesn't exist, is blocked etc, and it's being argued that this helps hackers determine valid usernames.
Is there a way to do this?