Your comments

It is basic opsec to not disclose if an attempted authentication attempt has a correct username on a platform such as this. 


This should be treated as a bug not a feature request.