Preventing Generation of Verbatim Memorization in Language Models Gives a False Sense of Privacy