It's all too much for me to keep track of, but for some people it's no big deal to create new e-mail addresses every month.
Obviously it never works, as I get the "I see you're trying to create a new account" email, but one of these days he's going to figure out a way to take over one of those accounts and then I'll really be fked.
(1.) What are you imagining is the attack vector exactly?
(2.) Are you asserting that all website owners should build to Google’s (non-standard) behavior?
Can me and my wife both sign up to HN and use my email but hers be josh+swife@joshmanders.com and mine be josh@joshmanders.com?
That's a strange usecase, isn't it?
Having said that, in development, it's super nice to be able to create addresses with +'s in them.
On top of that, it's just as easy to set up a catchall email address -- an email box that accepts all mail for a domain, literally anything@mydomain.com. So a malicious actor could sidestep this security attempt with minimal effort, but it still inconveniences legitimate users despite being worthless from a security perspective.
It's just as easy to write a script to use ephemeral hosts that you don't need to sign up for. Things like Mailinator.
All it does is irritate people like me who use +words as prefilters for email (and to see which companies are selling my email/user data).