The Case for Unique Email Addresses
musings.tychi.me
musings.tychi.me
Whoever with more than two brain cells would notice and strip the suffix out, but they usually don't bother with a database leak.
Just think about focusing on your primary point.
For anything I don't care about and want better anonymity, I'm fine with using random, public disposable email addresses.
Samsung is one I remember which wouldn't let me use samsung@domain.com, I managed to get by with smsung@domain.com. Definitely one for the password.
Then again, we should be using unique passwords for everything anyway, so a password manage is a must regardless of how you handle emails.
Otherwise my rule is to use the central part of the domain name (no www or TLD), or it's easy enough to just search my email archive for messages from whatever service.
Using keepassxc + its browser and mobile extensions make this easier than typing the address in myself. I was astounded at how bad the ux the paid pw mamagers I've used is
1) Companies that conveniently forget that you opted out of marketing emails every 9 months or so, now I can blacklist them.
2) Twice now has a service had a data breach and I've only found out because I've received spam to the unique email
When Adobe lost both my address and password I tried contacting their support (I was paying customer). The support person repeatedly said they checked and my credentials were safe. This regardless the fact I had proof. Very disappointing.
Since then I had couple other situations like that.
I guess companies assume users are idiots and use same password everywhere and so they feel safe nobody can prove it is them ho lost it.
I could do <servicename>@example.com to make things easier but this is less secure than <random>@example.com
This was very easy with Unix mail clients twenty years ago — what is wrong with Mail that it doesn't support this functionality?