https://github.com/topics/username-search
I use different usernames per-site, but I tend to take a couple seconds to think of something (hopefully) clever.
https://github.com/topics/username-search
I use different usernames per-site, but I tend to take a couple seconds to think of something (hopefully) clever.
Do you also use a different email address on each site, or do all the unique usernames ultimately link back to one email?
I think an important distinction is that the email address is often private. My HN account and my reddit account may have the same email address, but Reddit and HN would need to coordinate to figure that out. If they both sell user data, or suffer database breaches, get subpoenas, then a third party could link the accounts. For sites that support username search by email address or treat email address as public data, yeah, that's exposed.
For usernames: a series of HTTP GETs can find likely examples of username reuse:
* news.ycombinator.com/user?id=$username
* reddit.com/u/$username
* twitter.com/$username
This is cheap, easy, scalable, has automated tooling, etc. So I worry enough to pick a new username, and let my password manager remember it.
Many services today use emails as their userid, and even often the login username (account display name being separate), so I think it's probably more common for attackers to match passwords with common emails rather than common usernames. But they can & will still do both, so the unique username certainly has some use.
(it also helps a lot with tracing who's sold your data to a spammer)
> Distinct emails is just defense in-depth. > (it also helps a lot with tracing who's sold your data to a spammer)
Not only that, if when you first sign up with BigCo you give them your email address as bigco@example.com then when one eventually stops dealing with BigCo one be certain that all email addressed to bigco@example.com can be rejected at your email server without a second thought, no need to scan for spam, just reject everything addressed to that alias.
A good friend of mine takes this a step further and does it through DNS (which of course he self-hosts as well as his mail server). He would give his email to BigCo as firstname@bigco.example.com. Once he's done with BigCo then he removes the records for bigco.example.com and there's no way to even look up a relevant mailserver to send email to firstname@bigco.example.com!
I do wish this was easy and automated.
You can reply from all addresses described above. The FF extension makes pre-registration of random addresses a little easier by putting a button on e-mail form fields.
There isn't convenient integration with password managers, that I know of.
You could be de-anonymised. Particularly by correlating your sign-ups using your-own-subdomain.mozmail.com. Or if the service is hacked. There's some argument that makes this service harder to generate spam with, and therefore less likely to be blocked. That's yet to be seen, I suppose.
Fastmail also offers this service, so I think it's becoming a popular enough idea that password managers may start to see value in introducing it. Hopefully...
Looks like we’re getting really close.
It is, on MacOS and iOS. HideMyEmail works for normals, and Sign-in w/ Apple defaults it on.
Approaches for randomly generated usernames are probably the best way to go. DDG's @duck.com email service (and similar) is pretty fantastic if you're forced to use an email.
Good?: product1@sebastianmiller.ismyrealname product2@sebastianmiller.ismyrealname