Not air tight, not truly “OpSec,” but people do call me crazy for having a separate e-mail for every service. This has caught three leaks so far–if you receive spam you immediately know which service got pwned. If that happens I delete the e-mail and move on. Takes some effort, but is worth it in my opinion.
It can be handy to do this if you have a custom domain for your email and allow for wildcard addresses…
Not mine, but typically some corporations and government agencies block USB ports or have devices that record everything going through those ports.
What is your definition of "Operation" because my threat-model is probably not your threat model.
But in the past, not doing crimes, gave crazy good results.
I guess if you care about being security you are a fed now? I smell alphabet soup.