Spot on with my own observations. My one addendum is that if you do make your email and/or phone available (even in odd places like whois records) that you seriously handle the security implications in regards to hacking vectors. Here is an example: https://ello.co/gb/post/knOWk-qeTqfSpJ6f8-arCQ
Simple measures will possibly save your butt if a serious attempt was made: Do not to answer security question fields truthfully, instead use long, random, high-entropy strings. Do not use text based 2FA, when app 2FA is available. Do not use text based 2FA as a backup to app based 2FA (e.g. Google). Etc.