Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My solution for this is to use a unique email address for each site/ service. That way if I see that hn@mydomain.com has appeared in a breach, I know both where the leak came from and which password to change. Also helps identify the source of any spam emails...


You can also do this with Gmail by adding a . Or two randomly in your email.


Gmail and other MTAs support +something in the e-mail address user part too. If you forget your password, you do have to dig through your e-mail and figured out which one you used, but this method does let you track down when someone sells/shares your e-mail address or 3rd parties.


You just have to remember the exact username/email you used in case you forget it. That can include the sitename itself, or some simple transform, but sometimes services change names... so make sure to keep records of exactly the email used for each service (or don't delete your email from them), forgetting that is worse than losing the password, since there's often no helpful recovery service they offer.


The bigger problem is MANY MANY sites don't accept the (+) in an email address.


Yes. More and more sites are using common frameworks and/or validation libraries where a + is not considered to be an acceptable part of the recipient name.


this method does let you track down when someone sells/shares your e-mail address or 3rd parties.

Unless they strip out the +something part.


Based on my experience this unfortunately does occur, as does removal of dots in the local part.


spamgourmet.com is this idea as a free (and awesome) service.


Good idea




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: