4 ms·
Seems pretty limited to be honest - the usernames aren't going to be unique enough for anything where they have to be globally unique. Unless you include number
by mcjiggerlog 4y ago
Seems pretty limited to be honest - the usernames aren't going to be unique enough for anything where they have to be globally unique. Unless you include numbers on the end that is, but that's just ugly.
LastPass's username generator is much better: https://www.lastpass.com/username-generator https://www.lastpass.com/username-generator. With "lowercase" only and "Easy to say" turned on, the suggestions are really good. This is my go-to when I need a username, and that's as a Bitwarden user!
- AdmiralAsshat 4y agoHow useful is this, though, for just a username? I would think the purpose here would be that you would use unique aliases per service to limit your own risk in the event of a site breach. However, the vast majority of websites these days require a username and an email address. In which case, if I've got 50 unique usernames but they're all tied to a single email, how much am I really protecting myself if the email address gets included in the breach?
- bwbuhse 4y agoOne thing I do, which no clue how helpful it really is, is use a custom domain for my emails with support for catch-all addresses. When I sign up for a new site, I typically put my email as something like "<site-name>@<my-domain>.com". If my data were exposed, I guess someone who realized that could try any variation of the site's name to figure out the exact one in my address, but you could always do something more unique than that. Even something like generate a BitWarden password and use it as the user for the domain.
- mcjiggerlog 4y agoI also use random email aliases for my domain. The random username is because I don't want people to be able to search my username for a service and link me to other accounts online.
- amflare 4y agoIt's less a protection schema and more a canary schema. I use plus-addressing for basically every online account that I create that does not need to be professional in nature. The benefit is that if I start receiving emails from Foo.com sent to myemail+bar@example.com, I know that my bar.com account got compromised and I can do something about it to limit my exposure.
- antifa 4y agoI've found that a lot of websites don't like "+" or even intentionally detect it to reject it or subvert the user's interest. I think a good system would be a randomly generated handle like nick836742@example.com where my real email probably isn't nick@example.com, but the number is different for each service.
- woojoo666 4y agoOne very slight benefit I see is (better) standardization of username generation. If everybody has their own method of generating usernames (eg long string of numbers vs 2 random words), then it's possible to differentiate usernames based on the style. Now that generation is automated via lastpass or bitwarden, there are two standard styles and makes it harder to fingerprint users based on it
- slaymaker1907 4y agoI agree on uniqueness. I think you really want at least 40 bits of entropy (so no expected conflicts up until about a million usernames).