I think using email address as the login ID helps hackers. Once they get an email address and reused password combination, they can go searching for places where that combination is good.
On sites where I can, I select a unique username that adds another layer someone would have to guess. In combination with 2-part authentication and strong passwords, it should stop all but the most determined and sophisticated scumbags.
On sites where I can, I select a unique username that adds another layer someone would have to guess. In combination with 2-part authentication and strong passwords, it should stop all but the most determined and sophisticated scumbags.