In your “What can I do” section, should add: “do not add google/apple/facebook(meta)/github sign on in the first place” Not only are we centralizing identity to entities known to shutdown accounts for vague reasons. It can introduce painful debugging issues, increased support costs, and loss of sales. Personally, dealt with an issue where a user signed up with “Sign in with Apple” but forgot whether they provided App…
As a developer I can sympathize having dealt with frustration implementing SSO but as a user (and I'm aware I may be in the minority on HN) I've bailed out of trying quite a few webapps that don't offer Sign in With Google or Sign in With Apple. There is a psychological effect where I dread the image of whatever half broken bespoke registration flow or inane password requirements someone came up with when I only see…
All the privacy of throwaway email addresses with strong passwords. Services can store passwords in plaintext and use public blockchains as databases for all I care.
Figuring our which service leaked my email and blocking all messages from it is one click away.