Having a domain under the .us TLD once seemed appealing to me for practical reasons: It's short, consistently inexpensive, and hasn't already sold the vast majority of its useful namespace to squatters. Unfortunately, it forbids WHOIS privacy services, which makes it a privacy and security hazard for personal domains. Pity, that.
From TFA: Will WHOIS requests leak my address? Nope. Even though you must supply your address in the registration form, a WHOIS request for your locality domain will only show information about the registrar.
I suppose it might be true for .city.state.us subdomains, but those fail my first criterion (they're not short), and are themselves a privacy hazard since they substantially narrow the search space for personal info about the domain owner. So it doesn't refute my criticism.