We've, um, changed our password policy, says CafePress amid reports of 23m pwned accounts



While it doesn't allow for two-way communication, if you're signing up for a website mainly to get one-way newsletters, promos, etc., I use abine's email alias service (Blur). If I start getting dodgy emails from a site that I registered on with the alias, I simply turn that alias off. Any further spam to that address bounces back to the sender. You can then delete that alias completely. Problem solved. And it's free.

Second idea: if you're signing up for a commercial site and not actively engaging in buying from them, don't put in all your info unless it's required. And you could always put in bogus info (fight fire with fire). If and when you're ready to purchase something, change to your real info, order your merch, and then revert to the bogus info. Change password, too.

Yeah, sites should be more careful, but so should consumers.

