Other than that: yeah, I've generated and set some very long (40-80+ chars) passwords which I've promptly deleted from my own records on occasion. I don't think I've swapped out email addresses though that's an option. I could see that resulting in an account being hijacked though, depending on how email addresses are handled in the account-recovery flow.