@ryanc doesn't that depend on the attack scenario? my main worry is that my user profile ends up in one the tracking databases of commercial surveillance merchants. they are not going to put up a post-it that someone with an unusual fingerprint may just be me and to double-check for non-changing attributes, but create a new profile because that's way cheaper and good enough for their main use-case