I'd add using unique email addresses to that as well.
And FFS web-based business, if you don't absolutely *need* people to create an account to make a one-off purchase from you, don't bloody well force them to.
Here's your semi-regular reminder to NOT REUSE PASSWORDS and to USE A PASSWORD MANAGER so that changing passwords is easier for you.