couldn't they do something like the email address is yourusernameatyourdomain.comandanextrabityoutset@posterous.com which would be an id you could remember?
or both... assign a random GUID, and then allow the user to set it something they want if they choose. That's probably the simplest way, and of course the simpler the better for both development and security.