I used to get the Facebook phishing messages to my e-mail, so created a Facebook account with a new e-mail address which is separate from my real e-mail address, therefore I won't have to open any malware.
The same goes for Twitter, I get direct messages for strange links, but I never click on them due to the fact of the shorthand my friends wouldn't use and that some of the messages are from people who have got the 'Twitter Egg' as their profile picture; it's by default for anyone who didn't know or use Twitter.
My Twitter account also uses a separate e-mail address for the same reason.