@phesslerEach individual user may not consider a given credential as worth needing MFA, but since most users reuse passwords, it's arguably better move for the ecosystem and site operators to require some kind of MFA. Otherwise, if one site gets popped, a wave of user accounts could be abused in bulk and require operator intervention. Whether or not mass lockout/reset is inconvenient enough for the individual user to think MFA is a good trade-off may vary.@munin