I can live with 2-factor to email addresses. Less secure than phones, but better than nothing.
BTW, I think that the sign-on username should not be the Freeper name.
Meaning, I much prefer using a password generator to create each of:
- account username
- account password
Thus, both of those, are known only to the account holder.
Strong password requirement would probably be easiest to implement. Also maybe require new password if you haven’t logged in for more than a year or something.
Not sure how hard it is to make a magic link to a reset password page but that would solve the password emailed as plain text.