Quoted from robin:I create a quick first version today of a more secure login. This first version works by sending a one-time login code to your registered e-mail address. This is not entirely secure of course (and not really 2-factor) but it would have stopped that scammer today and is also the simplest and cheapest solution to implement. It also doesn't require Pinside asking for your phone number. That said, I'm still planning a real two factor option (sms or google authenticator/authy) for people who want their accounts really secure. Remember, getting your account broken into is also bad for your own rep!
I'm considering this added security to be mandatory for everybody. It would only appear when logging in from a new IP address OR when logging in after a
Sounds pragmatic, effective and easy to use. Ship it