Point is people have to choose a password and supply an email (for the company to spam) just to comment on a news article or submit a bug report. Of course passwords are reused for all that type of website.
2FA is a PITA when you don't even care if your account is hacked.
If money or reputation is concerned people take more care.
It is trivial to set a long random cookie on a machine that provides 2FA for all repeated use of a service until the user deletes tokens or changes device. No need for bad UX.
It is trivial to set a long random cookie on a machine that provides 2FA for all repeated use of a service until the user deletes tokens or changes device. No need for bad UX.