Sort:  

Yes, you're right that was a brain-fart. We do ask for your phone number. My assumption is that the engineers determined that the costs of requiring that every user enable 2FA before being able to get an account (in terms of increasing barriers to entry and adding an extra step to the sign up process) outweigh the costs. Most people want us to be decreasing the friction in the sign up process not increasing it. But thanks for your feedback.

This might be an opportune time to examine the results of that decision, as but ~11% of accounts opened in 2016 - including bots - remain active.

Most people have been leaving. I'll take fewer signups, in exchange for a better retention rate, if that's the cost.