I just accidentally used my Logos password on feedback.faithlife.com, which seems to use an external system. So I changed my Logos password after that, and I found that there's no choice of multi-factor authentication there, hence the suggestion here.
Older threads on the topic:
- 2014: https://community.logos.com/forums/t/87601.aspx
- 2017: https://community.logos.com/forums/t/154701.aspx
So it seems appropriate to suggest again after another 3 years.
In those threads other issues are mentioned such as at rest encryption. But let's focus on multi-factor authentication only here.
Reasons are
1. Without Multi-factor authentication, once your password is known it is game over. And less-than-optimal practice by majority of users such as password reuse, coupled with other companies' security breaches make it very likely a pair of email and password is leaked somewhere and could be used to log into someone's Logos account. This are numerous password databases floating around out there.
2. The frequency of these security breaches (recall that some other companies' breach can harm Logos users too) mean that it is now something not very rare, but increasingly more probable.
3. We are having a COVID year... This may not directly related to Logos users. But the rise of work-from-home has attracted a lot of hacking activities.
4. While it seems like we are not attractive targets (hacking our account to do what here?), some hacking activities are based on pure hatred and nothing can create more hate than religion, so may be we're not that small of a target after all.