I still find the claim Someone can misuse card details to be a very alarmist sentence. Card details are not stored on the platform in any way. Nobody could log in, and get your details to use elsewhere or on another account for example.
Feel free to request new features in our feedback area. We have no problem with that, and encourage as much. This is however, not a security flaw in our platform. Its actually a security flaw elsewhere (they got the passwords from somewhere), and flaw in that the users themselves are using the same user/pass combinations.
I'm incredibly confused by your statement on 2FA. If you set up google authenticator for example, yes it requires the user to participate. However it also requires a user to participate to verify using email. You can enforce users to set this up. In the case of old users who have not logged in, you could also enforce password changes for those user, which will send an email to enforce a password change, invalidating all passwords for those users. The tools are indeed there to do this. I understand they aren't the tools you personally would like, however they are present for you to use.
We fully understand you would like to see changes on that. We love the thoughts our users come up with at times. Nobody at all has dismissed your suggestion. What is not going to happen though, is even if we decide to add something of this nature, we are not going to add a new method of logging into the software overnight. I'm sure you can appreciate very quickly making large changes in account security is what causes security issues in the first place?