1) FTX *requires* 2FA in order to deposit. Why?
Well, it turns out that LOTs of people's usernames and passwords are basically public. If 10 years ago you signed up for some random website and it got hacked, your UN/PWD are probably for sale right now.
haveibeenpwned.com
Conversation
2) Everyone says they'll use a new password every time. But unless you use a password manager you probably don't--you'd forget them all! So instead people re-use credentials.
