1) FTX *requires* 2FA in order to deposit. Why?
Well, it turns out that LOTs of people's usernames and passwords are basically public. If 10 years ago you signed up for some random website and it got hacked, your UN/PWD are probably for sale right now.
haveibeenpwned.com
Conversation
a) USE 2FA. This is the single most important thing. The key thing about 2FA is that it changes every 30s, so 10 year old 2FA strings don't do anything. Alternately use physical 2FA devices.
