Earlier quoted context omitted.
Yes. Password leaks, bruteforcing, and some "rubber hose" attacks can be mitigated by 2FA.
Password leaks are server-side. If they don't know how to properly hash passwords, how you can trust them to implement correctly 2FA? Bruteforcing is not realistic with even medium password strength. If by "rubber hose", you mean physically coercion, what would forbid the attackers to coerce you for your email or your phone as well? I think that the main reason 2FA has been pushed, it's for the Facebooks or the Googl…
Yes. Google and Facebook aren't the only ones.
> I think that the main reason 2FA has been pushed, it's for the Facebooks or the Google to have good reasons to get your valid email and your valid phone number.
You don't need a valid phone number to implement 2 factor authentication. There are implementations that require it, sure. But it's not the only way.