I really hope other services start offering it as a feature. Namecheap, I'm looking at you. DNS web apps are a huge possible attack vector. Also, RE the Google one time use passwords for POP/IMAP. They are all lower case, alpha/numeric, and 8 chars long. How secure are they against brute force? Why wouldn't Google offer 16 char options, or even longer? Is 8 good enough?
The least they could do if offer IP whitelisting like Linode does.