I don't consider getting access to a website via the most insecure blogging platform on the internet "hacking".
Not sure why you say that. WordPress.com offers 2-Factor Auth: http://en.support.wordpress.com/security/two-step-authentica... There are also tons of available security plugins & pretty extensive documentation on hardening a self-hosted install: http://wordpress.org/plugins/tags/security http://codex.wordpress.org/Hardening_WordPress
Having 2-Factor auth is meaningless if you can bypass the auth itself.