When will On Demand support two factor authentication? Simple login/password security on world-accessible web sites just doesn't cut it these days.
There is a non-proprietary, open standard for two-factor authentication. It's called RFC 4226. This is the same standard that Google uses for Gmail and that is implemented by the Google Authenticator smartphone app and others.
The algorithm, based on SHA-1, is easy to implement, and key management and distribution is easy as well.
Atlassian needs to get on the bandwagon before something really damaging and embarassing happens.