It's fine for people who actually REMEMBER their password, and don't change phone numbers. Which lots (and lots and lots) of people fail to do.At this point, it should be on by default, with a slew of warnings and "are you sure?" click boxes before disabling.
I have it on too... but it's not for everyone.