With all the theft threads lately, and ePassporte being unwilling to refund any stolen funds, I must say I'm more than a little disturbed.
I've seen other people make security suggestions, but haven't seen anyone post the most simple:
Allow us to limit account access to individual IPs. A stolen password would be useless unless they were also sitting in front of my personal computer.
If the IP changes, have a support system in place we can use to update the IP, a security question or such.
