I think 2FA merits being in core, but I'd speak up for letting site owners configure whether it's required.
Could this be included in 1.8 as well since this increases security a lot for user accounts
