Hello, Would there be any interest in implementing a 2FA solution for the dcrwallet/paymetheus/decredtion wallets? Main defense would be against an attacker that can steal your wallet files and possibly your password (through a virus) but not your physical 2FA. Some alternatives for implementing 2FA would be: 1- Software TOTP (Google Authenticator on Phone) 2- U2F keys (yubikeys) 3- PKCS#11 tokens & smartcarts 4- Hardware TOTP The main use for this feature would be on your hot, non-voting wallet. Every operation on the wallet would require both the password (see concerns on the other security thread https://forum.decred.org/threads/security-concerns-that-need-somewhat-urgent-attention.5219/) and the 2FA token to proceed. This would probably (haven't checked the dcrwallet source yet to confirm) involve a significant change on the wallets software to make sure that stealing the combination of wallet file + password cannot compromise the original wallet seed. Either decoding the wallet's private key or the private key itself would need to be somehow related to the 2FA device. I'm writing this to get a feel for whether this would be a feature the decred community would be interested in and if developed would accept patches for, before possibly starting to develop it myself.