On Password reuse - Implementing a one factor, password based auth puts the accounts security in the users hands. There are lots of email, password lists from hacked web services (Linkedin,Yahoo Voices, Gawker, etc.) in the wild and users all too commonly reuse their weak passwords across multiple services.
If a user couldn’t figure out how to set up Firefox Sync previously by following the instructions and taking a set of digits from one device and entering them into another, what hope have they of picking a strong and unique password?