So.. there's a desire at UM to allow users to opt in to 2FA.. allowing
users to chose to require 2FA for services that don't require it

I'm trying to figure out if cosign could support this, and what would
have to change to allow it.  Seems like there'd need to be..
- some sort of preference store
- an interface to actually opt-in / opt-out
- if the preference were based on cosign service name, we'd need to
associate some user friendly service identifier

Ideas?  Suggestions?


