I was wondering how much additional security this could give AEM if it 
supported adding Fido U2F as 2FA. it wouldn't require external services like 
TOTP and other variations. Additionally it would dramatically slow down an 
offline attack and greatly increase the cost to do it.

What do you think?

