The Internet is a place full of unique nooks and crannies, where you could make a new friend at every corner! Sadly, though, there's always risks at those junctions as well.
Even if not for anything but peace of mind, I think it might be beneficial to add some optional account security settings to the site.
These could include:
- Requiring someone to re-sign in when on a different device
- Requiring someone to re-sign in when at a [drastically] different location
- Enabling 2FA (email or app)
- Generating security questions
- Offering a choice of whether the user would have to sign in every time regardless of previous options
- "Whitelist" and "blacklist" certain IPs (default login we have now/always go through security process)
- etc. etc. might add more
...of course, some people would prefer not to have all those enabled, so having it be an opt-out function would probably be for the best.